Risk & Compliance

CMMC Phase II Is Paused. Phase I Is Not.

CMMC Phase II Is Paused. Phase I Is Not.
12:47

On July 13, 2026, the Department of Defense suspended CMMC Phase II requirements and launched a 60-day reform review. Phase I self-assessments remain mandatory and fully enforceable. Defense contractors must continue implementing NIST SP 800-171 Revision 2 and maintaining accurate scores in the Supplier Performance Risk System (SPRS) or risk losing contract eligibility.

On July 13, 2026, the Department of Defense (DoD) suspended CMMC Phase II requirements. The announcement cited prohibitive compliance costs and bureaucratic burdens, particularly for small and midsize businesses across the Defense Industrial Base (DIB). The Small Business Administration estimated that future CMMC phases could cost small and midsize businesses more than $7 billion annually. With more than 100,000 companies needing assessments and roughly 100 authorized third-party assessment organizations (C3PAOs) in place, the scale of the problem was undeniable.

The suspension removed the requirement for C3PAO certification at CMMC Level 2. It also froze Phases 3 and 4 and all future implementation milestones until further notice.

What it did not do is eliminate your compliance obligations.

Phase I self-assessment requirements remain fully enforceable. DFARS clause 252.204-7012 continues to bind every defense contractor handling covered defense information. If your contract includes CMMC clauses today, those clauses are still your contract.

What the Suspension Actually Changed

The suspension was issued via two policy memoranda, not a formal rule change. The CMMC program rule and DFARS 252.204-7021 remain intact. No Federal Register document was issued. Title 32 CFR Part 170 is unamended.

Here's what changed operationally:

    • Program managers may now designate only CMMC Level 1 (Self) or Level 2 (Self).
    • Level 2 (C3PAO) and Level 3 (DIBCAC) designations are suspended.
    • Active solicitations requiring higher designations must be amended as soon as practicable.

Here's what did not change:

    • DFARS 252.204-7019 still conditions contract award on a current assessment score in SPRS.
    • DFARS 252.204-7012 still requires 72-hour incident reporting to DIBNet and full flowdown to subcontractors.
    • Government-led assessments continue. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) retains full authority to conduct select assessments.

The compliance burden shifted. The legal risk did not.

Phase I Requirements: What You Must Do Right Now

Phase I took effect on Nov. 10, 2025. It applies to every defense contractor and subcontractor handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).

Level 1 (FCI): Annual self-assessment against 15 security requirements under FAR clause 52.204-21. No Plans of Action and Milestones (POA&Ms) permitted. Results must be entered into SPRS with an annual affirmation.

Level 2 (CUI): Self-assessment every three years against all 110 security requirements in NIST SP 800-171 Revision 2, under DFARS clause 252.204-7012. Annual affirmations required. POA&Ms permitted under defined conditions but must be closed within 180 days.

Both levels require a named senior Affirming Official to sign off on results entered into SPRS. That signature is a legal certification.

Critically, the DoD confirmed it will enforce NIST SP 800-171 Revision 2 as the interim baseline, not Revision 3. That distinction matters for budgeting and planning.

Self-Attestation Now Carries Greater Legal Risk

Removing the third-party assessor doesn't reduce your liability. It increases it.

Under the C3PAO model, a third party validated your compliance posture. Under self-attestation, your leadership's signature carries that weight. The Department of Justice's Civil Cyber-Fraud Initiative, launched in October 2021, specifically targets false cybersecurity certifications by federal contractors. The exposure includes treble damages under the False Claims Act.

Two additional risks compound this:

First, many contractors already created a documented paper trail by initiating C3PAO assessments. Gap assessments filed before the suspension recorded deficiencies in writing. Those records survive the suspension and are accessible to government auditors.

Second, subcontractors face a layered risk. The suspension binds DoD personnel, not prime contractors. DFARS 252.204-7021(f) requires primes to flow down the substance of CMMC clauses. A prime managing its own liability may retain higher requirements in subcontract terms. Don't assume relief flows downhill automatically. Confirm any changes to your flowdowns in writing before altering your assessment plans.

The DoD's New Direction: Brilliant at the Basics

Alongside the suspension, the DoD's Chief Information Officer launched the "Brilliant at the Basics" campaign. The campaign defines 10 core IT cybersecurity practices for DIB partners, with an emphasis on small and midsize businesses.

The 10 practices are:

    • Phishing-Resistant Multi-Factor Authentication (MFA): Upgrade away from SMS and push notifications to phishing-resistant methods
    • Comprehensive Asset Inventory Management: Maintain a dynamically updated inventory of hardware, software, identities and data
    • Strategic Technical Debt Reduction: Identify and retire legacy infrastructure, unsupported software and unnecessary interfaces
    • Flexible Technology Stack: Maintain a modular, interoperable architecture using open standards
    • Logical Segmentation: Divide environments into isolated zones to limit lateral movement following a breach
    • Risk-Based Vulnerability Management: Prioritize remediation based on actual exploitability, not generic severity scores
    • Security in the Development Lifecycle: Integrate secure coding and automated scanning early in engineering
    • Secure AI Adoption: Establish technical guardrails to prevent sensitive data from entering public AI systems
    • Resilient Backup and Disaster Recovery: Maintain immutable, logically vaulted backups with tested restoration procedures
    • Continuous Technical Workforce Readiness: Invest in ongoing training across security and technical personnel

These practices align directly with current NIST SP 800-171 Revision 2 requirements. They also signal the direction of any reformed framework. Building toward these outcomes now reduces compliance risk regardless of how Phase II is restructured.

