On July 13, 2026, the Department suspended CMMC Phase II. The date every defense manufacturer had circled, November 10, 2026, is gone, and no replacement date exists. If you read that headline and felt relief, read the rest of this page before you act on it.

Here is the part most of the coverage buried. The certification got suspended. The obligation did not. DFARS clause 252.204-7012 still binds your company today, exactly as it did on July 12. Your prime still cannot award you covered work unless your assessment is current and posted. The annual affirmation you sign still carries the same exposure it carried last week. What went away was the outside assessor who was going to check your work. What stayed is all of the work.

What actually happened on July 13?

The Department announced the immediate suspension of CMMC Phase II requirements and stood up a reform task force to review the program. In its own words, the Phase II requirements were "originally scheduled for November 10, 2026," and "all Phase I self-assessment requirements remain firmly in place."

The review is aimed at aligning CMMC with the Acquisition Transformation System directives, which the Department describes as "prioritizing speed to capability, lowering barriers for small, medium, and non-traditional businesses, and replacing bureaucratic compliance with scalable, resilient cybersecurity measures."

Read that last clause again, because it is the most important sentence in the announcement, and I will come back to it.

One note on the source, since you will check it. The Department's CIO site now brands itself as the Department of War. The regulation still says Department of Defense, and this article follows the regulation.

What is still in force?

The program is paused in Phase 1, which is not the same as paused. Phase 1 has been running since November 10, 2025, and it still requires the following.

Level 1 is an annual self-assessment against the 15 requirements in FAR clause 52.204-21, with an annual affirmation, entered into SPRS. No plans of action are permitted.

Level 2 is a self-assessment every three years against the 110 security requirements in NIST SP 800-171 Revision 2, with annual affirmation, entered into SPRS. The requirement is imposed by DFARS clause 252.204-7012. Plans of action are permitted within limits and must be closed within 180 days.

The Department also said it will enforce compliance with NIST SP 800-171 Rev 2 "through self-assessments and select government-led assessments" during the review period. That phrase deserves your attention. A scheduled third-party assessment comes with a date on a calendar and months of runway. A government-led assessment arrives when it arrives.

One correction worth making, because the industry says it constantly and it is not what the regulation says. Your prime cannot see your SPRS score. DFARS 252.204-7020(f) limits access to DoD personnel and to the assessed contractor itself. What your prime has is stronger than a look at your number. Under 252.204-7020(g)(2), the prime may not award you a covered subcontract at all unless you have completed at least a Basic assessment within the last three years. Not a lower score, not an awkward conversation. No award. If your assessment has gone stale, you are not a supplier with a bad number, you are a supplier the prime is barred from using.

And the sentence the Department wrote into its own page, which answers the only question that matters:

This action does not eliminate the requirement for companies to protect information in accordance with DFARS clause 252.204-7012.

Does this mean we can stand the program down?

No, and the reasoning is worth understanding rather than taking on faith.

The controls did not change. The 110 requirements in NIST SP 800-171 are the same 110 requirements they were in June. What changed is who checks them and when. Before July 13, a certified third party was going to walk your enclave on a known date. Now the checking falls to you, to your annual affirmation, and to whatever the review returns.

That is not a lighter load. It is the same load with the deadline removed and the accountability moved onto your signature. An affirmation is a representation to the United States government. If the score behind it cannot be defended, the statute that governs the gap is not a cybersecurity regulation. It is the False Claims Act, and it does not care that Phase II was suspended.

Your prime does not care either. The flowdown in your contract came from DFARS 252.204-7012, not from the CMMC rollout schedule, and a prime that sent you a compliance letter in May did not send it because of a November date. If you want to know what your prime expects now, the answer is not in this article and it is not on a government website. Ask them. The suspension did not answer that question for you.

What does the reform actually signal?

Come back to that clause: "replacing bureaucratic compliance with scalable, resilient cybersecurity measures."

That is the Department saying, in public, that too much of what CMMC produced was paperwork rather than security. Anyone who has watched a manufacturer buy a binder of policies from a vendor, score themselves a 110, and change nothing on the shop floor already knew that. The Department has now written it down.

Read it as a signal about direction. Whatever the task force returns, it is unlikely to reward a company that bought documentation and likely to reward one that can show controls actually running. Those are different assets, and only one of them survives a change in the assessment regime.

This is the honest read, and I want to be plain that it is a read, not a fact. The task force has not reported. Nobody knows what replaces Phase II or when. What I can tell you is the shape of the bet, and the bet is this: the shop that built the controls into the work has the same operating capability on July 16 that it had on July 12. The shop that was racing a date now has nothing to race and nothing built.

What should we do this week?

Four things, in this order.

Pull your SPRS score and find the evidence behind it. Not the score. The evidence. If a government assessor asked tomorrow to see the artifacts behind any one of those 110 requirements, could you produce them without a scramble? That question was always the real one. The suspension just removed the excuse to answer it in October.

Look at your next affirmation date. That is your live deadline. It did not move. It is the one date in this whole regime that is still on your calendar, and it is the one that carries your signature.

Call your prime. Ask what their compliance letter means now. They may not know yet. The conversation is still worth having, and having it makes you the supplier who called.

Keep building. If you had a plan to close your gaps by November, the gaps are still there. The only thing that changed is that nothing external is forcing you now. That is precisely when the difference between a company with an operating discipline and a company with a deadline becomes visible.

The bottom line

The deadline was rented urgency, and the landlord just took it back. What is left is the urgency you actually own: a clause that binds today, an award your prime cannot make without your current assessment, and an affirmation you sign with your own name.

If your compliance program only made sense because of a date in November, you did not have a compliance program. You had a countdown. The companies that will be fine when the task force reports are the ones building the floor right now, while everyone else reads the headline as a reprieve.

Sources

  • DoD CIO, About CMMC. The July 13, 2026 suspension notice, the reform task force, the Phase 1 pause, the Level 1 and Level 2 self-assessment requirements, and the DFARS 252.204-7012 carve-out. Retrieved July 16, 2026.
  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. The clause that imposes the NIST SP 800-171 requirement and that the suspension explicitly leaves in force. Retrieved July 16, 2026. Note the trailing period in that link. It is part of the address, and acquisition.gov returns a 404 without it, which is why the link printed on the Department's own CMMC page does not resolve.
  • FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems. The 15 requirements behind CMMC Level 1.
  • NIST SP 800-171 Revision 2. The 110 security requirements referenced by DFARS 252.204-7012 and CMMC Level 2. NIST's page marks Revision 2 as withdrawn and superseded by Revision 3, and Revision 2 is still the correct reference here: the Department assesses against Revision 2, and the DoD CIO page cites it by name as of July 2026. Do not read the withdrawal banner as meaning the 110 requirements moved.
  • DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements. Paragraph (f) limits SPRS score access to DoD personnel and the assessed contractor. Paragraph (g)(2) is the one that binds your prime: it may not award a covered subcontract unless the subcontractor has completed a Basic assessment within the last three years. Retrieved July 16, 2026.
  • 32 CFR Part 170. The CMMC Program rule, including the plan-of-action provisions and the phased implementation the suspension pauses.