DoD Suspends CMMC Phase 2: What Changed on July 13 — and What Didn't | Stealth Technology Group
Update — July 13, 2026: DoD paused CMMC Phase 2 certification. NIST 800-171 and your signed affirmation did not pause. See What Still Applies →
Compliance & Certification

DoD Suspends CMMC Phase 2: What Changed on July 13 — and What Didn't

Michael Bannach, CISSP July 2026
~6 min read

On July 13, 2026, the Department of Defense did something few in the defense industrial base saw coming: it suspended the Phase 2 implementation of the CMMC program — the requirement, scheduled to take effect November 10, 2026, that contractors hold a third-party (C3PAO) CMMC Level 2 certification as a condition of contract award.

The announcement came via memoranda from the Department's Chief Information Officer and the Under Secretary of Defense for Acquisition and Sustainment, and it landed with two very different readings. Some contractors heard "CMMC is dead" and started cutting their compliance budgets. Others read the actual documents. This post is for the second group — and for the first group, before that budget decision becomes expensive.

What Was Actually Suspended

  • Third-party C3PAO certification as a condition of award. The November 10 trigger date for mandatory Level 2 certification in new solicitations is off.
  • DIBCAC-led Level 3 assessments during the review period.
  • DFARS 252.204-7021 certification language in active solicitations. Contracting officers were directed to amend solicitations and modify contracts to remove the paused requirements.

Why DoD Hit Pause

The Department's stated reasoning was arithmetic, not philosophy. More than 100,000 defense contractors would eventually need assessments; roughly a hundred authorized assessment organizations exist to perform them. Officials also cited compliance costs projected in the billions per year falling hardest on the small and mid-sized businesses DoD is actively trying to keep in the industrial base. In announcing the pause, the DoD CIO was blunt: the math simply didn't work — while emphasizing that the Department was not reducing cybersecurity requirements.

Alongside the suspension, DoD stood up a CMMC Reform Task Force with a 60-day mandate to recommend changes — everything from small adjustments to a substantial overhaul is on the table — and issued a public Request for Information seeking industry input on cost drivers and reforms.

What Did NOT Pause — Read This Twice

Here's the part that separates informed contractors from exposed ones. Every one of the following remains fully in force:

Requirement Status After July 13
All 110 NIST SP 800-171 controls (DFARS 252.204-7012) Still contractually required for anyone handling CUI
Level 1 / Level 2 self-assessments in solicitations Still required — Phase 1 was not suspended
SPRS score submission (DFARS 7019/7020) Still required and still auditable
Annual executive affirmation of continuous compliance Still required — with False Claims Act exposure attached
Incident reporting (DFARS 7012) Unchanged
Subcontractor flow-down Unchanged — primes still hold you to it
Existing C3PAO certifications Remain valid; voluntary assessments continue

Key Takeaway: DoD paused the third-party assessor — not the requirements, and not your signature. An executive at your company still affirms, annually and under legal exposure, that your NIST 800-171 self-assessment is accurate. That obligation didn't move an inch on July 13.

The Prime Contractor Wildcard

Within days of the announcement, the major primes made something clear: DoD's pause is not their pause. Supplier notices urged subcontractors to keep maturing their cybersecurity programs, and some primes maintained their own Level 2 certification deadlines for suppliers regardless of the federal timeline. If your revenue flows through a prime, their supplier requirements are your requirements — and primes now view a strong, evidence-backed posture as a way to de-risk their own supply chains during the uncertainty.

What Smart Contractors Are Doing Now

  • Verifying their SPRS score against evidence — the affirmation obligation makes accuracy the top priority.
  • Continuing NIST 800-171 implementation — every plausible outcome of the review is built on the same 110 controls, so no work is wasted.
  • Closing POA&M items instead of carrying them.
  • Watching their solicitations for amended language as contracting officers implement the change.
  • Talking to their primes before canceling or scheduling anything assessment-related.

The pause is real. So is everything it didn't touch. Contractors who use this window to get their evidence in order will be glad they did — whatever the task force sends back.

Michael Bannach

Michael Bannach, CISSP

Michael Bannach is the President & CEO of Stealth Technology Group, a CyberAB Registered Provider Organization. He holds the Certified Information Systems Security Professional (CISSP) credential and brings 25+ years of enterprise IT and cybersecurity experience guiding defense contractors through NIST 800-171 implementation and CMMC readiness.

Not sure what the pause means for your contracts?

We'll walk your specific contract clauses and prime requirements and tell you exactly what still applies — no charge, no sales pitch.

Get Started Today