Solutions Who We Serve Insights & Events About Contact
Published on July 20, 2026 9 min read

CMMC Phase 2 Is On Hold: What Contractors Should Do Now

Hand touching a glowing circular interface over a blue world map, suggesting data security across a global network.

Summary: On July 13, 2026, the Department of Defense (DoD) paused CMMC Phase 2 third-party certification and launched a 60-day review. Your obligations haven’t changed: DFARS 252.204-7012, your SPRS self-assessment score, and False Claims Act exposure remain in force. With third-party verification gone for now, your self-attestation carries more weight, not less. Here’s where defense contractors should focus during the phase.

The news broke on July 13. If you’re a defense contractor, it’s worth reading past the headline.

On that date, the Department of Defense (DoD) paused the Cybersecurity Maturity Model Certification (CMMC) Phase 2 third-party certification requirement and stood up a CMMC Reform Task Force to review the program. The task force has 60 days, putting its report on or about mid-September. The mandate set to take effect November 10, 2026, requiring a formal assessment by a Certified Third-Party Assessment Organization (C3PAO), for applicable Level 2 contracts.

If you’ve spent the past few years and real budget preparing for third-party certification, this lands as a whiplash. So it’s worth being precise about what changed.

The reason DoD gave is specific to Phase 2’s third-party requirement, not to the security standard underneath it. Reaching CMMC Level 2 has always meant implementing the 110 controls in NIST 800-171, a standing Phase 1 obligation for anyone handling CUI, and one this pause leaves fully intact.

Phase 2 was a mandatory assessment by an authorized C3PAO as a condition of award, and that layer is where the system jammed.

The reasons for the pause are clear enough: the complexity of third-party assessments was creating real friction in the defense industrial base. As Under Secretary of War Michael Duffey framed it, the decision “ensures we maintain a strict security baseline while removing paralyzing costs.” Read that carefully, the baseline stays. What was removed is the friction of the third-party audit, not the obligation to secure the data underneath it.

What Exactly Did the CMMC Phase 2 Suspension Change?

The suspension is narrower than the headline suggests. What’s on hold is the requirement for external C3PAO verification under Phase 2. Your target CMMC level hasn’t changed and neither have the self-assessment requirements per Phase 1. The 60-day review is meant to recalibrate the program, not wind it down.

What hasn’t changed at all:

  • Your Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 obligation to safeguard covered defense information.
  • The requirement to maintain a current self-assessment score in the Supplier Performance Risk System (SPRS), refreshed annually and backed by real artifacts. For Level 2, that still means measuring against a 110-point scale with a minimum passing score of 88.
  • Your False Claims Act exposure tied to an inaccurate score, which carries more weight now, not less.

One more thing worth tracking: DoD has opened a public Request for Information (RFI), with responses due August 14, 2026. If the future shape of CMMC matters to your business, that comment window is your chance to help shape it.

At a glance: What the July 13 pause did, and didn’t touch

Requirement Status What it means for you
CMMC Phase 2 third-party (C3PAO) certification Paused The Nov. 10, 2026 milestone is on hold; no external assessment is required for now.
CMMC Phase 3 (Level 3) and Phase 4 milestones Paused Future implementation milestones are suspended until further notice.
DFARS 252.204-7012 Still in force Safeguard covered defense information and report cyber incidents, as before.
CMMC Phase 1 self-assessment (Levels 1 and 2) Still in force Required since Nov. 10, 2025; self-assessment is now the primary mechanism.
NIST SP 800-171 Rev 2 (110 controls) Still in force The security baseline is unchanged; Level 2 still needs a score of at least 88 out of 110.
SPRS score and annual affirmation Still in force Keep it current, accurate, and backed by evidence you can produce.
False Claims Act exposure (DOJ CCFI) Still in force An inaccurate self-attestation carries more weight now, not less.
Prime contractor requirements Still in force Many primes set their own security bar regardless of CMMC timelines.

Status reflects DoD guidance as of July 2026. Confirm against modifications to your specific contracts.

Does the CMMC Pause Reduce My Compliance Liability?

No. If anything, the pause sharpens that liability. Suspending third-party verification doesn’t lift the legal weight off your self-attestation; it concentrates on it, because there’s no longer an assessor scheduled to catch what your own review might have missed.

An SPRS score is not intended to be an estimate or a best guess. It should represent a documented evaluation of your implementation of NIST SP 800-171 and be supported by evidence demonstrating how each requirement was evaluated.

Woman focused on a laptop at her office desk with a stack of documents, reviewing compliance paperwork

With your SPRS score now standing on its own, that self-attestation is the government’s primary window into your posture. The Department of Justice (DOJ) Civil Cyber-Fraud Initiative has been using the False Claims Act to pursue exactly these cases since October 2021, and the cases are real rather than theoretical.

A California-based defense contractor settled for $9 million in 2022 after allegations it misrepresented compliance with NIST SP 800-171 requirements. A university settled for $1.25 million in 2024. And in mid-2026, a California defense contractor and its private equity firm settled for $1.75 million over self-disclosed cybersecurity violations.

