The CMMC Pause Is Not a Pass: What the 60-Day Phase II Suspension Means for Defense Contractors

By Lukasz Czechura · July 27, 2026 · 7 min read

Executive summary. On July 13, 2026, the Department of War (DoW) suspended CMMC Phase II - the requirement for contractors to pass a third-party certification assessment before winning awards - and launched a 60-day reform review of the entire program. The certification mandate that was set to take effect on November 10, 2026 is on hold until further notice. But the obligations underneath it did not go away: DFARS 252.204-7012 and NIST SP 800-171 compliance are still enforced. For defense contractors, this is not a reprieve from security - it’s a window to get it right without the exam pressure. The organizations that treat the pause as a pass are the ones most likely to be caught out when the program returns.

What actually happened

In a July 13 memo - clarified in a follow-up the next day - the Department of War directed the immediate suspension of CMMC Phase II requirements “scheduled to take effect on November 10, 2026,” along with all pending and future CMMC implementation milestones across DoW contracts and solicitations. The DoW Chief Information Officer stood up a CMMC Reform Task Force to run a “comprehensive top-to-bottom review” of the certification program and deliver findings within 60 days, putting recommendations in front of leadership around mid-September 2026.

The rationale, in the memo’s own words: the current program, “while intended to enhance security, imposes significant and often prohibitive burdens on the Defense Industrial Base.” The review is aligned to an acquisition-reform push built around fewer barriers, faster capability, and less bureaucracy.

What was paused

The pause targets the third-party assessment layer of CMMC - the part that would have forced contractors to pass a Certified Third-Party Assessor Organization (C3PAO) audit to reach CMMC Level 2, or a government-led assessment for Level 3, before receiving an award. Specifically:

  • The Phase II rollout scheduled for November 10, 2026 is suspended until further notice.
  • All pending and future CMMC milestones are on hold during the review.
  • Active solicitations with Level 2 (C3PAO) or Level 3 assessment requirements are to be amended “as soon as practicable,” and existing contracts amended before the next option period is exercised.

What still applies - this is the part that matters

The pause removes an exam. It does not remove the coursework. Every one of these obligations remains fully in force:

  • DFARS 252.204-7012 - the clause requiring you to safeguard Covered Defense Information and report cyber incidents is unaffected.
  • CMMC Phase I self-assessment - Level 1 and Level 2 self-assessment expectations continue.
  • NIST SP 800-171 Revision 2 - contractors must still meet the 800-171 controls, verified through self-assessment and select government-led assessments.

In other words, the standard of security you are contractually required to meet has not dropped by a single control. What changed is who checks your work, and when. The government is explicitly reserving the right to run its own assessments in the interim - and a false self-attestation of 800-171 compliance carries real False Claims Act exposure. The Department of Justice has already shown it will pursue cyber-attestation cases.

Why the pause is a trap for the unprepared

It is tempting to read “60-day review” as “60 days off.” That reading is where contractors get hurt. Three reasons:

  • The obligation never lifted. You can still be assessed, and you can still be liable for an inaccurate self-attestation, today.
  • The program is likely to return. A reform review is not a repeal. The most probable outcome is a leaner CMMC that still rests on NIST 800-171 - so the controls you build now are not wasted.
  • Timelines compress on the rebound. When assessment requirements come back, C3PAO capacity is finite. Contractors who paused will be competing for the same limited assessor slots as everyone else who paused, on a shorter runway.

What to do with the next 60 days

Use the window the way it was meant to be used - to build real security instead of racing an audit clock:

  • Know your true score. Complete an honest NIST 800-171 self-assessment and calculate your SPRS score. If it’s not accurate, fix that first - it’s the number you’re attesting to.
  • Close the gaps that carry the most risk. Build a real System Security Plan and a Plan of Action & Milestones, and work the highest-impact controls first.
  • Watch the Task Force. Track the 60-day review and any industry feedback opportunities, and be ready to adapt when revised guidance lands around mid-September.
  • Keep your attestations honest. Do not certify what you have not implemented. Accuracy is your best protection against enforcement.

How Inttelio helps

A pause is the best possible time to get ahead - no assessment deadline breathing down your neck, and a clear standard (NIST 800-171) to build against. Inttelio helps defense contractors and their suppliers turn this window into an advantage: an honest 800-171 gap assessment, an accurate SPRS score, a defensible SSP and POA&M, and the roadmap to be genuinely assessment-ready when Phase II returns in whatever form the review produces.

Our compliance team can benchmark you against 800-171 and CMMC today, our vCISO leadership can own the remediation program end to end, and our penetration testing validates that the controls actually hold up. If you want to know exactly where you stand before the exam pressure comes back, talk to our team.

And when it comes to keeping score, OscalIQ - our compliance product - now helps organizations track CMMC and NIST 800-171 Level 1 and Level 2 compliance with SPRS scoring, POA&M management, and evidence tracking, so the work you do during the pause stays organized, defensible, and ready to show when assessments resume.

Frequently asked questions

Is CMMC cancelled?

No. On July 13, 2026 the Department of War suspended CMMC Phase II and launched a 60-day reform review - it did not repeal the program. The certification requirement that was scheduled to take effect on November 10, 2026 is paused until further notice, but the underlying cybersecurity obligations remain in force and the program could return in a revised form.

What still applies during the CMMC pause?

DFARS 252.204-7012 remains fully in effect, along with CMMC Phase I self-assessment requirements. Contractors must still safeguard Controlled Unclassified Information under NIST SP 800-171 Revision 2, verified through self-assessments and select government-led assessments. The pause removes the near-term third-party (C3PAO) assessment mandate, not the duty to be secure.

What is the 60-day CMMC review?

The Department of War Chief Information Officer established a CMMC Reform Task Force to conduct a top-to-bottom review of the program and deliver findings within 60 days - putting recommendations before DoW leadership around mid-September 2026. The stated goal is fewer barriers, faster capability delivery, and less bureaucracy for the Defense Industrial Base.

Should we stop our CMMC preparation?

No. The safeguarding obligations that CMMC was built to verify have not changed, and a revised program is likely to still require compliance with NIST 800-171. Treating the pause as a pass leaves you exposed to DFARS enforcement and False Claims Act risk today, and behind your competitors when assessments resume. The smart move is to keep building the controls and use the breathing room to do it properly.

Need help with this?

Inttelio helps businesses in Chicago and nationwide get secure and audit-ready. Let’s talk.

Book a free consultation