CMMC

CMMC Phase 2 Suspended: What Actually Changed for Your CMMC Level 2 Compliance Timeline

CMMC Phase 2 Suspended: What Actually Changed for Your CMMC Level 2 Compliance Timeline

If you read the July 13 news and assumed CMMC is dead, that is not what happened. If you read it and now have no idea whether your upcoming assessment still counts, that is the more useful question to be asking. The Department of War suspended the requirement for third-party certification. It did not suspend the requirement to have your security posture in order, to score it accurately, or to answer for that score if it turns out to be wrong.

Here is what that distinction means for your timeline, whether you have a prime contractor waiting on a Level 2 certificate or not.

For orientation on the certification structure this news is changing, see What is CMMC 2.0 Level 1?

What happened to the CMMC Phase 2?

On July 13, 2026, the Department of War suspended CMMC Phase II: the transition, originally set for November 10, 2026, that would have required third-party (C3PAO) certification for Level 2 and government-led assessment for Level 3. The suspension was implemented through a CIO memo signed July 10 and announced by DoW CIO Kirsten Davies alongside Under Secretary of War for Acquisition and Sustainment Michael Duffey.

During the suspension, contracts can only carry Level 1 (Self) or Level 2 (Self) designations. No waivers are being issued while the review runs. Active solicitations that still list Level 2 (C3PAO) or Level 3 requirements are supposed to be amended to remove them as soon as practicable, and existing contracts are to be updated at their next option period or scheduled modification. Level 1 self-assessment requirements are untouched.

A CMMC Reform Task Force now has 60 days from the announcement to review the program and report back to the DoW CIO, putting a report around mid-September 2026. Davies and Duffey have both declined to rule out narrowing, restructuring, or cancelling the program outright once that review concludes. The stated rationale is cost and capacity. DoW’s own announcement cited an estimate of more than $7 billion a year in aggregate compliance costs for small and mid-sized businesses, alongside a figure of roughly 100 authorized C3PAOs available to eventually assess more than 100,000 businesses. Davies framed the move as “reducing red tape.”

DoW has also opened a formal comment period. Its Request for Information, “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base,” is open for public comment through 12:00 PM ET on Friday, August 14, 2026. If your organization has a specific view on how CMMC should work, this is the window to submit it.

What has not changed

Everything that makes a contractor’s security posture real is still in force. NIST SP 800-171 Rev. 2, the baseline guideline DoD requires for protecting controlled unclassified information, still applies in full. SPRS scoring, annual affirmations, and the DFARS 252.204-7012 clause requiring that reporting are all still active and still enforced under the False Claims Act. DoW has said it will continue to rely on self-assessments and government-led DIBCAC reviews during the suspension.

The clearest evidence that this obligation carries real consequences is not hypothetical. On June 18, 2026, the Department of Justice announced that LOGZONE Inc., a Huntsville, Alabama defence contractor, agreed to pay $507,144 to resolve False Claims Act allegations tied to two Navy contracts. LOGZONE had self-reported a perfect SPRS score of 110 in October 2021. A DCMA DIBCAC assessment completed in February 2024 found the company’s actual score was -170, near the bottom of the assessment scale. DOJ alleged the company knowingly billed the Navy from May 2021 to March 2025 while non-compliant. The case started with a routine government assessment.

That is the risk profile that matters right now. With Phase II suspended, self-assessment now carries the full weight of the compliance requirement for most contractors. An inaccurate score carries the same legal exposure LOGZONE faced, whether or not a C3PAO was ever going to check it.

Not sure your SPRS score would hold up under a DIBCAC review? Get your CMMC self-assessment checked by a credentialed advisor before you submit it.

Does this change your CMMC timeline?

The answer depends on where your certification requirement actually comes from.

If your CMMC obligation came only from the federal Level 2 timeline, and no prime contractor has its own certification demand, self-assessment is now your ceiling and your floor. There is currently no path to a mandatory C3PAO audit under the federal program, and no clear date for when or if that changes. Getting an accurate, advisor-reviewed self-assessment submitted and defensible is the complete requirement in front of you today.

If your prime contractor requires a Level 2 C3PAO certificate as a condition of the subcontract, this suspension does not touch that. The federal pause is a Department of War policy action. It does not rewrite your subcontract, and it does not change the DFARS clauses your prime flows down to you. Several large primes, including L3Harris, Lockheed Martin, Northrop Grumman, Boeing, Parsons, and Elbit America, have been requiring Level 2 certification from suppliers on their own timelines, independent of the federal deadline. If that is your situation, nothing here changes what you owe your prime.

Where Carbide fits with this update to CMMC

The suspension sharpens a distinction that was already true: a C3PAO and an advisory team are not doing the same job, and they are not allowed to.

The Cyber AB’s Code of Professional Conduct bars a C3PAO from providing consulting, remediation, or preparation services to an organization it also assesses. That is a structural conflict-of-interest rule that applies to every C3PAO, regardless of size or specialty. A C3PAO can tell you what is wrong. It cannot help you fix it, and if it tried, the resulting certification could be challenged or revoked. That is exactly why the ecosystem has a separate category of Registered Provider Organizations for preparation work, kept apart from the C3PAOs that perform the independent assessment.

Carbide is not a C3PAO. Carbide’s credentialed advisory team can interpret your controls, help you close the gaps, and stand behind the self-assessment before it goes into SPRS, using the automation platform to keep evidence organized and mapped to each control along the way. That combination, a platform that keeps the work organized and an advisor who can act on what it finds, is what most contractors need right now.

If you have no prime flow-down requirement, this means you can get to a defensible self-assessment with expert review and skip the C3PAO expense entirely, unless a specific contract calls for it. If you are still early in scoping which level applies to your business, our free CMMC 2.0 self-assessment is the fastest way to find out.

Finish your self-assessment with expert help and skip the C3PAO expense unless your contract specifically requires it.

If your prime still requires a Level 2 certificate regardless of the federal pause, the calculus is different but the value is related. With fewer contracts currently requiring a C3PAO audit at the federal level, contractors who still need certification may find scheduling easier than they would have under the original November deadline crunch. Carbide can get your evidence audit-ready either way, so you are not starting remediation the week your prime sets a deadline.

If your prime still requires a Level 2 certificate, we’ll get your evidence audit-ready.

What is still uncertain

A few things are unresolved and must be monitored.

The Reform Task Force’s conclusion is not public yet, and officials have explicitly declined to rule out narrowing, restructuring, or cancelling CMMC once the review is done. Any formal change to the underlying rule, 32 CFR Part 170, or the DFARS clauses themselves would require a separate rulemaking process, which takes months regardless of what the task force recommends.

A separate development adds a wrinkle worth tracking if you also serve civilian federal agencies. On June 23, 2026, the FAR Council published a proposed rule that would require civilian federal contractors to meet the newer NIST SP 800-171 Rev. 3 baseline once finalized, with comments due July 23, 2026. DoD has yet to adopt Rev. 3 for CMMC and would need its own rulemaking to do so. If you sell into both DoD and civilian agencies, you could end up managing two versions of the same baseline guideline depending on how each review resolves. For more background on how the certification structure works while this plays out, see CMMC 2.0 compliance: what you need to know.

What to do next

The suspension changed who is checking your work in the near term. It did not change what your work has to look like. Getting your self-assessment accurate, documented, and reviewed by someone credentialed to catch what you might miss is the highest-value compliance step available to nearly every contractor right now, regardless of which segment above describes you.

Talk to a Carbide advisor about what the July 13 suspension changes for your specific contracts.

Share