On July 13, 2026, the Department of War suspended CMMC Phase 2, pausing the third-party certification requirement that was set to start hitting contracts on November 10, 2026. The certification is on hold. The cybersecurity requirements underneath it are not. If you hold a DoD contract today, your NIST 800-171 and DFARS obligations still apply exactly as they did last week.
What did the Department of War actually suspend?
The Department suspended CMMC Phase 2, the phase that would have required many contractors to pass an independent, third-party CMMC assessment before contract award. It also paused other pending and future CMMC implementation milestones written into current contracts. Phase 1 self-assessment requirements, NIST SP 800-171, and DFARS clause 252.204-7012 were left in place.
The distinction that matters: this suspends how compliance gets verified (a certificate from a third-party assessor), not what you have to comply with. Here is the split, according to the Department of War’s announcement and the accompanying DoD CIO memo:
| Suspended (paused during the review) | Still required (enforced right now) |
|---|---|
| CMMC Phase 2 third-party assessments | NIST SP 800-171 Rev 2 (all 110 security requirements) |
| New CMMC assessment milestones in current contracts | DFARS 252.204-7012 (safeguarding CDI + 72-hour incident reporting) |
| The November 10, 2026 Phase 2 start date | CMMC Phase 1 self-assessment requirements |
| Future CMMC implementation milestones | Self-assessment score posted in SPRS (DFARS 252.204-7019/7020) |
The Department also stood up a CMMC Reform Task Force and gave it 60 days to review the program and recommend a more scalable approach for the defense industrial base. For solicitations and contracts that already name a CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, the implementation memo directs contracting officers to remove those requirements by amendment or modification, so expect paperwork changes on affected awards.
Is CMMC still required for defense contractors?
The CMMC certificate is paused; the security standard behind it is not. During the 60-day review, the Department of War said it will keep enforcing baseline cybersecurity through NIST SP 800-171 Rev 2 self-assessments and select government-led assessments. Your contractual duty to protect controlled unclassified information has not changed, and neither has your liability if you misrepresent it.
Treat “suspended” as “the deadline moved,” not “the requirement went away.” Every prime’s flow-down obligation to its subcontractors still stands, and every contract that already names DFARS 252.204-7012 still binds you to it. Keep in mind that the memo binds government contracting officers, not your prime’s subcontract terms. A prime managing its own risk can keep requiring certification from subcontractors, so confirm any change to your flow-downs in writing before altering assessment plans.
What are defense contractors still legally required to do?
You are still required to implement the full NIST 800-171 Rev 2 control set, safeguard covered defense information under DFARS 252.204-7012, report cyber incidents within 72 hours, and keep an accurate self-assessment score in SPRS. None of these depend on CMMC Phase 2. They were in your contract before the certification program existed, and they remain enforceable today.
NIST 800-171 Rev 2: all 110 controls
You are expected to implement all 110 security requirements in NIST SP 800-171 Rev 2, document them in a System Security Plan (SSP), and track every gap in a Plan of Action and Milestones (POA&M). One note that trips teams up: CMMC Level 2 still maps to Rev 2. NIST published Rev 3, but DoD has not adopted it for CMMC (DoD Class Deviation 2024-O0013). Build to Rev 2, not Rev 3.
DFARS 252.204-7012: safeguarding and reporting
DFARS 252.204-7012 requires you to safeguard covered defense information on your systems, report cyber incidents to DoD within 72 hours of discovery, preserve affected media, and flow the same clause down to your subcontractors. This clause was untouched by the suspension. If it is in your contract, it is live.
Why did the Pentagon suspend CMMC Phase 2?
The Department pointed to cost and capacity. As reported by DefenseScoop, DoW Chief Information Officer Kirsten Davies cited a severe assessor shortage (roughly 100 authorized third-party assessors against more than 100,000 businesses that would need an assessment) and warned that future CMMC phases could cost small and mid-sized defense businesses upward of $7 billion a year. Her summary: “the math just simply doesn’t math.”
