Published July 14, 2026

On July 13, the Department of War announced the suspension of CMMC Phase 2, the third party assessment requirement originally set to take effect November 10, 2026. Phase 1 self-assessment and Level 2 self-assessment obligations remain fully in force and are unaffected by this action.

We want to be direct about the most important point first.

Your DFARS 252.204.7012 Obligation Has Not Changed

Your obligation to protect Controlled Unclassified Information under DFARS 252.204.7012 has not changed, and this suspension does not affect it. This clause exists independent of CMMC entirely. It was in effect before CMMC was created, it remains in effect now, and it is not something the Department has suspended, paused, or reviewed as part of this action. If your contracts include this clause, and most CUI handling contracts do, you are still contractually obligated to implement the security requirements of NIST SP 800.171 Revision 2, maintain your System Security Plan, and report cyber incidents according to the timelines that clause requires. CMMC was built as a verification layer on top of this existing obligation. Removing or delaying the verification layer does not remove the obligation underneath it.

With that as the foundation, here is our broader read on what this suspension does and does not mean.

This is a pause, not a repeal. 

CMMC’s underlying legal basis remains in effect. The regulation that created the program, 32 CFR Part 170, has not been changed or removed.

Fully repealing CMMC would require a formal notice and comment rulemaking process, which has not occurred and typically takes months to complete once started. A memo alone cannot accomplish what only that process can.

The Department’s memo pauses pending and future CMMC milestones “until further notice,” with no set date for when the pause ends. A CMMC Reform Task Force has 60 days to deliver recommendations, but that deadline applies only to when recommendations are due, not to when the pause itself resolves. We would not assume a fixed timeline for what comes next.

Certification investment made now is not at risk. 

Organizations that complete Level 2 certification during this review period retain that certification and the market position it provides, particularly given the assessor capacity constraints the Department cited publicly, with well over 100,000 businesses needing third party assessment against a fraction of that number of available assessors nationally.

Our Recommendation: Continue on your current compliance timeline. Whatever emerges from this review, a revised framework, a delayed Phase 2, or something restructured, being assessment ready positions your organization ahead of the field rather than behind it. Pausing active work risks losing ground on a readiness timeline that typically runs 12 to 18 months, particularly if requirements return with a shorter runway than the original schedule provided.

We would also note a risk we think is important to flag plainly. Treating this suspension as a reason to delay work required under DFARS 252.204.7012, whether that work is CMMC specific or not, carries real exposure, particularly for organizations that continue representing themselves as compliant without maintaining the underlying practices required to support that representation.

This post reflects our assessment of the current regulatory landscape and is not legal advice. Any decision regarding an active engagement, contract, or compliance timeline in response to this announcement should be made in consultation with your organization’s legal counsel.

We are monitoring this announcement and the Reform Task Force closely and will share updates as they become available.

Have specific questions about how this affects your certification timeline or contracts? Bring them to CMMC Connect, our monthly session where we work through real questions live. 

FAQs:
Is CMMC Phase 2 cancelled?

No. CMMC Phase 2 is suspended, not cancelled. On July 13, 2026, the Department of War held all pending and future CMMC implementation milestones in abeyance “until further notice.” Fully rescinding CMMC would require formal notice and comment rulemaking, which has not occurred.

What should you do during the 60 day review?

Keep building toward NIST SP 800.171 readiness. Nothing about this suspension changes your contractual obligation to protect CUI. Organizations that stay on their current compliance timeline will be positioned ahead of the field regardless of what the task force recommends.

Don’t cancel or pause active certification work over this news alone. Certification investment made now is not at risk, and pausing risks losing ground on a readiness runway that typically takes 12 to 18 months, particularly if requirements return with less lead time than originally planned.

Why did the Department suspend CMMC Phase 2?

The Department cited an SBA study finding that over 100,000 businesses needed a third-party assessment, with only around 100 certified assessors available to conduct them. Officials also cited compliance costs pushing small and non-traditional businesses out of the defense industrial base.

If I already completed CMMC Level 2 certification, does it still count?

Yes. Certification completed before or during this suspension is retained, along with the market position and contract eligibility it provides.

Is this suspension the same as previous CMMC delays?

CMMC has been revised before, including the shift from the original 2020 interim rule to CMMC 2.0 in 2021. This suspension differs in that it uses existing regulatory discretion under 32 CFR Part 170 rather than a rulemaking process, and it affects an already-published final rule rather than a proposed one.

 

Want updates as this review develops?