Scrutineer.ai
All posts
Compliance

CMMC Phase 2 Suspended: What Defense Contractors Still Must Do

The DoD suspended CMMC Phase 2 on July 13, 2026, pausing third-party C3PAO assessments. Phase 1 self-assessments, NIST SP 800-171 Rev 2 and DFARS 252.204-7012 all remain in force. Here is what changed, what did not, and what to do with the gap.

By the Scrutineer team

July 2026 · 10 min read

Last updated July 2026. CMMC Phase 2 is suspended, not canceled. On July 13, 2026 the Defense Department halted the Phase 2 transition that was scheduled to begin November 10, 2026, pausing mandatory third-party C3PAO assessments while a newly created CMMC Reform Task Force runs a 60-day review. Everything else stands. Phase 1 Level 1 and Level 2 self-assessments, NIST SP 800-171 Rev 2 and DFARS 252.204-7012 remain in force, and no replacement date has been announced.

If you run compliance at a defense contractor, the practical translation is short: your assessment date moved, your obligations did not. This is what changed, what did not, and what to do with the gap.

What exactly did the DoD suspend?

The suspension covers the Phase 2 milestone and everything scheduled after it. Phase 2 would have required CMMC Level 2 certification assessments performed by an authorized third party, a C3PAO, as a condition of award on applicable contracts starting November 10, 2026. New Level 2 C3PAO and Level 3 DIBCAC procurement designations are paused alongside it.

The announcement came from DoD CIO Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey. The stated reasoning was capacity and cost. Davies pointed to more than $7 billion a year in aggregate compliance cost falling on small and medium-sized businesses, and to a supply problem that is hard to argue with: over 100,000 defense contractors would need assessments against roughly 100 certified assessors. Her summary of the arithmetic was that "the math just simply doesn't math" for smaller firms trying to hit the transition dates. A Government Accountability Office report in March had already flagged that the standards risked pushing small businesses out of the defense industrial base entirely.

What still applies after the CMMC Phase 2 suspension?

More than most of the relieved commentary suggests. The table below separates what is paused from what is still binding today.

Requirement Status after July 13, 2026
Phase 1 Level 1 and Level 2 self-assessmentsStill required in applicable contracts
NIST SP 800-171 Rev 2, all 110 requirementsStill required for CUI
DFARS 252.204-7012 safeguarding and incident reportingStill required where the clause is in your contract
SPRS score postingStill required
Annual affirmation by a senior Affirming OfficialStill required
System Security Plan and POA&MStill required
Mandatory C3PAO Level 2 assessments (Phase 2)Paused, no new date
New Level 3 DIBCAC procurement designationsPaused

Worth stressing the affirmation line, because it is the one that carries personal exposure. A senior company official named under 32 CFR 170.22 attests that the organization continues to meet the requirements. That attestation is made to the government, and a false one carries False Claims Act risk regardless of whether a third party is checking your work this year. Self-assessment does not mean self-graded generously.

Does this mean CMMC is going away?

No. The Department described it as a pause and simultaneously stood up a task force to recommend changes, which is not how programs get quietly killed. The pressure that created CMMC has not changed either: the defense supply chain remains a primary target for state-backed intrusion, and the DFARS safeguarding clause that predates CMMC is still in every relevant contract. The most likely outcome is a rescoped program, probably lighter on small businesses and phased over a longer runway, rather than a repeal.

Planning on the assumption that CMMC disappears is the expensive bet. Contractors who paused their programs after the first CMMC delay in 2021 spent the following four years rebuilding the same documentation twice.

What should defense contractors do during the pause?

Treat the next several months as unpriced preparation time, which is the cheapest kind. Five things pay off regardless of what the task force recommends.

Scope the CUI boundary properly. This is the highest-leverage work in all of CMMC and it is entirely within your control. Every requirement applies to the systems in scope, so shrinking that boundary shrinks the whole program. Contractors who enclave controlled unclassified information into a defined environment routinely cut assessment scope and cost by more than half compared with those who leave CUI scattered across a general corporate network.

Get an honest SPRS score. The DoD scoring methodology starts at 110 and subtracts weighted points, with the heaviest requirements costing five points each. Many contractors are carrying scores calculated optimistically two years ago against systems that have since drifted. Recalculate against what your environment actually does today.

