Last updated — August 28, 2026
The short answer: yes. What was suspended on 13 July 2026 was the certification machinery. The underlying obligation to secure Controlled Unclassified Information, assess yourself against NIST SP 800-171, and report a score to SPRS was never suspended and is still enforceable today.
That distinction is doing an enormous amount of work, and it is being missed across the defense industrial base. In the weeks since the announcement, contractors have stood their programs down entirely. Some are now less compliant than they were in June, and every one of them still has a signed affirmation on file.
What actually happened on 13 July 2026
The Department of War suspended the CMMC Phase 2 requirements that were scheduled to take effect on 10 November 2026, along with pending and future CMMC implementation milestones. Chief Information Officer Kirsten A. Davies announced a 60-day study of the future of the program, to be carried out by a CMMC Reform Task Force drawing on industry feedback gathered through a public Request for Information.
The stated rationale was cost and burden: the Department framed the pause around “prohibitive compliance costs and bureaucratic burdens” falling on small and mid-sized suppliers, while insisting the underlying security baseline remains.
It is worth being precise about that last part, because it is the part everyone skips. The announcement explicitly stated that Phase 1 self-assessment requirements remain “firmly in place.”
What is suspended, and what is not
| Obligation | Status today |
|---|---|
| Third-party certification by a C3PAO (Phase 2) | Suspended |
| The 10 November 2026 milestone | Suspended |
| Future CMMC implementation milestones | Suspended pending review |
| DFARS 252.204-7012 safeguarding obligations | In force |
| NIST SP 800-171 Rev 2 implementation | In force |
| Self-assessment and SPRS score submission | In force |
| The annual affirmation | In force |
| 72-hour incident reporting to DIBNet | In force |
| Government-led DIBCAC assessments | In force |
| False Claims Act exposure for a wrong score | In force, and increasing |
Read that table again with a particular question in mind: which row was ever the thing that actually put money at risk?
It was never the certificate. It was the score you submitted and the affirmation you signed under it.
Why the suspension does not reduce your exposure
In June 2026 — a month before the suspension — the Department of Justice settled with an Alabama defense contractor, LOGZONE Inc., for $507,144. The company had self-reported a perfect SPRS score of 110. A government assessment put the real figure at −170.
No whistleblower was involved. DOJ has indicated the matter did not arise from a qui tam complaint or an insider tip; it came out of a government audit. That detail matters more than the dollar figure, because it means the usual reassurance — “nobody inside would report us” — is not a defense.
Nothing in the Phase 2 suspension touches any of that. The False Claims Act is not part of the CMMC program. It applies to the representation you made, and it applied before CMMC existed.
What the Reform Task Force is likely to change
The 60-day review period from 13 July puts recommendations at roughly mid-September 2026. Nobody outside the Department knows what they will say, and anyone telling you otherwise is guessing.
What can be said with more confidence is what is unlikely to change. The 110 requirements of NIST SP 800-171 Rev 2 are not a CMMC invention. CMMC was a verification wrapper around a standard that already existed and that DFARS already required. Reforming the wrapper does not repeal the contents.
The plausible outcomes cluster around how compliance is verified and how much of the burden falls on small suppliers: more self-attestation, a longer phase-in, scoped-down requirements for low-risk contracts, or a reduced set for the smallest firms. Every one of those still requires you to know your current position against the 110.
What to do between now and then
The pause is genuinely useful, but only if you use it. The organisations that come out of this well will be the ones treating it as breathing room rather than a cancellation.
- Verify your current SPRS score is defensible. Not comfortable — defensible. If someone assessed you tomorrow against the 320 objectives, would they arrive at your number? If you cannot answer that, this is the only item on the list that matters.
- Fix your scope. Scope determines cost more than any other single decision, and most contractors have never formally defined theirs. An overscoped environment is the most expensive mistake in this program.
- Write the System Security Plan properly. It is required by 3.12.4 today, suspension or not, and it is the document a government assessor reads first.
- Build the evidence, not just the controls. Assessors do not score intentions. Most failures are not missing controls; they are working controls nobody can prove.
- Do not stand down your program. When the Task Force reports, the contractors with a current score, a real SSP and organised evidence will absorb whatever it says in weeks. The ones who stopped will start from nothing, against a deadline.
The one-sentence version
Certification is paused; the obligation is not, the enforcement is not, and the affirmation you signed is still a certification to the United States government.
Related reading
Get your position straight
Free download · 1 page · PDF
Do you need CMMC Level 1 or Level 2?
Four ordered steps that settle which level applies to you, taken straight from the contract clauses — plus the four things people most often get wrong.
If you already know you hold CUI, the CMMC Level 2 Readiness Kit covers all 110 requirements and 320 assessment objectives — scoping, System Security Plan, policies, evidence list and POA&M. If you hold only FCI, the CMMC Level 1 Self-Assessment Workbook covers the 15 practices and 59 objectives.
Provided for general information. Not legal, audit or certification advice. Rules cited are current as at August 2026; the CMMC Program is under active review, so confirm the position before making contractual commitments.
