On 13 July 2026, the Department released two memoranda suspending the upcoming CMMC implementation deadlines, including the 10 November 2026 transition to Phase 2 โ the point at which third-party C3PAO certification was to become a prerequisite for contracts involving controlled unclassified information. Phases 3 and 4 were suspended with it. A CMMC Reform Task Force was stood up to conduct a 60-day top-to-bottom review and deliver implementation recommendations.
This site covered the suspension itself when it happened, under the heading that suspended is not repealed.
That 60-day clock reports on or about 13 September 2026 โ roughly three weeks from the date of this article. This piece is about that decision point: what could come out of it, what does not change under any outcome, and what a contractor mid-way through assessment preparation should do in the intervening weeks.
What remains in force right now
This is the part that gets lost, and it is the part that carries enforcement risk today.
The suspension of third-party assessment as a contract prerequisite did not suspend any underlying cybersecurity requirement.
Specifically, all of the following continue to apply, unchanged:
DFARS 252.204-7012. Contractors handling covered defense information must provide adequate security by implementing NIST SP 800-171, must report cyber incidents to the Department within 72 hours of discovery, must preserve images of affected systems for at least 90 days, and must flow the clause down to subcontractors.
NIST SP 800-171. The 110 security requirements, plus a System Security Plan and Plans of Action and Milestones for anything not implemented.
DFARS 252.204-7019 and -7020. The requirement to have a current assessment score posted in the Supplier Performance Risk System (SPRS), and to keep it current. This site has covered the SPRS submission procedures in detail.
CMMC Phase 1. Level 1 and Level 2 self-assessment requirements took effect 10 November 2025 and remain in force. During the suspension, program managers and requiring activities may include CMMC Level 1 self-assessments or Level 2 self-assessments in procurement documents.
False Claims Act exposure. This is the one that should concentrate attention.
Why the FCA point dominates everything else
The Department of Justiceโs Civil Cyber-Fraud Initiative has produced a run of settlements built on a straightforward theory: a contractor that represents compliance with cybersecurity requirements while not meeting them has made a false claim.
The mechanism does not depend on CMMC at all. It depends on the score in SPRS and the representations in the contract.
A self-assessment score submitted to SPRS is an affirmative representation to the government. If that score overstates implementation โ because it was optimistic when submitted, because it was accurate then and the environment has since drifted, or because POA&M items were quietly closed without remediation โ the exposure is FCA exposure, with treble damages and per-claim penalties, and it is live today irrespective of what the Task Force recommends.
The suspension of third-party assessment increases this risk rather than reducing it, for a simple reason: self-assessment is the only mechanism operating, and self-assessment is where score inflation happens. The C3PAO assessment was, among other things, the control that would have caught overstated self-assessments. Removing it for now leaves the representation in place and removes the verification.
The single most valuable thing a contractor can do in the next three weeks is verify that its current SPRS score is defensible against evidence. Not plausible โ defensible, with artefacts, against each of the 110 requirements it claims.
Four plausible outcomes
The Task Force was directed to analyse industry feedback and propose recommendations reflecting realistic, scalable security measures that prioritise speed to capability and lower barriers for small and non-traditional businesses. That framing constrains the plausible outcomes.
Outcome 1 โ Phase 2 resumes on a delayed timeline. The programme proceeds substantially as designed with a new phase-in schedule. Preparation work retains its full value.
Outcome 2 โ Scope narrows. Third-party certification is retained but applied to a smaller population โ higher contract thresholds, a narrower definition of what triggers Level 2, or certification limited to specific mission areas. Given the explicit direction about small and non-traditional businesses, some version of this is the most likely single outcome. Larger primes and anyone handling substantial CUI remain in scope; the long tail moves to self-assessment.
Outcome 3 โ Self-assessment plus attestation replaces certification for most. Third-party assessment is reserved for a small set, with the majority moving to enhanced self-assessment accompanied by senior executive attestation. This would mirror the direction of travel elsewhere in compliance โ the CCPA risk assessment attestation regime being a recent example โ and it would increase individual accountability while decreasing assessment cost. Contractors reading this as a relaxation would be misreading it.
