Last updated September 29, 2026. We’ll update this page as soon as the CMMC Reform Task Force’s recommendations are made public.
The short answer: Yes, CMMC Phase 2 is suspended. On July 13, 2026, the Department of War (formerly the Department of Defense) suspended the requirement for third-party CMMC certification that was set to start appearing in contracts on November 10, 2026, and on September 3 it made that suspension binding on contracting officers through a formal class deviation. Nothing else paused. DFARS 252.204-7012, NIST SP 800-171, your SPRS score, CMMC Level 1 and Level 2 self-assessments, and the annual affirmation your company signs are all still required today, and an inaccurate affirmation still carries False Claims Act liability.
If you only read one line of this article, make it this one: the government stopped checking your homework, but you still have to turn it in, and you’re now the only one vouching for it.
The mistake to avoid: reading “paused” as “cancelled”
Here’s what worries us. A lot of contractors are going to see “CMMC paused” in a headline, put their remediation work on hold, and wait to see what the task force says. Then, sometime in the next year, someone at the company signs the annual affirmation anyway, because that requirement never went away.
That’s the worst combination there is: the gaps are still open, and now there’s a signed statement to the federal government saying they aren’t. If you’ve slowed down your NIST SP 800-171 work since July, this is the article telling you to pick it back up.
There’s a second reason to keep going, and it has nothing to do with auditors. When a lot of companies in one industry ease off at the same time, attackers notice. The contractors who keep improving their security while everyone else waits stop being the low-hanging fruit. That protection is worth having whatever the task force decides.
What exactly did the Pentagon suspend?
Two memos went out on July 13, 2026. The first, from the Department of War Chief Information Officer, titled “Removing Barriers to Defense Industrial Base Expansion,” suspended Phase 2 of the Cybersecurity Maturity Model Certification program and created a CMMC Reform Task Force to review it. The second, from the Under Secretary for Acquisition and Sustainment, told contracting officers how to carry it out.
Phase 2 was the part of the rollout that would have required most contractors handling Controlled Unclassified Information (CUI) to pass an independent assessment by a certified third-party assessor, called a C3PAO, before they could win a contract. That’s what’s on hold, along with the later Level 3 milestones.
For contracts and solicitations already in motion, the guidance is specific:
- Open solicitations that include a Level 2 (C3PAO) or Level 3 requirement are to be amended to remove it.
- Existing contracts with those requirements are to be modified to remove them, at the latest before the next option period is exercised.
- Until that modification is actually issued, the requirement in your contract stands. Don’t treat a news story as a contract change.
Then on September 3, 2026, the Pentagon’s acquisition policy office issued Class Deviation 2026-O0025, directing contracting officers to remove third-party assessment requirements from contracts. As Washington Technology reported, that turned the suspension from a policy announcement into an enforceable acquisition rule, which makes it harder to reverse quickly in either direction.
Why they hit pause
The Department’s stated reasons were cost and capacity. Officials pointed to an estimated $7 billion a year in compliance costs for small and midsize contractors, and to a basic supply problem: more than 100,000 companies in the defense industrial base needing third-party assessments, and roughly 100 certified assessment organizations to do them. Pentagon CIO Kirsten Davies summed up the small business side bluntly, telling DefenseScoop that “the math just simply doesn’t math.”
Worth noticing what nobody said: nobody said the security controls were unnecessary. The Department has been consistent that it’s reducing the red tape around verification, and that the requirement to protect defense information hasn’t changed.
What is still required right now?
Here’s the part that gets lost when a headline says “CMMC paused.” Almost everything that matters day to day is untouched.
| Requirement | What it asks of you | Status today |
|---|---|---|
| DFARS 252.204-7012 | Protect CUI using the 110 security controls in NIST SP 800-171, and report cyber incidents to the Department within 72 hours of discovery. | In force. This has been in defense contracts since 2017. |
| NIST SP 800-171 (Rev. 2) | The actual 110 controls: access control, multifactor authentication, audit logging, incident response, encryption, and the rest. | In force. |
| DFARS 252.204-7019 / 7020 | Complete a NIST SP 800-171 self-assessment and post your score in the Supplier Performance Risk System (SPRS). | In force. A current SPRS score is still a condition of award. |
| FAR 52.204-21 and CMMC Level 1 (Self) | Basic safeguarding of Federal Contract Information, with an annual self-assessment and affirmation. | In force. |
| CMMC Level 2 (Self) | Self-assess against all 110 NIST SP 800-171 controls and post the result in SPRS. | In force. This is Phase 1, and Phase 1 didn’t pause. |
| Annual affirmation | A senior official at your company affirms in SPRS that you meet the requirements and will keep meeting them. | In force. This is a certification to the federal government. |
| CMMC Level 2 (C3PAO) certification | Independent third-party assessment before award. | Suspended. |
| CMMC Level 3 | Government-led assessment for the most sensitive programs. | Suspended along with the later rollout milestones. |
Read that table again with your SPRS score in mind. The only thing that went away is the outside check.
