On July 13, 2026, the Department of Defense (now operating under the secondary designation Department of War, or DoW) announced the immediate suspension of CMMC Phase 2 requirements. Phase 2 had been scheduled to take effect November 10, 2026, roughly four months from that announcement, and would have made third-party C3PAO certification mandatory for most contracts involving Controlled Unclassified Information. Along with Phase 2, the DoD suspended the pending Phase 3 and Phase 4 milestones. A 60-day CMMC Reform Task Force is now conducting a top-to-bottom review of the entire program, with a report due to CIO Kirsten Davies around mid-September 2026.

For any Orange County defense contractor who has been paying attention to the CMMC enforcement timeline, this is genuinely the biggest CMMC development since the program went into effect in November 2025. It is also, importantly, not what most contractors initially assumed it was. The suspension is real, but the underlying cybersecurity obligations remain fully in force. And in one specific and increasingly dangerous way, self-attesting contractors are now exposed to more legal risk, not less.

Here is what the CMMC 2.0 update actually changed, what it explicitly did not change, and what every Orange County defense contractor should be doing between now and mid-September when the Task Force report is due.

July 13, 2026
DoD announces immediate suspension of CMMC Phase 2
~2,000
defense contractors already certified at CMMC Level 2 voluntarily
$7B
projected annual small business compliance cost cited by SBA
$507K
Alabama contractor FCA settlement, June 18, 2026 (weeks before suspension)

What was actually suspended

The DoD’s suspension covers three specific things. First, the Phase 2 transition scheduled for November 10, 2026, which would have made mandatory Level 2 C3PAO certification a condition of award for applicable CUI contracts. Second, all pending and future implementation milestones (Phases 3 and 4). Third, and most immediately actionable, any active solicitations that already included CMMC Level 2 C3PAO or Level 3 assessment requirements must now be amended to remove those requirements.

During the suspension period, DoD contracting officers may only include CMMC Level 1 (Self) or Level 2 (Self) assessment requirements in new government contracts. Third-party assessments by C3PAOs remain available for contractors who choose to pursue them voluntarily (roughly 2,000 defense contractors have already earned Level 2 certification under the pre-suspension framework), but the DoD is not requiring them.

The stated rationale from CIO Kirsten Davies focused on three specific concerns. Prohibitive compliance costs were the primary driver: SBA data suggested future CMMC phases could cost small and mid-sized businesses more than $7 billion annually, with individual compliance bills approaching $600,000. The C3PAO capacity crisis was a secondary factor, with roughly 80 authorized assessors serving 80,000+ contractors and wait times projected to exceed 18 months by Q3 2026. And the broader Acquisition Transformation System framework, led by Secretary Pete Hegseth, prioritized speed to capability and lower barriers for small and non-traditional defense businesses over what Davies called the program’s “paralyzing costs” and “red tape.”

What was explicitly NOT suspended (and this is the part that matters most)

The suspension is narrower than most contractors initially assumed. Nearly every underlying cybersecurity obligation remains fully in force. The suspension is a specific pause on one verification mechanism, not a broad rollback of the security requirements themselves.

NIST SP 800-171 Rev. 2 remains active. All 110 security controls organized across 14 control families remain the required standard for protecting CUI. Contractors handling covered defense information must still implement these controls in full.

DFARS clause 252.204-7012 remains active. The clause requiring contractors to safeguard covered defense information, implement NIST SP 800-171, and rapidly report cyber incidents (within 72 hours) remains in every applicable DoD contract.

SPRS self-assessments remain mandatory. During the suspension, contracts can only require CMMC Level 1 (Self) or Level 2 (Self), and contractors still submit their scores to the Supplier Performance Risk System and affirm them annually. Senior official affirmations under penalty of False Claims Act liability remain in effect.

Government-led DIBCAC assessments continue. The Defense Industrial Base Cybersecurity Assessment Center still conducts on-site government assessments of contractors, particularly those handling higher-sensitivity CUI. The suspension does not affect these.

Prime contractor flowdowns remain enforceable. Prime contracts that flowed CMMC-adjacent cybersecurity requirements down to subcontractors are still binding on those subs. The Pentagon’s announcement does not change the terms of existing contracts, and primes are not obligated to renegotiate flowdowns even if the underlying regulatory requirement changed.

DoJ Civil Cyber-Fraud Initiative remains fully active. This is the piece contractors most consistently underweight. The Department of Justice continues to pursue False Claims Act cases against contractors whose self-attested cybersecurity representations do not match their actual security posture. On June 18, 2026, less than a month before the suspension announcement, an Alabama defense contractor agreed to pay $507,144 to resolve FCA liability specifically related to cybersecurity violations. That enforcement pattern continues.

The False Claims Act problem the suspension quietly created

The counterintuitive outcome of the CMMC 2.0 update is that self-attesting contractors may now face more legal risk, not less. Here is why. Under the pre-suspension framework, a C3PAO assessor would validate a contractor’s SPRS score before contract award. The gap between what a contractor claimed and what an assessor found would surface during the audit process, giving the contractor an opportunity to remediate before the government relied on the score for contracting decisions.

