CMMC Phase 2 Is Paused. Here Is What Still Applies to Defense Contractors.
The CMMC Phase 2 pause moved the certification date, not the obligation. Phase 1, DFARS 7012, and your SPRS score still apply. Here is what to do before the September review.
A compliance lead at a 300-person avionics supplier read the July headline and forwarded it to her CEO with one line on top. "Looks like CMMC is on hold." That instinct feels right. It is about to cost her the cheapest six months of readiness she will ever get.
Here is the short version, and it is the one that matters. On July 13, 2026 the Department of Defense suspended CMMC Phase 2, the third-party certification step, pending a review. The CMMC Phase 2 pause did not touch whether your systems have to be secure, your self-assessment score honest, or your affirmation defensible. Phase 1 still applies, and the obligations underneath CMMC never went anywhere.
Is CMMC still required after the Phase 2 pause?
Yes. On July 13, 2026 the Department suspended CMMC Phase 2, the third-party certification step, pending a review. Phase 1 self-assessment stays in effect, and the safeguarding duty, an accurate score in the Supplier Performance Risk System (SPRS), and the annual affirmation all still bind. The pause changed when certification is verified, not whether the obligation applies.
Let me walk through what actually moved, what did not, and how to spend the window.
What actually changed on July 13
The Department suspended CMMC Phase 2, the stage where third-party certification by a C3PAO, a CMMC Third-Party Assessment Organization, would have become a condition of contract award. That step was set for November 10, 2026. It is now on hold pending a 60-day review, with a report expected around mid-September 2026. Contractors are already calling it the CMMC suspension.
During the review, new solicitations may ask only for Level 1 or Level 2 self-assessment, the Level 2 C3PAO requirement is being pulled from active solicitations and existing contracts, and the waiver process is paused. The Department framed it as lowering the compliance barrier for smaller businesses. For scale, it estimated in November 2025 that roughly 70,000 contracts would eventually require Level 2.
That is the whole of what moved. Now the part that did not.
What the pause did not touch
The Department paused the transition to third-party certification. It did not repeal the rules underneath CMMC. Those rules live in contract clauses and regulations that predate CMMC and stand on their own authority. Every one of them still binds.
- DFARS 252.204-7012, the clause most people just call DFARS 7012. Safeguard covered defense information to NIST SP 800-171 Revision 2, report a cyber incident within 72 hours of discovery, and preserve incident evidence for at least 90 days.
- Your SPRS score. Under DFARS 252.204-7019, a current assessment score, one not more than three years old, must sit in the Supplier Performance Risk System before award.
- The annual affirmation. A named senior official still affirms your compliance every year. That rule was not repealed.
- Your primes. Flow-down deadlines were never tied to the DoD clock, and they have not moved.
Notice the through-line. Not one of these depends on Phase 2. Third-party certification was a way to verify the work. Pausing the verification does not pause the work.
Why enforcement makes this a window, not a break
If the rules still bind, the next question is whether anyone enforces them during a pause. They do. The exposure sits in the False Claims Act, and it attaches to the affirmation your senior official already signed. When a contractor posts a score that a later government assessment cannot support, the gap becomes the case.
The record is recent. In June 2026 the Department of Justice settled a False Claims Act case with LOGZONE, Inc. for $507,144. The company had reported a perfect NIST SP 800-171 Revision 2 score of 110, while a later assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) scored the same environment at -170. LOGZONE did not admit guilt.
Sit with that spread. A self-reported 110 became an assessed -170. The scoring method subtracts weighted points for unmet requirements, so a weak environment lands far below zero.
Here is the twist the pause creates. Self-assessment is now the only designation on the table. Nothing sits between your posted score and your award except your own attestation. That makes an honest, provable score matter more, not less.
What should you do during the review window?
Treat the months before the mid-September report as room to get ahead, not time off. Five moves, in order.
- Freeze the phase calendar, not the security program. Strip the original certification-deadline assumption out of your plan. Keep funded remediation and evidence work running.
- Map your data and clause scope. Flag where your CUI and covered defense information actually live, across systems, users, and suppliers. Scope drives cost, so this move sets up every other one.
- Reconcile your SPRS score to evidence. Match the number you posted to your current System Security Plan, your scoring math, and your real artifacts. Fix what you cannot support before someone else finds it.
- Build the evidence package now. Asset inventory, network diagram, System Security Plan, policies, procedures, named control owners. The government assessment authority never paused.
- Close the CUI handling gap. Marking, training, storage, destruction, and the disclosure-reporting channel ride on DFARS 252.204-7012 and sit off most CMMC checklists.
Run those five and you come out of the review window with a defensible position, whatever the report lands on. That is the pattern across our CMMC readiness work, where the teams that reconcile the score against evidence early are the ones that walk into an assessment without surprises.
Where this goes next
The direction is not settled. The task force is expected to report around mid-September 2026, and it may reshape what scalable cybersecurity looks like for smaller contractors. Until then, the plain reading is the safe one. CMMC is under review, not cancelled. Phase 1 is in effect. The duties underneath it are unchanged. For the fuller picture of the phased rollout, see our federal contractors guide to CMMC. Date your assumptions to July 13, 2026 and watch the September report.
Frequently Asked Questions
Is CMMC cancelled?
No. CMMC is under review, not cancelled. On July 13, 2026 the Department suspended Phase 2, the third-party certification step, and opened a 60-day review. Phase 1 self-assessment stays in effect, and the safeguarding rules under DFARS 252.204-7012 and NIST SP 800-171 Revision 2 still apply. Treat the program as paused at the verification step, with the underlying obligations fully live.
Do I still need a SPRS score during the pause?
Yes. DFARS 252.204-7019 still requires a current self-assessment score in the Supplier Performance Risk System before award, and current means not more than three years old unless the solicitation says less. The pause removed the third-party check, not the score requirement. An outdated or unsupported score is still a problem the moment you bid.
Can I stop my CMMC work until the review ends?
Stopping is the expensive choice. The obligations under DFARS 252.204-7012 and the annual affirmation still bind, enforcement continues, and your primes are still flowing requirements down on their own timelines. The contractors who use the window to reconcile their score and evidence come out ready. The ones who stand down come out exactly where they started.
What happens after the mid-September 2026 review?
The task force is expected to report around mid-September 2026 with recommendations on scalable cybersecurity for smaller businesses. The forward phase dates are now uncertain and should be treated as pending revised guidance. The safeguarding baseline, NIST SP 800-171 Revision 2 under DoD Class Deviation 2024-O0013, is not expected to change through this review.
Does CMMC Level 2 still mean 110 requirements?
Yes. CMMC Level 2 is assessed against the 110 security requirements of NIST SP 800-171 Revision 2, the baseline pinned by DoD Class Deviation 2024-O0013. Revision 3 is arriving through a separate proposed FAR rule, not through CMMC, so your contractual baseline stays at Revision 2 for now. Build to the 110 you already have.
The bottom line
The pause rewards the contractors who use it. Spend the window proving your SPRS score against real evidence and closing your CUI gaps, and you hold a defensible position no matter what the report says. Stand down, and you keep the same signed affirmation and the same exposure behind it. If you are not sure the score you posted would survive a government assessment, that is the gap to close now.
This article provides general information about CMMC requirements and timelines. It is not legal advice. Consult your compliance or legal team for final interpretation of how these requirements apply to your specific contracts and obligations.
Not sure your SPRS score would survive a government assessment?
InterSec runs a CMMC gap review that reconciles your posted score against your SSP and evidence, the way an assessor would. As an RPO, we prepare you for the assessment. We do not issue the certificate.