Published July 14, 2026
On July 13, the Department of War announced the suspension of CMMC Phase 2, the third party assessment requirement originally set to take effect November 10, 2026. Phase 1 self-assessment and Level 2 self-assessment obligations remain fully in force and are unaffected by this action.
We want to be direct about the most important point first.
Your DFARS 252.204.7012 Obligation Has Not Changed
Your obligation to protect Controlled Unclassified Information under DFARS 252.204.7012 has not changed, and this suspension does not affect it. This clause exists independent of CMMC entirely. It was in effect before CMMC was created, it remains in effect now, and it is not something the Department has suspended, paused, or reviewed as part of this action. If your contracts include this clause, and most CUI handling contracts do, you are still contractually obligated to implement the security requirements of NIST SP 800.171 Revision 2, maintain your System Security Plan, and report cyber incidents according to the timelines that clause requires. CMMC was built as a verification layer on top of this existing obligation. Removing or delaying the verification layer does not remove the obligation underneath it.
With that as the foundation, here is our broader read on what this suspension does and does not mean.
This is a pause, not a repeal.
CMMC’s underlying legal basis remains in effect. The regulation that created the program, 32 CFR Part 170, has not been changed or removed.
Fully repealing CMMC would require a formal notice and comment rulemaking process, which has not occurred and typically takes months to complete once started. A memo alone cannot accomplish what only that process can.
The Department’s memo pauses pending and future CMMC milestones “until further notice,” with no set date for when the pause ends. A CMMC Reform Task Force has 60 days to deliver recommendations, but that deadline applies only to when recommendations are due, not to when the pause itself resolves. We would not assume a fixed timeline for what comes next.
Certification investment made now is not at risk.
Organizations that complete Level 2 certification during this review period retain that certification and the market position it provides, particularly given the assessor capacity constraints the Department cited publicly, with well over 100,000 businesses needing third party assessment against a fraction of that number of available assessors nationally.
Our Recommendation: Continue on your current compliance timeline. Whatever emerges from this review, a revised framework, a delayed Phase 2, or something restructured, being assessment ready positions your organization ahead of the field rather than behind it. Pausing active work risks losing ground on a readiness timeline that typically runs 12 to 18 months, particularly if requirements return with a shorter runway than the original schedule provided.
We would also note a risk we think is important to flag plainly. Treating this suspension as a reason to delay work required under DFARS 252.204.7012, whether that work is CMMC specific or not, carries real exposure, particularly for organizations that continue representing themselves as compliant without maintaining the underlying practices required to support that representation.
This post reflects our assessment of the current regulatory landscape and is not legal advice. Any decision regarding an active engagement, contract, or compliance timeline in response to this announcement should be made in consultation with your organization’s legal counsel.
We are monitoring this announcement and the Reform Task Force closely and will share updates as they become available.
Have specific questions about how this affects your certification timeline or contracts? Bring them to CMMC Connect, our monthly session where we work through real questions live.



