What was suspended: the Phase II acquisition transition. During the review, requiring activities may designate only Level 1 (Self) or Level 2 (Self) — Level 2 (C3PAO) and Level 3 (DIBCAC) requirements may not be designated, and affected solicitations and contracts are to be amended. November 10, 2026 is no longer an operative transition date. What did not change: DFARS 252.204-7012 safeguarding, NIST SP 800-171 Rev 2 implementation, the 72-hour incident report, DFARS 7019/7020 SPRS currency and government assessment authority, and 32 CFR Part 170 itself — the Program Rule was not repealed. The practical read: the suspension changes when certification is verified, not whether your systems must be secure, your SPRS score honest, and your affirmations defensible. Freeze the phase calendar, not the security program.
This article describes the position as of July 28, 2026. The program review is ongoing and further guidance was promised. Clause applicability must always be confirmed against your actual solicitation, contract, order, and flowdowns — this is educational analysis of public sources, not legal advice or contract review.
What actually happened
On July 13, 2026, the Department of War issued direction suspending the Phase II transition of the Cybersecurity Maturity Model Certification (CMMC) program, pending a 60-day program review by a newly established CMMC reform task force. A public request for information was opened to collect industry feedback.
Phase II was the step that would have broadly required third-party certification — assessments performed by a CMMC Third-Party Assessment Organization (C3PAO) — as a condition of award. It was scheduled to begin November 10, 2026.
The suspension moved the certification checkpoint. It did not move the security requirements, the reporting clock, or the honesty standard attached to your SPRS score.
That distinction is the whole article. A large share of the DIB read the headline as “CMMC is dead” and quietly stopped work. That is the single most expensive misreading available right now — because the obligations that actually carry contractual and legal consequence today were never part of Phase II.
What was suspended
- The Phase II acquisition transition. During the review, requiring activities may designate only Level 1 (Self) or Level 2 (Self) in procurements.
- Level 2 (C3PAO) and Level 3 (DIBCAC) designations. These may not be designated in new requirements during the suspension, and affected active solicitations and contracts are to be amended or modified.
- The November 10, 2026 date. It is no longer an operative transition date. Later phase dates should be treated as pending revised guidance — not quietly rescheduled to a date you invented.
The direction contemplates that affected solicitations and contracts are amended or modified. That is a contracting-officer action, not a self-help one. Confirm your specific position in writing with your contracting officer — do not assume a requirement lapsed on its own.
What did not change — the part that matters
Everything below remains in force. None of it was part of the Phase II transition:
| Authority | What it still requires | Status |
|---|---|---|
| FAR 52.204-21 | 15 basic safeguarding requirements for systems handling Federal Contract Information (FCI) | Operative when included / applicable |
| DFARS 252.204-7012 | Adequate security, NIST SP 800-171 Rev 2 implementation, 72-hour cyber incident reporting, media preservation, FedRAMP-Moderate-equivalent cloud protections, and flowdown | Remains in effect |
| DFARS 252.204-7019 / -7020 | A current NIST SP 800-171 assessment score posted in SPRS, and government assessment access | Remain operative |
| 32 CFR Part 170 | The Program Rule defining Levels 1–3, assessment types, POA&M limits, scoring, and annual affirmations | Not repealed |
| Phase I self-assessments | Level 1 and Level 2 self-assessment requirements in solicitations, with affirmation | Still designated |
Read that table again with a procurement eye. Your SPRS score still gates award eligibility under 7019/7020. Your 72-hour reporting duty is unchanged. Your annual affirmation still carries the representation risk it always did. The suspension touched none of it.
Knowingly false or materially misleading cybersecurity representations can create False Claims Act exposure — and enforcement has been active in precisely this area. A suspended certification mandate does not make an inflated SPRS score safer to leave posted. If anything, the review period is the cheapest time you will ever have to correct one.
