If you’re a defense contractor and you’ve spent the last month thinking CMMC went away, this one’s for you. It didn’t. And the most expensive mistake being made across the defense industrial base right now is reading the word “suspended” as “stand down.”
Here’s where things actually stand, what just happened, and what you’re still legally on the hook for.
The Timeline, Straight
On July 13, the Department of War — the renamed Department of Defense — announced the immediate suspension of all CMMC Phase 2 requirements that had been scheduled to take effect November 10, 2026. Phase 2 was the big one: third-party assessments across contracts involving sensitive but unclassified information.
At the same time, the department stood up a CMMC Reform Task Force, led by the DoW Chief Information Officer, and charged it with a complete review of the program.
A Request for Information went out July 14 asking industry for feedback on cost drivers, administrative burdens, which security controls produce real outcomes, availability of commercial solutions, and specific policy reform recommendations. Comments were due at noon Eastern on Friday, August 14 — which just closed.
The task force delivers its recommendations to the CIO within 60 days of the announcement. That puts the report on or about September 13, 2026.
So the comment window is shut, and the clock is now running on a report that will shape what the defense industrial base has to do for years.
What’s Still In Force — Read This Part Twice
Phase 1 never stopped. Self-assessment requirements that took effect last November remain fully in force on applicable contracts. Nothing about the Phase 2 suspension touched them.
Your DFARS obligations never stopped either. DFARS 252.204-7012 and the NIST SP 800-171 requirements underneath it are separate from CMMC and were not suspended. If you handle controlled unclassified information, you are still required to implement those controls, still required to maintain a System Security Plan, and still required to report cyber incidents within 72 hours.
Your existing contract terms didn’t change. If CMMC language is already written into a contract you’ve signed, that language is still binding. A program-level pause doesn’t rewrite executed agreements.
And false statements are still false statements. Any self-assessment score you’ve submitted to SPRS is a representation to the government. The pause doesn’t make an inflated score retroactively fine. This is the exposure people forget about, and it’s the one with real legal teeth behind it.
The Good: The Review Is Not Unreasonable
The cost concern is legitimate, and it came from inside the building. The DoW CIO cited Small Business Administration data suggesting future CMMC phases could cost small and midsize businesses more than $7 billion annually. That’s not a lobbying number from a trade group — it’s the government’s own analysis of what it was about to impose.
Small suppliers were getting squeezed out. The defense industrial base depends on machine shops, specialty manufacturers and niche engineering firms — companies with genuine expertise and no compliance department. When certification costs more than a small supplier’s annual margin, you don’t get a more secure supply chain. You get a smaller one, concentrated in fewer large primes. That’s arguably worse for both security and cost.
Asking what actually works is the right question. The RFI specifically asks which controls produce tangible security outcomes. That’s a better question than most compliance regimes ever ask of themselves. Compliance frameworks tend to accumulate requirements and rarely subtract them, and a genuine look at which controls earn their cost is overdue.
The Bad: Pauses Have Costs Too
The threat didn’t pause. Adversaries targeting defense suppliers are not waiting for the task force report. The vulnerability CMMC was built to address — sensitive defense information sitting on under-protected small contractor networks — is exactly as real this week as it was in June.
Companies that did the work got punished. Plenty of contractors spent real money getting ready for a November deadline that evaporated with four months’ notice. That’s a genuine cost borne by exactly the businesses that took the requirement seriously, and it damages trust in the next deadline the government sets.
Uncertainty is expensive on its own. “We’re reviewing it” is one of the hardest environments to plan in. Do you keep spending toward a standard that might change? Stop and risk scrambling later? Small businesses feel this worst — they’re the least able to hedge and the most affected by whatever comes out in September.
And there’s no guarantee it gets easier. Everyone is reading this pause as a prelude to relaxed requirements. The task force was asked for “realistic, scalable” measures — which could mean simpler, or could mean restructured with the same substance and a different implementation path. Nobody outside that room knows yet.
What To Actually Do Between Now And September
Keep implementing NIST SP 800-171. Whatever CMMC becomes, it will be built on those controls. That work is not wasted under any plausible outcome.
Make sure your SPRS score is accurate. If it’s optimistic, fix it now while you’re doing so voluntarily rather than under scrutiny.
Keep your System Security Plan and POA&M current. Still required. Still the first thing anyone asks for.
Don’t cancel your assessment prep — reschedule it. The capacity constraint on qualified assessors doesn’t disappear because of a pause. When requirements resume, everyone who stood down will be competing for the same limited assessor pool at the same time.
And put September 13 on your calendar. That report is the next real signal.
The Takeaway
CMMC Phase 2 is suspended. CMMC Phase 1, DFARS 252.204-7012, NIST SP 800-171, your executed contract terms, and the accuracy of everything you’ve told the government are all still very much in force.
The review itself is defensible — the cost concerns are real and came from the government’s own data. But a pause is not a repeal, and the contractors who treat it as one are going to have a difficult autumn.
That’s why we cover both sides at GRiNDLiiFE. Empowerment doesn’t come from being told what to think. It comes from getting the full picture and deciding for yourself.
Stay ahead of compliance changes at grindliife.com — where discipline meets technology, and we always give you the whole story.
Note: This article is educational and is not legal advice. Contract obligations vary. Consult qualified counsel about your specific requirements.