Write the SSP as if someone will read it. Assessors have consistently reported that documentation quality, not technical control implementation, is where organizations fail. A System Security Plan that describes each requirement, how it is met, and where the evidence lives is the artifact that turns a two-week assessment into a three-day one.

Fix configuration management. The CM family is a common failure area because it demands things ad hoc environments rarely have: documented baseline configurations, enforced security settings, and a change process that records what was approved and when. Teams that already deploy through a repeatable pipeline with documented, logged and reversible deployments tend to clear this family quickly, because the evidence is a by-product of how they already work. Teams making changes by hand on production servers generally do not.

Close the POA&M items that were waiting on the deadline. A plan of action with items perpetually dated "before the assessment" is now a plan with no forcing function. Re-date them against your own calendar.

Should we still get a C3PAO assessment voluntarily?

For some contractors, yes. If you compete for work where a prime contractor asks about certification status, an early assessment is now a differentiator rather than a checkbox, and assessor availability has never been better than it is during a pause. Joint Surveillance Voluntary Assessments have also historically carried forward toward certification.

For most small contractors the honest answer is to wait. Paying for an assessment against requirements that a reform task force is actively reviewing risks buying a result against a superseded standard. Spend the money on remediation and scoping instead, both of which hold their value under any version of the program.

How does CMMC compliance software help while assessments are paused?

The pause changes what is urgent, not what is true. You still need to know which of the 110 requirements you meet, hold evidence proving it, and keep both current as your environment changes. That is exactly the work that decays fastest when a deadline disappears, and the work that is most painful to reconstruct later.

Control mapping and continuous evidence collection turn compliance from a project you restart before each deadline into a state you hold. CMMC compliance software that connects read-only to your cloud, identity and ticketing systems can map what you already run to each NIST SP 800-171 requirement, show what each open gap costs against your SPRS score, and flag drift the day a control breaks rather than during assessment fieldwork.

One caution when shopping. Most platforms marketed as CMMC tools were built for SOC 2 or ISO 27001 and had a NIST 800-171 mapping added later. The crosswalk genuinely saves work, since access control, logging and incident response overlap heavily across frameworks. What no crosswalk does is the CUI scoping, and that is the part that determines your cost. Ask any vendor how they handle boundary definition, not just how many frameworks they list.

Frequently asked questions

When was CMMC Phase 2 suspended? July 13, 2026. The Defense Department announced the suspension of the Phase 2 transition and all later milestones, roughly four months before Phase 2 was due to take effect on November 10, 2026.

Do I still need a CMMC self-assessment in 2026? Yes, if your contract carries the requirement. Phase 1 took effect November 10, 2025 and remains active, so applicable new contracts and option years still require a Level 1 or Level 2 self-assessment with a score posted in SPRS and an annual affirmation.

How long is the CMMC pause? Unknown. The CMMC Reform Task Force has 60 days from mid-July 2026 to deliver findings and recommendations, but no replacement date for Phase 2 has been announced and the recommendations themselves may reshape the timeline further.

Does the suspension affect DFARS 252.204-7012? No. The DFARS safeguarding clause and its 72-hour incident reporting requirement predate CMMC and operate independently. If that clause is in your contract, it binds you today exactly as it did before July 13.

Is NIST 800-171 Rev 3 required now? No. CMMC Level 2 remains tied to NIST SP 800-171 Revision 2. Rev 3 exists and is a plausible subject for the task force to consider, but until a rule change says otherwise, Rev 2 is the standard you are assessed against.

If you are working the same controls for a commercial audit at the same time, the overlap is worth exploiting deliberately rather than running two programs. Our guides on running a cybersecurity risk assessment and ISO 27001 software cover the control families that carry across, and audit readiness software covers keeping evidence current between assessments. Scrutineer is decision support and readiness tooling; certification is issued only through the official CMMC assessment process by an authorized C3PAO or the government DIBCAC.

See Scrutineer scrutinize your posture

Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.

Scrutinize on real evidence, not stale spreadsheets

Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and scores vendor risk continuously, and returns a readiness report with a prioritized gap list. AI scrutinizes, you decide.

Automated evidence · Per-control statuses · Prioritized gap list

Mapped controls · evidence-linked rationale for every status · an accredited auditor issues the attestation.