«  View All Posts

What Does the CMMC Phase II Suspension Mean for Contractors?

July 29th, 2026 | 5 min. read

By Claudine Santiago

CMMC certification shield illustrating Cybersecurity Maturity Model Compliance for DoD contractors and defense compliance updates.

On July 13, 2026, the Department of War (DoW) announced the suspension of CMMC Phase II certification requirements and Phase III milestones pending a 60-day program review. Although it removes the immediate assessment requirements, it does not remove your obligation to protect controlled unclassified information under DFARS 252.204-7012.

If you work in the Defense Industrial Base, you have likely spent the past year preparing for CMMC Level 2 certification. Then, without warning, the rules changed.

On July 13, 2026, the Department of War announced it was suspending CMMC Phase II requirements before the initial November 10, 2026 deadline. For contractors mid-assessment or mid-remediation, the announcement raises an obvious question: what does this mean for your compliance program?

Intelligent Technical Solutions (ITS) has helped defense contractors navigate cybersecurity compliance for years. We track changes like this closely because a paused certification requirement is not the same as a paused security obligation.

Misrepresenting your cybersecurity posture can put your contracts at risk and may create False Claims Act exposure.

In this article, we'll cover:

What Is CMMC Phase II, and who does it affect?   
What changed with the CMMC Phase II suspension? 
What do defense contractors still need to do? 

What Is CMMC Phase II, and Who Does It Affect?

CMMC Phase II was the second stage of the Department's planned CMMC rollout. It would have required certain Defense Industrial Base contractors and subcontractors to pass a Level 2 assessment by a certified third-party assessment organization, or C3PAO.

The requirement would have applied to certain contracts involving controlled unclassified information, or CUI. Prime contractors would also have needed to pass the right security requirements down to affected subcontractors.

Phase II is now suspended, along with the government-led Level 3 assessments planned for Phase III. However, Phase I self-assessments, SPRS reporting, and existing DFARS obligations remain in effect.

Read: CMMC Certification: Its Process and Timeline Explained

What Changed with the CMMC Phase II Suspension?

The Department of War suspended the CMMC Phase II requirements that were set to begin on November 10, 2026. This means certain third-party and government-led assessment requirements will not take effect as planned.

The suspension affects the following areas:

 

D-Shape Number 1 The C3PAO Certification Step Is Paused

Phase II would have required contractors seeking CMMC Level 2 certification to complete an assessment by a certified third-party assessment organization before qualifying for certain contract awards.

Effective immediately, this C3PAO assessment is no longer required as a condition of award under the suspended CMMC Phase II requirements. Government-led CMMC Level 3 assessments, which were scheduled to begin in November 2027, are also paused.

These changes give affected defense contractors more time to prepare, but they do not remove the need to maintain strong cybersecurity controls or comply with CMMC requirements that remain in effect.

 

D-Shape Number 2 Contracting Officers Must Remove Suspended Requirements

Program managers must identify active solicitations and contracts that include suspended CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) requirements. Contracting officers and agreements officers must remove these requirements through a solicitation amendment or a contract modification.

For existing contracts, the change must occur before the next option period or scheduled administrative modification.

 

D-Shape Number 3 A Reform Task Force Is Reviewing the Program

A CMMC Reform Task Force will review the entire program and deliver recommendations to the Department Chief Information Officer (CIO) within 60 days.

The DoW also released a public Request for Information (RFI) to gather direct feedback from DIB companies on practical strategies to inform the task force. Responses are due by 12 PM ET on Friday, August 14, 2026.

 

Why Did the Department Suspend CMMC Phase II?

Department CIO Kirsten Davies framed the suspension around limited assessor capacity and high compliance costs. Department figures cited more than 100,000 Defense Industrial Base companies requiring third-party assessments, compared with roughly 100 available assessors.

Davies also projected that compliance under the current model would cost small and midsize businesses more than $7 billion each year.

These challenges were creating barriers for small and innovative companies in the DIB. The suspension gives the Department time to review the certification program, consider ways to reduce compliance burdens, and decide how CMMC implementation should move forward.

 


What Still Applies to Defense Contractors?

This is the part of the announcement most likely to be misread. Although the suspension removed a verification mechanism, it did not remove a security obligation.

In their July 13, 2026, release, the DoW said:

"It is critical to note that this action does not eliminate the requirement for companies to protect federal data. All defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012."

