← Back Faculty Insights CMMC Phase II Suspension: What Changed, What Remains in Effect, and What Contractors Should Do Now July 16, 2026Last Updated: July 21, 2026 Research compiled by FPS | Current as of July 16, 2026FPS Experts: Eric Crusius and Perry KeatingOn July 13, 2026, the Department of War announced the immediate suspension of the next phase of the Cybersecurity Maturity Model Certification program. Phase II was scheduled to begin on November 10, 2026 and would have expanded the use of mandatory third-party CMMC assessments.What is the government saying about the suspension and what are they telling their personnel?The Department of War (DoW) characterizes the suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements as a strategic pause to review and reform the program over a 60-day period.https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/The DoW states that the suspension aligns with a broader Acquisition Transformation Strategy aimed at putting the acquisition enterprise on a "wartime footing" to rapidly expand production and the fielding of new technology. A major priority of this 60-day review is to ensure the Defense Industrial Base remains secure while lowering barriers to entry and avoiding "significant burden on the small and non-traditional businesses that are foundational to American manufacturing and innovation".The Under Secretary of War has issued strict directives to Program Managers, requiring activities, and contracting officers regarding how to handle procurements during this suspension:Only Self-Assessments Permitted: Personnel are instructed to only include CMMC Level 1 (Self) or Level 2 (Self) assessments in procurement requests. They are explicitly forbidden from designating third-party assessments, such as CMMC Level 2 (C3PAO) or Level 3 (DIBCAC), during this period.Amend Active Solicitations: If an active solicitation already includes a CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, personnel must initiate amendments to explicitly remove those requirements as soon as practicable.Modify Existing Contracts: For existing contracts or agreements that contain third-party certification requirements, contracting officers are directed to remove them via modification before the exercise of the next option period or during the next scheduled administrative modification.Enforce Existing Baselines: Personnel are told to continue enforcing baseline cybersecurity compliance with NIST SP 800-171 Rev 2 and the safeguarding and reporting requirements outlined in DFARS 252.204-7012.Suspend Waivers: Because program managers can simply choose requirements that do not mandate third-party assessments during this pause, no waivers are to be granted while the program is under review.What does the Cyber A/B say?In response to the suspension of the CMMC Phase II requirements, The Cyber AB (the official accreditation body for the program) released a statement expressing that they are "surprised and disappointed" by the pause. However, they remain highly confident in the program's long-term viability. https://www.cyberab.org/News-Events/Press-Releases/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements#!#article-titleHere are the key points from their statement and their CEO, Matthew Travis:Third-Party Verification is Crucial: The Cyber AB is confident that the immense investments already made by the defense industrial base and the "absolute criticality of third-party verification" will prove to be indispensable after the government's rigorous 60-day review. They are standing by to cooperate with the CMMC Reform Task Force to provide accurate information and recommend program improvements.The CMMC Ecosystem Remains Open: The organization explicitly clarified that only the Phase II implementation requirements are suspended. All other elements of the CMMC program remain fully operational and available. This includes voluntary C3PAO Level 2 certification assessments, CMMC professional exams, sanctioned training courses, and Registered Practitioner support services.Certifications Remain a Competitive Advantage: As mentioned previously, Travis stressed that NIST SP 800-171 and DFARS 7012 requirements remain firmly in place for contractors. He emphasized that achieving a Level 2 certification through a C3PAO remains a "compelling calling card" for subcontracting opportunities and acts as the "best insurance policy against False Claims Act risk".Commitment to Improvement: Travis noted that protecting the warfighter requires the right balance of "security and efficiency". While he defended the CMMC's private-sector, market-based approach as the "converse of bureaucracy," he acknowledged that there is still room for innovation and that stakeholders are eager to contribute to the reform.The Cyber AB also announced that they will further address the Phase 2 pause and the Reform Task Force at their upcoming CMMC Town Hall on July 28.What insights do the legal and compliance professionals such as Protiviti and Hunton Andrews Kurth give?Hunton's Advice Hunton advises contractors currently handling Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) on government contracts to:Maintain Audit-Level Rigor: Continue tracking NIST SP 800-171 Rev 2 self-assessment scores and 2026 submissions