Is CMMC paused, and what does the July 2026 suspension actually change?

Partly. On July 13, 2026 DoD suspended the Phase 2 move to mandatory third-party certification, pending a 60-day review. The self-assessment, the SPRS score, the annual affirmation, and DFARS 252.204-7012 were not paused.

On July 13, 2026 the Department of War announced the immediate suspension of CMMC Phase 2 — the transition, scheduled for November 10, 2026, under which contracts involving Controlled Unclassified Information would begin requiring certification by an accredited third-party assessment organization. A CMMC Reform Task Force was given 60 days to study the program and report, which puts its findings in mid-September 2026. The stated reason was cost: the Department cited Small Business Administration data indicating that CMMC compliance was pushing small innovators out of the defense industrial base.

What was actually suspended

One thing: the requirement for a C3PAO assessment as a condition of award, or of exercising an option, on CUI contracts. During the review, program managers may only insert Phase 1 requirements — Level 1 and Level 2 self-assessment — into new solicitations. If you were budgeting for a third-party assessment this winter, that date no longer exists, and nobody outside the task force yet knows what will replace it.

What was not suspended

  • DFARS 252.204-7012: safeguarding covered defense information and reporting cyber incidents within 72 hours. This clause has been in contracts since 2017 and did not move.
  • The NIST SP 800-171 self-assessment, and the requirement to post the resulting score in the Supplier Performance Risk System (SPRS).
  • The annual affirmation of continuing compliance that accompanies that score.
  • Level 1 and Level 2 self-assessment requirements in new solicitations, in force since November 10, 2025.
  • Government-led assessments: the Department said it will continue to enforce NIST SP 800-171 through self-assessments and select assessments of its own.

In practice, the thing a prime asks a small supplier for — an SPRS score, a System Security Plan, a plan of action for the gaps — is exactly the thing that did not pause. Primes report supply-chain readiness upward regardless of which phase the program is in, and a blank score reads the same way it did in June.

What the review could decide

Nobody outside the task force knows. The plausible range runs from a delayed Phase 2 with the same structure, through a narrower third-party requirement reserved for the most sensitive programs, to a program that leans on self-assessment and government spot checks for the long term. Every one of those outcomes rests on the same 110 requirements in NIST SP 800-171, the same SSP, the same score. What changes between them is who checks the paperwork, not whether it has to exist.

What to keep doing

Score yourself honestly and post it. Write the SSP that matches the network you actually run. Keep the plan of action dated and current. If the third-party requirement returns, a shop with those three artifacts is at the front of an assessor queue that will be long; if it does not, the same three artifacts are what the self-assessment and the affirmation are made of. This site sells readiness and documentation; it is not a C3PAO and does not certify anyone, and the pause changes nothing about that either.

Dates in this article are current as of September 2, 2026. If the task force has reported by the time you read this, check its findings before relying on the November date in either direction.

Find out where you actually stand

The free calculator scores all 110 NIST SP 800-171 requirements using the official DoD Assessment Methodology weights — the same arithmetic your prime sees in SPRS. About twenty minutes, no cost, nothing stored unless you ask for the emailed report.

Related questions