Outcome 4 โ Deeper restructuring. The maturity-model framing is replaced or substantially reworked, with a longer runway. Least likely within the stated timeframe, but it is what โtop-to-bottomโ leaves room for.
What is not on the list: elimination of the underlying requirements. No outcome removes DFARS 7012, NIST SP 800-171, the SPRS score, or the 72-hour incident reporting duty. Those sit in the DFARS and in contracts, not in the CMMC rule.
The no-regrets position
The useful analytical move is to identify the work that retains its value under all four outcomes, and do that work now. It is most of the work.
Actually implement NIST SP 800-171. Required today under DFARS 7012, unchanged under every outcome. Every hour spent on genuine implementation is an hour that pays regardless.
Get the SPRS score right. Re-run the self-assessment against evidence. Where the score is overstated, correct it and update SPRS. A corrected score is a manageable commercial problem; an uncorrected overstatement is an FCA problem.
Finish the CUI scoping. Knowing where CUI lives, how it flows, and what the assessment boundary is has value under every outcome and is the prerequisite for all of them. It is also the task contractors most often defer because it is tedious and cross-functional.
Close POA&M items rather than carrying them. POA&M items are, by definition, a documented statement that a required control is not implemented. Carrying a long POA&M through an FCA-focused enforcement environment is a poor position.
Maintain the evidence file. Screenshots, configuration exports, policy documents, training records, log samples โ organised by requirement. Under Outcome 1 or 2 this is the assessment package. Under Outcome 3 it is what makes the attestation defensible. Under all of them it is what answers a DOJ inquiry.
Keep flow-down current with subcontractors. DFARS 7012 flow-down is a present obligation, and supply chain assurance survives every outcome.
What to pause, and what to be careful about pausing
Some spend is genuinely outcome-dependent, and pausing it is reasonable.
Reasonable to pause: scheduling and paying for a C3PAO assessment where the contract requirement is suspended and no customer is demanding it; large consulting engagements scoped specifically to certification readiness rather than to control implementation; capital spend justified solely by a November 2026 date.
Be careful about pausing: anything that is also a NIST SP 800-171 requirement. The failure mode here is a contractor that halts its โCMMC programmeโ and inadvertently halts its 800-171 remediation, because internally the two were the same project with one name. Separate the budget lines before pausing either. If the programme cannot distinguish certification-specific spend from control-implementation spend, that is itself a finding.
Also be careful about losing the team. Cybersecurity programme staff hired for a November 2026 deadline will be reassigned or will leave during a pause, and the capability will have to be rebuilt when the timeline resumes. Retention through the review period is cheaper than reconstitution after it.
What to do in the next three weeks
Verify the SPRS score against evidence. The highest-value action available, for the reasons above.
Separate your budget and project lines into control implementation versus certification readiness, so that decisions after 13 September can be made surgically rather than by pausing everything.
Prepare a one-page brief for leadership covering each of the four outcomes and what the organisation does in each case. The value is in having the decision pre-made: when the recommendations land, the organisation acts in days rather than spending a month re-litigating strategy.
Talk to your primes. For subcontractors, the primeโs contractual flow-down requirements may be more demanding and faster-moving than the Departmentโs timeline. Several primes have continued to require certification readiness of their supply base irrespective of the suspension, because their own exposure did not change. That conversation is worth having before September.
Watch for the recommendations, not for a rule. The Task Force reports recommendations. Any change to the acquisition requirement then has to move through rulemaking, which takes considerably longer than the announcement. Expect a period of stated direction without changed regulation, and resist reading the announcement itself as an operative change.
The summary
A suspension is a change to when a third party checks, not to what is required. The requirements sit in DFARS clauses and in NIST SP 800-171, and they are in contracts that are being performed today.
The contractors who will come out of this period well are the ones who used it to make their SPRS score true. The ones who will come out of it badly are the ones who read a suspended deadline as a suspended obligation โ and who will discover the difference through a False Claims Act inquiry rather than through an assessment.
This article is provided for informational purposes only and does not constitute legal advice.



