Phase II is suspended, the rules still apply, and your compliance budget didn't get a refund
Before you read on, watch this breakdown of what changed, what didn't, and what you should be doing right now.
The Department of War set a November 10, 2026 deadline for Phase II of its Cybersecurity Maturity Model Certification (CMMC) program, a federal requirement that defense contractors prove they're protecting sensitive government data, with independent verification to back the claim.
More than 100,000 contractors spent the better part of two years and, in many cases, hundreds of thousands of dollars preparing for it. On July 13, 2026 the DoW suspended Phase II, froze Phases 3 and 4 alongside it, and announced a 60-day review of the whole program. A CMMC Reform Task Force has 60 days from July 13 to review the program and report back, putting a report around mid-September 2026.
The Cyber AB, the official accreditation body the DoW created specifically to oversee CMMC, found out the same way everyone else did, which is what happens when you build a program for four years and then decide to rethink it without telling the people you built it with.
There were roughly 100 authorized assessment organizations to handle those 100,000 companies. The DoW Chief Information Officer, in announcing the suspension, cited that bottleneck as one of the reasons. The math on this was not a surprise. It was visible for anyone who cared to look, which raises a reasonable question about why it took until four months before the deadline to notice.
But none of that changes what contractors are required to do with sensitive government data. The security obligations are intact. The 110 controls remain. Self-assessments still need to happen, and the senior official who signs that affirmation still carries exposure if the numbers are wrong. What got suspended was the outside audit that would have verified it.
That distinction matters, and the rest of this piece explains why.
What Paused and What Didn't
CMMC has three levels, and they don't all sit in the same place right now, which is already more nuanced than most of the coverage suggests.
Level 1 covers contractors handling basic federal contract information, the non-public data generated under a government contract. It requires meeting 15 foundational security practices, things like password controls and limiting who can access systems, verified through an annual self-assessment. Level 1 was not touched by the suspension. If you're at Level 1, nothing about your obligations changed on July 13.
Level 2 is where most defense contractors land and where the suspension has impact. It covers contractors handling Controlled Unclassified Information (CUI), sensitive but not classified data like technical drawings, export-controlled material, or anything the government considers too important to leave unprotected but not important enough to classify. Level 2 requires meeting all 110 security controls in a federal standard called NIST SP 800-171. Those 110 controls still apply. What the suspension removed is the requirement for a Certified Third-Party Assessment Organization (C3PAO), an outside firm the DoW authorizes to run formal assessments, to come in and verify that you're actually meeting them. Under the pause, you assess yourself. The solicitations that still list the third-party audit requirement are supposed to be amended to remove it. Whether that amendment happens quickly or quietly depends, as always, on who's paying attention.
Level 3, the highest tier covering the most sensitive programs, uses a government-led assessment rather than a private one and requires 134 total controls. It's also frozen entirely, which presumably surprised the contractors who were already nowhere near ready for it.
The shorthand: the security requirements didn't move. The verification requirement did. Those are not the same thing, and conflating them is how organizations end up in trouble when the program comes back, as it almost certainly will in some form.
The Five Things That Still Apply After the Suspension
Here's where it gets consequential for anyone inclined to treat the suspension as a hall pass.
When a contractor self-assesses under Level 2, a senior company official signs an affirmation confirming that the organization meets the requirements. That's not a checkbox on a form nobody reads. That affirmation is a legal document, and the False Claims Act, the federal law that covers false statements made to the government in connection with contracts, did not pause alongside the CMMC timeline. The penalties under the False Claims Act run to three times the damages plus substantial fines per false claim. The government has used it against defense contractors before and will again.
If your organization signs off on compliance it hasn't earned, the legal exposure is identical to what it was before July 13. The suspension relieved the audit pressure. It didn't relieve the obligation, and it certainly didn't relieve the person who signed that affirmation of the consequences if the numbers are wrong.
The SBA cited per-company compliance costs approaching $600,000 for Level 2. If an organization spent a meaningful fraction of that getting ready and is now tempted to coast on the suspension, the math on that decision looks different once a False Claims Act investigation is in the mix.
With all that in mind, here's where each type of organization stands right now:
If you're at Level 1, keep doing your annual self-assessment and document it properly.
If you're at Level 2, continue working through the 110 controls, and make sure whoever is signing that affirmation understands what they're signing.
If you were counting on a third-party assessor to find your gaps, find them yourself in the meantime, because the September task force report could bring the audit requirement back with a shorter runway than the original.
If you were using the November deadline as the reason to finally take security seriously, the suspension may buy you some time, but should not undercut the urgency with which you being your control implementation.
If you're watching the September review, know that the task force could narrow the program, extend the timeline, or recommend scrapping Phase II entirely. It could also bring it back largely intact with a harder deadline.
Nobody knows, including, apparently, the Cyber AB.
The Program Blinked But Your Obligation Didn't
If you're a defense contractor who spent the last two years building toward Phase II certification, the honest answer is: keep going. The deadline pressure is off, but the work was never really about the deadline. It was about protecting data that the federal government has deemed sensitive enough to regulate, and that obligation didn't take a 60-day vacation with the task force.
The 60-day review that’s currently underway ends around mid-September. Regardless of the decisions the task force makes and recommendations they publish, what won't change is that the underlying security requirements exist because the data is genuinely sensitive and the threat to it is genuine. The DoW's math problem with 100,000 companies and 100 assessors is real. The $600,000 compliance cost cited by the SBA for small businesses is real. The program has structural problems that deserve a serious look. None of that means the data got safer on July 13.
The rug got pulled, but the floor is still there. Anyone who stops walking is making a choice, and the person who signed the affirmation will own it.


