Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
KNOWLEDGE BASECompliance FrameworksEDITOR REVIEWED

CMMC Phase II Is Suspended — What You Still Have to Do

The certification checkpoint moved. Your obligations did not. Here is precisely what was suspended on July 13, what remains fully in force, and what belongs on your next 30 days.

TL;DR

What was suspended: the Phase II acquisition transition. During the review, requiring activities may designate only Level 1 (Self) or Level 2 (Self) — Level 2 (C3PAO) and Level 3 (DIBCAC) requirements may not be designated, and affected solicitations and contracts are to be amended. November 10, 2026 is no longer an operative transition date. What did not change: DFARS 252.204-7012 safeguarding, NIST SP 800-171 Rev 2 implementation, the 72-hour incident report, DFARS 7019/7020 SPRS currency and government assessment authority, and 32 CFR Part 170 itself — the Program Rule was not repealed. The practical read: the suspension changes when certification is verified, not whether your systems must be secure, your SPRS score honest, and your affirmations defensible. Freeze the phase calendar, not the security program.

Fast-moving policy — verify before you act

This article describes the position as of July 28, 2026. The program review is ongoing and further guidance was promised. Clause applicability must always be confirmed against your actual solicitation, contract, order, and flowdowns — this is educational analysis of public sources, not legal advice or contract review.

What actually happened

On July 13, 2026, the Department of War issued direction suspending the Phase II transition of the Cybersecurity Maturity Model Certification (CMMC) program, pending a 60-day program review by a newly established CMMC reform task force. A public request for information was opened to collect industry feedback.

Phase II was the step that would have broadly required third-party certification — assessments performed by a CMMC Third-Party Assessment Organization (C3PAO) — as a condition of award. It was scheduled to begin November 10, 2026.

The suspension moved the certification checkpoint. It did not move the security requirements, the reporting clock, or the honesty standard attached to your SPRS score.

That distinction is the whole article. A large share of the DIB read the headline as “CMMC is dead” and quietly stopped work. That is the single most expensive misreading available right now — because the obligations that actually carry contractual and legal consequence today were never part of Phase II.

What was suspended

  • The Phase II acquisition transition. During the review, requiring activities may designate only Level 1 (Self) or Level 2 (Self) in procurements.
  • Level 2 (C3PAO) and Level 3 (DIBCAC) designations. These may not be designated in new requirements during the suspension, and affected active solicitations and contracts are to be amended or modified.
  • The November 10, 2026 date. It is no longer an operative transition date. Later phase dates should be treated as pending revised guidance — not quietly rescheduled to a date you invented.
If you hold a contract with a C3PAO requirement

The direction contemplates that affected solicitations and contracts are amended or modified. That is a contracting-officer action, not a self-help one. Confirm your specific position in writing with your contracting officer — do not assume a requirement lapsed on its own.

What did not change — the part that matters

Everything below remains in force. None of it was part of the Phase II transition:

AuthorityWhat it still requiresStatus
FAR 52.204-2115 basic safeguarding requirements for systems handling Federal Contract Information (FCI)Operative when included / applicable
DFARS 252.204-7012Adequate security, NIST SP 800-171 Rev 2 implementation, 72-hour cyber incident reporting, media preservation, FedRAMP-Moderate-equivalent cloud protections, and flowdownRemains in effect
DFARS 252.204-7019 / -7020A current NIST SP 800-171 assessment score posted in SPRS, and government assessment accessRemain operative
32 CFR Part 170The Program Rule defining Levels 1–3, assessment types, POA&M limits, scoring, and annual affirmationsNot repealed
Phase I self-assessmentsLevel 1 and Level 2 self-assessment requirements in solicitations, with affirmationStill designated

Read that table again with a procurement eye. Your SPRS score still gates award eligibility under 7019/7020. Your 72-hour reporting duty is unchanged. Your annual affirmation still carries the representation risk it always did. The suspension touched none of it.