Why the pause actually raises your risk
Under Phase 2, a third-party assessor would have looked at your environment before you got the contract. If your SPRS score was optimistic, you’d have found out from an assessor, privately, with time to fix it.
With Phase 2 suspended, that safety net is gone. The number in SPRS is your number. The affirmation is signed by someone at your company. And both of those are statements to the federal government.
That matters because of the False Claims Act. Under the Act, knowingly submitting a false claim for payment to the government triggers triple damages plus a penalty for every false claim, and “knowingly” includes reckless disregard. You don’t have to intend to deceive anyone. Signing an affirmation without checking whether it’s true can be enough. And whistleblowers, often a company’s own IT or compliance staff, can bring these cases themselves and share in the recovery.
This isn’t theoretical. The Department of Justice launched its Civil Cyber-Fraud Initiative in 2021 specifically to pursue contractors who misrepresent their cybersecurity. According to Mayer Brown’s review of DOJ’s fiscal 2025 results, cybersecurity cases accounted for about $52 million across nine settlements in a record year for False Claims Act recoveries.
The clearest example came three weeks before the suspension. On June 18, 2026, DOJ announced that LOGZONE Inc., a Navy contractor, agreed to pay $507,144 to resolve allegations that it billed on two contracts without meeting their cybersecurity requirements. According to Crowell & Moring’s analysis, the company had posted a perfect SPRS score of 110 in 2021. When the Department’s own assessors (DIBCAC) reviewed it in 2024, they scored it at negative 170. That case didn’t start with a whistleblower. It started with a government assessment, and those government assessments are still happening during the pause.
A 280-point gap between the score you posted and the score an assessor finds is the kind of thing that turns an IT problem into a legal one.
And the pause doesn’t grandfather anything. Every SPRS score your company has already posted, and every affirmation it has already signed, is a statement already on file with the government. If one of those numbers was generous, it was generous before July 13, and it’s still generous today. The suspension changed what happens at contract award going forward. It didn’t change what you’ve already told the government.
When will the task force report, and what could it do?
The task force’s 60-day review started July 13 and closed September 11. Its recommendations went to CIO Kirsten Davies, who decides what gets made public and when. As of late September they have not been released, and reporting points to late September or October. The Department has said it is weighing both rollbacks of planned requirements and possible expansions, such as security for operational technology.
The Department has plenty of input to work from. As of early September, DefenseScoop reported more than 1,100 responses to the task force’s request for information, over 3,000 attendees at listening sessions around the country, and more than half of respondents in favor of the pause and some level of reform. The request asked about cost drivers, which controls actually protect CUI, which ones impose the most burden for the least security, commercial tools the Department could accept, and how to make self-assessments meaningful.
Davies has also signaled a direction: moving from point-in-time assessments toward continuous monitoring, paying more attention to operational technology at manufacturers, and cleaning up inconsistent CUI marking.
The honest way to think about CMMC right now is as a moving target. CMMC is here to stay. It’s also moving in a way it didn’t used to, and the dates you planned around a year ago may not hold. So don’t build your plan around a deadline. Build it around the controls, because those are the one part every version of CMMC has in common.
Realistically, the outcome falls into one of four buckets:
- Reinstated as written, with a new start date for third-party certification.
- Restructured, for example with fewer or reprioritized controls, tiers based on risk, or continuous monitoring in place of one-time audits.
- Delayed further while the details get worked out.
- Formally amended through rulemaking.
What’s unlikely is CMMC simply disappearing. The program itself is written into federal regulation (32 CFR Part 170) through a formal notice-and-comment process, and undoing a regulation takes the same kind of process. More to the point, every one of those four outcomes still rests on NIST SP 800-171. Whatever the task force recommends, the controls you’d need to meet are the same controls you’re required to meet today under DFARS 7012.
What should you do while the pause is on?
The companies that come out of this in the best shape will be the ones that used the pause to get honest. Here’s where we’d start.
- Re-score yourself honestly. Walk all 110 controls and ask whether each one is actually implemented today, not planned, not in progress. SPRS scoring starts at 110 and subtracts weighted points for every gap, so a score can drop well below zero. If the number you posted was aspirational, fix it now while it’s your idea.
