// Capability Statement — Download PDF
Insights / The CMMC 2.0 dilemma
CMMC 2.0

The CMMC 2.0 dilemma: certify now, or wait out the pause?

The Pentagon suspended Phase 2 on July 13, 2026 while a task force rethinks the program. What paused, what's still binding, and how to spend wisely until September.

On July 13, 2026, the Pentagon suspended the Phase 2 rollout of CMMC — the phase that was supposed to make third-party assessments a condition of new contract awards. Level 2 C3PAO assessments and Level 3 government assessments are paused while a CMMC Reform Task Force reviews the program's costs, assessor capacity, and structure, with recommendations due about 60 days out — mid-September 2026. If you run a defense industrial base company, you now face a genuine dilemma: keep spending toward certification, or wait and see what survives the review.

The math that broke Phase 2

The suspension wasn't ideological — it was arithmetic. By the Pentagon's own numbers, more than 100,000 DIB companies still needed a third-party assessment, against roughly 100 authorized assessors (C3PAOs). SBA-derived estimates put future compliance costs for small and midsize businesses above $7 billion a year. The DoD CIO's stated concern: prohibitive costs and assessment bottlenecks were pushing innovative small suppliers out of the defense market entirely.

What paused — and what didn't

Status after July 13, 2026
Level 2 C3PAO assessments in new solicitationsPaused pending task-force review
Level 3 government assessmentsPaused
The CMMC rule itself (48 CFR, effective Nov 2025)Still on the books
Phase 1 self-assessments & affirmationsStill required
NIST 800-171 via DFARS 252.204-7012Never paused — contractual today
SPRS score submissions (DFARS 7019/7020)Still required

The dilemma, both sides

Certify-now argument: the 110 controls of NIST 800-171 are the floor under every likely outcome, assessor capacity will be scarce again the moment a new timeline drops, and companies already certified are first in line when primes pick teammates. Wait-and-see argument: a C3PAO assessment is a five-to-six-figure spend against rules that a task force is actively rethinking — levels, self-assessment scope, and phase dates could all move by fall.

Both arguments are right, which is what makes it a dilemma. The resolution is to separate the two things the market conflates: the security work and the certificate.

What we'd do before September

Treat NIST 800-171 implementation as the constant — it's contractually required today and survives every reform scenario. Close your gap analysis, fix your POA&Ms, keep your SPRS score honest and current, and assemble assessment-ready evidence as you go. Hold the C3PAO purchase decision until the task force reports. That way a lighter regime costs you nothing, and a restarted Phase 2 finds you at the front of the line rather than the back of a 100,000-company queue.

Quick answers

Is CMMC dead?
No. The July 2026 action suspended Phase 2 third-party assessment requirements while a reform task force reviews the program. The CMMC rule remains in force, Phase 1 self-assessments continue, and DoD has said contractor cybersecurity requirements are not going away.
Do I still need my SPRS score and 800-171 self-assessment?
Yes. DFARS 252.204-7012, 7019, and 7020 were never paused. NIST 800-171 implementation, current SPRS scores, and annual affirmations remain contractual obligations independent of the CMMC pause.
When will there be clarity?
The CMMC Reform Task Force was given 60 days from July 13, 2026 — pointing to recommendations around mid-September 2026. New phase dates, if any, would be announced after that review.
Put this to work

Need it done, not just explained?

This is the work we do every day. Tell us where your program stands and we'll give you a straight answer.

Talk to Ausper