CMMC Phase 2 Suspension: What the New DoD CMMC Deviation Means for Defense Contractors
Updated: September 2026
The Department of Defense has suspended the advancement of CMMC Phase 2, stopping the planned November 10, 2026 expansion of third-party CMMC assessment requirements while it reviews the future of the Cybersecurity Maturity Model Certification program.
But CMMC has not been repealed.
CMMC Level 1 and Level 2 self-assessments remain available during the suspension. NIST SP 800-171 Revision 2 remains the cybersecurity standard the Department says it will enforce for CUI through self-assessments and selected government-led assessments. And the underlying safeguarding requirements in DFARS 252.204-7012 remain in effect.
That creates three questions for defense contractors:
- What exactly did the CMMC suspension change?
- Can DoD legally suspend part of a program that already exists in federal regulation?
- What should contractors do while CMMC Phase 2 is suspended?
The short answer to the third question is the most important:
Don’t spend as though the old CMMC certification timeline is guaranteed. But don’t comply as though CMMC is dead.
What Changed With the CMMC Phase 2 Suspension?
On July 13, 2026, DoD announced the immediate suspension of the transition to CMMC Phase 2, which had been scheduled to begin November 10, 2026.
The implementing memorandum, 26-P-1023, goes considerably further than simply announcing a delay.
During the suspension, program managers and requiring activities may designate only:
- CMMC Level 1 (Self)
- CMMC Level 2 (Self)
They may not designate CMMC Level 2 (C3PAO) or CMMC Level 3 (DIBCAC) assessments during the suspension.
DoD also directed program managers to initiate amendments to active solicitations containing Level 2 C3PAO or Level 3 DIBCAC requirements. For existing contracts containing those requirements, contracting officers are directed to remove them by modification before the next option exercise or during the next scheduled administrative modification.
In other words, this is not merely DoD saying “we’re delaying the next phase.” The Department has instructed its acquisition workforce not to impose the third-party and DIBCAC assessment designations during the suspension, and to remove them from affected solicitations and contracts through the appropriate amendments or modifications.
Read DoD’s official CMMC program page for the source documentation on the suspension.
What Did Not Change?
This may be the most misunderstood part of the CMMC suspension.
The cybersecurity requirements did not disappear simply because third-party certification was paused.
DoD’s implementing memorandum expressly states that it will continue enforcing baseline compliance with NIST SP 800-171 Revision 2 through CMMC self-assessments and selected government-led assessments. It also expressly states that the cybersecurity requirements in DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect.
The Department’s CMMC website similarly says Phase I self-assessment requirements remain in place.
That distinction matters. CMMC is primarily a mechanism for verifying cybersecurity compliance. It is not the original source of every cybersecurity obligation imposed on defense contractors. For contractors handling Covered Defense Information and CUI, contractual cybersecurity requirements existed before CMMC. Pausing one verification mechanism does not automatically eliminate those underlying obligations.
Is CMMC Dead?
No.
32 CFR Part 170 still exists. That regulation establishes the CMMC program architecture, including CMMC levels, assessments, affirmations, POA&Ms and other program requirements. The current regulation expressly states that CMMC does not alter separately applicable requirements to protect FCI or CUI, including FAR 52.204-21 and DFARS 252.204-7012. It describes CMMC as a means of verifying implementation of the applicable security requirements.
DFARS 252.204-7021 also still exists. When applicable to a contract, that clause requires the contractor to maintain the specified CMMC status, restrict applicable FCI/CUI processing to systems with the required status, make annual affirmations, report applicable CMMC UIDs, and flow appropriate requirements to subcontractors.
So saying “DoD canceled CMMC” goes too far. A more accurate description is:
DoD has suspended advancement of the CMMC phased implementation schedule and, during its review, has limited acquisition activities to Level 1 and Level 2 self-assessment designations.
That’s very different from repealing the CMMC regulations.
Why Did DoD Suspend CMMC Phase 2?
The Department’s stated rationale focuses heavily on cost, bureaucracy, small-business participation and expansion of the Defense Industrial Base.
DoD said that information, including reports from the Small Business Administration, indicated CMMC compliance was causing companies to leave the DIB. It established a CMMC Reform Task Force and initiated a review intended to reduce compliance barriers while maintaining cybersecurity.
SBA’s account is even more revealing. SBA said the suspension followed months of engagement between DoD, SBA and small-business stakeholders. SBA estimated that more than 120,000 DIB small businesses would be affected and argued that the compliance model could impose substantial costs and strain assessment capacity.
The CMMC Reform Task Force subsequently asked industry about reducing cost, improving self-attestation, using existing commercial cybersecurity capabilities and improving operational resilience.
