Orbital FederalFederal

Cyber Compliance

What the CMMC Phase 2 suspension actually means

On 13 July 2026 the Department suspended Phase 2 and stood up a reform task force. A lot of contractors read that as a reprieve. For most of them it isn't one.

The short answer

The certification tier was suspended. The security obligation was not. DFARS 252.204-7012, NIST SP 800-171 implementation, SPRS score posting, and annual affirmations all continue exactly as before, and government-led assessments still happen.

If you were treating 10 November 2026 as your deadline rather than treating the requirement as the requirement, the suspension bought you time — not absolution. And the affirmation you sign is still a personal accountability instrument.

What actually happened

Two memoranda issued on 13 July 2026 suspended Phase 2 of the CMMC acquisition rollout with immediate effect, along with Phases 3 and 4. Phase 2 was the consequential one: from 10 November 2026 it would have made independent third-party assessment by a C3PAO a condition of contract award for contractors handling Controlled Unclassified Information.

Alongside the suspension, the Department established a CMMC Reform Task Force and directed it to conduct a top-to-bottom review and report to the CIO within 60 days — placing recommendations in the mid-September 2026 timeframe. An RFI collected industry input, with responses due 14 August 2026. The stated aim is a framework that prioritises speed to capability, lowers barriers for small and non-traditional businesses, and replaces third-party compliance models with what the Department describes as scalable, realistic security measures.

What did not change

This is the part that gets lost in the headline. Every one of the following remains in force:

  • Phase 1 — in effect since 10 November 2025, with self-assessment levels designated in solicitations
  • DFARS 252.204-7012 — safeguarding covered defense information, and 72-hour cyber incident reporting
  • NIST SP 800-171 — the control set you are actually measured against
  • DFARS 252.204-7019 and -7020 — current SPRS score submission, and government access to conduct assessments
  • Annual affirmations — signed by a named individual, with the accountability that implies
  • The program rule itself, at 32 CFR Part 170

Nor were existing certifications invalidated. If you completed a Level 2 assessment, that stands. The suspension concerns whether certification gates award in new solicitations — not the validity of work already done.

Who is now more exposed, not less

Counterintuitively, the suspension increases risk for a specific population: contractors whose compliance was documentary rather than operational, and who were relying on the Phase 2 date to force the issue.

The pattern we see repeatedly looks like this. A score was posted to SPRS two or three years ago. The System Security Plan describes an environment that has since changed — new SaaS, a migration, an acquisition, remote work that became permanent. The POA&M exists but has no dates, or has dates that passed. And someone signs the annual affirmation anyway, because the alternative conversation is uncomfortable.

That combination is a false affirmation exposure, and it does not depend on CMMC at all. It depends on DFARS clauses that were never suspended, and on assessments the government can still conduct. The Phase 2 deadline was, for many organisations, the thing that was finally going to force the cleanup. Removing it removed the forcing function, not the liability.

What to do between now and whatever comes next

The strategic answer is to do the work that survives any outcome. Almost everything genuinely useful here is framework-agnostic:

1. Fix your scope first

Decide precisely where CUI lives, moves, and is processed — and where it does not. Scope is the single largest driver of both cost and score, and it is the decision most organisations never documented properly. An enclave you can defend beats an enterprise you cannot.

2. Make the SSP describe reality

If a stranger read your System Security Plan and then looked at your environment, would they recognise it? If not, that gap is your largest single finding, and it is entirely within your control to close.

3. Put dates and owners on the POA&M

A plan of action with no milestones is not a plan. Size it against the capacity you actually have, not the capacity you wish you had.

4. Re-derive your SPRS score honestly

Show the arithmetic. Sequence remediation by point value against effort. A defensible score you can explain is worth more than a flattering one you cannot.

5. Walk the building

A meaningful share of 800-171 is physical: who gets into the room, how media is handled and destroyed, how visitors and maintenance are escorted, what happens to a drive when it leaves. Most cyber consultancies write those controls from a template and never look at the facility. Assessors do look.

What we would not do right now

  • Don't buy a certification-shaped product. Until the framework lands, tooling sold against a specific assessment tier may be solving a problem that changes shape.
  • Don't stand down your programme. The obligations continue and restarting costs more than maintaining.
  • Don't assume your primes relaxed. Flow-downs are contractual. A prime that wrote security requirements into your subcontract still has them, whatever the Department does with Phase 2.
  • Don't wait for certainty to fix the SSP. That document is wrong today regardless of what happens in September.
Currency and caveat Accurate as of 17 August 2026. This file moves — phases get suspended, rules get amended, task forces report. What applies to you depends on the clauses in your specific contracts, and nothing here is advice on your obligations. Confirm with counsel, your contracting officer, or us against your actual contract set.

Questions

What contractors are asking

Is CMMC cancelled?
No. Phase 1 of the acquisition rollout remains in effect and has been since 10 November 2025. What was suspended on 13 July 2026 is Phase 2 — which would have begun on 10 November 2026 and made third-party C3PAO certification a condition of contract award — along with Phases 3 and 4. The program rule at 32 CFR Part 170 still exists. A CMMC Reform Task Force is reviewing the program and was directed to deliver recommendations to the Department's CIO within 60 days, placing that report in the mid-September 2026 timeframe.
What still legally binds us today?
DFARS 252.204-7012 still requires you to safeguard covered defense information and report cyber incidents. NIST SP 800-171 implementation is still the standard you are measured against. DFARS 252.204-7019 and -7020 still require a current SPRS score and government access for assessment. Annual affirmations still apply, and they carry personal accountability for the person who signs them. None of that was suspended.
Should we stop our CMMC preparation work?
Almost certainly not, and the reason is that most of the work was never CMMC-specific. Scoping where CUI lives, implementing the 800-171 controls, writing an SSP that describes the environment you actually run, and maintaining a POA&M with real dates are obligations under DFARS regardless of what happens to the certification tier. Stopping now means paying twice — once to unwind, once to restart when the framework lands.
What happens to a certification we already hold?
Certifications issued under the existing program were not invalidated by the suspension. The suspension concerns whether certification becomes a condition of award in new solicitations, not the status of assessments already completed. If you invested in a Level 2 assessment, that investment stands.
When will we know what replaces Phase 2?
The task force was directed to report within 60 days of the 13 July memoranda, which puts recommendations around mid-September 2026. Recommendations are not rules — any change to the acquisition requirement would still need to work through rulemaking or class deviation. Expect the picture to become clearer in the autumn and the mechanics to take longer.

Next Step

Do your score, your SSP, and your reality agree?

A scoped gap assessment answers that in weeks. We are not a C3PAO — which is exactly why we can be honest about what we find.

Prefer to talk? 866.960.7475 · info@orbitalfederal.com