The July 13, 2026 suspension paused CMMC's move to required third-party assessments, not the security requirements themselves. Contracts may now require only CMMC Level 1 or Level 2 self-assessments, while NIST SP 800-171 Rev 2, 72-hour incident reporting, SPRS scores and annual affirmations all remain in effect for contractors handling controlled information.
This article describes a program under active review. It reflects official documents retrieved on 2026-09-29. The review task force's findings had not been published on that date; this article will be updated when they are.
What did the Department of War announce?
On July 13, 2026 the Department of War (the Department of Defense's current name in official documents) suspended Phase 2 of CMMC implementation and set up a CMMC Reform Task Force to review the program. Phase 2 had been scheduled to begin in November 2026 and would have made independent Level 2 assessments by authorized third-party assessment organizations (C3PAOs) a broad condition of contract award.
The Chief Information Officer's implementation memorandum (26-P-1023) sets out the operating rules during the suspension (DoW CIO memorandum, retrieved 2026-09-29):
- "The upcoming November 2026 transition to Phase 2 of CMMC implementation is suspended."
- Program managers and requiring activities "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self)."
- Active solicitations that included Level 2 (C3PAO) or Level 3 (DIBCAC) requirements are to be amended to remove them. Existing contracts with those requirements are to be modified "prior to the exercise of the next option period or during the next scheduled administrative modification."
- No waivers will be granted during the review, and "further guidance will be promulgated at the conclusion of the CIO's 60-day review."
What remains in force?
The same memorandum is explicit: "during this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments. The cybersecurity requirements outlined in the clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect."
In practical terms, for a contractor that holds controlled information:
| Obligation | Source | Status during the suspension |
|---|---|---|
| Implement NIST SP 800-171 Rev 2 | DFARS 252.204-7012; class deviation 2024-O0013 | In effect |
| Report cyber incidents within 72 hours and preserve images for 90 days | DFARS 252.204-7012 | In effect |
| Keep a current assessment score in SPRS | DFARS 252.204-7019 and 7020 | In effect |
| CMMC Level 1 (Self) and Level 2 (Self) where a contract requires them, with annual affirmation | 32 CFR Part 170; DFARS 252.204-7021 | In effect |
| Basic safeguarding of FCI | FAR 52.204-21 | In effect |
| Level 2 (C3PAO) or Level 3 (DIBCAC) as a new contract requirement | 32 CFR Part 170 | Suspended |
Sources: DFARS 252.204-7012, DFARS 252.204-7019, DFARS CMMC rule, FAR 52.204-21, all retrieved 2026-09-29.
Does the suspension mean contractors can stop preparing?
No, for three reasons.
The requirements did not change. What was paused is how compliance is verified before award, not what has to be implemented. A contractor that handles covered defense information was required to implement NIST SP 800-171 before CMMC existed and still is.
Self-assessments carry weight. A Level 2 self-assessment and the annual affirmation are representations to the government, signed by a company official, about the state of your systems. An inflated SPRS score or an affirmation that does not match reality is a legal exposure in its own right, independent of CMMC's timeline. The implementation memorandum also refers to "select Government-led assessments" continuing during the suspension.
The program is under review, not cancelled. The task force is reviewing how the program should work, including its cost to small businesses. Its findings may change assessment scope or process. Until a rule change is published, the regulations in 32 CFR Part 170 and the DFARS clauses remain the law, and the work needed to meet NIST SP 800-171 will be needed under almost any outcome.
What should defense suppliers do now?
- Check your contracts and open solicitations. If one included a Level 2 (C3PAO) or Level 3 requirement, expect an amendment or modification; confirm with the contracting officer or your prime rather than assuming.
- Re-check your SPRS score. Make sure it reflects your current environment, is less than three years old, and that its plan-of-action dates are realistic.
- Keep implementing. Use the time a third-party deadline would have consumed to close open requirements properly.
- Test incident reporting. Confirm who would report a cyber incident to DoD within 72 hours, how, and how system images would be preserved.
- Watch for the review's outcome. Treat any summary of it, including this one, as secondary to the official DoD CIO documents and the Federal Register.
For the full picture of how NIST SP 800-171, the DFARS clauses and CMMC fit together, see our CMMC and NIST SP 800-171 guide. If you are unsure whether you hold CUI at all, start with what is CUI?.
Jowers Technology Solutions helps contractors assess and implement NIST SP 800-171 controls and keep their documentation accurate. We are not a third-party assessment organization and do not issue CMMC results. If you want an honest view of where your environment stands, request an assessment.