with the exact same rigor and documentation discipline that would be required for a formal third-party (C3PAO) audit.Preserve Granular Evidence: Preserve evidence that supports the implementation of each individual security control, rather than just keeping track of the final numeric score.Affirm Only Current Facts: Ensure that any sign-off by an affirming official is strictly based on verified, current facts, rather than aspirational or "future-state" compliance plans.Monitor Legal and Policy Developments: Closely monitor the CMMC Reform Task Force's 60-day review, as well as related False Claims Act (FCA) dockets, for signals regarding the ultimate shape of the compliance framework.What are the Cost Implications? CMMC Certification vs. NIST SP 800-171 Rev 2 Self-AssessmentBecause CMMC Level 2 is built directly on the 110 controls in NIST SP 800-171 Rev 2, the underlying technical remediation, system security plan (SSP), and plan of action and milestones (POA&M) work is largely the same either way. The real cost delta is the formal, independent C3PAO assessment layer that Phase II would have required. Illustrative, industry-wide ranges for a small-to-midsize DIB contractor are below; actual costs vary with scope, current security maturity, and number of systems handling CUI.Cost ComponentCMMC Level 2 (C3PAO Certification)NIST SP 800-171 Rev 2 (Self-Assessment Only)NIST SP 800-171 control remediation & implementation (initial year)$148,200 for small businesses and $543,400 for other than small businesses$148,200 for small businesses and $543,400 for other than small businessesSSP / POA&M documentation (according to industry studies)$12,000 - $60,000$12,000 - $60,000Formal assessment / attestation feeC3PAO assessment: $105,000 (DoD estimate)Self-assessment & annual affirmation: $36,643 (DoD estimate)Approximate total$265,200-$708,400$196,843 - $640,043 (no third-party audit fee)https://www.hunton.com/government-contracts-intelligence-briefing/dow-suspends-cmmc-phase-ii-nist-sp-800-171-self-assessment-becomes-the-interim-standard-with-rising-false-claims-act-exposureProtiviti's Advice Protiviti urges contractors to view the Phase II suspension as a "pause," not a cancellation, emphasizing that the current DoD review is evaluating how compliance is verified, not whether cybersecurity is required. https://www.protiviti.com/us-en/insights-paper/cmmc-phase-ii-suspension-facts-vs-fiction?utm_source=protiviti_social&utm_medium=organic_social&utm_campaign=insights_paperTheir recommendations include:Continue Protecting Data: Organizations must continue to safeguard CUI and FCI, as the underlying contractual requirements under DFARS 252.204-7012 and NIST SP 800-171 remain fully active and enforceable.Maintain Compliance Documentation: Contractors should keep up with required self-assessments, accurate SPRS score submissions, System Security Plans (SSPs), and Plans of Action & Milestones (POA&Ms). Protiviti stresses that evidence, audit trails, policies, and technical artifacts remain critical for demonstrating compliance.Beware of False Claims Act Risk: False Claims Act exposure has not changed. Contractors remain legally responsible for the accuracy of their self-assessments and compliance assertions made to the government, so they must be extremely careful about what they attest to.Use the Review Period Wisely: Instead of halting cybersecurity improvement efforts, contractors should use this 60-day review period to close known security gaps, mature their capabilities, and prepare for potential future government-led audits.Review Active Contracts: Organizations should monitor their active contracts and solicitations for potential modifications from contracting officers, and avoid making business decisions based on the false assumption that cybersecurity requirements have been relaxed.FACTS vs. FICTION:FictionFactKey point"CMMC has been canceled."CMMC has not been canceled. The Department of Defense has suspended the Phase II rollout and launched a review of the program. Phase I requirements remain in effect.Think "pause," not "cancel." The CMMC program remains active while DoD evaluates potential reforms."We no longer need to comply with NIST SP 800-171."NIST SP 800-171 requirements remain in place and continue to form the basis for protecting Controlled Unclassified Information (CUI).The security requirements remain. Organizations handling CUI must continue implementing and maintaining required controls."DFARS cybersecurity requirements are gone."DFARS 252.204-7012 requirements remain fully enforceable. Contractors are still required to protect covered defense information.Contractual obligations have not changed. The requirement to protect government information remains."We should stop our cybersecurity improvement efforts."Organizations should continue executing their cybersecurity roadmap and remediation activities.Continue the journey. Strong cybersecurity remains essential regardless of how the certification process evolves."All of our CMMC preparation work was wasted."Readiness efforts remain valuable and continue to support compliance, audit readiness, cybersecurity maturity, and operational resilience.Keep building. SSPs, POA&Ms, policies, procedures, evidence repositories, and security improvements still