A dark tactical graphic showing the four-phase CMMC rollout timeline with Phase 2 marked SUSPENDED in amber and Phase 1 still active in blue, headlined 'CMMC Phase II — Suspended: The Baseline Still Stands,' indicating a 60-day Department of War review.
SITREP // GOVCON // CMMC PHASE II SUSPENDED

CMMC Phase II Suspended: What the Department of War’s Announcement Actually Means for Defense Contractors

On July 13, 2026, the Department of War suspended CMMC Phase II — the mandatory third-party certification that was set to take effect this November — and launched a 60-day review of the entire program. If your first instinct is to stand down your compliance work, read this first. The suspension changes the deadline and the assessment mechanism. It does not change your legal obligation to protect federal data. Phase I self-assessments remain mandatory, NIST SP 800-171 Rev 2 is still the enforced standard, and DFARS 252.204-7012 still binds every contractor and subcontractor exactly as it did last week. Here is what actually changed, what didn't, and why the contractors who keep executing are the ones who win when the rules re-form.

On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements — the mandatory third-party certification that was scheduled to take effect on November 10, 2026 — and opened a 60-day review of the entire Cybersecurity Maturity Model Certification program.

For the defense industrial base, this is a significant development, and the reaction across the sector today will split into two camps. One camp will read “suspended” as “cancelled” and stand down their compliance work entirely. The other will recognize that a pause in a deadline is not a repeal of an obligation. The first camp is walking into a costly misunderstanding. This dossier is for the second.

Here is the disciplined read on what actually changed, what explicitly did not, and what a defense contractor should do about it starting now.

What Actually Changed

The Department suspended the transition to Phase II, effective immediately — including pending and future CMMC implementation milestones across Department of War solicitations and contracts. In practical terms, the mandatory requirement to obtain third-party certification from a C3PAO before contract award, which was the defining feature of the November 10 Phase II milestone, is on hold.

The Department also announced a 60-day study and a new CMMC Reform Task Force to conduct a top-to-bottom review of the certification program. According to the release, the effort is tied to Secretary of War Pete Hegseth’s Acquisition Transformation System, with stated goals of prioritizing speed to capability and lowering barriers for small, medium, and non-traditional businesses. The Department cited data, including reporting from the Small Business Administration, indicating that CMMC compliance costs were pushing innovative companies out of the defense industrial base. The Task Force will synthesize industry feedback gathered through a public Request for Information and deliver its final report to the Department CIO within 60 days.

You can read the announcement in full in the Department of War’s official release, Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements, published July 13, 2026. We recommend every contracts and compliance lead read the primary source directly — the distinctions in the next section come straight from it.

In short: the third-party certification mechanism and its November deadline are paused while the government reconsiders how — not whether — to enforce cybersecurity across the DIB.

What Did NOT Change — And This Is the Part That Matters

Read the announcement carefully and the throughline is unmistakable: the government paused a compliance mechanism, not a security obligation. Four things remain fully in force.

Phase I self-assessments remain firmly in place.

The announcement is explicit on this point. If your contracts require a Level 1 or Level 2 self-assessment, that requirement did not move. You are still expected to assess yourself against the standard and stand behind that assessment.

NIST SP 800-171 Rev 2 is still the enforced standard.

The Department stated plainly that during this interim period it will enforce cybersecurity compliance with NIST SP 800-171 Rev 2 — through self-assessments and select government-led assessments. The 110 controls that formed the backbone of CMMC Level 2 did not disappear. The government simply shifted, for now, from third-party verification back toward self-attestation and its own spot-checks. Note that phrase carefully: select government-led assessments. The government reserving the right to assess you directly is not a relaxation of the standard.

DFARS clause 252.204-7012 still binds you.

This is the line every contractor needs to internalize. The release states directly that the action does not eliminate the requirement to protect federal data, and that all defense contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012. That clause — with its requirements to implement NIST 800-171 and to report cyber incidents within 72 hours — has been in your contracts for years, and it is untouched. The legal obligation to protect Controlled Unclassified Information is exactly as binding today as it was last week.

The False Claims Act exposure did not go anywhere.

Because self-assessment is now the operative mechanism, the accuracy of your self-attestation matters more than ever, not less. If you attest to a NIST 800-171 posture you cannot actually demonstrate, and you are handling federal contracts, the Department of Justice’s Civil Cyber-Fraud Initiative still has every tool it had yesterday. A suspended third-party audit does not sanitize a false self-assessment.

