GrayVolk
GrayVolk
Analysis · August 4, 2026

CMMC Phase 2 is suspended.
Here's what actually changed.

On July 13, 2026 the Department of Defense halted the transition to CMMC Phase 2 and froze the phases behind it. If you read the headlines and concluded that CMMC is dead and you can stand down, that is the expensive misreading. Here is what was paused, what still binds you today, and what we would do in the next thirty days.

The Short Version

What happened: DoD CIO Kirsten Davies issued Memorandum 26-P-1023 on July 13, 2026, suspending the transition to CMMC Phase 2 — which had been scheduled for November 10, 2026 — and placing Phases 3 and 4 in abeyance. A CMMC Reform Task Force is running a 60-day top-to-bottom review.

What it isn't: a repeal. The CMMC program rule stands. The DFARS was not amended. This is a policy pause on the certification timeline, not a removal of your security obligations.

The one-line takeaway: the deadline to be certified moved. The requirement to be secure — and to attest truthfully that you are — did not.
Paused vs. Still Binding

The distinction that matters.

Most of the confusion comes from treating "CMMC" as one thing. The certification machinery is paused. The security obligations underneath it are not.

⏸ Suspended

The November 10, 2026 transition to Phase 2. Mandatory C3PAO third-party certification for most CUI contracts. Phase 3 and Phase 4 milestones. Any assumption that a certificate will be a pre-award condition on a fixed date.

▶ Still in force

Phase 1 obligations. Level 1 and Level 2 self-assessment requirements in new contracts. DFARS 252.204-7012 safeguarding and incident reporting. Your SPRS score and the affirmation you sign to support it. Flow-down of security requirements from primes to subs.

📄 Unchanged underneath

NIST SP 800-171 — the same 110 requirements, assessed as 320 objectives across 14 domains. The standard was never what was suspended; only the mechanism for verifying it by a third party on a set date.

Why DoD Hit The Brakes

Cost and capacity.

Two problems converged, and neither was really about whether the security controls are worth having.

Cost. DoD cited Small Business Administration data indicating that future CMMC phases could cost small and mid-size businesses billions of dollars a year. For a 20-person machine shop, a third-party certification cycle can rival a year of profit.

Capacity. There are roughly a hundred authorized C3PAOs against a population of well over a hundred thousand companies that would eventually need assessing. Even at a punishing pace, the arithmetic does not close by November.

This is worth understanding precisely, because it tells you what reform will likely target: the cost and mechanics of proving compliance — not the expectation that you protect CUI.
The Expensive Misreading

"Suspended" is not "safe to ignore."

Your attestation is still an attestation

An SPRS score submitted to DoD is a representation to the government. Overstating it does not become less consequential because a certification deadline moved. False Claims Act exposure around cybersecurity representations has been an active enforcement theme, and nothing in this memo touches it.

Primes did not pause

Flow-down obligations are contractual, not regulatory-calendar-driven. Primes who have already built CMMC expectations into their supplier requirements are unlikely to unwind them because DoD is reviewing its own timeline.

Check your live solicitations

Some solicitations already carry CMMC requirements written under the prior timeline. Counsel across the bar has flagged that these need reviewing rather than assuming they lapse automatically. If you are mid-bid, read the clause — don't infer it.

The pause has an end date

A 60-day review is short. Whatever emerges — a longer runway, tiered requirements, more self-assessment, cheaper verification paths — companies that used the interval to close real gaps will be in a materially better position than those that stood down.

Time-Sensitive

You can put your view on the record.

The Reform Task Force issued a Request for Information seeking industry input on readiness, cost drivers, control implementation, commercial alternatives and actionable policy reform. Responses are accepted until 12:00 p.m. Eastern on Friday, August 14, 2026.

If you are a small supplier who has been quietly absorbing the cost of this program, this is the rare moment when a specific, numbers-backed account of what it actually costs you is being solicited directly. Reform shaped without small-supplier data will not accidentally come out in small suppliers' favour.

Next 30 Days

What we'd actually do.

Not "carry on as before" — the pause is real and worth using. But used, not wasted.

01 · Confirm where you genuinely stand

Not the score you submitted eighteen months ago — where you are today, domain by domain. If your SPRS figure and your reality have drifted apart, that gap is the actual risk, and it is worse now than it was before you had breathing room to fix it.

02 · Re-read your live contracts and bids

Identify every solicitation and award carrying CMMC or 7012 language. Establish what is contractually binding on you today, independent of the phase timeline.

03 · Close the non-negotiables first

MFA, logging, access control, incident response, media handling. These are the items that show up in every framework, will survive any reform, and are the ones a prime will ask about next quarter regardless of what DoD decides.

04 · Respond to the RFI

By August 14. Specific costs, specific burdens, specific alternatives that would work for a company your size.

05 · Keep your POA&M honest and current

Whatever verification model emerges, a documented, dated, actively-worked plan is evidence of good faith. A stale one is evidence of the opposite.

06 · Don't buy a certificate you can't yet use

With timing unsettled, be wary of anyone selling urgency this month. Spend on closing gaps, not on locking in an assessment slot against a date that no longer exists.

Our Read

What we expect next.

This is judgment, not fact, and we will mark it clearly as such. We would expect reform to preserve the NIST SP 800-171 baseline while attacking the cost of proving it: a longer runway, more scope for self-assessment at the lower end, possibly risk-tiering so that not every supplier faces the same verification burden, and pressure to expand assessor capacity before any hard date returns.

What we would not expect is DoD concluding that CUI in the supply chain no longer needs protecting. The threat that motivated CMMC did not pause on July 13.

Plan for the standard to hold and the mechanics to change. That combination favours companies who quietly fixed things during the pause — and punishes those who read "suspended" as "solved."
Sources

DoD CIO Memorandum 26-P-1023 — Implementing Suspension of CMMC Phase II (primary source)
SBA Office of Advocacy — RFI for the CMMC Reform Task Force
Wiley — DoD Pauses CMMC 2.0 Implementation
Crowell & Moring — Reconsidering CMMC requirements in active solicitations
Federal News Network — Pentagon suspends Phase 2, launches review

This article is general information about a developing policy situation, current as of August 4, 2026. It is not legal advice. Contract-specific questions belong with your counsel and your contracting officer.

Use The Pause

Find out where you actually stand.

An AI-guided pass across all 14 CMMC Level 2 domains, with a prioritized POA&M — about 30 minutes, no consultant booking required. The best possible use of a suspended deadline.