What the Department of War Actually Announced
On July 13, 2026, the Department of War suspended CMMC Phase II — effective immediately, including pending and future implementation milestones across solicitations and contracts. Small suppliers were already seeing CMMC requirements appear in RFPs. Those are now suspended, and a 60-day study under a new CMMC Reform Task Force is underway.
The RFI — Your Window to Be Heard
The Department CIO published a Request for Information form. If you’re a vendor, subcontractor, or supplier, this is your opening to tell the government directly what the compliance burden actually looked like from your side. The Task Force is synthesizing that feedback into its recommendations over the next 60 days.
This Doesn't Erase Anything — What's Still in Force
Phase I self-assessments are still in place. The 110 NIST 800-171 controls didn’t go anywhere. DFARS 252.204-7012 still legally obligates you to protect federal data. And the government retains the right to audit. The suspension is a review, not a repeal — the timeline may change, but the obligation doesn’t.
The C3PAO Bottleneck Nobody Talks About
Part of what drove this: a limited pool of authorized assessors created a supply-and-demand squeeze, and small businesses were getting priced out. The pause gives the government room to fix that. But Phase II isn’t gone — the question is when it returns and how it rolls out through procurement.
If You Were Mid-Certification — What to Do Now
Breathe. The urgency is gone, which means you can actually think through where your money goes instead of accepting whatever offer lands on the table. If you haven’t started, this is a good time to start properly. You have time — you don’t have forever. Sixty days moves fast.
The Marching Orders — Be Honest About Your Self-Assessment
The elephant in the room: if you’re panicking about this suspension, it’s because you didn’t actually believe your own self-attestation. Do a real self-assessment. Close your gaps. Submit the RFI. Slow is smooth, smooth is fast — and this is prime time for exactly that.
// INCOMING SITREP
The episode is the rapid-response briefing. The companion Sitrep is the systematic breakdown — the four obligations still in force, why self-attestation risk goes UP not down, and the full marching orders, with a direct link to the Department of War's official statement. Read the SITREP dossier.
ACCESS THE BRIEF »Breaking Format: The CMMC Phase II Suspension
We broke our normal format for this one, because the news demanded it.
In Episode 023 — recorded just days ago — we walked defense contractors through the CMMC certification timeline in detail: the November 10 deadline for Phase II, the mandatory C3PAO third-party certification, the Level 2-to-Level 3 dependency, the whole clock bearing down on the defense industrial base. Two days later, the Department of War changed the picture.
On July 13, 2026, the Department suspended CMMC Phase II — effective immediately, including pending and future CMMC implementation milestones across Department of War solicitations and contracts. Small suppliers and vendors who were already seeing CMMC requirements appear in RFPs and bids? Those requirements are now suspended.
This transmission is the rapid-response briefing: what happened, what it means, and — most importantly — what it does not mean.
What the Department Actually Announced
Phase II was the mandatory third-party certification requirement. As we covered last episode, it meant you could no longer self-attest to Level 2 — you had to hire a certified third-party assessment organization (a C3PAO) to certify you. That’s the piece that’s on hold.
Alongside the suspension, the Department announced a 60-day study and a new CMMC Reform Task Force to conduct a top-to-bottom review of the program. The effort is tied to Secretary of War Pete Hegseth’s Acquisition Transformation System, and the stated goal is balance: maintain security without creating a barrier that pushes small and non-traditional businesses out of the defense industrial base entirely.
That concern wasn’t theoretical. Our CISO has been sitting in SBA meetings with small businesses across the country, and the pattern was consistent — companies saying they couldn’t afford compliance, that they’d stop bidding on federal contracts and pivot to private clients, or that they might have to close if federal work was the bulk of their business. The government’s aim here is scalable security, not more bureaucracy — cybersecurity verification that isn’t a barrier to entry.
There’s an action item in this for you. The Department CIO published a Request for Information form. If you’re a vendor, subcontractor, or supplier with something to say about the compliance burden, go fill it out. The Task Force is actively synthesizing industry feedback into its recommendations. This is a genuine window to have your voice heard — and those windows don’t stay open long.
What This Does NOT Mean
Here’s where contractors are going to get themselves in trouble.
This is not a cancellation. It’s a suspension and a review. The requirement may come back looking different, or with a longer timeline — but it’s coming back. And in the meantime, four things are completely unchanged:
Phase I self-assessments are still in place.
They’ve been in effect and they remain in effect. You still need to be at that security level, do the self-assessment, and have an executive sign the attestation confirming your controls are in place.