The numbers that still govern your program
| Number | What it is |
|---|---|
| 110 | NIST SP 800-171 Rev 2 requirements still required for CUI |
| 72 hours | The DFARS 7012 cyber-incident reporting window |
| 15 | FAR 52.204-21 basic safeguarding requirements for FCI |
| 80% | Minimum score (88 of 110) for a Conditional CMMC status under the Program Rule |
| 180 days | The window to close POA&M items and convert a Conditional status to Final |
If you want to understand where the 110 and the score actually come from, start with Your SPRS Score, Explained — the arithmetic is unchanged by the suspension.
Why the review was ordered
Two pressures, both structural, both publicly reported:
- Cost to small and mid-size business. Small Business Administration data cited by the Department suggested future CMMC phases could cost small and midsize businesses more than $7 billion annually.
- Assessor capacity. Roughly 100,000 companies were expected to need assessments against on the order of 100 authorized C3PAOs — a throughput mismatch that no schedule could absorb.
That matters for how you plan. This was not a determination that the security requirements were wrong; it was a determination that the verification pipeline could not carry the load on the announced timetable. Programs that assume the requirements are going away are betting against the stated rationale.
Read your contract in three layers
The cleanest way to reason about any defense contract right now is to separate three things that people routinely collapse into one:
- The standing architecture. FAR 52.204-21, DFARS 7012 / 7019 / 7020 / 7021, and 32 CFR Part 170. This is the durable law-and-clause layer. It was not repealed.
- The current implementation direction. The July 13, 2026 suspension. This governs which assessment types may be designated right now — and it is temporary by construction.
- Vendor and ICT source allowability. Governed separately through acquisition, program, and supply-chain direction. A product can satisfy every cybersecurity requirement and still be excluded from a particular contract or system.
Layer 2 is the only one that changed on July 13. Teams that had not separated the layers experienced the suspension as “everything is uncertain.” Teams that had, changed exactly one line in their plan — the phase calendar — and kept going.
Rev. 2 is still the baseline — treat Rev. 3 as planned uplift
A second, quieter thread runs alongside the suspension. In June 2026 the FAR Council published a proposed government-wide CUI rule as part of a broader FAR overhaul. It would extend a common CUI method across executive-agency acquisitions — not only defense work — and it points at NIST SP 800-171 Revision 3.
It is a proposed rule, not an operative clause. So the planning boundary is precise:
- CMMC and DFARS 7012 use Rev. 2 today. That is your contractual baseline. Do not represent Rev. 3 as your current CMMC baseline.
- Do not postpone Rev. 2 remediation while waiting for a future rule to land.
- Maintain a Rev. 3 delta plan — the family reorganization and organization-defined parameters — so an uplift is a planned project rather than an emergency.
If the endpoint side of that uplift is on your mind, Windows Pro vs. Enterprise for NIST 800-171 Rev 3 covers where the licensing wall actually sits.
The layer people miss: source allowability
Here is the failure mode that the suspension news is currently hiding, and it will outlast the review.
A FedRAMP authorization or a CMMC status does not establish that a given vendor, service, model, API, or subprocessor is permitted on every defense contract. Source allowability is governed independently — through acquisition, program, supply-chain, and contract direction. A service can be perfectly compliant on the cybersecurity axis and still be excluded, or ordered removed, from a covered contract.
This is not hypothetical or new: supply-chain exclusion authority is long-established in statute and in the DFARS supply-chain-risk clauses. What is new is how fast the dependency surface is growing — particularly with AI services, which arrive with models, hosting platforms, APIs, agents, embedded integrations, and subprocessors behind them, often adopted without a procurement review.
Three durable moves, none of which depend on any particular vendor or news cycle:
- Keep an AI and ICT dependency register. An AIBOM/SBOM-style inventory of models, APIs, hosting platforms, agents, libraries, data sources, embedded integrations, subprocessors, and downstream consumers. You cannot assess — or remove — what you never inventoried.
- Put a source-allowability gate in front of adoption. Require contract, program, supply-chain, and legal review before a new AI or ICT source enters a defense workflow. Do not treat FedRAMP or CMMC eligibility as blanket approval.
- Design for portability. Modular integrations, controlled prompt and configuration repositories, portable test suites, and a documented alternative — so that a source restriction becomes a migration, not an outage.