// INCOMING TRANSMISSION

Status: Secure Episode 024 — The CMMC Phase II Suspension: What Defense Contractors Need to Do Now breaks format for a rapid-response briefing on the announcement. Our CISO brings the view from inside SBA meetings with small businesses, explains the C3PAO pricing squeeze that drove the reform, and answers the question every contractor mid-certification is asking. Listen for the operator's read on why 'suspended' is not 'safe.'

INITIATE PLAYBACK »

Why “Suspended” Is Not “Safe”

The strategic misread available today is seductive: the deadline moved, so the pressure is off, so the budget can be reallocated. Resist it, for three reasons.

First, the threat did not pause. The adversaries targeting the defense industrial base — the ransomware-as-a-service operators, the credential-harvesting campaigns, the nation-state actors pre-positioning in critical infrastructure — did not read the Department of War’s press release and stand down. The reason CMMC exists is that defense contractors are under sustained attack. That reality is completely unchanged by a shift in certification paperwork.

Second, the standard is still the standard. The government did not say the DIB is over-secured. It said the certification process was too costly and bureaucratic for small and non-traditional businesses. The 60-day review is explicitly aimed at producing “realistic, scalable security measures” — not at lowering the security baseline. Reading a process reform as a security holiday inverts the actual message.

Third, this is a suspension and a review, not a repeal. In 60 days, the Task Force delivers a report, and some new form of enforcement will follow. The contractors who used this window to keep maturing their NIST 800-171 posture will be ready for whatever the reformed program looks like. The contractors who stood down will be doing the same scramble in a few months that they were doing this month — except with less runway and, quite possibly, a competitive field that has moved on without them.

The Opportunity Hiding in the Pause

Here is the reframe worth sitting with. For months, the pressure driving CMMC readiness was a hard November deadline and a C3PAO queue that was filling faster than contractors could book slots. That external clock created a scramble. The suspension removes the scramble — and hands disciplined contractors something rare: time to do the work properly instead of frantically.

The organizations that treat this as breathing room to genuinely close their NIST 800-171 gaps — to run the real risk assessment, remediate the actual weaknesses, and build a defensible, documented security posture — come out of the 60-day window stronger and calmer than they went in. When the reformed requirements land, they adapt from a position of readiness rather than starting from zero. And in the meantime, they are actually more secure, which was the entire point.

The paperwork paused. The mission didn’t.

Marching Orders During the Suspension

Keep your Phase I self-assessment current and honest.

It is still required. Make sure your SPRS score reflects reality, not aspiration.

Continue implementing NIST SP 800-171 Rev 2.

It remains the enforced standard, and it is the foundation of whatever the reformed program becomes. Every control you implement now is durable regardless of how the certification mechanism changes.

Do not let a valid self-assessment drift into a false one.

With self-attestation back as the operative mechanism, the accuracy of your attestation is your primary exposure. If there is daylight between what you attested and what you run, close it.

Watch for the RFI and the 60-day report.

The Department is actively soliciting industry feedback. If compliance cost has been a genuine barrier for your organization, this is the window to have your voice heard — and to be ready to move the moment the reformed requirements are published.

Keep protecting covered defense information.

DFARS 252.204-7012 is unchanged. The incident-reporting clock, the safeguarding requirement — all of it still applies.

Execute the Standard

The Department of War suspended a certification mechanism. It did not suspend the threat, the standard, or your contractual and legal obligation to protect federal data. The contractors who understand that distinction — who keep executing on NIST 800-171 while the certification program is redesigned — are the ones who will be ready, secure, and competitive when the new rules take shape. The ones who mistake a paused deadline for a permission slip will find themselves exposed on all three fronts.

If your organization needs to make sense of what this suspension means for your specific contracts, keep your NIST 800-171 self-assessment defensible, or use this window to genuinely close your security gaps before the program re-forms, that is the work we do. Verify your security posture at watchur6.com/secure, or establish a secure line at watchur6.com/contact.

Trust but verify your own posture. The standard is still the standard. Execute it.

This Sitrep is based on the Department of War’s official release dated July 13, 2026. As the 60-day review progresses, guidance may evolve — we will update the WatchUr6 Sitrep as the reformed program takes shape.

SECURE YOUR PERIMETER.

DON'T WAIT FOR THE BREACH TO READ THE SITREP.

Join The Watch for immediate access to Declassified Sitreps and Strategic Intel before the threat reaches your door.