TL;DR: On July 13, 2026, the Department of War suspended CMMC Phase II, the third-party certification requirement that was set to take effect November 10, 2026. If you handle controlled unclassified information for a defense contract, your self-assessment obligations, your DFARS requirements, and your legal exposure for an inaccurate SPRS score did not change. Here is what the suspension covers, what still applies, and three moves to make in the next 60 days.
What changed on July 13
The Department of War announced the Department’s July 13 memo that it was pausing CMMC Phase II, the requirement for a Certified Third-Party Assessor Organization to certify Level 2 compliance before contract award. That requirement was scheduled to take effect on November 10, 2026. The suspension also puts Phase III, originally set for November 2027, and Phase IV on hold, and it directs contracting officers to remove Level 2 and Level 3 requirements from active solicitations and contracts.
The Department created a CMMC Reform Task Force to run a 60 day, top to bottom review of the program. Industry feedback through a formal request for information is due August 14, 2026, and the Task Force’s report is expected around mid September.
What did not change
Three things remain exactly as they were before July 13.
- Your DFARS obligations. DFARS clause 252.204-7012 requires you to protect controlled unclassified information, implement the 110 controls in NIST SP 800-171 Rev 2, report cyber incidents within 72 hours, and use a FedRAMP Moderate equivalent cloud environment.
- Your self-assessment requirements. CMMC Phase I, in force since November 2025, still requires an annual Level 1 self-assessment or a triennial Level 2 self-assessment with an annual affirmation in SPRS.
- Your legal exposure. An inaccurate SPRS score now carries more risk, not less. The Department of Justice’s Civil Cyber-Fraud Initiative treats a false self-assessment as a False Claims Act matter, and with third-party verification paused, your self-reported score is the only evidence anyone has of your compliance.
What this means for you
The suspension is not a cancellation, and treating it like one is the most expensive mistake you can make in the next two months. The Department has been clear that it is reducing certification burden, not lowering the cybersecurity bar. Contractors who quietly stop remediation work now risk being caught flat footed when the Task Force’s revised requirements land, likely sometime this fall.
Three things to do while the review runs:
- Validate your SPRS score. If no one outside your IT team has pressure tested your self-assessment, do it now. An inflated or stale score is a liability, not a shortcut.
- Pressure-test your scope. Third-party audits are paused, but a defensible scoping document, System Security Plan, and Plan of Action and Milestones are still what protects you if a contracting officer or a DOJ investigator asks questions.
- Keep remediation moving. Every open item on your POA&M is a future audit finding waiting to happen. The 60 day window is planning time, not a pause button.
Get ready for what’s next
The Task Force’s report is expected in mid-September, and the Department has said it will revisit the program’s structure after that review. Whatever comes back, it is unlikely to relax the underlying security requirements. It is more likely to change how compliance gets verified, which means the contractors who spend the next 60 days fixing their scoping, tightening their SPRS score, and closing out their POA&M will be the ones ready to move, not the ones scrambling to catch up.
The bottom line: the audit is paused. Your obligations are not. Use this window as planning time, not a holiday.
Join Matt Schiavone, Phil Jorgensen, Steve Aldape, and me on Sikich‘s October 29 webinar, CMMC After the Pause, where we will cover the Task Force’s findings, what a defensible self-assessment requires, how an enclave strategy can shrink your compliance boundary, and what it takes to stay audit-ready year round.
Register for the October 29 webinar: CMMC After the Pause
Want help pressure-testing your scope or your SPRS score before the Task Force reports back? Talk to Sikich’s CMMC team and we will walk through where you stand and what to fix first.
This publication contains general information only and Sikich is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or any other professional advice or services. This publication is not a substitute for such professional advice or services, nor should you use it as a basis for any decision, action or omission that may affect you or your business. Before making any decision, taking any action or omitting an action that may affect you or your business, you should consult a qualified professional advisor. In addition, this publication may contain certain content generated by an artificial intelligence (AI) language model. You acknowledge that Sikich shall not be responsible for any loss sustained by you or any person who relies on this publication.