CMMC Updates

Disclaimer: This white paper is provided for general informational purposes only and does not constitute legal advice. Each firm’s actual obligations are established by the clauses in its own contracts and subcontracts. The regulatory situation described here is evolving; all statements reflect guidance in effect as of July 29, 2026, while the report of the CMMC Reform Task Force remained pending. Readers should verify current status against the primary sources cited before acting.

CMMC Phase II White Paper

Executive Summary

On July 13, 2026, the Department of War (DoW) announced the immediate suspension of Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, which had been scheduled to take effect on November 10, 2026, along with all pending and future CMMC implementation milestones. [1, 2, 3] The action removes, for the duration of a formal review, the Department’s requirement that contractors obtain third-party or government-led certification assessments as a condition of contract award. It does not remove any underlying obligation to protect federal information.

The distinction matters because the suspension arrived by memorandum, not by regulation. The two July 13 documents, a policy memorandum from the DoW Chief Information Officer and an implementation memorandum from the Office of the Under Secretary for Acquisition and Sustainment, were released under publication case 26-P-1023. [1, 6] No Federal Register action accompanied them. The CMMC Program rule at 32 CFR Part 170 and the acquisition rule implementing it, including DFARS clause 252.204-7021, remain in force exactly as written. [6, 9] What has stopped is the Department’s exercise of its discretion to require the higher assessment types, not the regulatory framework itself.

During the suspension, program managers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self) in requirements documents. Level 2 (C3PAO) and Level 3 (DIBCAC) may not be designated, and no CMMC waivers will be granted during the review period. [1] The Department has directed that active solicitations containing the suspended requirements be amended as soon as practicable, and that existing contracts be modified before the next option exercise or during the next scheduled administrative modification. [1, 3]

Everything else stands. Contractors handling Controlled Unclassified Information (CUI) remain bound by DFARS 252.204-7012 to implement NIST SP 800-171 Revision 2, to report cyber incidents to the Department within 72 hours, and to flow those requirements down to subcontractors. Phase 1 self-assessment requirements, Supplier Performance Risk System (SPRS) scores, and annual affirmations of compliance remain fully in effect, and the Department will continue select government-led assessments. [1, 3, 8] Because a signed SPRS affirmation is a representation to the government, the practical enforcement weight of the program now rests more heavily, not less, on the accuracy of self-assessments.

A CMMC Reform Task Force has been established to conduct a top-to-bottom review of the program and deliver recommendations to the DoW CIO within 60 days, placing its report in mid-September 2026. A public Request for Information closed the comment window at 12:00 p.m. Eastern on August 14, 2026. [5, 11, 12, 14] This paper summarizes what the suspension changed, the cost and capacity data that prompted it, the direction the review may take, the parallel movement of the proposed FAR CUI rule toward NIST SP 800-171 Revision 3, and the practical steps contractors in three different postures should take while the outcome is pending.