What the CMMC Reform Task Force Is Reviewing

The DoD established a CMMC Reform Task Force reporting to the CIO, with a mandate to complete a comprehensive review within 60 days. A public Request for Information (RFI) closed on Aug. 14, 2026, with five of the seven questions focused on compliance burden and cost.

The task force is expected to recommend streamlined assessment methodologies, updated evidence requirements and revised contractor segmentation. Officials have not ruled out ending the program in its current form.

Two milestone dates matter:

    • Mid-September 2026: Task Force report due to the DoD CIO
    • Watch for: A class deviation, DFARS rule, or amendment to 32 CFR Section 170.3(e) that would constitute an actual legal change

A policy memo suspends discretion. A regulatory change amends the law. Until the latter occurs, the codified framework governs.

How to Prepare Now: A Clear Action Plan

The contractors who use this period to build don't be the ones scrambling when Phase II returns in some form. Here's what to do:

Don't pause compliance efforts. Continue Phase I self-assessments. Maintain your SPRS score. An inflated or inaccurate score is now a litigation risk, not just a business risk.

Preserve your compliance infrastructure. Dismantling a CUI enclave and rebuilding it costs more than maintaining it. Government-led assessments continue. DIBCAC digs deeper than a C3PAO assessment.

Validate SPRS accuracy now. If your current score doesn't reflect your actual security posture, correct it before a government-led assessment surfaces the gap.

Inventory your contracts. Identify every contract and proposal that includes CMMC clauses. Confirm treatment with your contracting officers in writing before changing any assessment plans.

Review compliance vendor and C3PAO agreements. If you have active agreements, review them for termination, deferral and refund rights while you have leverage. That ecosystem is consolidating.

Submit an RFI response if the outcome affects your costs. Small and midsize voices are underrepresented in policy processes. The task force is specifically seeking industry input on compliance burden.

Phase I Compliance Isn't Optional

The Phase II suspension didn't reduce the risk of non-compliance. It redistributed it.

Without a third-party assessor between you and the government, your documentation, your SPRS score and your affirmations carry more weight than they did before. DIBCAC continues to conduct government-led assessments. The False Claims Act continues to apply. Your contracts continue to bind.

Organizations that maintain Phase I compliance and build toward the "Brilliant at the Basics" framework will be better positioned regardless of what the CMMC Reform Task Force recommends. Those who misread the suspension as relief may face a gap they can't close quickly if a reformed Phase II returns with a compressed timeline.

Now is the time to assess your current posture, close open gaps and make your self-attestation defensible.

Frequently Asked Questions

Did the July 2026 suspension eliminate CMMC requirements?
No. The suspension paused Phase II requirements, which included third-party C3PAO certification at CMMC Level 2. Phase I self-assessment requirements remain fully mandatory. DFARS clause 252.204-7012 and NIST SP 800-171 Revision 2 obligations are unchanged.

What happens if my SPRS score is inaccurate after the suspension?
Your SPRS score is a legal certification. An inaccurate score exposes your organization to liability under the False Claims Act and the DOJ's Civil Cyber-Fraud Initiative, which can carry treble damages. Correct any inaccurate scores before a government-led DIBCAC assessment surfaces the discrepancy.

Do subcontractors get the same relief as prime contractors?
Not automatically. The suspension binds DoD personnel, not prime contractors. Many primes will maintain higher CMMC requirements in subcontract flowdowns to manage their own liability. Confirm any changes to your flowdown requirements in writing before adjusting assessment plans.

What is the CMMC Reform Task Force expected to recommend?
The task force is reviewing assessment methodologies, evidence requirements and contractor segmentation. Gartner analysis from July 2026 notes the program has been restructured once before, reducing certification levels from five to three. A streamlined framework with lower compliance overhead for small businesses is the most likely outcome.

Should I continue preparing for CMMC Level 2 certification during the suspension?
Yes. Contractors with completed C3PAO certifications retain that status. DFARS 252.204-7021(d)(1)(i) allows a higher certification level to satisfy any lesser designation during the suspension, which creates a competitive advantage in contract awards and in mergers and acquisitions due diligence.

What is the "Brilliant at the Basics" campaign and does it replace CMMC?
The "Brilliant at the Basics" campaign is a DoD CIO initiative that defines 10 core IT cybersecurity practices for DIB partners, particularly small and midsize businesses. It does not replace CMMC. It signals the direction of the reformed framework and aligns with current NIST SP 800-171 Revision 2 requirements. Building toward these practices now reduces compliance risk under any future framework.

Similar posts

Be The First To Know

Stay up to date with the latest articles, announcements, and upcoming events, delivered straight to your inbox.