The Department’s July 13 suspension delays CMMC’s next assessment phase, including new Level 2 C3PAO and Level 3 DIBCAC designations. It does not suspend self-assessments, SPRS records, or contractual safeguards for covered defense information.

Key takeaways

  • The planned November 10, 2026 transition to CMMC Phase II has been suspended, with no replacement date announced in the official materials reviewed.
  • During the suspension, requiring activities may designate CMMC Level 1 (Self) or Level 2 (Self), but not Level 2 C3PAO or Level 3 DIBCAC assessments.
  • Level 2 self-assessments remain tied to the 110 requirements in NIST SP 800-171 Rev. 2, with assessment results and annual affirmations entered in SPRS.
  • Applicable DFARS 252.204-7012 safeguards, incident-reporting duties and subcontract flowdowns remain contractual obligations.
  • Contractors should review active solicitations and contracts for amendments or modifications rather than assuming preexisting CMMC language has automatically changed.

A July policy change, not an August compliance holiday

The Department of Defense, identified in current official materials as the Department of War, suspended the planned transition to Cybersecurity Maturity Model Certification Phase II on July 13, 2026. The Phase II transition had been scheduled for November 10, 2026. The Department also put pending and future CMMC implementation milestones on hold while a CMMC Reform Task Force conducts a 60-day review of the program.

The distinction matters for defense-facing manufacturers, installers, integrators and technology suppliers: this is a pause in the next assessment phase, not a withdrawal of baseline safeguarding duties. The Department’s release and CIO guidance expressly preserve Phase I self-assessment requirements and the contractual requirement to protect covered defense information.

What the suspension stops

During the suspension period, program managers and requiring activities may include only CMMC Level 1 (Self) or CMMC Level 2 (Self) requirements in procurement requests and requirement documents. They may not designate CMMC Level 2 assessments performed by a CMMC Third-Party Assessment Organization, commonly called a C3PAO, or Level 3 assessments performed by the Defense Industrial Base Cybersecurity Assessment Center.

The implementing guidance also directs action on procurement documents already in motion. For active solicitations containing Level 2 C3PAO or Level 3 DIBCAC requirements, requiring activities are to initiate amendments removing those requirements. For existing contracts or agreements carrying those designations, contracting or agreements officers are directed to remove them through a modification before the next option period or at the next scheduled administrative modification.

That direction should not be read as an automatic revision to every document. Bidders and subcontractors should examine the specific solicitation, award, modification and flowdown they are working under, and address unresolved requirements with the responsible contracting channel.

What remains in place under Phase I

CMMC Level 1 remains an annual self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21 for systems handling Federal Contract Information. CMMC Level 2 self-assessments remain required on a three-year cycle for applicable procurements, with annual affirmation. The Department’s CMMC guidance states that Level 2 Self is aligned to the 110 requirements in NIST SP 800-171 Revision 2.

Assessment results and affirmations remain operationally important because the guidance calls for their entry in the Supplier Performance Risk System. A lapse in the required annual Level 2 affirmation can cause the related assessment status to lapse. Teams responsible for estimating, procurement, IT, physical-security integration and project delivery should therefore keep the supporting evidence behind their declared status current rather than treating the pause as a reason to defer documentation.

DFARS duties still govern covered defense information

The Department’s suspension memo states that the cybersecurity obligations in DFARS 252.204-7012 remain effective. For covered contractor information systems outside government-operated IT services, that clause requires implementation of the applicable NIST SP 800-171 security requirements, subject to the contract and authorized contracting-officer direction.

The clause also retains practical incident-response obligations. A contractor that discovers a cyber incident affecting a covered contractor information system or covered defense information must review for compromise and rapidly report the incident to DoD; the clause defines rapid reporting as within 72 hours of discovery. It also requires preservation and protection of affected-system images and relevant monitoring or packet-capture data for at least 90 days after the report.

For prime contractors, the requirement to flow DFARS 252.204-7012 down to subcontractors whose performance involves covered defense information remains especially significant. Cybersecurity due diligence should extend to field-service firms, engineering partners, managed IT providers and other lower-tier suppliers that may receive, create, store or transmit protected project information.

A practical response for contractors and integrators

Organizations should separate assessment timing from security implementation. First, identify which systems, file repositories, engineering workstations, collaboration platforms and cloud services process or protect covered defense information or CUI. Next, map the applicable contract clauses and CMMC status requirements to those systems and to each relevant subcontractor.

Maintain evidence supporting self-assessment results: system security plans, asset and software inventories, access-control records, multifactor-authentication deployment, patch and vulnerability-management records, backup and recovery evidence, incident-response procedures, training records and plans of action and milestones where permitted. Procurement teams should also retain current SPRS and affirmation ownership information so that responsibility does not become unclear during a bid or option exercise.

The reform review may change how CMMC is assessed later. For now, the more defensible operating assumption is that the Department has delayed certain independent-assessment requirements while continuing to enforce the cyber hygiene and contractual safeguards that protect defense information.