I’ve had the same conversation four times this month with a few of our clients. A senior executive from a client called me up recently, relieved, and sayings, “So we’re off the hook on CMMC, right? I saw it got suspended.” In actuality, that is not what happened, and that gap in understanding is exactly where contractors get hurt.

Here is the simple version: On July 13, DoD suspended the third-party assessment requirement that was supposed to start for CMMC Phase 2 on November 10. DoD however, did not suspend the requirements related to CMMC certification. It paused one specific, expensive piece of it: mandatory C3PAO certification of your cybersecurity program.

DoD’s CIO, Kirsten Davies, explained the reasoning plainly: “The math just simply doesn’t math for small to medium-sized businesses to even get compliant by the transition date.” The numbers behind that statement are real: industry estimates put small and mid-sized contractors’ compliance cost above $7 billion a year, against roughly 100 accredited C3PAO assessors trying to certify a defense industrial base of more than 100,000 companies. 

DoD then initiated a 60-day review period and stood up a CMMC Reform Task Force, which took in over 1,100 public comments. That review closed September 11. As of this week, the findings haven’t been made public; they will go first to Davies, and whether or when she releases them is still an open question. Nobody at KSG has seen a leaked version, and I’d be skeptical of anyone who claims they have.

The part that actually changed the game

The July suspension was a pause, and as we all have experienced in the past that sometime ‘pauses’ get reversed. To bolster our assumption, something interesting happened on September 3rd. John Tenaglia, DoD’s principal director for defense pricing, contracting and acquisition policy, issued a class deviation, its third revision, ordering third-party CMMC requirements stripped from contracts, citing the Revolutionary FAR Overhaul rather than the November 2025 final CMMC rule.

That’s harder to walk back than a memo. A suspension is one official’s call, reversible by another memo. A binding class deviation baked into acquisition regulation takes a rulemaking process to undo. If Phase 2 returns, it likely comes back through a new rule, not a reversal of this one. The requirement is paused, but the mechanism that paused it just got a lot more permanent, and that’s the real story behind every headline that says CMMC Phase 2 has been suspended.

Is CMMC still required? Yes.

Nothing about Phase 1 changed. If you handle Controlled Unclassified Information (CUI), you still self-assess against the 110 controls in NIST SP 800-171, submit your score to SPRS, and hold to your contract’s POA&M timeline. DFARS 252.204-7012 is still in force.

At this point, I would like to point the reader’s attention to a company named LOGZONE, and recent events impacting LOGZINE as a cautionary tale for others. LOGZONE Inc., a Huntsville, Alabama contractor on two Navy contracts, carried a self-assessment score of negative 170 out of a possible 110 for nearly four years, all while continuing to bill against contracts that required NIST 800-171 compliance. In June, the Department of Justice settled a False Claims Act case against them for $507,144. Notice what didn’t happen: nobody accused LOGZONE of faking a good score. Their reported score reflected real, sustained gaps. The liability came from billing as compliant anyway, a distinction that should worry more companies than it does.

What the Task Force report probably does

I don’t know what’s currently in the report under review at the Pentagon, and neither does anyone outside a small circle there. But four outcomes have circulated in industry analysis for weeks: the program resumes on a new schedule; certification narrows to fewer, higher-dollar contracts while everyone else self-assesses; the center of gravity shifts to self-assessment paired with a senior executive’s personal attestation; or DoD reworks the maturity model outright, which would surprise me this late.

My own read is that the narrowed-scope outcome is most likely, since it lets DoD solve the assessor bottleneck without abandoning third-party verification on the contracts carrying the most sensitive CUI. I’ve been wrong about CMMC’s next move before, though, and so has everyone else tracking this since 2020.

What I’d actually do this week

Whatever the Task Force decides, it doesn’t touch your Phase 1 obligations or your False Claims Act exposure on a score that doesn’t match reality. That risk is yours to manage now, not once a new rule is finally published.

If it’s been a while since anyone independently checked your SPRS score against actual evidence, that’s the highest-value hour you can spend this week. We built a free SPRS self-assessment calculator directly into our CMMC practice page, because too many companies are more likely in the same lane as, LOGZONE was, carrying an SPRS score that no one had stress-tested. So, run our score calculator from our CMMC practice page, or talk to us directly, before you learn the hard way which score is factually true.

We’ll have more to say once the Task Force findings surface. Until then, the safest approach to managing your CMMC compliance requirements would be to take necessary steps to improve your SPRS score The only change that really holds water is that an expensive gate got paused, and the gate behind it, which requires an organization to is continue self-assessing to meet CMMC requirements is still very much open.