matter."The government is backing off cybersecurity."Cybersecurity remains a top priority for the DoD. The review focuses on certification processes and administrative burden-not security expectations.Cybersecurity is still the mission. The discussion is about how compliance is verified, not whether security is required."The government is accepting self-attestations again, so audit readiness no longer matters."Organizations remain responsible for demonstrating compliance and supporting self-assessment assertions with appropriate evidence.Evidence still matters. Documentation, policies, procedures, technical artifacts, and audit trails remain critical."If CMMC changes, we no longer need to identify and protect CUI."Organizations that receive, process, store, or transmit CUI remain responsible for protecting that information.The data did not change. Understanding where CUI resides and how it is protected remains fundamental."The DOJ will stop pursuing cybersecurity enforcement cases."False Claims Act exposure and DOJ Civil Cyber-Fraud Initiative enforcement remain unchanged.Be careful what you attest to. Companies must be able to support compliance claims with evidence."SPRS scores are no longer important."Self-assessments and SPRS reporting remain part of the current compliance framework.Maintain accurate records. Organizations should continue managing SPRS scores, documentation, and affirmations."Existing contracts with CMMC requirements will stay as-is."The DoD has indicated that certain solicitations and contracts containing CMMC certification requirements may be amended during the review period.Review your contracts carefully. Monitor modifications and guidance from contracting officers."Small businesses can just wait until the government decides what to do."The Reform Task Force is expected to deliver recommendations within 60 days, and future requirements may evolve quickly.Use this time wisely. Stay informed, improve cybersecurity, and maintain readiness for future changes."CMMC is over."The certification process is temporarily paused, but cybersecurity requirements remain in force.Continue protecting CUI and FCI. The security mission remainSourceshttps://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/https://www.cyberab.org/News-Events/Press-Releases/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements#!#article-titlehttps://www.hunton.com/government-contracts-intelligence-briefing/dow-suspends-cmmc-phase-ii-nist-sp-800-171-self-assessment-becomes-the-interim-standard-with-rising-false-claims-act-exposurehttps://www.protiviti.com/us-en/insights-paper/cmmc-phase-ii-suspension-facts-vs-fiction?utm_source=protiviti_social&utm_medium=organic_social&utm_campaign=insights_paper
Research compiled by FPS | Current as of July 16, 2026FPS Experts: Eric Crusius and Perry KeatingOn July 13, 2026, the Department of War announced the immediate suspension of the next phase of the Cybersecurity Maturity Model Certification program. Phase II was scheduled to begin on November 10, 2026 and would have expanded the use of mandatory third-party CMMC assessments.What is the government saying about the suspension and what are they telling their personnel?The Department of War (DoW) characterizes the suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements as a strategic pause to review and reform the program over a 60-day period.https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/The DoW states that the suspension aligns with a broader Acquisition Transformation Strategy aimed at putting the acquisition enterprise on a "wartime footing" to rapidly expand production and the fielding of new technology. A major priority of this 60-day review is to ensure the Defense Industrial Base remains secure while lowering barriers to entry and avoiding "significant burden on the small and non-traditional businesses that are foundational to American manufacturing and innovation".The Under Secretary of War has issued strict directives to Program Managers, requiring activities, and contracting officers regarding how to handle procurements during this suspension:Only Self-Assessments Permitted: Personnel are instructed to only include CMMC Level 1 (Self) or Level 2 (Self) assessments in procurement requests. They are explicitly forbidden from designating third-party assessments, such as CMMC Level 2 (C3PAO) or Level 3 (DIBCAC), during this period.Amend Active Solicitations: If an active solicitation already includes a CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, personnel must initiate amendments to explicitly remove those requirements as soon as practicable.Modify Existing Contracts: For existing contracts or agreements that contain third-party certification requirements, contracting officers are directed to remove them via modification before the exercise of the next option period or during the next scheduled administrative modification.Enforce Existing Baselines: Personnel are told to continue enforcing baseline cybersecurity compliance with NIST SP 800-171 Rev 2 and the safeguarding and reporting requirements outlined in DFARS 252.204-7012.Suspend Waivers: Because program managers can simply choose requirements that do not mandate third-party assessments during this pause, no waivers are to be granted while the program is under review.What does the Cyber A/B say?In response to the suspension of the CMMC Phase II requirements, The Cyber AB (the official accreditation body for the program) released a statement expressing that they are "surprised and disappointed" by the pause. However, they remain highly confident in the program's long-term viability. https://www.cyberab.org/News-Events/Press-Releases/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements#!