When the Department of War suspended CMMC Phase 2 on July 13, it started a clock: a newly formed CMMC Reform Task Force was given 60 days to review the program and deliver recommendations to the Department's Chief Information Officer. That clock runs out in roughly the second week of September 2026. The public comment window has already closed — industry responses to the Department's request for information were due August 14.

So what happens next, and what should a small contractor do between now and then? Here is an honest look at the possibilities — and the one strategy that wins under all of them.

What the report is — and isn't

The Task Force delivers recommendations, not policy. The Department then decides what to adopt, and rule changes of any size take time to implement. So don't expect a switch to flip in September. Expect a direction: a signal of whether third-party certification returns largely as designed, returns in a narrower or slower form, or stays parked while the Department leans on self-assessment for longer.

We've seen this movie before. The original CMMC program was paused for review in 2021 and came back streamlined as CMMC 2.0 — five levels became three, and most third-party assessment requirements were narrowed, not abandoned. A pause for reform has historically been exactly that: a pause, followed by a leaner version of the same idea.

The three plausible outcomes

OutcomeWhat it would look likeWhat it means for you
Phase 2 resumes, adjustedThird-party certification returns with a new timeline, possibly narrower scope or phased tiers to relieve assessor capacity.The companies that kept working during the pause are first in line and audit-ready. Everyone else is back on a deadline treadmill — possibly a shorter one.
A longer self-attestation eraThe Department extends its current interim posture: SPRS self-assessment as the primary mechanism, backed by government-led (DIBCAC) spot assessments.Your self-reported score and the records behind it become the whole ballgame — and False Claims Act exposure for overstated scores grows, because self-attestation is the control.
Structural redesignA bigger rethink: different tiers, different verification models, expanded small-business accommodations.New rules take longest to write. The interim regime — honest SPRS scores under existing DFARS clauses — runs even longer.

Notice what all three outcomes share. In every scenario, NIST SP 800-171 stays required by DFARS 252.204-7012, a current self-assessment score in SPRS stays a condition of award under 7019, and the honesty of that score is enforceable under the False Claims Act. There is no outcome where the work you do now is wasted.

What primes are doing while the government decides

One thing the suspension did not touch: what your prime contractor requires of you. DFARS 252.204-7012 obligates primes to flow cybersecurity requirements down to subcontractors handling Covered Defense Information, and many primes wrote C3PAO certification or evidence of 800-171 implementation into their own subcontract terms and supplier scorecards. Nothing requires them to relax that — and a defensible answer to "how do you manage supply-chain risk" is worth more to a prime now, not less. If your revenue runs through subcontracts, the requirements that bind you this fall may be set in Falls Church or Fort Worth, not the Pentagon.

The play between now and the report

  1. Get your SPRS score current and honest. If your posted score reflects where you planned to be rather than where you are, fix that first. It is the number the government checks today, and the number a False Claims Act case would be built on.
  2. Keep your SSP current. A System Security Plan is required by the clauses already in your contracts, and it is the first document any reviewer — prime, DIBCAC, or future assessor — asks for. A stale SSP is the fastest credibility loss available.
  3. Put dates on your POA&M. An undated remediation plan reads as a wish list. A dated one reads as a program.
  4. Collect evidence for what you've marked implemented. Under self-attestation, an "implemented" with nothing behind it is an assertion. Screenshots, configuration exports, and policy documents turn assertions into records.
  5. Don't buy anything you can't explain. If the report changes assessment requirements, the tools and consulting scoped to the old regime may need rework. The fundamentals above are regime-proof; exotic commitments made this month may not be.

Walk into September with your numbers already straight

CMMC Map walks you through all 110 NIST 800-171 requirements in plain English, calculates your DoD-weighted SPRS score as you go, and generates the SSP and POA&M behind it. The full assessment is free — no card, no trial clock.

Start your free assessment
Free to assess · Documents $149/mo

What we'll be watching for

When the report lands, we'll publish a plain-English breakdown of what changed and what it means for small contractors — the same day we can read it.