If you saw the headline—“Department suspends CMMC”—and felt your shoulders drop, you’re not alone.
A lot of defense contractors read that announcement and thought the requirement they had been preparing for simply went away.
Here’s the honest version: it didn’t.
The Department suspended an important part of the CMMC implementation schedule. It did not shut down the CMMC Program or erase the underlying safeguarding requirements in applicable defense contracts.
Phase I self-assessment requirements remain in place. The Department also stated that it will continue enforcing baseline compliance with NIST SP 800-171 Revision 2 through CMMC Level 1 and Level 2 self-assessments, along with selected government-led assessments.
There is also a short window—closing August 14—when defense contractors can help shape what comes next.
Misread this moment and you do more than stand still. You hand the pen to someone else.
What actually got suspended?
Read the official guidance—not just the headlines.
On July 13, 2026, the Department suspended the upcoming November 10 transition to Phase II and placed the phased implementation schedule on hold while it conducts a broader review of the program.
During the suspension, program managers and requiring activities may designate only:
CMMC Level 1 (Self)
CMMC Level 2 (Self)
They may not designate:
CMMC Level 2 (C3PAO)
CMMC Level 3 (DIBCAC)
The Department’s guidance also directs contracting officials to amend active solicitations containing Level 2 C3PAO or Level 3 DIBCAC requirements. Existing contracts containing those requirements are to be modified before the next option period or during the next scheduled administrative modification.
That is meaningful relief for contractors facing an immediate third-party or government-led certification requirement.
However, do not assume that a headline automatically changed your specific solicitation, contract, or subcontract. Review the document that currently governs your work and confirm whether the appropriate amendment or modification has been issued.
You can read the details in the Department’s official CMMC Phase II suspension guidance.
What did not disappear?
Several major cybersecurity responsibilities remain in place when they apply to your organization:
Phase I CMMC self-assessment requirements
FAR 52.204-21 requirements for safeguarding Federal Contract Information
DFARS 252.204-7012 requirements for protecting Covered Defense Information and reporting cyber incidents
NIST SP 800-171 Revision 2 requirements for covered environments
Applicable prime-contractor and subcontractor flow-down requirements
Selected government-led assessments
The need to maintain evidence supporting cybersecurity representations and assessment results
Authorized C3PAOs also remain operational, and voluntary CMMC Level 2 certification assessments remain available. The assessors, practitioners, training providers, and supporting organizations that make up the CMMC ecosystem did not shut down.
The Department paused one part of the contractual rollout while it decides what the program should look like going forward.
Why “suspended” does not mean “gone”
The cybersecurity work expected of defense contractors did not begin with CMMC.
CMMC was created to provide greater confidence that contractors were actually implementing safeguarding requirements that had already existed for years through FAR, DFARS, and NIST standards.
Suspending the Phase II rollout changes when certain certification requirements can be included in solicitations and contracts. It does not automatically make the underlying contractual cybersecurity work optional.
A contractor who interprets “suspended” as permission to stop is making a bet against its contractual obligations and future enforcement risk.
Contractors that understand the difference will continue protecting sensitive information, maintaining defensible assessment results, organizing evidence, and improving their security posture.
Those that walk away may find themselves scrambling when the review ends—especially if the revised program changes timelines, assessment models, or evidence expectations.
The part nobody is talking about: you have a voice.
Alongside the suspension, the Department opened a formal Request for Information titled “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base.”
The Department wants feedback about what is working, what creates unnecessary cost, what discourages small-business participation, and how the assessment model could be improved without weakening cybersecurity.
A CMMC Reform Task Force is conducting a 60-day review of the program. Responses to the RFI will help inform its recommendations and potential policy reforms.
That does not mean every recommendation will be adopted. An RFI is not a vote.
But it is the Department’s formal channel for putting real-world cost, implementation, and operational information in front of the people reviewing the program.
Think about who will respond.
Large prime contractors will. Industry associations will. CMMC ecosystem organizations will.
Many small defense contractors will not. Some will assume their voices do not count. Others may never hear that the RFI exists.
If small businesses do not describe the cost, staffing, scoping, and operational challenges they experience, the next version of the program may be shaped primarily by the organizations that did participate.
If your company will have to live with the revised requirements, you should have a voice in the process.