#article-titleHere are the key points from their statement and their CEO, Matthew Travis:Third-Party Verification is Crucial: The Cyber AB is confident that the immense investments already made by the defense industrial base and the "absolute criticality of third-party verification" will prove to be indispensable after the government's rigorous 60-day review. They are standing by to cooperate with the CMMC Reform Task Force to provide accurate information and recommend program improvements.The CMMC Ecosystem Remains Open: The organization explicitly clarified that only the Phase II implementation requirements are suspended. All other elements of the CMMC program remain fully operational and available. This includes voluntary C3PAO Level 2 certification assessments, CMMC professional exams, sanctioned training courses, and Registered Practitioner support services.Certifications Remain a Competitive Advantage: As mentioned previously, Travis stressed that NIST SP 800-171 and DFARS 7012 requirements remain firmly in place for contractors. He emphasized that achieving a Level 2 certification through a C3PAO remains a "compelling calling card" for subcontracting opportunities and acts as the "best insurance policy against False Claims Act risk".Commitment to Improvement: Travis noted that protecting the warfighter requires the right balance of "security and efficiency". While he defended the CMMC's private-sector, market-based approach as the "converse of bureaucracy," he acknowledged that there is still room for innovation and that stakeholders are eager to contribute to the reform.The Cyber AB also announced that they will further address the Phase 2 pause and the Reform Task Force at their upcoming CMMC Town Hall on July 28.What insights do the legal and compliance professionals such as Protiviti and Hunton Andrews Kurth give?Hunton's Advice Hunton advises contractors currently handling Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) on government contracts to:Maintain Audit-Level Rigor: Continue tracking NIST SP 800-171 Rev 2 self-assessment scores and 2026 submissions with the exact same rigor and documentation discipline that would be required for a formal third-party (C3PAO) audit.Preserve Granular Evidence: Preserve evidence that supports the implementation of each individual security control, rather than just keeping track of the final numeric score.Affirm Only Current Facts: Ensure that any sign-off by an affirming official is strictly based on verified, current facts, rather than aspirational or "future-state" compliance plans.Monitor Legal and Policy Developments: Closely monitor the CMMC Reform Task Force's 60-day review, as well as related False Claims Act (FCA) dockets, for signals regarding the ultimate shape of the compliance framework.What are the Cost Implications? CMMC Certification vs. NIST SP 800-171 Rev 2 Self-AssessmentBecause CMMC Level 2 is built directly on the 110 controls in NIST SP 800-171 Rev 2, the underlying technical remediation, system security plan (SSP), and plan of action and milestones (POA&M) work is largely the same either way. The real cost delta is the formal, independent C3PAO assessment layer that Phase II would have required. Illustrative, industry-wide ranges for a small-to-midsize DIB contractor are below; actual costs vary with scope, current security maturity, and number of systems handling CUI.Cost ComponentCMMC Level 2 (C3PAO Certification)NIST SP 800-171 Rev 2 (Self-Assessment Only)NIST SP 800-171 control remediation & implementation (initial year)$148,200 for small businesses and $543,400 for other than small businesses$148,200 for small businesses and $543,400 for other than small businessesSSP / POA&M documentation (according to industry studies)$12,000 - $60,000$12,000 - $60,000Formal assessment / attestation feeC3PAO assessment: $105,000 (DoD estimate)Self-assessment & annual affirmation: $36,643 (DoD estimate)Approximate total$265,200-$708,400$196,843 - $640,043 (no third-party audit fee)https://www.hunton.com/government-contracts-intelligence-briefing/dow-suspends-cmmc-phase-ii-nist-sp-800-171-self-assessment-becomes-the-interim-standard-with-rising-false-claims-act-exposureProtiviti's Advice Protiviti urges contractors to view the Phase II suspension as a "pause," not a cancellation, emphasizing that the current DoD review is evaluating how compliance is verified, not whether cybersecurity is required. https://www.protiviti.com/us-en/insights-paper/cmmc-phase-ii-suspension-facts-vs-fiction?utm_source=protiviti_social&utm_medium=organic_social&utm_campaign=insights_paperTheir recommendations include:Continue Protecting Data: Organizations must continue to safeguard CUI and FCI, as the underlying contractual requirements under DFARS 252.204-7012 and NIST SP 800-171 remain fully active and