On July 13, 2026, the Department of War paused CMMC Phase 2, effective immediately, pending a 60 day strategic review. The SBA publicly backed the decision the same day.

If you are a defense contractor, you are going to hear one sentence a lot this week: CMMC is dead. That sentence is wrong, and acting on it is the most expensive mistake you can make right now.

Here is what actually happened, and what you are still on the hook for.

What did the Department of War actually pause?

It paused Phase 2, the milestone scheduled for November 10, 2026 that would have required a Certified Third Party Assessment Organization, a C3PAO, to certify your Level 2 compliance before you could win covered work.

The Department's own reasoning was arithmetic. Roughly 100,000 companies in the defense industrial base needed assessments, and there are about 100 approved assessors. One official put it as "the math just simply doesn't math." The SBA Administrator described the framework as an untenable barrier pushing qualified suppliers out of defense contracting.

So the audit is on hold. That is the entire change.

Is CMMC cancelled?

No. And the distinction matters more than it sounds.

The Department paused the assessment mechanism. It did not touch the underlying obligation. In its own words, it will continue to enforce cybersecurity compliance with NIST SP 800-171 Rev 2 through self assessments and select government led assessments.

There is a further point that most of this week's commentary is skipping, and Emile Sayegh, CEO of CyberSheath, put it well: CMMC is no longer a proposed framework or agency guidance. It completed the federal rulemaking process and became part of the Department's regulatory framework. What moved this week was an implementation timeline. The rule itself is still a rule.

Read that alongside the phrase "select government led assessments," which means DIBCAC. The Defense Industrial Base Cybersecurity Assessment Center did not go anywhere, and a DIBCAC audit has never been the gentler option.

What do defense contractors still have to do?

Everything you were already doing, minus the C3PAO booking.

  • DFARS 252.204-7012 still applies. You are still contractually bound to safeguard covered defense information. This clause is in your contract today and nothing that happened this week removed it.
  • NIST SP 800-171 Rev 2 is still the standard. All 110 controls, all 14 families.
  • Phase 1 self assessments remain in force. Level 1 self assessment for Federal Contract Information. Level 2 self assessment for Controlled Unclassified Information.
  • Your SPRS score still gets posted, and your affirming official still signs it.

What history says about a CMMC pause

This is not the first time CMMC has been paused, and the last time is instructive.

When CMMC 1.0 was paused in 2021, many organizations read it as permission to wait. Sayegh's observation is that years later, many of those same organizations are still struggling to implement the foundational requirements of NIST SP 800-171. They did not use the time. The pause ended, the requirements came back, and they were exactly as far behind as when they started, except with less runway.

That is the trap sitting in front of the defense industrial base again this week.

Cybersecurity does not become easier because a deadline moves. Deferring the work does not delete it. It converts it into technical debt, and when requirements return, and they have every time, that debt has to be repaid on a compressed schedule at a higher cost.

The part most contractors are about to miss

With the third party auditor removed from the picture, your own signature is now the primary thing standing between your company and the government's view of your compliance.

That should make you more careful, not less.

The Department of Justice has spent years pursuing government contractors under the False Claims Act for misrepresenting their cybersecurity posture through its Civil Cyber-Fraud Initiative. Nothing about this week's announcement softened that exposure. An inflated SPRS score was a liability yesterday and it is a liability today. The difference is that yesterday a C3PAO might have caught it before the government did. Now nobody catches it before the government does.

The pause did not remove risk. It moved it, off the assessor and squarely onto the executive who signs the affirmation.

What should you do in the next 60 days?

The CMMC Reform Task Force has 60 days to review the program and report back, which puts a decision somewhere around the second week of September. Officials have not ruled out larger changes, up to and including scrapping the framework.

That uncertainty argues for a specific posture, not paralysis.

