The CMMC Suspension: What Changed and What Didn't

Last updated July 22, 2026 — maintained as the Reform Task Force acts

What happened

On July 13, 2026, the Department of War CIO suspended CMMC Phase II requirements and directed a CMMC Reform Task Force to review the program end to end. The Department's stated reason: Phase II compliance costs and administrative burden were creating unacceptable roadblocks for small and mid-size defense contractors. The official memo is posted in the DoD CIO library, and the Department asked industry for reform input by August 14, 2026.

What was suspended

Phase II — the requirement for third-party (C3PAO) certification assessments in new contract awards. Certification timelines and the assessment queue are paused while the Task Force works.

What remains binding

The suspension did not touch the underlying data-protection obligations. If you handle Controlled Unclassified Information:

  • NIST SP 800-171 remains the security baseline for CUI, required by contract.
  • DFARS 252.204-7012 still requires safeguarding covered defense information and 72-hour incident reporting — and its cloud provisions still apply.
  • DFARS 252.204-7019/-7020 still require a current NIST SP 800-171 self-assessment score in SPRS.
  • Phase I self-assessments and annual affirmations continue.A company official still signs an affirmation of compliance — and the DOJ's Civil Cyber-Fraud Initiative has already produced False Claims Act settlements over cybersecurity misstatements. With certification paused, the affirmation you sign is where the scrutiny concentrates.

What a small contractor should do now

  1. Keep your SPRS score current — and make it defensible. A score you can trace to evidence is an asset; a guessed score is a liability with a signature on it.
  2. Treat the affirmation as the deliverable. Before your official signs, know exactly which requirements are met, which have open plans of action, and what evidence stands behind each claim.
  3. Bound your CUI footprint. Scope is the biggest cost lever you control. The less of your business that touches CUI, the less there is to protect, evidence, and answer for. Reform direction favors bounded environments.
  4. Don't dismantle what you've built. The protective controls NIST 800-171 asks for are the ones that stop real intrusions. Certification mechanics are under review; the security obligations — and the threat — are not.
  5. Watch the reform, not the rumors.The Task Force is expected to move quickly. Decisions should track the Department's actions, not speculation.

How Blue Heron Defense helps

Our front door is a Defensible Self-Assessment: an automated readiness evaluation of your environment that produces a current, evidence-backed SPRS picture — which requirements you meet, which gaps need plans of action, and what your affirming official would be signing against. It is a self-assessment support engagement, not a certification, and we say so plainly: no one can certify you right now, and we don't pretend otherwise.

From there, if you need a place to handle CUI without dragging your whole company into scope, we build and operate bounded GCC High enclaves that configure, evidence, and document themselves — so compliance is a by-product of operating, not a yearly scramble.

Stay current

CMMC reform will move over the coming months. We publish updates as the Task Force acts — see the CMMC news feed, or get updates by email: