Fortinetics
← Insights · CMMC · · 10 min read

CMMC Phase 2 is suspended: what the July 13 memos actually say — and what still binds you

On July 13, 2026 the Department of War CIO suspended the November 2026 CMMC Phase 2 transition and held all pending CMMC milestones in abeyance. Program managers may no longer designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments, active solicitations must be amended to strip them, and no waivers will be granted during a 60-day review. What did not change: DFARS 252.204-7012 is still in effect and NIST SP 800-171 Rev 2 compliance is still enforced through self-assessment. A primary-source read of both memos.

July 13, 2026. The Department of War CIO suspended the November 2026 CMMC Phase 2 transition and held all pending and future CMMC implementation milestones in abeyance until further notice. Program managers may no longer designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments; active solicitations carrying those requirements must be amended to remove them; and no waivers will be granted during a 60-day review by a new CMMC Reform Task Force. What did not change: DFARS 252.204-7012 is still in effect, and NIST SP 800-171 Rev 2 compliance is still enforced through self-assessment. This is a read of both signed memos.

For two years the single most important date in defense cybersecurity was November 10, 2026 — the day CMMC Phase 2 would make C3PAO-assessed Level 2 certification the default for contracts involving CUI. We have written about that date repeatedly, and so has everyone else in this field. It is now suspended.

Two memoranda dated July 13, 2026 and cleared for open publication under case 26-P-1023 did it:

  • “Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of Cybersecurity Maturity Model Certification Requirements” — signed by Kirsten A. Davies, Department of War Chief Information Officer.
  • “Implementing Department of War Chief Information Officer’s Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements” — signed by Michael P. Duffey, Under Secretary of War for Acquisition and Sustainment, with an Attachment 1 setting out the procedures.

The most consequential thing about this announcement is the part that will get lost in the noise: the certification mechanism paused, but the security obligations did not. A contractor who reads “CMMC suspended” as “stand down” is walking into the exposure that was always the real one.

What is actually suspended

The CIO memo is direct about scope:

“The upcoming November 2026 deadline to transition to Phase 2 of CMMC implementation is suspended. Additionally, all pending and future CMMC implementation milestones across DoW solicitations and contracts are held in abeyance until further notice.”

The implementing procedures translate that into four operative changes:

1. No third-party or government CMMC assessment designations. Program managers “may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self).” Level 2 (Self) is aligned to NIST SP 800-171 Rev 2; Level 1 (Self) remains the FAR 52.204-21 basic safeguarding self-assessment for FCI.

2. Existing requirements come back out. If a requirements package already included Level 2 (C3PAO) or Level 3 (DIBCAC), program managers “must initiate amendments to active solicitations” that explicitly remove those requirements, and the contracting officer “must issue a corresponding solicitation amendment as soon as practicable.” For contracts already carrying the requirement, contracting officers are “directed to remove them via modification prior to the exercise of the next option period or during the next scheduled administrative modification.”

3. No waivers. “Due to suspension of the CMMC Phase II implementation… no waivers shall be granted during the review of the program.”

4. A 60-day review with a stated direction. A CMMC Reform Task Force is “to be immediately established to conduct a top-to-bottom 60-day review of the certification program,” charged with recommending a framework that “replaces prohibitive, third-party compliance models with scalable, realistic security measures.”

Both memos state the directive is effective immediately.

What still binds you — read this part twice

This is where the practitioner value is, because the memos are unambiguous and the market summary will not be. From the CIO memo’s Interim Cyber Posture:

“During this suspension, the Department will continue enforcing baseline compliance with NIST SP 800-171 Rev 2 through DIB self-assessments and select government-led assessments… The cybersecurity requirements outlined in DFARS clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting are still in effect.”

And, on the scope of the suspension itself: “All other contractual cybersecurity clauses in contracts remain intact.”

Concretely, none of the following moved:

  • DFARS 252.204-7012 — the safeguarding requirement and the 72-hour cyber incident reporting obligation to DC3. Still in force, explicitly. Our 7012 reporting-gap piece is unaffected by this announcement.
  • NIST SP 800-171 Rev 2 — still the baseline. The delivery mechanism is self-assessment rather than a C3PAO, but the 110 requirements are the same 110 requirements.
  • DFARS 252.204-7019 and -7020 — your SPRS score obligations and the DoD Assessment Methodology. These are separate clauses from CMMC and are not touched by a CMMC suspension. Note also that the interim posture retains “select government-led assessments” — this is not a blanket end to the government showing up.
  • False Claims Act exposure. This is the one that should hold your attention. FCA liability attaches to the SPRS score you affirmed, not to a CMMC certificate. No breach is required and no assessor needs to visit. A score that was never supported by an actual implementation was a problem before July 13 and is exactly as much of a problem after it. The DOJ Civil Cyber-Fraud settlements did not pause.
  • Prime flowdown. DoW suspending its own requirement does not rewrite the subcontract you already signed, and it does not stop a prime from requiring whatever assurance it wants from its supply chain. Primes have spent two years building CMMC expectations into supplier programs; some will keep them. See how primes actually evaluate CMMC subs.

The short version: the assessment stopped; the requirements did not.

Why this happened, in the memo’s own words

The stated rationale is industrial-base capacity, not a judgment that the security bar was wrong:

“Recent data and feedback, including reports from the Small Business Administration, highlight that the current CMMC program is structurally incompatible with our need to rapidly expand the DIB. The combination of prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines is actively forcing innovative new entrants and small businesses to opt out of DoW contracts and freezing critical suppliers out of the market.”

That diagnosis will be familiar to anyone who has looked at the arithmetic. Roughly 100 authorized C3PAOs against a population in the tens of thousands of organizations needing Level 2 was never going to clear by November 2026, and the assessor bottleneck has been the visible constraint for two years. The memo frames the suspension as alignment with the Secretary of War’s Acquisition Transformation System and Executive Order 14265, and closes with the thesis: “We will not defeat our adversaries with compliance checklists; we will defeat them by rapidly fielding superior capabilities produced by an expanded, resilient American industrial base.”

Whatever you make of that framing, the operative facts are the four changes above.

What to do now

  1. Do not dismantle your 800-171 program. This is the mistake that will be expensive. The requirements are explicitly still enforced, the SPRS score still carries FCA exposure, and the review is chartered to produce a reformed framework rather than nothing. A program paused at 40% implementation is a program that gets caught by whatever replaces this.
  2. Do not assume a clause is gone until you see the modification. The direction to strip C3PAO and DIBCAC requirements runs to program managers and contracting officers. Until an amendment or modification actually issues against your solicitation or contract, the document you signed is the document you are held to. Track it; do not infer it.
  3. Re-check your SPRS score honestly. With third-party assessment off the table, the self-attested score is once again the government’s primary window into your posture — and the one with False Claims Act consequences attached. If your score was aspirational on the theory that a C3PAO would eventually force the work, that theory just expired in the wrong direction.
  4. Reprice, don’t cancel, a booked C3PAO engagement. Program managers cannot designate a C3PAO assessment during the suspension, so a certification event has no contractual demand behind it right now. That is a scheduling decision. The readiness work underneath it still has a buyer: your prime, your next option exercise, and whatever the Task Force recommends.
  5. Consider responding to the RFI. The Department opened “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB)” with responses due August 14, 2026 at 12:00 PM Eastern. If your organization has direct evidence about assessment cost, capacity, or timeline burden, this is the open window to put it on the record.
  6. Put mid-September on the calendar. A 60-day clock from July 13 lands around mid-September 2026 for the Task Force’s recommendations, and both memos promise further guidance at its conclusion. Plan to re-plan then.

The honest read

We have told clients for two years that CMMC certification was a deadline problem and that the security architecture underneath it was the durable part. That framing just got tested, and it held. Every organization that treated CMMC as an architecture program — build the enclave, implement the controls, generate evidence as a byproduct — is fine today and will be fine under whatever the Task Force recommends. Every organization that treated it as a certificate to acquire before a date is now discovering it optimized for a date that moved.

The suspension is real relief on cost and schedule, and for small suppliers being squeezed out by assessor capacity it is meaningful. It is not relief from safeguarding CUI, from reporting an incident within 72 hours, or from the accuracy of the score you have already affirmed. Those were always the obligations with teeth.

If your CMMC plan just lost its deadline and you are trying to work out what is still load-bearing, that is a short conversation and worth having before the 60-day review lands. Our CMMC and DFARS practice is reading this the same way we read every rule change: what actually binds, what actually moved, and what you would regret unwinding.

Related reading: DFARS 252.204-7012 and the 72-hour reporting gap · CMMC self-assessment vs C3PAO · How primes evaluate CMMC subs · Designing a CUI enclave · CMMC framework overview