  1. Do not stop. Your 7012 obligation is live regardless of what the task force recommends.
  2. Get your self assessment honest. It is now the artifact carrying all the weight. If your SPRS score was aspirational, fix it before someone else reads it.
  3. Do not spend on a C3PAO booking right now. That is the one line item you can genuinely defer.
  4. Redirect that budget into remediation. The gaps do not close themselves, and closing them is what both the current rules and any plausible future rules will ask of you.
  5. Treat the 60 days as build time, not downtime. You have been handed something you did not have on Friday: room to build the program properly instead of racing a date. The firms that use it to reduce technical debt and mature their operations will be in a stronger position no matter which way the Department goes.
  6. Watch September. We will be watching it too, and we will tell you what lands.

The honest uncertainty

There are three questions nobody in government has answered yet, and we are not going to pretend otherwise:

  • What happens to contracts and solicitations that already carry the CMMC clause?
  • What is the fate of the C3PAO ecosystem, and of companies part way through certification?
  • What happens to the underlying DFARS rule itself?

If a consultant tells you they know, they are guessing. Wait for the task force.

If you already certified, you did not waste your money

Some of the loudest reaction this week is coming from companies that invested early and now feel punished for it.

They should not. A certified contractor is a contractor who can already demonstrate, on paper and in practice, that it protects controlled information. That was a competitive advantage on Friday and it is a competitive advantage today. The buyer on the other side of a contract still has to trust you with their data, and nothing about a paused audit changed what they are looking for.

Bottom Line

Where this leaves you

The compliance deadline that everyone was racing toward is gone. The compliance obligation that sat underneath it is not. If your CMMC plan was built entirely on the November date, that plan needs rewriting this week. If it was built on actually securing controlled information, it survives the news intact.

Frequently asked questions

Is CMMC cancelled?

No. Phase 2, the third party certification requirement scheduled for November 10, 2026, is paused pending a 60 day review. The underlying requirement to protect covered defense information under DFARS 252.204-7012 and to comply with NIST SP 800-171 Rev 2 remains in force. CMMC completed federal rulemaking and remains part of the Department's regulatory framework.

Do I still need to do a self assessment?

Yes. Phase 1 self assessment requirements remain in effect, including the Level 2 self assessment and SPRS affirmation for contractors handling Controlled Unclassified Information.

Do I still need a C3PAO assessment?

Not right now. The third party certification requirement is paused until further notice. The Department will use self assessments and select government led assessments in the interim.

Can I be audited at all?

Yes. The Department explicitly retained select government led assessments, which means DIBCAC can still assess you.

Is my SPRS score still a legal exposure?

Yes. Your affirming official still signs it, and the Department of Justice has pursued contractors under the False Claims Act for cybersecurity misrepresentation. Removing the outside auditor does not remove the liability. It concentrates it.

When will we know more?

The CMMC Reform Task Force is expected to report within 60 days of July 13, 2026, which points to roughly mid September.

Your next step

The self assessment is now the artifact carrying all the weight, so the first move is a clear-eyed read on where you actually stand against all 110 NIST 800-171 controls. That is what a gap assessment is for, and the next 60 days are the right time to run one.

If you are a defense contractor, you may also qualify for a fully funded CMMC Gap Assessment Grant through Cyber Grants Alliance, which covers all 110 NIST 800-171 controls at no cost to you.

Request a NIST Gap Assessment

Sources

  • Department of War release, "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements," July 13, 2026
  • Department of War CIO, implementation memo on the pause of CMMC Phase II
  • U.S. Small Business Administration, "SBA Commends U.S. Department of War's Pause of CMMC Phase II for Small Defense Contractors," July 13, 2026
  • Emile Sayegh, CEO, CyberSheath, "CMMC Phase II Is Paused. The Mission Is Not." LinkedIn, July 13, 2026
Disclaimer: This article is for general informational purposes only and does not constitute legal or contract compliance advice. The CMMC program is under active review and requirements may change. Always confirm your obligations against your contract clauses and current Department guidance before making compliance decisions.