Back to Blog
    cmmc
    nist-800-171
    defense-contractors

    CMMC Phase 2 Is Suspended: What Defense Contractors Should Do Next

    Dustin CollettJuly 14, 2026

    The Department of War has suspended the next phase of the Cybersecurity Maturity Model Certification (CMMC) program, interrupting a rollout that would have required many defense contractors to complete third-party cybersecurity assessments beginning November 10, 2026.

    For contractors facing a difficult certification schedule, the announcement may provide welcome breathing room. It does not, however, eliminate the underlying requirements to protect Controlled Unclassified Information (CUI), implement applicable security controls, or accurately report cybersecurity compliance to the federal government.

    The immediate question for defense contractors is therefore not whether compliance work can stop. It is how to use this pause responsibly while the Department determines what comes next.

    What the CMMC Suspension Changes

    On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II and the associated implementation milestones planned for upcoming solicitations and contracts.

    According to the Department's official announcement:

    • The transition to CMMC Phase II is suspended.
    • The November 10, 2026, implementation milestone will not proceed as scheduled.
    • A CMMC Reform Task Force will review the program and provide recommendations within 60 days.
    • Contracting personnel are being directed to address affected requirements in current and future acquisitions.
    • Phase I self-assessment requirements remain active.
    • The government may continue conducting selected assessments of contractor cybersecurity programs.

    The review could result in a revised assessment structure, a narrower certification requirement, expanded government assessments, or a different method of validating contractor security.

    Until the task force completes its work, contractors should treat the future certification process as unsettled.

    Why the Rollout Was Paused

    The Department cited scalability, cost, and administrative burden as central problems with the planned implementation.

    Industry reporting indicated that more than 100,000 companies could have required third-party assessments, while the number of available assessors remained far below what would have been necessary to complete those reviews on schedule. Breaking Defense reported that Department Chief Information Officer Kirsten Davies described a fundamental mismatch between the assessment workload and available capacity.

    The Department also expressed concern that the cost and complexity of the program were discouraging smaller businesses and nontraditional suppliers from participating in the Defense Industrial Base (DIB).

    These are implementation problems rather than evidence that contractor cybersecurity no longer matters. The government still depends on private companies to protect sensitive technical, operational, and acquisition information from theft and misuse.

    Which Requirements Remain in Effect

    The suspension applies to the CMMC Phase II rollout. It does not cancel the cybersecurity clauses already included in many defense contracts.

    Contractors and subcontractors may still be required to comply with Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, which governs the safeguarding of covered defense information and the reporting of cyber incidents.

    Related obligations may include:

    • Implementing applicable requirements from National Institute of Standards and Technology Special Publication 800-171 Revision 2.
    • Maintaining a current and accurate System Security Plan (SSP).
    • Documenting eligible incomplete controls through Plans of Action and Milestones (POA&Ms).
    • Reporting qualifying cyber incidents to the Department.
    • Preserving and submitting forensic information when required.
    • Maintaining an assessment score in the Supplier Performance Risk System (SPRS).
    • Completing applicable CMMC Phase I self-assessments.
    • Providing required affirmations of continued compliance.

    The Department's CMMC program overview continues to describe Phase I requirements, annual affirmations, and the use of NIST SP 800-171 for Level 2 environments.

    A certification schedule and a contractual security obligation are not the same thing. One can be delayed while the other remains fully enforceable.

    Why Accurate SPRS Reporting Still Matters

    An SPRS score should reflect the controls operating in the contractor's environment at the time the score is calculated. It should not be based solely on planned improvements, informal assumptions, or controls that exist only in policy documents.

    A defensible score normally requires supporting evidence, including:

    • Technical configurations.
    • Current policies and procedures.
    • Network and data-flow diagrams.
    • Access-control records.
    • Security logs and monitoring records.
    • Training documentation.
    • Incident-response materials.
    • An SSP that accurately describes the environment.
    • POA&M entries that reflect known and eligible gaps.

    The suspension may reduce the likelihood of an immediate C3PAO review, but it does not make an unsupported score safer.

    Federal contractors can face serious consequences when cybersecurity representations do not match actual practices. In June 2026, the Department of Justice announced a False Claims Act settlement involving allegations that a defense contractor failed to meet cybersecurity requirements while submitting claims under government contracts.

    Not every control gap creates False Claims Act liability. The facts, contract language, knowledge, materiality, and representations involved all matter. Even so, contractors should understand that cybersecurity documentation and affirmations may be examined after an incident, complaint, investigation, or government assessment.