The affirmation risk did not pause

Knowingly false or materially misleading cybersecurity representations can create False Claims Act exposure — and enforcement has been active in precisely this area. A suspended certification mandate does not make an inflated SPRS score safer to leave posted. If anything, the review period is the cheapest time you will ever have to correct one.

The numbers that still govern your program

NumberWhat it is
110NIST SP 800-171 Rev 2 requirements still required for CUI
72 hoursThe DFARS 7012 cyber-incident reporting window
15FAR 52.204-21 basic safeguarding requirements for FCI
80%Minimum score (88 of 110) for a Conditional CMMC status under the Program Rule
180 daysThe window to close POA&M items and convert a Conditional status to Final

If you want to understand where the 110 and the score actually come from, start with Your SPRS Score, Explained — the arithmetic is unchanged by the suspension.

Why the review was ordered

Two pressures, both structural, both publicly reported:

  • Cost to small and mid-size business. Small Business Administration data cited by the Department suggested future CMMC phases could cost small and midsize businesses more than $7 billion annually.
  • Assessor capacity. Roughly 100,000 companies were expected to need assessments against on the order of 100 authorized C3PAOs — a throughput mismatch that no schedule could absorb.

That matters for how you plan. This was not a determination that the security requirements were wrong; it was a determination that the verification pipeline could not carry the load on the announced timetable. Programs that assume the requirements are going away are betting against the stated rationale.

Read your contract in three layers

The cleanest way to reason about any defense contract right now is to separate three things that people routinely collapse into one:

  1. The standing architecture. FAR 52.204-21, DFARS 7012 / 7019 / 7020 / 7021, and 32 CFR Part 170. This is the durable law-and-clause layer. It was not repealed.
  2. The current implementation direction. The July 13, 2026 suspension. This governs which assessment types may be designated right now — and it is temporary by construction.
  3. Vendor and ICT source allowability. Governed separately through acquisition, program, and supply-chain direction. A product can satisfy every cybersecurity requirement and still be excluded from a particular contract or system.
Why the separation pays

Layer 2 is the only one that changed on July 13. Teams that had not separated the layers experienced the suspension as “everything is uncertain.” Teams that had, changed exactly one line in their plan — the phase calendar — and kept going.

Rev. 2 is still the baseline — treat Rev. 3 as planned uplift

A second, quieter thread runs alongside the suspension. In June 2026 the FAR Council published a proposed government-wide CUI rule as part of a broader FAR overhaul. It would extend a common CUI method across executive-agency acquisitions — not only defense work — and it points at NIST SP 800-171 Revision 3.

It is a proposed rule, not an operative clause. So the planning boundary is precise:

  • CMMC and DFARS 7012 use Rev. 2 today. That is your contractual baseline. Do not represent Rev. 3 as your current CMMC baseline.
  • Do not postpone Rev. 2 remediation while waiting for a future rule to land.
  • Maintain a Rev. 3 delta plan — the family reorganization and organization-defined parameters — so an uplift is a planned project rather than an emergency.

If the endpoint side of that uplift is on your mind, Windows Pro vs. Enterprise for NIST 800-171 Rev 3 covers where the licensing wall actually sits.

The layer people miss: source allowability

Here is the failure mode that the suspension news is currently hiding, and it will outlast the review.

A FedRAMP authorization or a CMMC status does not establish that a given vendor, service, model, API, or subprocessor is permitted on every defense contract. Source allowability is governed independently — through acquisition, program, supply-chain, and contract direction. A service can be perfectly compliant on the cybersecurity axis and still be excluded, or ordered removed, from a covered contract.

This is not hypothetical or new: supply-chain exclusion authority is long-established in statute and in the DFARS supply-chain-risk clauses. What is new is how fast the dependency surface is growing — particularly with AI services, which arrive with models, hosting platforms, APIs, agents, embedded integrations, and subprocessors behind them, often adopted without a procurement review.

