As the Dust Settles on the CMMC Suspension: Five Details That Should Shape Your Next 60 Days
A week ago, the Department of War suspended CMMC Phase II, and the defense industrial base spent about seventy-two hours trying to figure out what it meant. That was a reasonable response. The announcement moved faster than the details did, and a lot of teams had to make quick judgment calls with incomplete information.
The details have caught up. Here is what has come into focus since July 13, and how it may change the calculus if you made a decision in that first week.
1. The suspension is broader than the headline suggested
The initial coverage centered on the November 10, 2026 Phase II transition. The suspension is actually broader: Phases 3 and 4 and all future implementation milestones are frozen until further notice. Washington Technology’s reporting confirmed the suspension extends to CMMC Phase 3, the Level 3 assessments originally slated for November 2027.
If you were building a multi-year roadmap toward Level 3, that roadmap no longer has a government-defined endpoint. That is not the same as Level 3 going away. It means the schedule you were planning against does not currently exist, and it is worth revisiting your milestones with that in mind.
2. There is exactly one real deadline in the interim: August 14
Most of the dates in circulation right now are estimates. One is not.
The Department CIO is forming a CMMC Reform Task Force to review the program and report back within 60 days, placing that report in mid-September 2026. To inform the review, the Department posted a formal Request for Information on SAM.gov the same day as the announcement. Responses are due August 14, 2026.
The RFI asks industry to submit input on compliance challenges with the current program, including cost and implementation experience. Per the announcement, the Task Force will use these responses in its review.
The August 14 date is the only fixed deadline during the interim period. If your organization plans to submit, that is the window.
3. The stated reason for the suspension was capacity and cost
The early speculation ran toward politics. The Department’s stated rationale was arithmetic.
DoW CIO Kirsten Davies cited internal data showing that more than 100,000 Defense Industrial Base companies needed a third-party assessment from a C3PAO, while only about 100 C3PAOs existed to conduct them. She also cited Small Business Administration data suggesting future CMMC phases could cost small and midsize businesses more than $7 billion annually.
The Department characterized the review as a 60-day, top-to-bottom examination of the certification program, and stated the goal is reducing red tape rather than reducing cybersecurity.
Whatever view you take of the decision, the stated driver is useful for planning. An assessment-capacity problem points toward a replacement that is less dependent on a small pool of external assessors. Nobody knows the final shape yet, but the nature of the problem suggests something about the direction of the fix.
4. Your solicitations and contracts are being actively amended
This is the operational detail that is easiest to miss, and the one most worth checking this week.
During the suspension, contracts can only carry Level 1 (Self) or Level 2 (Self) designations, and no waivers are being issued while the review runs. Per the implementation memo, active solicitations that still list Level 2 (C3PAO) or Level 3 requirements are to be amended to remove them as soon as practicable, and existing contracts are to be updated at their next option period or scheduled modification.
Practically, that means two things. If you are mid-capture on a bid that still lists a C3PAO requirement, expect that language to come out. If you hold a contract with Level 2 (C3PAO) in it, the change arrives at your next option period, not immediately. A pass through your portfolio now, noting which contracts are affected and when each comes up for amendment, will save you surprises later.
5. The mechanism was a memo, not a rule, and that matters for planning
The suspension was effected by two memoranda released July 13 under publication case 26-P-1023: a policy memorandum from the CIO and an implementation memorandum from the undersecretary for acquisition and sustainment. It was not a rule.
That distinction matters for how you plan. A memo can be reversed considerably faster than a rule can be rewritten, and the 32 CFR final rule that established CMMC still exists. What the Department suspended was the implementation of a phase, not the regulatory foundation underneath it.
Officials declined to rule out ending the program entirely, and the Cyber AB was not notified before the announcement. That is a genuinely wide range of possible outcomes, from full restart to significant restructuring. The practical planning posture is to stay ready for more than one of them.
