The Pentagon Just Suspended CMMC Phase 2. Stopping Your Readiness Program Is the Wrong Read.
The deadline moved. The False Claims Act exposure on your last SPRS affirmation didn't.
The bottom line
On July 13, the Department of Defense suspended the November 10, 2026 transition to CMMC Phase 2 — the point where third-party Level 2 assessments would have become a condition of contract award — and launched a 60-day top-to-bottom review of the program. Phase 1 stays fully in force: self-assessments, SPRS score submissions, and annual affirmations signed by a senior official. The suspension changes when an assessor shows up. It does not change what you attested to last quarter, and it does not change the False Claims Act exposure attached to that attestation.
What changed
On July 13, 2026, DoD released two memoranda announcing the immediate suspension of upcoming CMMC implementation deadlines — including the planned November 10, 2026 start of Phase 2, when new solicitations involving Controlled Unclassified Information would routinely have required a Level 2 certification performed by an authorized C3PAO. The department simultaneously launched a 60-day review of the program, with a Request for Information aimed at reducing barriers to participation in the defense industrial base (Federal News Network; Greenberg Traurig client alert).
What did not change matters more than what did:
DFARS 252.204-7012 remains in force. If your contracts include it, you are contractually required to implement all 110 controls of NIST SP 800-171 today — not at some future assessment date.
Phase 1 remains in force. Level 1 and Level 2 self-assessments, scores entered into the Supplier Performance Risk System, and annual affirmations signed by a senior company official continue as before (Cyber Solutions summary).
The market context is stark. As of this spring, roughly 1,700 organizations held a Level 2 certification against an estimated 80,000 that will eventually need one, with about 104 authorized C3PAOs to serve them (Secureframe federal report; Cyber AB town hall recaps). The suspension is partly a recognition that the math was not going to work by November.
The framework lens
This is a CMMC 2.0 / NIST SP 800-171 story, but the mechanics translate directly for commercial readers:
CMMC Level 2 = NIST SP 800-171’s 110 controls, assessed either by self-attestation (Phase 1) or third party (suspended Phase 2). The suspension moves the assessment, not the control set.
SOC 2 readers: an SPRS affirmation is structurally the closest thing federal contracting has to a management assertion — except it is signed under implied certification doctrine, where a misstatement is a False Claims Act problem, not a qualified opinion.
ISO 27001 readers: think of the suspension as the certification body pausing audits while your Statement of Applicability remains contractually binding.
FedRAMP readers: the parallel is exact — control implementation obligations exist independent of when the assessment happens, and the agency’s review (like the FedRAMP 20x overhaul) reshapes the how, not the whether.
The decision
Whether to treat the suspension as budget relief — pausing the readiness program, releasing the consultants, deferring the enclave build — or as schedule relief: the same destination with a less punishing queue.
The companies that paused after previous CMMC delays (there have been several since 2020) consistently paid more later: readiness programs restarted cold, scope had drifted, and evidence had gone stale. Meanwhile the exposure that actually generates legal risk — a senior official’s signature on a self-assessment score that does not match reality — continued the entire time. DOJ’s Civil Cyber-Fraud Initiative has been settling exactly these cases since 2021.
There is also a queue argument. If the review lands where most observers expect — a phased return of third-party assessment with adjusted scope — the contractors who kept their readiness warm will book C3PAO slots first. The ones who paused will rediscover that 104 assessment organizations cannot serve 80,000 contractors, and the queue does not care whose budget cycle restarted late.
The control test
What should be true operationally, suspension or not:
A current, accurate System Security Plan (SSP) covering the CUI environment, with scope that matches how data actually flows today.
An SPRS score derived from a real assessment against NIST SP 800-171, with a documented methodology — not a score reverse-engineered from what the contract needs.
POA&M items with owners, funded remediation dates, and the 180-day closeout discipline Phase 2 would have enforced — kept as internal policy even while the external clock is paused.
The annual affirmation treated as a legal event: reviewed by counsel, supported by evidence, signed by someone who has actually seen that evidence.
CUI scoping controls (enclave boundaries, flow-down to subcontractors, FIPS-validated encryption) maintained as operational controls, not assessment-week theater.
A decision memo — written now — recording what your company chose to do during the suspension window and why. If the program returns harder, that memo is your board’s evidence of governance.
The evidence test
A board member, prime contractor, or DOJ attorney asking whether your Phase 1 posture is real should be able to see:
The SSP with a last-reviewed date inside the last 12 months and a named owner.
The scoring worksheet behind your current SPRS number, control by control.
The evidence package for the last affirmation: who signed, what they reviewed, when.
POA&M burn-down over time — items closing, not accumulating.
Subcontractor flow-down records: which subs handle CUI, what they attested, when you last checked.
Board or executive-committee minutes showing the suspension was discussed and a posture was chosen deliberately.
Weak evidence is an SPRS score with no worksheet behind it and an affirmation signed by someone who never saw the gaps. That combination survived fine when nobody was checking. It does not survive a False Claims Act complaint from a departing employee — the qui tam pipeline is how most of these cases now start.
Ask this at your next meeting
Who signed our last SPRS affirmation, what did they review before signing, and would that stand up as evidence of good faith?
Are we treating the Phase 2 suspension as permission to stop, or as schedule relief on the same destination — and where is that decision recorded?
If the program returns in modified form after the 60-day review, how fast can we re-mobilize, and is our C3PAO relationship warm or cold?
Three signals worth watching
The 60-day review’s RFI responses. DoD is explicitly soliciting input on reducing barriers for the defense industrial base (Greenberg Traurig). The shape of the responses — and who files them — will preview whether Phase 2 returns narrower, later, or restructured.
Certification velocity as a market signal. June 2026 set a record with 279 new Level 2 certifications (total ~1,717), yet available assessment capacity went unused for the eighth straight month (CMMC ecosystem tracking). If certifications keep climbing during the suspension, primes are enforcing their own timelines regardless of DoD’s.
Prime contractor flow-downs replacing the federal deadline. With the government clock paused, the contractual pressure moves to primes, several of which had already pushed Level 2 requirements ahead of the government timeline (CMMC Ready Now). Watch whether primes hold their dates — that, not the Federal Register, is now the binding constraint for most subs.
Sources
Federal News Network, “Pentagon suspends CMMC phase two requirements, launches review of program,” July 13, 2026 — https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/
Greenberg Traurig, “DoD Suspends CMMC Deadlines and Seeks to Reassess Requirements,” July 15, 2026 — https://www.gtlaw.com/en/insights/2026/7/dod-suspends-cmmc-deadlines-and-seeks-to-reassess-requirements
Cyber Solutions, “Understanding CMMC 2.0: July 13th Government Update,” July 14, 2026 — https://discovercybersolutions.com/cyber-security-news/cmmc-2-0-simplified-what-dod-contractors-need-to-know
Secureframe, “Federal Cybersecurity Report 2026,” June 25, 2026 — https://secureframe.com/blog/federal-cybersecurity-report-2026
CMMC.com, “June 2026 Cyber AB Town Hall Recap,” July 1, 2026 — https://www.cmmc.com/newsroom/cyber-ab-town-hall-06-2026
CMMC Ready Now, “CMMC Assessment Backlog: 103 C3PAOs vs. 80,000 Contractors,” July 13, 2026 — https://cmmcreadynow.com/blog/cmmc-assessment-backlog-beat-the-queue


