CMMC: Phase 2 suspended — program review outcome expected
What happens: On July 13, 2026 the Department of War suspended CMMC Phase II and paused the Phase III and IV milestones, ordering a 60-day program review. The November 10, 2026 third-party (C3PAO) assessment phase-in is off the calendar, and contracting officers are directed to remove Level 2 (C3PAO) and Level 3 (DIBCAC) requirements from existing contracts by modification before the next option period — Level 1 (Self) and Level 2 (Self) designations remain, and no waivers are granted during the review. What did NOT change: DFARS 252.204-7012 still requires NIST SP 800-171; DFARS 252.204-7019 and -7020 still require a current SPRS score and annual affirmation; Phase 1 self-assessments stay in force; and government-led DIBCAC assessments continue.
Who it affects: Defense suppliers, machine shops, and subcontractors handling federal contract information or CUI — at any tier.
Do this: Do not stand down. Keep your NIST 800-171 self-assessment and SPRS score current. An affirmation is a legal statement, and the Department of Justice's Civil Cyber-Fraud Initiative has pursued contractors over misrepresented cybersecurity compliance whether or not a certification deadline is pending. Watch for the review outcome around mid-September.
Source: Department of War — CMMC Phase II suspension memorandum · our full guide →