On July 13, 2026, the Department of War announced the immediate suspension of Phase 2 of the CMMC program — the phase that would have made third-party certification a condition of winning defense contracts starting November 10, 2026. A newly created CMMC Reform Task Force has 60 days to review the program and deliver recommendations to the Department's Chief Information Officer.

If you sell to the Department of War, this is genuinely significant news. It is also being widely misread. Here is what actually changed, what didn't, and what a small contractor should do about it.

What actually changed

Phase 2 was the enforcement step everyone was bracing for: from November 10, new DoW solicitations would begin requiring CMMC Level 2 certification by a C3PAO — a paid, third-party assessment — before award. That requirement is now suspended while the review runs. The Department has gone further and directed that active solicitations and contracts already containing Level 2 C3PAO or Level 3 assessment requirements be amended to remove them.

Practically, that means the certification deadline that drove most 2026 planning calendars — and most consultant pitches — is off, at least until the Task Force reports back in roughly mid-September 2026 and the Department decides what comes next.

What did not change

Every contractual cybersecurity obligation you had on July 12 you still had on July 14:

The enforcement mechanism moved — it didn't disappear. With third-party certification paused, your self-reported SPRS score is now the primary compliance signal the Department sees. The Department of Justice has already pursued False Claims Act cases against contractors that overstated their cybersecurity posture. An honest negative score is a plan. An inflated score is a liability.

Why the suspension happened

The short version: cost and complexity concerns for exactly the companies this blog serves. Industry feedback — much of it from small and mid-sized contractors facing five-figure assessment bills and six-figure remediation projects — argued the program as designed was consolidating the defense industrial base by pricing small suppliers out. The Task Force is reviewing the program's scope and burden and collecting comments through a public request for information.

Nobody knows what the review will produce. The plausible outcomes range from minor streamlining, to a longer phase-in, to a heavier reliance on self-assessment with spot audits. What no outcome will plausibly include is a retreat from NIST SP 800-171 itself — that standard is baked into DFARS clauses that sit in your contracts today.

The smart play for a small contractor

The suspension is a gift of time, and the right way to spend it costs almost nothing:

  1. Run an honest self-assessment. Score all 110 requirements against the DoD scoring methodology. Most companies' first honest score is negative — that's normal, and it's the starting line, not a verdict.
  2. Post your real score in SPRS. A current score is a condition of award today, suspension or no suspension.
  3. Write the SSP and POA&M. These documents are required by the clauses already in your contracts, and they're the first thing any future assessor — or prime contractor — asks for.
  4. Close the cheap gaps now. MFA, encryption settings, written policies, and training move your score materially and cost more in attention than money.

Contractors who spend the review window building a truthful, documented, improving posture will be ready for whatever the Task Force recommends. Contractors who read "suspended" as "cancelled" will be starting from zero when the music resumes — possibly on a shorter runway.

Know your real SPRS score before anyone asks for it

CMMC Map walks you through all 110 NIST 800-171 requirements in plain English and calculates your DoD-weighted SPRS score as you go. The full assessment is free — no card, no trial clock.

Start your free assessment
Free to assess · Documents $149/mo

Key dates to watch