Austin Buonasera
 • 
August 1, 2026
 • 
6
 Minute read

CMMC Phase II Is Temporarily Suspended. Your Compliance Work Is Not.

The Phase II suspension changes how CMMC may be assessed. It does not erase Phase I, NIST SP 800-171, DFARS 7012, or False Claims Act risk.

Quick Summary

Phase II is suspended while the DoW reviews the CMMC program. Phase I, NIST SP 800-171, DFARS 252.204-7012, 7019, 7020, and the duty to protect federal data remain. Keep fixing known gaps, make sure your score is defensible, and do not claim compliance you cannot prove.

Sunset over foggy mountains with dark silhouettes and a cloudy sky.

The headline is real. The conjecture is not useful.

On July 13, 2026, the Department of War suspended CMMC Phase II. It had been scheduled to take effect on November 10. Almost immediately, contractors started hearing that CMMC was dead, third-party assessments were finished, and Anti-CMMCers were shouting on LinkedIn that spending another dollar on compliance would be a waste.

That is bad advice.

CMMC L2 is not suspended. Phase II is suspended while the DoW conducts a 60-day review of the program. The requirement to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) is not suspended. Phase I self-assessments are still in place. NIST SP 800-171 Revision 2 is still the security baseline for contractors handling CUI. DFARS 252.204-7012, 7019, or 7020 did not disappear from anybody's contract.

Here's the simple version: the government is reconsidering how compliance should be verified. You still have to comply.

What was actually suspended

The DoW announcement suspended the move into Phase II, including the broader use of third-party assessments that was supposed to begin after November 10, 2026. It also paused pending and future CMMC implementation milestones while a new CMMC Reform Task Force reviews the program.

The task force has 60 days to deliver recommendations to the DoW CIO. During that period, the DoW says it will enforce NIST SP 800-171 Revision 2 through self-assessments and selected government-led (DIBCAC) assessments.

Phase I stays in place. Depending on the contract and the information involved, that can still mean a Level 1 or Level 2 self-assessment, a SPRS or eMass submission, an affirmation, and maybe even closing eligible POA&M items on schedule.

The Department's current CMMC guidance could not be much clearer: "This action does not eliminate the requirement for companies to protect information in accordance with DFARS clause 252.204-7012."

So no, this is not a 60-day break from cybersecurity. It is a review of how the certification program has been built and rolled out.

Small contractors have a legitimate complaint

I understand why a lot of small defense contractors are frustrated. The cost problem is real.

The Small Business Administration says total compliance costs could approach $593,800 for some small firms that need third-party certification and $388,600 for firms allowed to self-assess. Whether those estimates fit every company is beside the point. Personally, I strongly disagree with those figures. I think there is almost no data to support those claims. However, I recognize that a under the current program practices, a small manufacturer can spend a painful amount of money getting ready before it is eligible to win the work that would help pay for the effort.

The standard government answer has been that contractors can recover compliance costs through contract pricing or indirect rates. That may be true on paper. It does not solve the immediate cash-flow problem. The contractor still fronts the money, and recovery may be spread across years of performance.

That can shut good companies out of the Defense Industrial Base. It can also push companies to leave defense work entirely. The DoW is right to ask whether the current approach protects federal data without making it unnecessarily hard for small and non-traditional suppliers to compete.

I hope the review produces a more practical program. We should be able to lower the cost of proving compliance without lowering the level of security. But contractors should not turn a valid criticism of CMMC into an excuse to ignore requirements that are already in their contracts. There are accredited low-cost, low-barrier to entry CMMC Enclave solutions already available. For example, a 5 person company could be assessment ready is as soon as two weeks for under 20k using ATX Defense's CMMC Space built on Google Workspace and Google Cloud. Sound crazy? It's not. Just ask them how many C3PAOs are using their platform to meet the CMMC L2 requirements themselves. As a Google partner, that would be (and has been) my first recommendation to a small business needing quick, streamlined CMMC L2 compliance.

CMMC did not create the underlying obligation

This is the part that gets lost whenever CMMC is delayed or revised.

CMMC was created to verify security requirements that already existed. It did not invent the requirement to protect CUI.

If DFARS 252.204-7012, 7019, and/or 7020 applies to your contract, you still have to provide adequate security for covered contractor information systems. You still have to protect covered defense information and follow the incident reporting and preservation requirements. If the contract requires NIST SP 800-171, those 110 controls still must be properly implemented and documented.