This section deliberately states the general principle rather than tracking any single vendor dispute. Specific exclusion or removal directions are contract-specific and often reported before they are publicly documented — so treat press reporting as a prompt to verify against written contract direction from your contracting officer, never as the direction itself.
What to do in the next 30 days
- Freeze the phase calendar — not the security program. Strip November 2026/2027/2028 certification assumptions out of operating plans, and keep funded remediation and evidence work running.
- Reconfirm clause and data scope. Map FCI, CUI, CDI, and export-controlled information to actual contracts, systems, users, suppliers, and services. Clause applicability is not the same thing as general data sensitivity.
- Validate every SPRS score. Reconcile the posted score against the current SSP, the scoring methodology, objective-level evidence, POA&Ms, and the system boundary. Correct anything unsupported through the appropriate process.
- Keep the evidence package current. Asset inventory, network diagram, SSP, policies, procedures, technical artifacts, and named control owners — all of it stays live even while C3PAO designations are suspended.
- Reassess cloud and external service provider dependencies. Validate the exact offering's authorization or equivalency, incident terms, forensic access, shared-responsibility split, and support-personnel model.
- Stand up the source-allowability gate and dependency register described above.
- Put a governance owner on it. One accountable person maintaining the regulatory cutoff date, the clause matrix, the dependency register, and the Rev. 2 / Rev. 3 delta — and re-versioning the plan whenever official guidance changes.
Validate your SPRS score against real evidence. It is the one number the government can see today, it gates award eligibility under DFARS 7019/7020, it carries representation risk, and — unlike a C3PAO assessment — nothing about it is suspended.
What to watch next
- Post-review CMMC guidance. Further guidance was promised after the 60-day review; no replacement phase schedule has been published. Treat any date you hear before that as rumor.
- Final disposition of the June 2026 FAR CUI proposal — including whether the government-wide rule proceeds on Rev. 3.
- Written contract direction on any vendor, ICT, or AI source restriction relevant to your programs.
Update your contract playbooks when official text or direction changes — not when reporting appears.
Key takeaways
- Only the acquisition rollout was suspended. Phase II third-party certification and Level 3 designations are paused during a 60-day review; November 10, 2026 is no longer operative.
- The Program Rule was not repealed. 32 CFR Part 170 still defines the levels, POA&M limits, scoring, and affirmations.
- Your live obligations are untouched: DFARS 7012 safeguarding, NIST SP 800-171 Rev 2, 72-hour reporting, SPRS currency under 7019/7020, and FAR 52.204-21 for FCI.
- Rev. 2 is today's baseline; Rev. 3 is planned uplift. Don't represent the proposed FAR CUI rule as your current requirement.
- Certification status is not source approval. Keep a dependency register and a source-allowability gate — that risk is independent of CMMC entirely.
- Freeze the calendar, not the program. The suspension changed when certification gets verified, not whether you have to be secure and honest about it.
Sources
- DoD CIO — CMMC program (official program page and current implementation notices) ↗
- eCFR — 32 CFR Part 170 (CMMC Program Rule) ↗
- eCFR — 32 CFR 170.21 (POA&M requirements, conditional status and closeout) ↗
- Acquisition.gov — DFARS 252.204-7012 (safeguarding CDI and incident reporting) ↗
- Acquisition.gov — DFARS 252.204-7019 (assessment reporting) ↗
- Acquisition.gov — DFARS 252.204-7020 (NIST SP 800-171 DoD assessment requirements) ↗
- Acquisition.gov — DFARS 252.204-7021 (CMMC status requirement) ↗
- Acquisition.gov — FAR 52.204-21 (basic safeguarding of covered contractor information systems) ↗
- NIST SP 800-171 Rev 2 (current CMMC Level 2 / DFARS 7012 baseline) ↗
- NIST SP 800-171 Rev 3 (proposed FAR CUI baseline / transition planning) ↗
Cloud consoles and federal guidance change; confirm control text and clause language against the official publication that applies to your contract. This article is independent education and does not by itself establish compliance or confer CMMC certification.