These cases share a common thread: self-certified scores that couldn’t be backed by evidence when the government looked.

Many contractors posted their SPSR scores on professional judgment alone, without documented evidence behind each of the 110 controls, and that gap is exactly what the DOJ Civil Cyber-Fraud Initiative looks for. The moment the government asks you to prove a score you can’t substantiate, it stops being a compliance and becomes exposure.

The reassuring part is that the False Claims Act turns on knowing or reckless misrepresentations, not honest mistakes. A documented, good-faith assessment that fell short on a few controls sits in a different place than a score with nothing behind it. The practical takeaway is straightforward: keep the evidence that shows how you reached your number.

The Questions Worth Asking Right Now

The headline distracts you from the decision that matters. The real question was never whether you need to comply; you still do. It’s where to focus now, and that depends on where you are in the process.

If you’re already in a C3PAO assessment or close to finishing one, should you stop?

Probably not. On source-selection criteria we have reviewed solicitations released this year; agencies have weighed scoring in favor of C3PAO-certified offerors. In some cases, scoring a certification three times higher than a self-assessment. Contractors sitting out during the 60-day review period are creating an opening for those who don’t. A completed certification is a differentiator right now precisely because others are pausing.

If you’re not in a formal assessment, where should you focus?

Your SPRS score. It needs to be current, accurate, and backed by documentation you can defend. Your DFARS obligation is active today, and your score is visible to every prime evaluating you for work. Getting that right is the near-term priority regardless of how the task force review resolves.

Every contractor who has worked through their NIST 800-171 posture already has an asset. The question is whether your documentation is solid enough to defend it. A structured readiness review can tell you where the gaps are before the government does.

How Do I Scope My CUI Boundary for a Self-Assessment?

Before any controls can be assessed accurately, you need to know what you’re protecting and where it lives. This is where a lot of self-assessments start on shaky ground.

Contractors scope their CUI boundary informally, or not at all, and build their SPRS score on top of an incomplete picture. Controls can be technically compliant and still miss the mark if the boundary is wrong. That gap carries the same False Claims Act exposure as inaccurate control documentation.

CUI also moves. New contracts, new personnel, and expanding systems mean a boundary that was accurate 18 months ago may not reflect your environment today.

Getting this right is the prerequisite to everything else.

Glowing blue line graphs and network nodes over faint code, illustrating continuous cybersecurity compliance monitoring.

What Should Primes and Subcontractors Know Right Now?

Large prime contractors are not waiting for DoD to tell them what to require from their supply chain. Many run their own security requirements independent of CMMC timelines. Your SPRS score and the artifacts behind it remain table stakes for most prime relationships, review or no review. If you’re a sub and your prime hasn’t reached out yet, don’t assume the pressure is off. Reach out to them.

Final Thoughts: Keep the Compliance Clock Running

Start with your CUI boundary. If you don’t know what’s in scope, your self-assessment doesn’t either. Map it, document it, and keep it current as your contracts and systems evolve. From there, work through your self-assessment and make sure every control score is backed by evidence you can produce. Phase 1 has been in effect since November 10, 2025, so a SPRS score that isn’t current, accurate, and documented at the control level is a liability regardless of what Phase 2 does.

Then build a process for keeping your posture current between cycles. It’s the certification clock that’s paused, not the underlying compliance work. The two are easy to conflate right now, and that’s exactly the trap. Base your decisions on your actual business needs. Phase 2 will return in some form, and if you’ve kept your posture current, you’ll be ready.

Frequently Asked Questions

Is CMMC cancelled?

No. Only Phase 2, the third-party certification requirement, is suspended pending a 60-day review. CMMC Phase 1 self-assessment requirements remain in force, and DoD officials have not ruled out further changes once the review is complete.

Is CMMC Phase 1 still required?

Yes. Phase 1 has been in effect since November 10, 2025. You must still self-assess against NIST SP 800-171 and maintain a current score in SPRS.

When is the CMMC RFI due?

The Department opened a public Request for Information alongside the suspension. Responses are due August 14, 2026.

When will the Reform Task Force report?

Within 60 days of July 13, 2026 announcement, on or about mid-September 2026.

Does the pause affect DFARS 252.204-7012?

No. Your obligation to safeguard covered defense information is unchanged, and the DoD will continue enforcing NIST SP 800-171 through self-assessments and select government-led assessments.

Can I still face False Claims Act liability?

Yes. The DOJ Civil Cyber-Fraud Initiative continues to pursue inaccurate self-attestations, and cybersecurity settlements have continued into 2026. An inflated SPRS score is a legal liability with or without Phase 2.

How we can help

Aprio’s RAAS teams help defense contractors keep their CUI boundary, SPRS score, and evidence defensible year-round, so there are no unanswered questions when Phase 2 returns. Talk with our CMMC team to account for any new developments in your industry. Connect with us