If you have been following CMMC news this summer, you have probably seen a version of the headline that says CMMC is dead. It is not. On July 13, 2026, the Department of War suspended Level 2 certification of the Cybersecurity Maturity Model Certification program, which had been scheduled to take effect on November 10, 2026. That is a real change and it matters. However, the requirements associated with the Level 2 certification changed far less than most contractors think.

What is important to understand regarding the ‘change’ is that the Department of War (DoW) suspended (pending a review) the control compliance verification mechanism that was a requirement. It The proposed review period by the DoW did not however, suspend the security requirement that Defense Industrial Base (DIB) contractors need to comply with. If a DIB contractor handles Controlled Unclassified Information (CUI) for a DoW agency or customer, the contractor is still obligated to meet the same CMMC requirements, as was in place on July 12th, 2026. 

This post explains what was suspended, what is still fully enforced, what happens next, and how to decide what to pause and what to keep funding within a DIB contractor’s organization. Plain language, no hedging. 

What Was Suspended, and What Was Not 

Two memorandums came out of the DoW on July 13th, 2026. One, from the Department’s OCIO, order the suspension of the CMMC certification (Level 2) process, and subsequently creating a CMMC Reform Task Force. The second gave contracting officers instructions on how to handle solicitations and contracts already in flight. 
  •  Suspended 
  • Level 2 third-party certification. The requirement to obtain a CMMC Level 2* certification from an accredited C3PAO as a condition of contract award is paused. 
  • Level 3 assessments. DIBCAC-led Level 3 assessment requirements are paused as well. 
  • Level 3 and 4. The suspension is broader than the headlines suggested. All pending and future CMMC implementation milestones are frozen until further notice, not just the November date. 
  • Active solicitations. Contracting officers were directed to amend solicitations carrying Level 2 C3PAO or Level 3 requirements to remove those designations as soon as possible. 
  • Existing contracts. Modifications removing suspended requirements are to be issued before the next option period or the next scheduled administrative modification. 

Still Fully Enforced 

This is the part the headlines buried. 
  • CMMC Phase 1. Level 1 and Level 2 self-assessments are untouched. New solicitations can still designate Level 1 (Self) or Level 2 (Self).
  • NIST SP 800-171 Revision 2. All 110 controls still apply. Note that Level 2 maps to Revision 2, not Revision 3, under the controlling rule.
  • DFARS 252.204-7012. The safeguarding and cyber incident reporting clause is intact, including the 72-hour incident reporting obligation.
  • SPRS scores and annual affirmations. You still post your score. A senior official still signs the affirmation. Both remain conditions of award eligibility.
  • DFARS 252.204-7025 and 252.204-7021. The solicitation provision that puts you a contractor on notice of the required CMMC level, and the contract clause that governs compliance during performance, both still exist. Read your the solicitation rather than assuming.
  • False Claims Act exposure. The Department of Justice (DOJ) Civil Cyber-Fraud Initiative did not pause. More on this below, because as it still poses as is the real risk right nowat the moment.
  • 32 CFR Part 170. The CMMC program rule was not repealed. This was a policy memo, not a rulemaking memo, and a memo can be reversed as quickly as it was issued.