Responses are due through the official SAM.gov RFI by 12:00 p.m. Eastern on Friday, August 14, 2026.
It can start as a 20-minute move—not a major project.
Responding to a federal RFI sounds heavier than it needs to be.
You do not need to write like an attorney or hire a lobbyist. The Department needs specific, credible information from the companies that experience these requirements firsthand.
Start with questions such as:
What has CMMC implementation required from your company?
Which requirements have been especially expensive or difficult?
Where has the guidance been unclear?
What has made scoping your environment challenging?
How could the program reduce unnecessary burden without reducing security?
What would help smaller contractors remain competitive?
Which parts of the assessment process should be retained, changed, or simplified?
You can capture your core input in about 20 minutes. Then allow additional time to review, format, and submit the final response according to the RFI instructions.
We created a free CMMC RFI Response Kit to help. It explains the submission requirements, walks through the questions, and provides space to develop your response in your own words.
Download the Free CMMC RFI Response Kit
One important caution: keep your response clean.
Do not include proprietary information, classified information, Controlled Unclassified Information, export-controlled information, or other sensitive material. Use sanitized examples and aggregated cost or operational information when possible.
The goal is to make your experience visible—not expose information that should remain protected.
While you are at it, is your SPRS score defensible?
Here is the quieter risk in this conversation.
You may be preparing to tell the Department what cybersecurity implementation has cost your organization. Before you do, it is worth asking whether the assessment result already sitting in the Supplier Performance Risk System can withstand scrutiny.
Ask yourself:
When was our SPRS score last updated?
Does the score accurately reflect our current environment?
Can we support every point we claimed with policies, configurations, records, and other evidence?
Does our System Security Plan reflect how we actually operate?
Are our POA&M items accurate and being actively managed?
Has anyone outside our internal team reviewed the score and its supporting evidence?
The Department has made clear that Phase I self-assessment requirements remain in place. Your representations still carry weight, even while the future of third-party certification is under review.
The Cyber AB’s CEO described a C3PAO Level 2 certification as “the best insurance policy against False Claims Act risk.”
A certification is not a legal safe harbor, and no assessment can eliminate every enforcement risk. But the underlying point matters: independent validation can strengthen the evidence supporting your company’s cybersecurity representations.
You can read the full Cyber AB statement on the Phase II suspension.
If your current SPRS score is based on assumptions, outdated information, incomplete documentation, or security requirements that were never fully implemented, this pause does not solve that problem.
It gives you time to address it.
What should defense contractors do now?
Do not panic—but do not disengage.
Use this window to take four practical steps:
Review your contracts and solicitations.
Confirm which FAR, DFARS, CMMC, NIST, and prime-contractor requirements currently apply to your organization.Submit your RFI response.
Tell the Department what has worked, what has created unnecessary burden, and what a realistic security model should look like for small and midsized contractors.Validate your SPRS score.
Make sure your score, System Security Plan, POA&M, policies, configurations, and supporting evidence tell the same story.Keep moving on real security improvements.
Prioritize the work that protects sensitive information, reduces disruption, preserves customer trust, and strengthens your eligibility for future contracts—regardless of what the revised certification model becomes.
The bottom line
CMMC is not dead.
Phase II implementation has been suspended, and the broader program is under review. That is a significant change—but it is not the same as eliminating CMMC or the cybersecurity obligations already contained in applicable contracts.
The contractors that understand this moment will use it.
They will put their experiences into the official record. They will verify that their SPRS scores are defensible. They will keep improving their security environments. And they will be better positioned for whichever direction the Department takes next.
The rest may still be celebrating a suspension they misread.
Do not be in that group.
Read what changed. Make your voice heard. Then make sure your cybersecurity claims can stand up when someone asks for the evidence.
Download the Free CMMC RFI Response Kit
Book a CMMC Strategy Session with NerdsToGo Alexandria
NerdsToGo Alexandria is a Cyber-AB Registered Practitioner Organization providing CMMC implementation and readiness support to small and midsized defense contractors nationwide. NerdsToGo Alexandria is not a C3PAO and does not perform CMMC certification assessments. Certification assessments are conducted by authorized C3PAOs. This article is provided for educational purposes and does not constitute legal advice.