- Update your System Security Plan and your POA&Ms. Every open gap should have an owner and a date. Those documents are your evidence that you know where you stand.
- Talk to whoever signs the affirmation. Make sure they understand it’s a personal certification to the government, and make sure the evidence behind it exists and is current.
- Test the controls themselves. A policy that says you have multifactor authentication doesn’t prove it’s enforced everywhere. Independent testing, like a penetration test or a cybersecurity audit, shows you what an assessor would actually find.
- Be ready to report an incident within 72 hours. That DFARS 7012 clock didn’t pause either. Know who makes the call, who files the report, and how you’ll preserve evidence.
- Check your flow-downs. DFARS 7012 flows down to subcontractors that handle CUI. If you’re a prime, your subs’ posture is part of your risk. If you’re a sub, expect your primes to keep asking.
- If you were close to a third-party assessment, think twice before canceling it. It’s no longer required for award, but an independent result still validates your score and gives your customers evidence nobody else in your market may have.
How Pegasus helps defense contractors get ready
We work with manufacturers and defense contractors across Southeastern Pennsylvania on exactly this problem: getting from “we think we’re compliant” to “we can prove it.” That includes CMMC and NIST SP 800-171 readiness, cybersecurity audits that give you an honest baseline, penetration testing that shows where your controls actually hold up, and managed security to keep them working after the assessment is over.
If you’d like a second set of eyes on your SPRS score before you sign your next affirmation, get in touch.
Frequently asked questions
Is CMMC cancelled?
No. Only Phase 2, the requirement for third-party certification before contract award, is suspended. Phase 1 self-assessments, SPRS scores, annual affirmations, and the underlying DFARS 7012 and NIST SP 800-171 requirements all remain in effect.
Do I still need to post an SPRS score?
Yes. A current NIST SP 800-171 assessment score in SPRS is still a condition of award for contracts that include DFARS 252.204-7019 and 7020.
Do I still have to sign the annual affirmation?
Yes. The affirmation is part of Phase 1, which didn’t pause. It’s a certification to the federal government, so an inaccurate one can create False Claims Act exposure.
Does the suspension change DFARS 7012 incident reporting?
No. You still need to protect CUI with the NIST SP 800-171 controls and report cyber incidents to the Department within 72 hours of discovery.
My contract already has a CMMC Level 2 third-party requirement. Is it gone?
It’s supposed to be removed, but the requirement stays in force until your contracting officer actually issues a modification. The guidance calls for that to happen no later than the next option period. Until you have the modification in hand, treat the requirement as live.
Are there any other advantages to continuing the CMMC compliance journey, or to ask a different way, is there a disadvantage to halting CMMC compliance work?
YES! The whole point of CMMC is to improve cybersecurity defenses. Pausing your CMMC efforts will limit your awareness of your own cybersecurity posture. That could leave you exposed to an unknown vulnerability. Meanwhile, other companies in the defense industrial base (DIB) are also on the CMMC compliance journey and continue to harden their defenses, so you don’t want to be the weakest company on the block. Cybercriminals attack the easiest targets first and you don’t want to be the low-hanging fruit.
When will we know what happens next?
The task force’s 60-day review closed September 11, 2026, and its recommendations went to the Department’s CIO, who decides what to release and when. As of late September they have not been made public. We’ll update this article when they are.
Sources
- U.S. Department of War, “Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements,” July 13, 2026. war.gov
- Washington Technology, “CMMC’s Phase 2 suspension locked in with binding regulation,” September 2026. washingtontechnology.com
- DefenseScoop, “DOD halts cybersecurity requirements for CMMC Phase 2,” July 13, 2026. defensescoop.com
- DefenseScoop, “Pentagon pores over heaps of industry feedback on CMMC reform,” September 9, 2026. defensescoop.com
- Federal News Network, “Pentagon suspends CMMC phase two requirements, launches review of program,” July 2026. federalnewsnetwork.com
- Holland & Knight, “DOW Suspends CMMC Phase II Requirements,” July 2026. hklaw.com
- Crowell & Moring, analysis of the LOGZONE settlement, 2026. crowell.com
- Mayer Brown, “False Claims Act Enforcement: Record-Breaking Year Signals Continued Attention to Cybersecurity,” March 2026. mayerbrown.com
This article is general information about a regulatory change and isn’t legal advice. If you have specific questions about your contract obligations or your False Claims Act exposure, talk to your counsel.