CMMC Phase II Is Suspended. Your Compliance Obligations Are Not.
By Christina Sentry · July 13, 2026 · 26 views
The Department of War suspended CMMC Phase II requirements. Here is what is still enforceable, why your SPRS attestation matters more than ever, and why suspension does not mean termination.
On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements, which were scheduled to take effect on November 10, 2026. The suspension covers the Phase II transition along with pending and future CMMC implementation milestones across Department solicitations and contracts. A newly established CMMC Reform Task Force will conduct a comprehensive review of the certification program and deliver its recommendations to the Department CIO within 60 days.
Within hours, a dangerous shorthand started circulating in the Defense Industrial Base: CMMC is dead, compliance is optional, stand down.
Every part of that shorthand is wrong, and contractors who act on it are creating legal and competitive risk for themselves in real time. Here is what the announcement actually changes, what it does not touch, and what organizations seeking certification should do this week.
What Is Actually Suspended
The suspension applies to the Phase II requirements, meaning the scheduled rollout of third-party certification requirements in new solicitations and contracts, and to pending CMMC implementation milestones. The mechanism that would have required a C3PAO certificate as a condition of award is paused while the Reform Task Force does its work.
That is the full extent of it. It is a pause on one enforcement mechanism, not a repeal of the underlying obligation.
What Is Still Fully In Effect
Three things survived this announcement completely intact, and together they are the reason no contractor can afford to stand down.
DFARS 252.204-7012 still binds every contractor and subcontractor. The Department stated directly that this action does not eliminate the requirement to protect covered defense information. If you handle CUI, your contractual obligation to safeguard it under the 7012 clause is exactly what it was last week.
NIST SP 800-171 Rev 2 is now the explicitly enforced standard. During the interim period, the Department will enforce cybersecurity compliance with 800-171 Rev 2 through self-assessments and select government-led assessments. Read that carefully. The requirement did not disappear. The party checking your work changed, and government-led assessments, historically conducted by DIBCAC, are not known for being gentler than C3PAOs.
Phase I self-assessment requirements remain firmly in place. Your SPRS score is still a live representation to the federal government, attached to your active contracts.
The Attestation Is Where the Risk Lives Now
This is the part of the announcement that should have every executive's attention, and it is getting the least of it.
With third-party certification paused, the compliance system runs on self-attestation. That means the accuracy of your SPRS score is no longer a preparatory detail on the way to an assessment. It is the entire representation.
A posted score that overstates your actual implementation state was always a problem. In a self-attestation regime with select government-led assessments, it is the problem. False Claims Act liability attaches to the attestation itself, not to the certification schedule, and the Department of Justice has already demonstrated through its Civil Cyber-Fraud Initiative that it will pursue contractors whose cybersecurity representations do not match their environments.
The practical test is simple. If a government assessor walked in tomorrow and scored your environment against 800-171 Rev 2, would their number match the one you posted? If you are not certain, verifying that alignment is the most urgent compliance task on your desk. Not because of CMMC. Because of the score you have already submitted.
Suspension Does Not Mean Termination
The announcement establishes a 60-day review, not a sunset. The Task Force is charged with recommending scalable security measures that lower barriers for small and non-traditional businesses. That is the language of a program being reshaped, not erased. The statutory and contractual foundation underneath it, 800-171 and the 7012 clause, is untouched.
Which means the strategic question for every organization seeking certification is not whether requirements return, but what condition you will be in when they do.
Contractors who treat this as a pause keep closing gaps on their own timeline, calmly and affordably, and are standing at the front of the line when the reformed program takes effect. Contractors who treat this as a cancellation will be sprinting through gap assessments the week the successor requirements drop, competing for consultants and assessors with everyone else who stopped, and paying surge prices for the privilege.
Nothing you have built toward CMMC is wasted. Every policy, every control, every configuration maps to 800-171 Rev 2, which is the standard the government just told you it will enforce directly. The work was never really about the certificate. It was about the security posture the certificate attested to, and that posture is still the requirement.
What To Do This Week
First, verify your SPRS score against your actual implementation state, objective by objective, and correct it if it does not hold up. An accurate lower score is a compliance posture. An inaccurate high score is a liability.
Second, keep your remediation moving. The gaps you have already identified did not become acceptable this morning.
Third, document everything. If a government-led assessment or a reformed program arrives on short notice, your evidence trail is what turns a scramble into a formality.
The Bottom Line
The Department of War suspended a certification schedule. It did not suspend your obligations, your attestations, or the consequences of getting them wrong. The contractors who understand that distinction will spend the next 60 days quietly getting ahead. The ones who do not will find out what being behind costs.
If you are not certain your SPRS score would survive a government-led assessment, that is exactly the conversation to have now. Contact Cipher Sentinel for a CCA led review of your attestation against your actual environment.
Christina Sentry writes about CMMC, NIST 800-171, and defense industrial base compliance for the Cipher Sentinel blog. Cipher Sentinel is a CCA led CMMC compliance consultancy helping DoD contractors reach and maintain compliance faster and at lower cost.
Last edited by Christina Sentry · September 19, 2026 at 9:33 PM
Ready to get compliant?
Talk to a CCA today about your specific environment.