CybertronIT is a CyberAB-authorized Registered Practitioner Organization (RPO). We do CMMC readiness work. We are not a C3PAO and do not perform the certification assessment itself.
On July 13, 2026, the Department of War (DoW) suspended the CMMC Phase II requirement that would have forced Level 2 defense contractors to pass a third-party audit to win work. The deadline that everyone was racing toward, November 10, 2026, is off the calendar for now. The audit pressure eased. The security work did not.
If you've been getting emails telling you to beat the November deadline or lose your contracts, those emails are now out of date. Here's what actually happened and what a defense supplier should do about it.
The DoW suspended the transition to CMMC Phase II, effective immediately, along with pending and future CMMC implementation milestones across its solicitations and contracts. Phase II was the stage where Level 2 contractors would have needed a certificate from an accredited outside assessor (a C3PAO) as a condition of award.
The DoW also opened a 60-day, top-to-bottom review of the whole program and put out a public Request for Information asking industry where the compliance burden actually falls. The stated goal is to lower the barrier for small, medium, and non-traditional businesses and to replace paperwork-heavy compliance with security measures that scale.
The DoW's own CIO, Kirsten Davies, framed it as reducing red tape while keeping a security baseline, not walking away from security. Her words: strong cybersecurity and operational resilience remain critical, and the defense industrial base can hit both while the government cuts the parts that were paralyzing smaller firms.
Read the language carefully, because the difference matters. This is suspended pending review. It is not cancelled, and it is not over. The third-party audit requirement could come back, come back changed, or land somewhere else entirely once the review reports. Anyone telling you CMMC is dead is selling you the wrong story, the same way the deadline-panic crowd was selling you the other one.
If you're a Tier 2 or Tier 3 aerospace or defense supplier heading for Level 2, the single thing that changed is the expensive, scheduled, pass-or-lose C3PAO audit. That pressure is off for now.
What did not change is your obligation to actually secure the Controlled Unclassified Information you handle. During this interim period, the DoW says it will enforce the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments. In plain terms, you still have to meet the same security bar. You just show it yourself for now instead of paying an outside assessor to certify it.
So the smart read is not relief and it is not panic. It's this: the cost and the calendar crunch of a rushed certification just came off, and you got room to do the underlying work properly instead of cramming for an exam.
Phase I never went anywhere. The self-assessment requirements are firmly in place. If a solicitation requires a Level 1 or Level 2 self-assessment, that's still live.
The 110 controls of NIST 800-171 are still the standard. Level 2 was never just a piece of paper. It's a real control set covering access, audit logging, configuration management, incident response, media protection, and the rest. Suspending the outside audit doesn't shrink that list by a single control.
Your duty to protect CUI has been law since 2017. The DFARS 252.204-7012 clause obligates every contractor and subcontractor that touches covered defense information to safeguard it, full stop. The DoW went out of its way to say this suspension does not eliminate that obligation. It predates CMMC and it outlives this pause.
And here's the piece almost nobody is saying out loud. For Level 2 right now, you demonstrate compliance by scoring yourself against the 110 controls and having a senior company official affirm that score in the government's SPRS system. That affirmation is not a formality and it is not a free pass. It's a legally binding statement. If the score is wrong and you knew it, or should have, you've got False Claims Act exposure, and the Justice Department has been pursuing exactly those cases against contractors who certified security they didn't have. Self-certification means you own the number. Standing behind a false one is a bigger problem than any audit.
Three things, and they pull against each other on purpose.
First, self-certify properly. If you're subject to a Level 2 self-assessment, do it against all 110 controls, build the System Security Plan and the POA&M behind it, and make sure the number you affirm in SPRS is one you can actually defend. This is the work that matters most now, because your own signature is the thing standing behind it.
Second, don't overspend. If a vendor is pushing you to buy an expensive isolated enclave or a full certification sprint to beat a November deadline, that deadline no longer exists. Pause. Some businesses genuinely need an enclave and some architectures genuinely require one. But buying it in a panic, for a date that's off the calendar, is how you spend money on controls you may not need in the shape a vendor sold them. The honest move is to size the environment to what your contracts actually require, then decide.
Third, don't stand down. This is the mistake on the other side. The fundamentals are unchanged, the DFARS obligation is unchanged, and the third-party requirement could return in some form when the review wraps. A supplier who treats the pause as permission to stop is going to be scrambling later, and scrambling is where the expensive mistakes live. The businesses that use this window to quietly get their CMMC readiness in order are the ones who won't blink when the rules settle.
We're not saying this from a whiteboard. We run the same play in our own building. We carry our own compliance obligations every year, we know what a self-assessment costs in real hours, and we know the difference between a control that's documented and a control that's actually live on the network. That gap is the first thing we find on the networks we take over. This is also why we bundle CMMC readiness with Managed IT Services on the same engagement. The documentation and the live systems have to be run by the same team, or your SSP describes a business you no longer are by the next quarter.
If you want a straight read on whether this pause changes anything for your next contract, book a short call. Thirty minutes, no commitment. Bring any contract clauses, flowdown language, or supplier questionnaires you have in hand. We'll tell you what you're actually on the hook for, what you're not, and what a realistic timeline looks like now that the deadline moved. If we're not the right fit, we'll say so.
Is CMMC cancelled?
No. CMMC Phase II is suspended pending a 60-day review, not cancelled. The requirement for Level 2 contractors to pass a third-party (C3PAO) certification is on hold. Phase I self-assessment requirements remain in place, and the program could change and return once the review is complete.
Do I still need to meet NIST 800-171?
Yes. The 110 controls of NIST SP 800-171 Rev 2 are still the standard. During the interim period the DoW is enforcing them through self-assessments and select government-led assessments. Suspending the outside audit did not remove any of the controls.
Does the suspension end my duty to protect CUI?
No. DFARS 252.204-7012 has obligated contractors and subcontractors to safeguard covered defense information since 2017. The DoW stated directly that this suspension does not eliminate that requirement.
Should I stop my CMMC project?
Not if you're subject to it. The self-assessment obligation stands, the DFARS duty stands, and the third-party requirement may return in some form. The pause is a good window to do the underlying work properly without a rushed audit deadline, not a reason to stand down.
Is a self-assessment lower risk than a C3PAO audit?
It's less expensive and less scheduled, but it isn't risk-free. A senior official has to affirm your score in SPRS, and that affirmation is legally binding. A knowingly inaccurate score carries False Claims Act exposure. You own the number either way.
Posted by Emma Jones, CybertronIT.
Comments