That suggests the debate is no longer simply about when CMMC Phase 2 begins. It is increasingly about what CMMC should look like when the review is finished.
Is DoD Legally Allowed to Suspend CMMC Phase 2?
This is where the issue gets more interesting.
My view is that DoD has a meaningful legal argument for temporarily changing CMMC implementation, but that does not necessarily mean the Department could indefinitely rewrite the regulatory program through memoranda or guidance alone.
To understand why, it helps to separate three different layers of authority.
1. Congress
Congress directed DoD to establish and maintain a comprehensive framework for improving cybersecurity across the Defense Industrial Base. But Congress did not enact today’s entire CMMC architecture or DFARS 252.204-7021 word-for-word as a statute. That distinction leaves DoD with significant discretion over how it implements the cybersecurity framework.
2. 32 CFR Part 170
32 CFR Part 170 is the CMMC program rule. It establishes the regulatory architecture for CMMC. An agency memorandum, FAQ or RFI is not the same thing as amending a regulation through formal rulemaking. That becomes important if today’s temporary suspension eventually turns into a fundamentally different CMMC program.
3. 48 CFR and the DFARS
This is where CMMC intersects directly with federal contracting.
DFARS 204.7504 tells DoD when to use DFARS 252.204-7021. And the existing DFARS already contains an important date that is frequently overlooked: November 10, 2028.
Until November 9, 2028, DFARS 204.7504 calls for use of 252.204-7021 when the program office or requiring activity determines that the contractor needs a specific CMMC level. Beginning November 10, 2028, the trigger becomes broader: the clause is prescribed where the program office or requiring activity determines contractor information systems will process, store or transmit FCI or CUI in contract performance, subject to the rule’s exceptions.
That 2028 date matters enormously to the legal analysis, and it’s the same date we flag in our CMMC certification cost breakdown as the point where the C3PAO assessment requirement is currently expected to take fuller effect.
The “Donut Spare Tire” Problem
One useful way to think about the current CMMC suspension is a donut spare tire. A donut is designed to let you keep driving temporarily after a flat tire. It solves an immediate problem. But it isn’t designed to become your permanent tire.
The current CMMC regulations already contemplate a phased implementation period extending through November 2028. That arguably gives DoD considerably more room to adjust implementation inside the existing rollout period than it would have if the regulations already required universal application of the final framework. In that sense, DoD may currently be driving on the donut.
The harder legal question is: how long can it continue doing so before it has to change the tire?
If DoD ultimately decides that the CMMC program should permanently rely more heavily on self-assessment, commercial cybersecurity capabilities or risk-based third-party assessments, parts of that change may require amendments to the underlying regulations. An agency generally cannot simply make a legislative regulation disappear by issuing an FAQ, policy memorandum or press release. So the legal issue may become more significant if a temporary implementation suspension becomes a permanent regulatory redesign.
What Happens on November 10, 2028?
This may ultimately be one of the most important dates in the CMMC debate.
Under the DFARS currently on the books, the prescription changes on November 10, 2028. At that point, DFARS 204.7504 provides for use of 252.204-7021 where contractor information systems will be required to process, store or transmit FCI or CUI, subject to the specified exceptions.
That does not mean today’s CMMC program is guaranteed to return unchanged in 2028. Quite the opposite. DoD could amend the regulations before then. But if the Department wants the post-2028 framework to look materially different from what the current regulations prescribe, formal regulatory action may become increasingly important.
Could C3PAOs or Contractors Challenge the Suspension?
Potentially.
C3PAOs invested money, personnel and resources into a government-created certification ecosystem. Contractors and other interested parties could also encounter procurement-specific disputes involving CMMC requirements.
Possible legal theories could involve the Administrative Procedure Act, procurement law or arguments that agency implementation has departed from existing regulations. But that does not mean a lawsuit would automatically succeed. A plaintiff would still have to address issues such as standing, final agency action, reviewability, causation, the agency’s implementation discretion and the appropriate remedy.
And even if a court eventually concluded that DoD used an improper procedure, that would not necessarily mean the court would order DoD to restart CMMC Phase 2 exactly as originally planned. A court could instead require reconsideration, additional process or rulemaking.
So litigation is possible. An automatic judicial resurrection of the old CMMC timeline is not.
What Should Defense Contractors Do During the CMMC Suspension?
The biggest mistake a defense contractor can make right now is interpreting “CMMC Phase 2 suspended” as “cybersecurity compliance suspended.” DoD has explicitly said otherwise.
