The Department of War suspended CMMC Phase 2 on July 13, 2026, and opened a 60-day review of the certification requirement. Phase 1 obligations, and the underlying duty to protect CUI, have not gone anywhere.
The short version
On July 13, 2026, the Department of War suspended CMMC Phase 2 and launched a 60-day review of the program, citing prohibitive compliance costs for small and mid-size defense contractors. Phase 2, which would have significantly expanded third-party Level 2 certification requirements, had been scheduled to begin November 10, 2026 under the original DFARS rule. That date is no longer operative while the review is underway.
This is not a broader compliance holiday. Phase 1 requirements, self-assessments and Level 1 and 2 basics already appearing in solicitations, remain fully in force, and the underlying statutory and contractual obligations to protect Controlled Unclassified Information have not gone anywhere.
What's actually paused, and what isn't
The suspension applies specifically to Phase 2's expanded third-party assessment (C3PAO) requirements. Everything that was already live under Phase 1, self-assessment against NIST SP 800-171, SPRS score submission, and the underlying DFARS 7012 safeguarding obligations, continues to apply. Multiple law firms tracking the announcement have been direct about this: cybersecurity obligations remain, and so does enforcement risk under the False Claims Act for contractors who misrepresent their compliance posture. The suspension is a pause on the certification mechanism, not a pause on the underlying requirement to protect the data.
What the review is actually asking for
The Department of War has opened a formal Request for Information for a CMMC Reform Task Force, with comments due August 14, 2026. The RFI asks industry, especially small, medium, and non-traditional businesses working with the Department, to identify which cost drivers are real versus which security controls deliver meaningful risk reduction against which ones are mostly administrative overhead, to describe existing commercial cybersecurity tools that could satisfy requirements more efficiently, and to propose specific policy reforms. The stated goal is to reduce compliance and cost burdens on smaller contractors while still protecting federal data, not to weaken the program's substance.
If your organization has opinions about which CMMC controls are genuinely protective versus which ones mostly generate paperwork, this RFI is a real, time-limited channel to say so before the reform recommendations are finalized.
The bottleneck this pause doesn't fix
Even before the suspension, the CMMC ecosystem had a capacity problem worth understanding, because it will still be relevant whenever Phase 2 (or its replacement) eventually arrives. As of earlier this year, there were roughly 103 authorized C3PAO assessors against an estimated 80,000 Defense Industrial Base organizations that will eventually need Level 2 certification, with only around 1,000 organizations certified so far. That is not a problem the 60-day review is positioned to solve, since it is about accreditation throughput, not policy design. Contractors who wait for the reform outcome before starting any preparation are setting themselves up for the same assessor bottleneck whenever the next deadline lands.
What to actually do during the pause
Treat this as a planning window, not a reprieve. Keep current Phase 1 obligations current: self-assessments, SPRS scores, and POA&Ms should stay accurate and up to date regardless of what happens to Phase 2, since these remain contractually and legally binding. If your organization has a genuine, evidence-backed view on which controls are cost-effective versus which are not, submit it through the RFI process before August 14, 2026, since this is the actual mechanism shaping what comes next. Continue any Level 2 readiness work that was already underway rather than shelving it, both because the underlying NIST SP 800-171 controls remain required regardless of the certification mechanism, and because whatever replaces or restores Phase 2 will very likely still require most of the same technical groundwork. And do not assume enforcement risk has paused along with the certification deadline; False Claims Act exposure for misrepresenting your compliance posture is not tied to the Phase 2 timeline.
Where this fits in your compliance program
For organizations we work with on NIST SP 800-171 and CMMC readiness, this is a good moment to separate what changed from what didn't. The certification deadline moved. The underlying security requirement to protect CUI, and the assessor capacity problem that will greet whatever timeline eventually replaces Phase 2, did not. Programs that keep building real security posture during this window will be ahead regardless of how the 60-day review concludes; programs that treat the pause as permission to stop will be exactly as unprepared as before, just with less runway once a new deadline is set.
Sources
Department of War Office of Small Business Programs, CMMC Reform Task Force RFI (comments due August 14, 2026).
Morgan Lewis, "Department of War Suspends CMMC Phase II Requirements, but Cybersecurity Obligations Remain."
Jenner & Block, "Department of War Suspends CMMC Phase II, But Compliance Obligations Remain, As Does Enforcement Risk."
Industrial Cyber, coverage of the Phase II suspension and 60-day review.
CyberAB Marketplace data, as reported via industry compliance-platform analysis.
Related service
NIST 800-171 & CMMC readiness
AGILE ARMORY