On July 13, 2026, the Department of Defense announced the immediate suspension of CMMC Phase 2 — the requirement that would have made third-party (C3PAO) assessments mandatory for contractors handling controlled unclassified information (CUI). Phases 3 and 4 were frozen alongside it.
If you're a defense contractor, your first reaction might be relief. Maybe even a temptation to slow down or pause your compliance work.
Don't.
Here's what the headlines don't tell you: the suspension is a policy pause, not a regulatory repeal. The underlying requirements that matter most are still very much in effect — and in some ways, the risk has actually increased.

What Actually Changed
Let's be precise about what the DoD did and didn't do.
What changed: - Contracting officers may no longer designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) in new solicitations - Existing contracts with higher designations must be amended before the next option exercise - The CMMC Reform Task Force will review the program and report within 60 days - A public Request for Information (RFI) is open until August 14, 2026
What did NOT change: - DFARS 252.204-7012 (incident reporting and NIST SP 800-171 implementation) remains in full force - DFARS 252.204-7019 (SPRS assessment as a condition of award) is still required - DFARS 252.204-7020 (access for Medium and High assessments) is unchanged - Phase 1 self-assessment requirements are still a codified condition of award - The DOJ Civil Cyber-Fraud Initiative is still actively pursuing false cybersecurity certifications - NIST SP 800-171 Revision 2 remains the baseline standard
The suspension was enacted by memorandum, not by amending 32 C.F.R. Part 170 or issuing a DFARS class deviation. Until those regulatory changes happen, the legal framework is exactly what it was before July 13.
Why Your Self-Certification Just Got Riskier
Here's the part that isn't getting enough attention: removing the third-party assessor doesn't remove the requirement — it moves the risk onto your signature.
Phase 1 requires an annual affirmation of continuous compliance, entered in SPRS by a named senior official in your organization. That affirmation is a certification. And false certifications are the explicit target of the DOJ's Civil Cyber-Fraud Initiative, which carries treble damages.
Under the C3PAO model, an inflated SPRS score was a business risk. Under self-attestation plus government audits, it's a litigation risk. And DIBCAC (the government's assessment arm) digs deeper than any third-party assessor ever did.
If you've already completed a gap assessment that documented deficiencies, those records don't disappear just because Phase 2 was suspended. That paper trail still exists. The smart move is to remediate on a defensible timeline — not shelve the report and hope nobody asks.
The Practical Reality: Contracts, Not Headlines, Control
Your contract doesn't care about a policy memo. If your prime contractor flowed down CMMC requirements, those terms remain enforceable until the contract is modified in writing. Primes managing their own liability may keep higher requirements in place regardless of what the DoD memo says.
Subcontractors should be especially cautious. The memo binds DoD personnel, not your prime's subcontract terms. Relief does not automatically flow downhill. Before changing any assessment plans, confirm in writing with your prime contractor.
Why Keeping Momentum Is the Smarter Play
Here are four reasons to keep moving forward with your compliance work:
1. A reformed requirement could return quickly. The Task Force is due to report by mid-September. The RFI specifically asks about burdens on industry — which suggests the DoD is looking to restructure, not eliminate, the program. A pause that lasts a few months could be followed by a revised requirement that moves faster than the original timeline.
2. Unwinding and rebuilding costs more than maintaining. If you dismantle your CUI enclave, security controls, and documentation now, you'll pay more to rebuild them later. The organizations that maintain their posture through the pause will be weeks away from certification when the program restarts. Everyone else will be starting from zero.
3. Completed certifications retain real value. As of May 2026, 1,391 Final Level 2 certificates had been issued. Nothing in the suspension invalidates them. A completed Level 2 (C3PAO) certification satisfies any lesser designation during the suspension and remains a differentiator with primes and in M&A diligence.
4. The underlying threats haven't paused. The cybersecurity threats that CMMC was designed to address — ransomware, supply chain attacks, data exfiltration by foreign adversaries — are not taking a break while the DoD reviews its program. The controls you're implementing (inventory management, access controls, incident response, encryption) protect your business from real threats, not just regulatory requirements.
What You Should Do Right Now
- Keep your NIST SP 800-171 implementation on track. This is the foundation of everything. Don't stop.
- Validate your SPRS score. If it's inaccurate, correct it now. An inflated score under self-attestation is a liability.
- Proceed with scheduled assessments unless cost considerations genuinely warrant a delay. Completing the assessment validates your program.
- Review your compliance vendor and C3PAO agreements for termination, deferral, and refund rights while you have negotiating leverage.
- Inventory your contracts for CMMC clauses and confirm treatment with your contracting officers in writing.
- Submit an RFI response before the August 14 deadline. This is a rare moment when industry cost data can actually shape policy.
The Bottom Line
The CMMC Phase 2 suspension is a speed bump, not a stop sign. The requirements that protect your business and your contracts — NIST SP 800-171 implementation, incident response capabilities, access controls, and supply chain security — remain as important as ever.
Organizations that treat this as a breather will find themselves scrambling when the program restructures. Organizations that keep their foot on the gas will be certified, compliant, and ready when it does.
Not sure where your organization stands on CMMC readiness? Contact Virtue Technology Solutions for a no-pressure assessment of your current compliance posture.