Your prior representations are still there too. That includes your SPRS scores, self-assessments, annual affirmations, System Security Plans, and any Plan of Action and Milestones.

Those documents and scores need to match the environment. A policy is not proof that a control works. Buying a security product is not the same as configuring and monitoring it. And "our consultant handled the score" is not going to be a satisfying answer if the score is wrong.

Ask a blunt question: if the government or a prime asked for evidence tomorrow, could you produce it?

The False Claims Act risk did not pause

This is why telling contractors to stop all compliance work is more than careless. It can put the company in a worse position.

The Department of Justice has been using the False Claims Act in cases where contractors allegedly attested to one level of cybersecurity but delivered another. Recent settlements have involved missing System Security Plans, incomplete implementation of NIST SP 800-171, inaccurate assessment scores, and failures to follow contract security requirements.

During 2025, DOJ announced cybersecurity-related settlements involving MORSECORP, Raytheon companies and Nightwing, Aero Turbine, Georgia Tech Research Corporation, Swiss Automation, and others. In June 2026, Alabama defense contractor LOGZONE agreed to pay $507,144 to resolve allegations that it failed to comply with Navy cybersecurity requirements.

These were settlements of allegations, not trial verdicts. That distinction matters. The enforcement trend matters too.

DOJ has already made clear through its Civil Cyber-Fraud Initiative that cybersecurity promises can create False Claims Act exposure. A change to the CMMC assessment schedule does not change what your company submitted to SPRS, certified to a contracting officer, included in a proposal, or billed the government to provide.

If you know the score is wrong or a required control is missing, waiting for CMMC reform does not fix either problem.

What I would do during the review

First, check the contracts. Look at the clauses in current contracts and subcontracts, the flow-down language, the data you receive, and the statements the company has already made. Work from the actual requirement, not what somebody said on LinkedIn.

Then make sure the CUI scope is right. You need to know where CUI comes in, where it goes, who can reach it, and which systems are in scope. An environment that is scoped too broadly becomes needlessly expensive. An environment scoped too narrowly leaves data exposed.

Go back through the SPRS scores and test the controls behind them. Confirm the math. Confirm the evidence. If the score is not supportable, deal with it now.

Keep working on the basics: the SSP, open POA&M items, multi-factor authentication, properly managed devices, privileged access management, audit logging, backups, training, and incident reporting. None of that work becomes useless if the government changes the assessment model. Those are the bare-minimum practices that protect the data and the mission.

Keep evidence as the work gets done. Save configuration records, tickets, screenshots, logs, access reviews, and training records. Do not try to rebuild two years of evidence the week before somebody asks for it.

Be careful with the company's language too. Do not claim to be compliant, certified, or fully implemented unless the facts support it. The same rule applies to marketing materials, proposals, security questionnaires, SPRS submissions, and executive affirmations.

Industry also has a chance to tell the DoW what is not working. The current Request for Information asks about cost drivers, administrative burden, controls that reduce actual risk, and ways commercial security services could fit into the program. Comments are due August 14, 2026. If your company has dealt with these problems firsthand, give the task force specific examples instead of general complaints.

Do not plan on CMMC disappearing

CMMC has been delayed, reviewed, and reworked before. Every round produces the same group of people saying the whole thing is finally going away. So far, they have been wrong.

This review may reduce the role of C3PAOs. It may change which contracts require third-party assessments. We may see more self-assessments, more government-led assessments, or better recognition of commercial security platforms. Cost, timing, documentation, and enforcement could all change.

But the fact still remains, we do not know yet. Anyone claiming to know exactly what the task force will recommend is guessing.

What we do know for sure is that foreign adversaries still want the information held by the Defense Industrial Base, and current contracts still require that information to be protected.

Fix the gaps you already know about. Keep the scope tight. Make sure the score is honest. Build a security and compliance program that works outside the week of an assessment.

The government is debating who grades the work. You still have to do it.

Cards showing CPA firms scored 3/8 on client-data protection risks with notes on regulatory penalties and breaches.
3 minutes or less

Not sure what's exposed? Start here.

Answer a short set of questions about email, devices, vendors, backups, and access. No passwords, no system details — just the questions an attacker has already answered about you.
Get Your Risk Assessment