What has not changed at all
Worth restating clearly, because a week of commentary has muddied it.
Phase 1 self-assessments, SPRS scores, and DFARS 252.204-7012 safeguarding obligations remain fully in force. The suspension does not remove the current security obligation.
The clearest framing comes from the regulation itself rather than the commentary around it: the Department suspended a certification mechanism. It did not suspend the underlying requirement to protect federal information.
Or, as we put it on day one: the audit was the receipt, not the bill.
The part worth sitting with
Here is the piece of this we would want every client to understand, because it is easy to miss inside the relief narrative.
The suspension removed the one external check that stood between a contractor’s self-attested compliance score and a False Claims Act investigation. With no third-party assessor in the near term, the signature carrying the legal weight is yours. And prime contract flow-downs do not pause because a federal requirement did; those commercial obligations still bind you.
None of that is cause for alarm. It is cause for accuracy. The organizations in the best position when the review period ends will be the ones whose self-assessments genuinely reflect their environment, because that score is now carrying more weight, not less.
What to do between now and mid-September
Decide whether to respond to the RFI, and if so, submit by August 14. It is the only hard deadline in the interim and the formal channel the Department has opened for industry input on the program.
Take a pass through your contract portfolio. Identify every solicitation and contract carrying a Level 2 (C3PAO) or Level 3 requirement, and note when each is scheduled for amendment.
Validate your self-assessment. A C3PAO mock assessment remains a smart way to pressure-test your score before you certify it. With no external check in the pipeline, accuracy matters more than ever. If it has been a while since someone outside your team looked at your environment, this is a good moment.
Keep the security work moving. The engineering was never the paperwork. The suspension changed who checks your work in the near term. It did not change what the work needs to look like.
Watch mid-September. The Task Force report is the next real signal. The time between now and then is best spent preparing, whichever direction it goes.
The Department gave itself sixty days to rethink the program. Those same sixty days are available to you, and used well, they are enough to come out of this stronger than you went in.
Where Fortreum and Kovr fit
If the last week has a theme, it is that the requirements outlasted the mechanism. Whatever shape the program takes after the review, the work underneath it — knowing where your controls stand, keeping evidence current, and being able to show it — does not go away.
That is the problem the Kovr.AI platform was built for. Kovr reads your live environment, maps one body of evidence across every framework you need, and keeps it current, so your compliance posture reflects reality instead of a point-in-time snapshot. When the rules changed on July 13, Kovr customers did not have to rebuild anything. Their evidence was already framework-agnostic.
Paired with Fortreum’s assessment expertise as a top-5 FedRAMP 3PAO and authorized C3PAO, that means you can validate your self-assessment now, keep your program moving through the review period, and be ready for whatever the Task Force lands on in September — without betting your roadmap on a single version of the rules.
If it has been a while since someone outside your team pressure-tested your environment, the next sixty days are a good time.
Sources
- Department of War, “Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements,” press release, July 13, 2026. war.gov/News/Releases
- DoW CIO policy memorandum and USD(A&S) implementation memorandum, publication case 26-P-1023, signed July 10, 2026, released July 13, 2026.
- Federal News Network, “Pentagon suspends CMMC phase two requirements, launches review of program,” July 13, 2026.
- Washington Technology, reporting on scope of suspension including Phase 3 and Phase 4, July 13, 2026.
- Department of War Request for Information, SAM.gov, posted July 13, 2026; responses due August 14, 2026.
- Morgan Lewis, “Department of War Suspends CMMC Phase II Requirements, but Cybersecurity Obligations Remain,” July 2026.
- Sheppard Mullin / Government Contracts Law blog, “DoD Suspends CMMC Phase 2: What Contractors Need to Know,” July 2026.
- National Defense Magazine, “Pentagon Suspends Phase 2 of CMMC Program,” July 13, 2026.
- Fortreum, “CMMC Phase II Is Suspended. Your Obligation Is Not.” July 13, 2026. fortreum.com