The Department also referenced Small Business Administration data showing that compliance costs were pushing smaller and non-traditional companies out of the defense supply chain, the opposite of the program’s intent. The 60-day Task Force review is meant to find an approach that prioritizes speed to capability and lowers the barrier to entry for small firms.
Should you stop preparing for CMMC?
No. Stopping now trades a manageable project for a bigger one later, and it does nothing about the liability you already carry. Three reasons preparation still pays off: the underlying standard is still enforced, Phase 2 is paused rather than canceled, and false attestation carries real legal exposure regardless of the certification timeline.
That last point is the one contractors underestimate. If you have already attested to NIST 800-171 compliance you do not actually have, the suspension does not protect you. The Department of Justice’s Civil Cyber-Fraud Initiative continues to pursue False Claims Act cases against contractors that misrepresent their security posture in federal contracts. A moved deadline is not a moved liability.
What should defense contractors do in the next 60 days?
Use the pause as runway, not a stop sign. The contractors who come out ahead when the Task Force reports back are the ones who spent the 60 days closing real gaps instead of waiting. A focused plan for the window:
- Run a gap assessment against all 110 NIST 800-171 Rev 2 controls and get an honest, current SPRS score.
- Write or update your SSP so it reflects what your systems actually do, not what a template says they should.
- Build a realistic POA&M with owners and dates for every gap the assessment surfaces.
- Confirm your DFARS 252.204-7012 incident-reporting process actually works, including the 72-hour path and subcontractor flow-down.
- Fix the SSP and access-control gaps first, because those are the requirements most teams underestimate and the ones an assessor reads first.
- Submit a response to the CMMC reform Request for Information on SAM.gov by August 14, 2026 if the outcome affects your costs. Contractor input on cost and readiness is exactly what the Task Force is collecting, and small and mid-sized voices will be underrepresented unless they file.
See exactly what’s still required for your contracts
The rules did not get simpler when Phase 2 paused. They got easier to misread. If you are not sure which clauses bind your specific contracts, or where your real NIST 800-171 gaps are, a short call is the fastest way to find out. Nexeris works extensively with the defense industrial base on NIST 800-171, DFARS, and CMMC readiness.
Schedule a call and we will map what is still required for your contracts and what to close during the 60-day window. Our engagements are backed by a $10,000 credit if your assessment does not pass on the first attempt (terms apply per engagement agreement).
Common questions
Is CMMC canceled?
No. CMMC Phase 2 is suspended, not canceled. The Department of War paused the third-party certification requirement on July 13, 2026, and launched a 60-day review to redesign how the program works. The certification could return in a revised form once the CMMC Reform Task Force reports its recommendations.
Do I still need to meet NIST 800-171?
Yes. NIST SP 800-171 Rev 2 remains fully enforced. During the review period, the Department of War will verify baseline cybersecurity through self-assessments and select government-led assessments. Every contractor handling controlled unclassified information must still implement all 110 controls and keep a current SSP and POA&M.
Is DFARS 252.204-7012 still in effect?
Yes. The suspension did not touch DFARS 252.204-7012. If the clause is in your contract, you must still safeguard covered defense information, report cyber incidents to DoD within 72 hours, preserve affected systems, and flow the requirement down to your subcontractors. These obligations are independent of CMMC.
When was CMMC Phase 2 supposed to start?
CMMC Phase 2 was scheduled to take effect on November 10, 2026. That date, along with other pending and future CMMC implementation milestones in current contracts, is now suspended pending the outcome of the Department of War’s 60-day reform review announced on July 13, 2026.
Why did the Pentagon suspend CMMC Phase 2?
The Department cited prohibitive compliance costs, potentially over $7 billion a year for small and mid-sized defense businesses, and a severe assessor shortage of roughly 100 assessors for more than 100,000 businesses. SBA data also showed compliance costs pushing small and non-traditional firms out of the defense supply chain.
Should I pause my CMMC preparation?
No. The underlying NIST 800-171 and DFARS requirements are still enforced, Phase 2 could return in revised form, and false attestation still carries False Claims Act liability. Contractors who keep closing gaps during the 60-day window will be positioned to win awards when certification resumes.
