On July 13 the Department of War suspended Phase 2 of CMMC, the third party certification requirement that was set to start this November. Half the defense industrial base exhaled. The other half is furious.
Let me put my bias on the table before I say anything else. I do not run a C3PAO and I do not sell certifications. My work is readiness and cyber security advisory and consulting, so I have no certificate revenue to protect and no reason to tell you the sky is falling. That said, I have spent years helping companies build toward CMMC, so I know exactly what this pause feels like for the people who were mid-journey.
Here is what moved and what did not.
The suspension killed the third party assessment requirement, along with the later phases that would have followed. Phase 1 is still here. You still self assess against NIST 800-171. You still post your score in SPRS and sign the annual affirmation. DFARS 252.204-7012 has required contractors to protect covered defense information since 2017, and it is fully intact. All 110 controls are still the standard. Nothing about the level of security expected of you got easier. The only piece that went away is the outside party who was going to check your work.
.png?width=726&height=608&name=image%20(70).png)
This pause was coming, and the government knew it
You will see a lot of relief being expressed online this week from those excited that their mad dash to tighten up their program and get the C3PAO in place, along with the spend that goes with it, was just put on hold. Be careful with that. The relief is well earned, but do not let the excitement lull you into inaction. You might not have to pay for a C3PAO anymore, but you still have a compliance program to run, like it or not, and your obligation has not really changed.
There is a wide gap between killing a payment for a certificate and killing your investment in real security. I will come back to that. But first, let me be fair to the decision itself. The delivery model was broken anyway, and it was broken in a way that was documented well before July.
Back in March, the Government Accountability Office published a report warning that DoD had never assessed whether the private sector could supply enough assessors to run the program. DoD concurred. So the government's own auditor said the capacity did not exist, and the department agreed in writing.
The numbers say the same thing. The SBA put more than a hundred thousand small firms into the Phase 2 pipeline against roughly a hundred approved assessors. It estimated the cost of a third party certification at close to $600,000 for a small company, and just under $400,000 even for a firm that only had to self assess. A shop doing four million dollars a year cannot carry a six figure compliance bill, and a hundred assessors cannot clear a hundred thousand companies this decade. The program was pricing out the exact small innovators it was supposed to protect, and in turn locking them out. So the suspension is really the arithmetic catching up with the policy. It was inevitable.
.png?width=729&height=449&name=image%20(71).png)
What always bothered me about CMMC
I see a real tension here. CMMC was trying to do two hard things at once. It wanted to verify that contractors were genuinely protecting sensitive data, because years of self-attestation had failed and adversaries had walked off with real program information. It also wanted to keep the industrial base wide enough to build what the country needs, including the small and nontraditional shops that have the technology but not the compliance infrastructure. At the scale the program demanded, those two goals ran straight into each other, and that is what broke. But that collision was about the machinery not the responsibility.
Strip away the abstraction and that responsibility lands on a person. Somewhere in your company a manager is responsible for protecting that data and has to sign their name to say it is handled. That was that manager's responsibility with CMMC in force. It is the same manager's responsibility with CMMC on hold. Lawyers call it a standard of care. On the floor it is just the person whose neck is on the line. CMMC never created that responsibility. It only graded it. And the grade is the only thing that changed.
You are the last set of eyes now
In January 2021, a Massachusetts defense contractor called MORSECORP told the government its NIST 800-171 score was 104, near the top of a scale that runs from -203 to 110. That score was wrong. They found out just how wrong a year later, when the company brought in an outside firm to run a gap analysis and the real number came back at -142. MORSE left the inflated 104 on the books and kept winning work on it. It did not correct the number until a federal subpoena forced the issue years later, and last year it paid 4.6 million dollars to settle the False Claims Act case that followed.
.png?width=731&height=343&name=image%20(72).png)
Notice who paid that bill? The company that signed the number, and nobody else. And it was not blindsided. An outside firm had already told MORSE the real score. It buried that finding and left the inflated number in place. The assessment did its job. The company refused to listen, and the bill came due.
That is what an outside look is really for; it tells you whether you are actually meeting the bar, in time to fix the gaps before you put your name behind the number. Phase 2 was about to make that outside assessment mandatory for everyone handling CUI. The suspension pulled that requirement, and DoD has ordered it stripped out of active contracts. The price for getting your security wrong did not get pulled with it.
And the government auditor did not vanish along with the commercial one. DIBCAC still runs government led assessments, and the memo says those continue. For a manufacturer that means someone can still walk your floor and look at whether your business network is genuinely separated from your machine controllers, which a paper checklist was never going to catch anyway.