enforceable.Maintain Compliance Documentation: Contractors should keep up with required self-assessments, accurate SPRS score submissions, System Security Plans (SSPs), and Plans of Action & Milestones (POA&Ms). Protiviti stresses that evidence, audit trails, policies, and technical artifacts remain critical for demonstrating compliance.Beware of False Claims Act Risk: False Claims Act exposure has not changed. Contractors remain legally responsible for the accuracy of their self-assessments and compliance assertions made to the government, so they must be extremely careful about what they attest to.Use the Review Period Wisely: Instead of halting cybersecurity improvement efforts, contractors should use this 60-day review period to close known security gaps, mature their capabilities, and prepare for potential future government-led audits.Review Active Contracts: Organizations should monitor their active contracts and solicitations for potential modifications from contracting officers, and avoid making business decisions based on the false assumption that cybersecurity requirements have been relaxed.FACTS vs. FICTION:FictionFactKey point"CMMC has been canceled."CMMC has not been canceled. The Department of Defense has suspended the Phase II rollout and launched a review of the program. Phase I requirements remain in effect.Think "pause," not "cancel." The CMMC program remains active while DoD evaluates potential reforms."We no longer need to comply with NIST SP 800-171."NIST SP 800-171 requirements remain in place and continue to form the basis for protecting Controlled Unclassified Information (CUI).The security requirements remain. Organizations handling CUI must continue implementing and maintaining required controls."DFARS cybersecurity requirements are gone."DFARS 252.204-7012 requirements remain fully enforceable. Contractors are still required to protect covered defense information.Contractual obligations have not changed. The requirement to protect government information remains."We should stop our cybersecurity improvement efforts."Organizations should continue executing their cybersecurity roadmap and remediation activities.Continue the journey. Strong cybersecurity remains essential regardless of how the certification process evolves."All of our CMMC preparation work was wasted."Readiness efforts remain valuable and continue to support compliance, audit readiness, cybersecurity maturity, and operational resilience.Keep building. SSPs, POA&Ms, policies, procedures, evidence repositories, and security improvements still matter."The government is backing off cybersecurity."Cybersecurity remains a top priority for the DoD. The review focuses on certification processes and administrative burden-not security expectations.Cybersecurity is still the mission. The discussion is about how compliance is verified, not whether security is required."The government is accepting self-attestations again, so audit readiness no longer matters."Organizations remain responsible for demonstrating compliance and supporting self-assessment assertions with appropriate evidence.Evidence still matters. Documentation, policies, procedures, technical artifacts, and audit trails remain critical."If CMMC changes, we no longer need to identify and protect CUI."Organizations that receive, process, store, or transmit CUI remain responsible for protecting that information.The data did not change. Understanding where CUI resides and how it is protected remains fundamental."The DOJ will stop pursuing cybersecurity enforcement cases."False Claims Act exposure and DOJ Civil Cyber-Fraud Initiative enforcement remain unchanged.Be careful what you attest to. Companies must be able to support compliance claims with evidence."SPRS scores are no longer important."Self-assessments and SPRS reporting remain part of the current compliance framework.Maintain accurate records. Organizations should continue managing SPRS scores, documentation, and affirmations."Existing contracts with CMMC requirements will stay as-is."The DoD has indicated that certain solicitations and contracts containing CMMC certification requirements may be amended during the review period.Review your contracts carefully. Monitor modifications and guidance from contracting officers."Small businesses can just wait until the government decides what to do."The Reform Task Force is expected to deliver recommendations within 60 days, and future requirements may evolve quickly.Use this time wisely. Stay informed, improve cybersecurity, and maintain readiness for future changes."CMMC is over."The certification process is temporarily paused, but cybersecurity requirements remain in force.Continue protecting CUI and FCI. The security mission remainSourceshttps://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/https://www.cyberab.org/News-Events/Press-Releases/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements#!#article-titlehttps://www.hunton.com/government-contracts-intelligence-briefing/dow-suspends-cmmc-phase-ii-nist-sp-800-171-self-assessment-becomes-the-interim-standard-with-rising-false-claims-act-exposurehttps://www.protiviti.com/us-en/insights-paper/cmmc-phase-ii-suspension-facts-vs-fiction?utm_source=protiviti_social&utm_medium=organic_social&utm_campaign=insights_paper