★ Annual Review 2027 tickets now on sale Get your tickets →

News/Cyber & AI/CMMC Phase II Suspended: What the Reprieve Really Means for Contractors
Cyber & AI Brief

CMMC Phase II Suspended: What the Reprieve Really Means for Contractors

This article was researched and written by Ask Pub K, drawing on Pub K's curated library of authoritative GovCon documents. It has been lightly edited by Pub K's editors for accuracy and clarity.

On July 13, 2026, the Department of War (DoW) upended the cybersecurity compliance calendar the defense industrial base had been building toward for years. DoW suspended Phase II of the Cybersecurity Maturity Model Certification program — the phase that would have made third-party C3PAO assessments a condition of award for most contractors handling Controlled Unclassified Information — just months before its November 10, 2026, effective date.1 For a program years in the making, the halt was abrupt.

DoW’s memorandum placed all pending and future CMMC implementation milestones in abeyance and simultaneously stood up a CMMC Reform Task Force, charged with a 60-day review to recommend “realistic, scalable security measures” for the industrial base. A companion memo from Under Secretary Michael Duffey directed program managers and contracting officers to strip Level 2 (C3PAO) and Level 3 (DIBCAC) requirements from active solicitations “as soon as practicable” and from existing contracts by modification, generally no later than the next option exercise.3 SBA data citing compliance costs approaching $600,000 per firm — and their effect on pushing small and mid-sized businesses out of the DIB — featured prominently in DoW’s public justification.4

Every firm tracking this action has converged on the same warning: this is a pause on third-party certification, not a rollback of the underlying security obligations. DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) remains fully in force, including its 72-hour incident-reporting clock, media-preservation duties, and subcontract flowdown requirement.5 Phase I self-assessment obligations — Level 1 and Level 2 self-assessments and SPRS attestations — remain, in DoW’s words, “firmly in place.”6 Contractors must continue to maintain a current NIST SP 800-171 Rev. 2 assessment status and affirmation in the Supplier Performance Risk System to remain award-eligible, and DoW has reserved the right to conduct “select government-led assessments” in place of third-party certification during the review period.7

Contractors reviewing their DFARS flowdowns should be aware the clauses themselves are in flux independent of the suspension. Under DoW’s Revolutionary FAR Overhaul implementation — Class Deviation 2026-O0043 for DFARS Part 204, and a companion deviation consolidating information-security and supply-chain clauses into a new DFARS Part 240 — DFARS 252.204-7019 and -7020 have reportedly been retired and renumbered (commentators cite 252.240-7997 as 7020’s successor), while 252.204-7012 and the new CMMC-status provision at 252.204-7025 remain part of the operative clause set.8 Contractos should treat any pre-2026 clause citation as the legacy location pending verification against the deviation memo itself.

The task force’s 60-day review closed around September 11, 2026, with recommendations going first to CIO Davies before any public release — meaning contractors are, as of this writing, still operating in the suspension window with no confirmed Phase II replacement.9

This suspension relieves one enforcement mechanism, not cybersecurity risk. Contractors should keep self-assessments current in SPRS, maintain their System Security Plans and POA&Ms, confirm which DFARS clause numbers appear in their current contracts, and watch for the task force’s recommendations—which could reshape the compliance model again before year-end.

Regulations and agency deviations change frequently; this reflects the position as of September 25, 2026. Verify the CMMC Reform Task Force’s findings and current DFARS Part 240 clause numbering before relying on this summary.

Sources

  1. DoW CIO memorandum suspending CMMC Phase II, July 13, 2026.
  2. CMMC Reform Task Force charter memorandum.
  3. Under Secretary Duffey implementation memo.
  4. SBA compliance-cost data cited in DoW justification.
  5. DFARS 252.204-7012
  6. DoW statement on Phase I self-assessment obligations.
  7. DoW CIO memorandum suspending CMMC Phase II, July 13, 2026.
  8. DARS DFARS-RFO class deviations page.
  9. Inside Government Contracts, analysis of SPRS/self-assessment continuity during CMMC suspension.
Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.