The Justice Department's cyber fraud effort is fully operational, and the incentives behind it are only getting stronger. The whistleblower who flagged MORSE collected $851,000, and the plaintiffs' bar now has a playbook for these cases. Crowell & Moring is already warning DOJ could turn toward false Phase 1 self-assessments next. Read that as the pressure heating up, not cooling down.
You cannot put this back in the box
The primes spent the last five years building CMMC compliance into how they operate, and they are under the exact same rules you are. DFARS 7012 and the False Claims Act do not stop at the prime's front door. When a prime hands you CUI, your security becomes their exposure, because a breach at a sub, or a false attestation from one, lands on the prime that vouched for its supply chain. They need their subs secure to protect themselves, and regardless, no press release out of Washington is going to rewrite your subcontract.
The compliance standard is already heavily operationalized. Consider RTX. It bakes your CMMC status into its annual supplier registration process and will not issue a purchase order to a supplier handling CUI without it. Or Lockheed, which requires a green rating in its Exostar questionnaire as a condition of staying on the program. General Dynamics Mission Systems demands a minimum SPRS score of 88, no waivers. None of that is tied to the November date, and none of it moved this week. If you supply a major prime, your obligation this morning is the same as it was last week.
So the compliance program still exists along with the mandate, and all that we've lost is the professional validation process. The prime is already pulling your NIST 800-171 SPRS score out of the system by CAGE code, and until now the plan was to use the C3PAO certificate as the clean outside stamp that told them your reported score was accurate and trustworthy. That stamp is now gone. What is left in their hands is self-reported: your SPRS score and whatever their own questionnaire tells them. The prime is still holding all of its own liability, and I am guessing that with the independent check pulled out from under them, they are not going to shrug and trust the honor system. I am thinking it is more likely that this pause only ups the scrutiny of the SPRS score, and that this is not the moment to be carrying a number you cannot back up.
Do not mistake a memo for a repeal
Remember, this is just a pause. The rule itself is still on the books, codified in federal regulation, published last September and effective in November. A memo can stop the clock. Unwinding a final rule takes formal rulemaking, and that runs for months or years.
The last administration paused the first version of CMMC in 2021 for its own review. It came back as CMMC 2.0 with the same bones, and the contractors who tore their programs down spent the next three years catching up. My money says this returns in some form, probably leaner, quite possibly after the next election. And whatever it looks like in the end, there is a good chance it comes back less bureaucratic and more focused on real risk management. Whoever dismantles everything now is going to feel it later.
So what actually makes sense
Davies used a phrase in the memo that I would frame on a wall, "tangible cyber hygiene rather than bureaucratic red tape." She is describing where the money should have been going all along. Look, I am not here to knock compliance. It has its place and the checkboxes matter. But in more than twenty years doing this work, I have watched plenty of smart CIOs confuse a passing audit with a true measure of their actual risk.
So maybe you are miffed. You poured real effort into marching toward CMMC and the finish line just moved. None of it is wasted. You already know 800-171 cold from chasing that certificate. Point that same momentum at the framework itself. Test the controls regularly and model the realistic threats that target your enterprise specifically. Do that and you come out of this pause more secure than the certificate would ever have made you. And if the DoW changes its mind and a new certificate requirement lands on you, you will already be ready for it.
The bottom line
The certificate is on hold. What you owe when you hold government data has not moved an inch. That standard of care hasn't changed at all. All the pause really did was pull out the independent outside check that would have validated your attested score. You still sign the attestation. Now no one checks that number but you. So be careful how you reach it. They suspended the certificate. Nobody suspended the standard of care.
.png?width=728&height=565&name=image%20(73).png)
Sources
- Department of War, "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements," July 13, 2026 (war.gov)
- DoW CIO Memorandum 26-P-1023, "CMMC Reform," July 13, 2026
- U.S. SBA, "SBA Commends U.S. Department of War's Suspension of CMMC Phase II," July 13, 2026 (cost figures, assessor capacity)
- GAO-26-107955, "Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation," March 12, 2026
- U.S. DOJ, "Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations," March 26, 2025
- Crowell & Moring LLP, "Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review," July 2026 (crowell.com)
- Federal News Network, DefenseScoop, Breaking Defense, National Defense Magazine, coverage of July 13, 2026
- 32 CFR Part 170 (CMMC Program rule), Federal Register, October 15, 2024 (effective December 16, 2024)
- DFARS 252.204-7021 (48 CFR CMMC acquisition rule), Federal Register, September 10, 2025 (effective November 10, 2025)