    What Contractors Should Do During the Pause

    The suspension creates an opportunity to improve compliance without the same immediate pressure of the November deadline. Contractors should use that opportunity to strengthen their programs rather than placing them on hold.

    Review Applicable Contract Clauses

    Examine prime contracts, subcontracts, purchase orders, and flow-down requirements. Determine whether they include:

    • DFARS 252.204-7012.
    • DFARS 252.204-7019.
    • DFARS 252.204-7020.
    • Existing CMMC provisions.
    • Customer-specific cybersecurity requirements.

    Compliance decisions should be based on the actual terms of the contract, not solely on broad announcements about CMMC.

    Confirm the CUI Boundary

    Identify every system, user, location, application, and service that receives, stores, processes, or transmits CUI.

    Reducing unnecessary CUI exposure can lower compliance costs and simplify security management. A clearly defined enclave is often easier to protect and document than an entire company network with poorly understood data flows.

    Recalculate the SPRS Score

    Review each NIST SP 800-171 requirement against current evidence. Confirm that implemented controls are operating as described and that any deductions are calculated correctly.

    Do not increase a score because a control is budgeted, ordered, or scheduled for deployment. Planned remediation is not the same as implementation.

    Update the SSP and POA&M

    The SSP should accurately describe the present environment, including system boundaries, technologies, responsibilities, and control implementation.

    The POA&M should include eligible unresolved items, realistic completion dates, responsible parties, and current status. Completed items should be validated and closed, while newly discovered issues should be added.

    Continue Technical Remediation

    Prioritize controls that materially reduce risk, including:

    • Multifactor authentication.
    • Privileged-account management.
    • Endpoint detection and response.
    • Vulnerability and patch management.
    • Centralized logging and monitoring.
    • Secure remote access.
    • Incident-response preparation.
    • Backup protection and recovery testing.
    • Encryption of CUI in transit and at rest.
    • Control of cloud services and external sharing.

    These protections are valuable even if the final CMMC process changes substantially.

    Organize Supporting Evidence

    Maintain an evidence library aligned with NIST SP 800-171 requirements and assessment objectives.

    Evidence may include screenshots, exports, policies, tickets, reports, diagrams, configuration records, training logs, and test results. Organizing this material now can reduce disruption during a future government review, customer inquiry, or revised certification process.

    Review Affirmations Carefully

    The person submitting or approving an affirmation should understand what is being represented and what evidence supports it.

    Organizations should establish a review process that includes technical, operational, and leadership input before making formal compliance statements.

    Should You Cancel a Scheduled Assessment?

    Companies with a third-party assessment already scheduled should review the engagement before automatically canceling it.

    A formal certification assessment may no longer be necessary on the original timetable. However, parts of the engagement may still be useful if converted into:

    • A readiness assessment.
    • A gap analysis.
    • A documentation review.
    • An evidence-validation exercise.
    • A technical control assessment.
    • A remediation-planning engagement.

    The right decision will depend on the contract, customer expectations, assessment terms, current readiness, and cost.

    Contractors should distinguish between postponing an official certification event and abandoning independent validation. An experienced outside reviewer can still identify weaknesses that internal teams have overlooked.

    What May Replace CMMC Phase 2

    The task force has been given 60 days to recommend a path forward. Several outcomes are possible, including:

    • A smaller or more targeted third-party assessment program.
    • Greater reliance on government-led assessments.
    • Risk-based selection of contractors for review.
    • Different requirements based on contract sensitivity.
    • Increased use of automated evidence and continuous monitoring.
    • Revised rules for small businesses and lower-risk suppliers.
    • Broader changes to the current CMMC structure.

    At this stage, these are possibilities rather than confirmed policy.

    Contractors should avoid making expensive architectural changes based only on predictions about the replacement program. At the same time, controls required by existing contracts and NIST SP 800-171 remain a sound basis for continued remediation.

    Use the Additional Time to Improve Readiness

    The suspension of CMMC Phase II changes the near-term certification calendar, but it does not remove the need for effective cybersecurity or accurate compliance reporting.

    Defense contractors should use the pause to:

    • Verify contract requirements.
    • Correct unsupported SPRS scores.
    • Improve the accuracy of the SSP and POA&M.
    • Reduce the scope of CUI where practical.
    • Complete high-priority security improvements.
    • Prepare organized evidence for future reviews.

    The final structure of CMMC may change. A contractor's responsibility to protect sensitive government information remains.

    Collett Systems helps Wisconsin manufacturers and defense contractors evaluate NIST 800-171 readiness, review SPRS scoring, define CUI boundaries, and develop practical remediation plans. Contact Collett Systems to discuss a cybersecurity compliance review.