NIST SP 800-171 and the 110 controls are still the standard.
They didn’t disappear. That’s still your target, and the government explicitly retains the right to audit — they can come in and assess you directly if they have cause.
DFARS 252.204-7012 still binds you.
The clause requiring you to protect federal data is untouched. It has been in your contracts for years, and it’s exactly as binding today as it was last week.
False Claims Act exposure is unchanged.
If you self-assessed, self-attested, and the government later discovers that attestation wasn’t accurate, the DOJ can take you to court. As we covered in Episode 023, a false self-attestation is a fraud claim waiting to happen — and with third-party verification paused, self-attestation is now the only mechanism in play. That makes its accuracy your primary exposure, not a lesser one.
If you were already in the process of getting Level 2 — continue. This gives you a breather. It doesn’t give you an exit.
The C3PAO Bottleneck Behind the Pause
Part of what drove this decision is worth understanding, because it explains what the reform is likely to target.
There’s a limited pool of authorized C3PAOs, and basic supply and demand took over. With a small supply of assessors and the entire defense industrial base needing certification at once, prices climbed — and small businesses caught in the squeeze were the ones absorbing it. Call it what it is: contractors were getting gouged, not because anyone intended it, but because that’s what a bottleneck plus a hard deadline produces.
The pause gives the government room to fix that dynamic. But the underlying point stands: Phase II isn’t going away. The open questions are when the third-party certification requirement returns and how it rolls out through procurement — not whether it does.
If You Were Mid-Certification: What to Do Now
The most practical question from the episode: you were about to go through Level 2 — do you pump the brakes and wait for the 60-day review?
If you’re already in the process:
Breathe. Take the deep breath. The urgency is gone, and that’s genuinely good news — because now you can actually think through how you’re spending your money. You can investigate properly instead of accepting whatever offer lands on the table under deadline pressure. That’s a better outcome for you.
If you haven’t started yet:
This is a good time to start, precisely because there’s no immediate urgency. November 10 is not the date anymore. We just don’t know what the new date will be. People have been rushing to figure this out — continue that work, but do it right. Bring in someone who knows the controls and the CMMC requirements.
And the caution that matters:
You have some time. You don’t have forever. It’s a 60-day review, and they’re coming back with a decision.
There’s also a competitive argument here worth sitting with. Some companies will treat this as permission to step back and stop spending. Others will keep going — and end up ahead of the curve when the backlog returns and something gets pushed through. When that happens, the ones who stopped go to the back of the line.
The Marching Orders
Be honest about your self-assessment.
This is the elephant in the room. You were supposed to have an honest self-assessment showing compliance with the 110 controls. If this suspension made you panic — ask yourself why. Panic means you didn’t actually believe your own attestation. So do a real one. If your controls genuinely are in place, passing an assessment was never the problem; getting in the queue was.
Close your gaps — and use the POA&M runway.
If you have gaps, document them and work them. That’s what the time is for.
Submit the RFI and watch the clock.
Get the Department CIO’s form filled out. And mark your calendar — 60 days goes fast. Make sure you know what direction this is heading the moment the Task Force reports.
As our CISO put it: slow is smooth, and smooth is fast. This is prime time for exactly that. The pause is a boon — but a boon is time to move deliberately, not permission to stop moving.
The Bottom Line
The Department of War suspended a certification mechanism. It did not suspend the standard. It did not suspend the threat. And it did not suspend your legal obligation under DFARS to protect federal data.
NIST 800-171 is still enforced. Your self-assessment still has to be true. And in 60 days, some new version of this requirement shows up.
The contractors who hear “suspended” and stand down are going to be exposed on all three fronts — and scrambling again when the reformed program lands. The ones who treat this as breathing room to get genuinely secure will come out ready, compliant, and ahead.
The paperwork paused. The mission didn’t.
Go Deeper: The Full Breakdown
This episode is the rapid-response briefing. Our companion Sitrep is the systematic dossier: a section-by-section breakdown of the four obligations still in force, the counterintuitive reason your self-attestation risk goes up rather than down during the suspension, the full marching orders for the interim period — and a direct link to the Department of War’s official statement so you can verify every claim against the primary source yourself.
Trust but verify your own posture. Keep your self-assessment honest. Keep closing your gaps. Engage the review. Execute the standard.
// DECODED TRANSCRIPT
Access the full text logs of this transmission for compliance and review purposes.