Requirement

Status

DFARS 252.204-7012 obligations

Remains in effect

NIST SP 800-171 Rev. 2 implementation (all 110 security requirements)

Remains in effect

CMMC Phase I self-assessment

Remains in effect

SPRS scoring and annual affirmation

Remains in effect

C3PAO Phase II certification

Suspended

Government-led Level 3 assessment

Suspended


False Claims Act exposure remains even while CMMC Phase II certification is paused. This means federal agencies may continue pursuing contractors that knowingly misrepresent their cybersecurity posture.

An inflated SPRS score can create enforcement risk even when no third-party assessment was scheduled.

 

 

What Should Defense Contractors Do Now?

Defense contractors should continue their compliance work, review affected contracts, verify their SPRS scores, and adjust assessment plans based on their current CMMC posture. ITS recommends the following actions:

Your Current Position

Recommended Action

Level 2 certified or assessment complete

Maintain your security environment and continue annual SPRS affirmations. Your certification can help demonstrate your implementation of NIST SP 800-171 requirements.

C3PAO engaged or assessment scheduled

Consider pausing the assessment instead of ending the relationship. Review your C3PAO agreement and cancellation deadlines before making a decision.

Mid-remediation or building an enclave

Continue the work, but rescope your efforts away from assessment-specific artifacts and toward control implementation and supporting evidence.

Not started or holding a low or negative SPRS score

Validate your SPRS score against your actual controls and address identified gaps. The suspension does not reduce False Claims Act exposure.

Prime contractor with flow-down obligations

Keep subcontractor security requirements and flow-down language in place. Consider maintaining private verification requirements despite changes in federal policy.

Active solicitation or award with Phase II language

Contact your contracting officer and request written confirmation of the amendment or contract modification.

Actions for the Next 30 Days

ITS recommends taking these steps over the next 30 days to manage compliance risk and prepare for future CMMC changes:

  • Review contracts and solicitations: Identify active agreements containing CMMC clauses that may require an amendment or modification.
  • Validate your SPRS score: Confirm that your reported score matches your actual control implementation and address any gaps.
  • Prioritize remediation spending: Pause unnecessary assessment preparation, but continue funding control implementation, remediation, and evidence development.
  • Maintain flow-down requirements: Prime contractors should keep applicable cybersecurity requirements in place for subcontractors that handle sensitive defense information.
  • Prepare to provide feedback: Respond to the Department's Request for Information, with comments due by 12 PM ET on August 14, 2026.

These 30-day actions help you maintain compliance momentum while the review is underway. By focusing on verified gaps, accurate reporting, and contract-specific responsibilities, you can reduce near-term risk without overinvesting in requirements that may change.

Stay Ahead of Your CMMC and DFARS Obligations

The CMMC Phase II suspension changes how cybersecurity compliance is verified, but it does not eliminate contractors' existing obligations to protect federal data. Organizations that continue strengthening their NIST SP 800-171 controls, documentation, and monitoring will be better positioned to adapt when the Reform Task Force completes its review.

ITS has helped Defense Industrial Base clients build and maintain compliant, audit-ready security programs. Our team can help you validate your SPRS score, close control gaps, and keep your contracts defensible while the program is under review.

Schedule a meeting with an ITS expert to review where your DFARS and NIST SP 800-171 compliance stands today and what to prioritize while CMMC Phase II is on hold.

Our team includes CMMC compliance experts, including Sean Harris, CISM, CCP, ITS Chief Risk and Compliance Officer, who can help you build a plan that positions you to adapt as the program changes.

Want to Learn More?

Check out these resources in our Learning Center:

 

Frequently Asked Questions

Q: Is CMMC Phase II canceled?

A: No. Phase II is suspended while the Department completes a 60-day review, and Phase I self-assessments remain in place.

Q: Do I still need to comply with DFARS 252.204-7012?

A: Yes, if the clause applies to your contract or subcontract. You must still protect covered defense information and meet NIST SP 800-171 requirements.

Q: Should I cancel my scheduled C3PAO assessment?

A: Do not cancel it right away. Review your contract requirements, C3PAO agreement, and cancellation deadlines before making a final decision.

Q: What should I do if my SPRS score does not match my actual controls?

A: Recalculate your SPRS score and correct any inaccurate submission. If your controls fall short, document and fix the gaps as soon as possible.

Q: What should I do if my active contract still has Phase II language?

A: Contact your contracting officer and ask how the suspension applies to your contract. Get written confirmation before assuming any contract requirement has changed.

Claudine Santiago

Claudine has 5+ years of experience in SEO and content writing, with expertise in technical and B2B content. She expresses herself through fashion and maintains balance through an active lifestyle at the gym. With a background in Psychology, Claudine is naturally curious about people and their stories. She channels this curiosity into crafting narratives that connect brands with audiences. Her passions and profession align, fueling her drive to create with imagination, curiosity, and heart.