For contractors handling CUI, the practical focus should remain on actual implementation of NIST SP 800-171, accurate assessment, and the ability to substantiate what the company represents to the government.
1. Keep implementing NIST SP 800-171
Do not stop remediation simply because the expected C3PAO deadline changed. If DFARS 252.204-7012 applies to your contract, the underlying safeguarding obligations remain relevant regardless of whether a C3PAO is scheduled to arrive.
2. Make sure your SSP reflects reality
Your System Security Plan should describe the environment you actually operate. Controls that are planned are not the same as controls that are implemented. Keep the SSP current as systems, cloud services, MSPs, personnel and technical configurations change.
3. Make sure your SPRS score is defensible
A self-assessment should be treated as a compliance representation, not as a paperwork exercise. The company should be able to explain why it took credit for each security requirement and produce evidence supporting that conclusion.
4. Preserve technical evidence
Policies alone are not sufficient evidence that technical controls operate. Contractors should maintain appropriate evidence such as system configurations, logs, access-control records, tickets, vulnerability scan results, training records, inventories, network diagrams, incident-response documentation and other artifacts supporting implementation.
5. Know exactly where your CUI is
A contractor should be able to answer:
- Where does CUI enter our organization?
- Where is it stored?
- Who can access it?
- Which endpoints, servers and cloud services touch it?
- Which MSPs, external service providers and subcontractors can access or protect those systems?
You cannot effectively secure, or assess, an environment you have not accurately scoped.
6. Review your subcontractors
The CMMC suspension does not make supply-chain risk disappear. Prime contractors should continue examining applicable cybersecurity flowdowns and understanding which subcontractors process, store or transmit FCI or CUI.
Also remember that commercial relationships matter. A prime contractor may impose cybersecurity requirements on suppliers contractually even where a particular government procurement does not currently require a C3PAO assessment.
7. Maintain CMMC assessment readiness
There is a difference between rushing to purchase a C3PAO assessment because of the old November 2026 timeline and abandoning assessment readiness altogether. Neither extreme makes much sense.
Continue closing meaningful gaps, collecting evidence, and maintaining an assessable environment. If third-party assessments return, whether broadly or on a more targeted basis, contractors that maintained readiness will be in a much stronger position.
Does Self-Assessment Reduce a Contractor’s Compliance Risk?
Not necessarily. It may actually make accurate internal compliance more important.
A third-party assessment gives a contractor an external checkpoint before or during certification. With greater reliance on self-assessment, more responsibility rests directly with the contractor to ensure its representations are supportable.
That creates an important principle for management: self-assessment does not mean self-exemption.
Cybersecurity representations to the government can have consequences. Depending on the facts, knowledge and materiality, knowingly inaccurate representations concerning required cybersecurity practices can create contractual and potentially False Claims Act exposure.
So the relevant question is not simply “will a C3PAO assess us this year?” A better question is: could we prove today that the cybersecurity representations we’re making to the government are accurate?
What Will Replace CMMC Phase 2?
We don’t know yet.
DoD’s review specifically sought industry input on commercial cybersecurity capabilities, self-attestation, reducing compliance costs and improving operational resilience.
Several outcomes therefore remain plausible. CMMC could return substantially as designed. Third-party assessments could return but become more targeted toward higher-risk contractors or information. Self-assessment and government-led assessments could play a larger role. Or DoD could undertake a more substantial regulatory rewrite before the broader 2028 implementation date. Congress could also intervene and prescribe requirements more explicitly.
What contractors should not assume is that the July 2026 announcement tells us exactly what CMMC will look like in 2028. It doesn’t.
The Bottom Line for Defense Contractors
The CMMC Phase 2 suspension changes the verification timeline and assessment requirements. It does not eliminate the underlying responsibility to protect FCI and CUI.
For defense contractors, that leads to a relatively simple strategy:
Don’t spend as though the old certification timeline is guaranteed. Don’t comply as though CMMC is dead. And don’t mistake self-assessment for self-exemption.
Continue implementing the security requirements that apply to your contracts. Keep your SSP and SPRS representations accurate. Preserve evidence. Understand your CUI environment. Validate your supply chain. And remain assessment-ready while DoD decides what the next version of CMMC will become.
Certification may be delayed. Enforcement doesn’t have to be.
This is exactly the gap Espresso Labs is built to close for defense contractors: continuous NIST SP 800-171 control enforcement, an SSP and evidence trail that stay current automatically, and an environment that’s ready the moment a C3PAO assessment is required, whenever that turns out to be.
This article reflects our interpretation of the current CMMC and federal acquisition regulatory landscape and is provided for general informational purposes. It is not legal advice.