The Pentagon suspended Phase 2 on July 13, 2026 while a task force rethinks the program. What paused, what's still binding, and how to spend wisely until September.
On July 13, 2026, the Pentagon suspended the Phase 2 rollout of CMMC — the phase that was supposed to make third-party assessments a condition of new contract awards. Level 2 C3PAO assessments and Level 3 government assessments are paused while a CMMC Reform Task Force reviews the program's costs, assessor capacity, and structure, with recommendations due about 60 days out — mid-September 2026. If you run a defense industrial base company, you now face a genuine dilemma: keep spending toward certification, or wait and see what survives the review.
The suspension wasn't ideological — it was arithmetic. By the Pentagon's own numbers, more than 100,000 DIB companies still needed a third-party assessment, against roughly 100 authorized assessors (C3PAOs). SBA-derived estimates put future compliance costs for small and midsize businesses above $7 billion a year. The DoD CIO's stated concern: prohibitive costs and assessment bottlenecks were pushing innovative small suppliers out of the defense market entirely.
| Status after July 13, 2026 | |
|---|---|
| Level 2 C3PAO assessments in new solicitations | Paused pending task-force review |
| Level 3 government assessments | Paused |
| The CMMC rule itself (48 CFR, effective Nov 2025) | Still on the books |
| Phase 1 self-assessments & affirmations | Still required |
| NIST 800-171 via DFARS 252.204-7012 | Never paused — contractual today |
| SPRS score submissions (DFARS 7019/7020) | Still required |
Certify-now argument: the 110 controls of NIST 800-171 are the floor under every likely outcome, assessor capacity will be scarce again the moment a new timeline drops, and companies already certified are first in line when primes pick teammates. Wait-and-see argument: a C3PAO assessment is a five-to-six-figure spend against rules that a task force is actively rethinking — levels, self-assessment scope, and phase dates could all move by fall.
Both arguments are right, which is what makes it a dilemma. The resolution is to separate the two things the market conflates: the security work and the certificate.
Treat NIST 800-171 implementation as the constant — it's contractually required today and survives every reform scenario. Close your gap analysis, fix your POA&Ms, keep your SPRS score honest and current, and assemble assessment-ready evidence as you go. Hold the C3PAO purchase decision until the task force reports. That way a lighter regime costs you nothing, and a restarted Phase 2 finds you at the front of the line rather than the back of a 100,000-company queue.
This is the work we do every day. Tell us where your program stands and we'll give you a straight answer.
Talk to AusperThis site uses essential browser storage only. With your OK, we’d also use analytics cookies to understand which content is useful. No choice is required — “Essential only” changes nothing. Cookie policy