On July 13, 2026, DoD CIO Kirsten Davies signed a memo suspending the Cybersecurity Maturity Model Certification Phase II requirements — the mandate that would have required mandatory third-party assessments by accredited C3PAO assessors starting November 10, 2026. A 60-day CMMC Reform Task Force review is now underway, with a report expected around mid-September 2026.

For the roughly 80,000 defense contractors and subcontractors who had been preparing for Phase II, the announcement created immediate confusion. Does the suspension mean the compliance work stops? Does it mean the program is being cancelled? And what happens to scheduled C3PAO assessments already on the calendar?

The short answer is that the suspension is narrower than the headlines suggest — and the contractors who use this window wisely will be better positioned regardless of what the task force recommends.

What the Suspension Actually Changed

Phase II of CMMC would have required defense contractors handling Controlled Unclassified Information (CUI) to obtain a third-party certification from an accredited C3PAO assessor before bidding on certain contracts. That requirement is now on hold pending the task force review. The DoD also opened a public Request for Information through August 14, 2026, inviting industry to submit cost and implementation data.

The suspension was driven by two compounding problems. First, the supply of accredited assessors was nowhere near sufficient to handle the demand — only approximately 100 certified C3PAOs were available to assess a potential pool of 80,000 companies. Second, the Small Business Administration had flagged that individual certification costs were approaching $600,000 per company for some contractors, creating a barrier that threatened to push smaller defense suppliers out of the industrial base entirely.

What Did Not Change

The suspension of Phase II does not touch the existing compliance obligations that are already in force. DFARS clause 252.204-7012 — which requires contractors to safeguard CUI, report cyber incidents within 72 hours, and flow those requirements down to subcontractors — remains fully enforceable. The underlying standard, NIST SP 800-171 with its 110 security controls, is still the benchmark. Phase I self-assessments, which require contractors to post a current SPRS score to the Supplier Performance Risk System, are still required. Government-led DIBCAC assessments continue. And the Civil Cyber-Fraud Initiative, which uses the False Claims Act to pursue contractors who misrepresent their cybersecurity posture, is still fully active.

Separately, the FAR Council published a proposed rule on June 23, 2026 that would extend CUI safeguarding requirements beyond DoD to all federal contracts — with a public comment period closing July 23, 2026. That proposed rule was not affected by the CMMC suspension.

The Practical Risk of Stopping

The most dangerous response to the suspension is to treat it as permission to stop. Contractors who dismantle controls they have already built, cancel scheduled assessments without checking their prime contractor flow-downs, or let their SPRS scores go stale are taking on real risk for a temporary pause in one specific requirement.

Prime contractors often impose CMMC-like requirements through their own subcontract flow-downs, independent of the federal rule. A suspension of the federal Phase II requirement does not automatically release a subcontractor from a contractual obligation to their prime. Any contractor with a scheduled C3PAO assessment should check their existing contracts before cancelling.

There is also a reputational dimension. The task force review is a 60-day window, not a cancellation. If the program resumes — with modifications to cost structure and assessor capacity — the contractors who maintained momentum will be in a materially better position than those who stopped.

What to Do During the 60-Day Window

The suspension creates a window that smart contractors can use productively. The first priority is to keep the SPRS score current and defensible. An accurate, well-documented self-assessment is the foundation of any compliance posture, and it is required regardless of what happens with Phase II. The second priority is to review existing contracts for prime contractor flow-downs that may impose independent CMMC obligations. The third is to watch the task force timeline — the report is expected around mid-September 2026, and the public RFI closes August 14.

For contractors who had been planning to respond to the RFI, the August 14 deadline is worth noting. If your organization has concrete data on assessment costs, assessor availability, or implementation burden, submitting that data is a direct way to influence how the program is restructured.

The Compliance Posture Argument

Beyond the immediate tactical questions, the CMMC suspension illustrates a broader point about compliance posture in the defense industrial base. The contractors who are least disrupted by this kind of regulatory uncertainty are the ones who built their cybersecurity programs against the underlying standard — NIST SP 800-171 — rather than against the certification requirement alone. A program built on the standard survives regulatory changes. A program built only to pass an audit does not.

For mid-market defense contractors and their PE sponsors, the practical implication is straightforward: the 60-day window is an opportunity to close gaps in the underlying controls, document the evidence that supports the SPRS score, and build the kind of audit-ready posture that holds up regardless of how the task force restructures Phase II.

Frequently Asked Questions

What exactly was suspended in CMMC Phase II?

The DoD suspended the requirement for mandatory third-party C3PAO assessments that would have taken effect November 10, 2026. A 60-day CMMC Reform Task Force review is underway. Phase I self-assessments, DFARS 252.204-7012 obligations, NIST SP 800-171 controls, and SPRS score requirements were not affected.

Should defense contractors stop their CMMC compliance work during the suspension?

No. DFARS 252.204-7012 and NIST SP 800-171 obligations remain in force. Prime contractor flow-downs may impose independent CMMC requirements regardless of the federal rule. The task force review is a 60-day pause, not a cancellation — contractors who maintain momentum will be better positioned when the program resumes.

What is the SPRS score and why does it still matter?

The Supplier Performance Risk System (SPRS) score is a self-assessed score that defense contractors are required to post, reflecting their implementation of NIST SP 800-171 controls. It was not suspended. An inaccurate or outdated SPRS score creates False Claims Act exposure under the Civil Cyber-Fraud Initiative.

What is the timeline for the CMMC task force review?

The 60-day review was initiated July 13, 2026, with a report expected around mid-September 2026. A public RFI for industry cost and implementation data closed August 14, 2026. The task force may recommend restructuring the program's cost structure, assessor capacity requirements, or phasing timeline.