Three durable moves, none of which depend on any particular vendor or news cycle:

  • Keep an AI and ICT dependency register. An AIBOM/SBOM-style inventory of models, APIs, hosting platforms, agents, libraries, data sources, embedded integrations, subprocessors, and downstream consumers. You cannot assess — or remove — what you never inventoried.
  • Put a source-allowability gate in front of adoption. Require contract, program, supply-chain, and legal review before a new AI or ICT source enters a defense workflow. Do not treat FedRAMP or CMMC eligibility as blanket approval.
  • Design for portability. Modular integrations, controlled prompt and configuration repositories, portable test suites, and a documented alternative — so that a source restriction becomes a migration, not an outage.
Scope note

This section deliberately states the general principle rather than tracking any single vendor dispute. Specific exclusion or removal directions are contract-specific and often reported before they are publicly documented — so treat press reporting as a prompt to verify against written contract direction from your contracting officer, never as the direction itself.

What to do in the next 30 days

  1. Freeze the phase calendar — not the security program. Strip November 2026/2027/2028 certification assumptions out of operating plans, and keep funded remediation and evidence work running.
  2. Reconfirm clause and data scope. Map FCI, CUI, CDI, and export-controlled information to actual contracts, systems, users, suppliers, and services. Clause applicability is not the same thing as general data sensitivity.
  3. Validate every SPRS score. Reconcile the posted score against the current SSP, the scoring methodology, objective-level evidence, POA&Ms, and the system boundary. Correct anything unsupported through the appropriate process.
  4. Keep the evidence package current. Asset inventory, network diagram, SSP, policies, procedures, technical artifacts, and named control owners — all of it stays live even while C3PAO designations are suspended.
  5. Reassess cloud and external service provider dependencies. Validate the exact offering's authorization or equivalency, incident terms, forensic access, shared-responsibility split, and support-personnel model.
  6. Stand up the source-allowability gate and dependency register described above.
  7. Put a governance owner on it. One accountable person maintaining the regulatory cutoff date, the clause matrix, the dependency register, and the Rev. 2 / Rev. 3 delta — and re-versioning the plan whenever official guidance changes.
If you only do one thing

Validate your SPRS score against real evidence. It is the one number the government can see today, it gates award eligibility under DFARS 7019/7020, it carries representation risk, and — unlike a C3PAO assessment — nothing about it is suspended.

What to watch next

  • Post-review CMMC guidance. Further guidance was promised after the 60-day review; no replacement phase schedule has been published. Treat any date you hear before that as rumor.
  • Final disposition of the June 2026 FAR CUI proposal — including whether the government-wide rule proceeds on Rev. 3.
  • Written contract direction on any vendor, ICT, or AI source restriction relevant to your programs.

Update your contract playbooks when official text or direction changes — not when reporting appears.

Key takeaways

  • Only the acquisition rollout was suspended. Phase II third-party certification and Level 3 designations are paused during a 60-day review; November 10, 2026 is no longer operative.
  • The Program Rule was not repealed. 32 CFR Part 170 still defines the levels, POA&M limits, scoring, and affirmations.
  • Your live obligations are untouched: DFARS 7012 safeguarding, NIST SP 800-171 Rev 2, 72-hour reporting, SPRS currency under 7019/7020, and FAR 52.204-21 for FCI.
  • Rev. 2 is today's baseline; Rev. 3 is planned uplift. Don't represent the proposed FAR CUI rule as your current requirement.
  • Certification status is not source approval. Keep a dependency register and a source-allowability gate — that risk is independent of CMMC entirely.
  • Freeze the calendar, not the program. The suspension changed when certification gets verified, not whether you have to be secure and honest about it.

Sources

Cloud consoles and federal guidance change; confirm control text and clause language against the official publication that applies to your contract. This article is independent education and does not by itself establish compliance or confer CMMC certification.

← Back to the knowledge base