Under the suspended framework, no independent assessor validates the score. The senior official signing the annual SPRS affirmation is now the sole party attesting to the accuracy of the cybersecurity representations. When the DoJ pursues an FCA case, the target is that affirmation and the person who signed it. As one industry analysis put it bluntly: “The audit is gone. The liability isn’t.” The enforcement model just shifted from “pass an audit” to “sign an affirmation the Department of Justice can prosecute you over.”

The MORSE Corp precedent applies here in full. MORSE self-attested an SPRS score of 104 (near the perfect 110), when the actual posture was negative 142. They settled with the DoJ for $4.6 million in January 2025. The whistleblower collected $851,000. That case pattern (self-attested representation, gap discovered, whistleblower or investigation surfaces the misrepresentation, treble damages and per-claim penalties follow) is not affected by the CMMC 2.0 update in any way. In some respects it becomes easier for the DoJ, because the contractor’s affirmation is the only representation the government relied on.

Red flag: If your SPRS score is inflated relative to your actual security posture, the CMMC Phase 2 suspension does not protect you. It arguably increases your personal exposure as the senior official who signs the annual affirmation. The C3PAO who would have caught the gap during assessment is no longer in the workflow. The DoJ’s Civil Cyber-Fraud Initiative absolutely is.

What contractors think changed vs. what actually applies

Contractor assumption after July 13 Actual reality
“CMMC is dead, we can pause compliance work” CMMC Phase 2 is suspended pending review. Underlying requirements remain fully in force.
“We don’t need NIST 800-171 anymore” NIST SP 800-171 Rev. 2’s 110 controls remain required under DFARS 252.204-7012.
“Self-attestation is safer than certification” Self-attestation is now the sole target of DoJ FCA enforcement. Personal liability increased.
“Our prime doesn’t care about CMMC anymore” Prime contract flowdowns are binding regardless of Pentagon announcements.
“Voluntary Level 2 certification is a waste now” The ~2,000 already-certified contractors now have measurable competitive advantage.
“The DoJ has moved on to other priorities” Alabama contractor paid $507K on June 18, 2026. Enforcement is active and current.
“CMMC will never come back” Task Force report due mid-September 2026. Program will likely return, possibly modified.

The competitive positioning shift for early-certified contractors

One outcome that is not being discussed enough: the roughly 2,000 defense contractors who invested in voluntary CMMC Level 2 C3PAO certification before the suspension are now in a distinctive market position. Their investment did not become worthless. Their certification is real, valid, and demonstrable. And their competitors who delayed pursuing certification are now in a compliance environment where the audit backstop has been removed, leaving them exposed to FCA risk without the third-party validation that would have insulated them.

For Orange County defense subcontractors who had begun serious remediation work in anticipation of Phase 2, the honest guidance is: continue the work. The controls you were implementing to prepare for a C3PAO audit are the same controls required by DFARS 252.204-7012 and NIST 800-171. Your remediation program was building genuine security posture, not just audit-ready documentation. That security posture pays off in three ways: reduced breach risk, defensible SPRS score for FCA purposes, and competitive advantage in a market where certified contractors are increasingly the ones primes want in their supply chain.

What defense contractors should do between now and mid-September

The 60-day CMMC Reform Task Force review ends around mid-September 2026, followed by DoD guidance that will define what the program looks like going forward. Contractors have a specific window to act. The honest playbook:

  1. Verify that your SPRS score accurately reflects your actual security posture. If it does not, the gap is now a personal liability for the senior official signing the annual affirmation. Correct inflated scores now, before an investigation or whistleblower surfaces the discrepancy.
  2. Continue NIST 800-171 implementation and remediation. The 110 controls remain required. Suspended C3PAO assessment does not translate to suspended security requirements. Every remediation effort you complete strengthens both your defensive posture and your FCA defensibility.
  3. Maintain SPRS reporting and annual affirmations. These remain required under existing DFARS clauses. Missing an affirmation deadline or filing an inaccurate one creates enforceable liability regardless of the Phase 2 status.
  4. Review your prime contract flowdowns. Contracts binding you to CMMC-adjacent cybersecurity requirements are still binding. Primes are not required to renegotiate. Talk to your contracting officer if you are uncertain about what applies.
  5. Do not cancel voluntary C3PAO assessments if underway. If you were in preparation for a voluntary Level 2 assessment, the certification is still valid and increasingly a competitive differentiator. The ~2,000 already-certified contractors are structurally advantaged in the current environment.
  6. Submit RFI feedback if your business has views. The DoD’s Request for Information “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base” is open for public comment through 12:00 PM ET on Friday, August 14, 2026. This is the window to influence what comes next.
  7. Watch for the Task Force report and subsequent DFARS action. The suspension was implemented through DoD memoranda, not through amended DFARS regulations. Whatever framework emerges from the review will require formal rulemaking before it becomes enforceable in contracts.
Key takeaway: The CMMC 2.0 update is real, but it changed less than most contractors think. Phase 2 mandatory third-party assessment was suspended. The underlying obligations to implement NIST 800-171, maintain accurate SPRS scores, submit annual affirmations, and comply with DFARS 252.204-7012 all remain in force. And the DoJ’s Civil Cyber-Fraud Initiative continues to pursue FCA cases against contractors whose representations do not match reality. Treat this as a pause in the audit mechanism, not a pause in the cybersecurity requirements. The contractors that continue their work are the ones positioned to win when the modified program returns.

The honest version

The July 13, 2026 CMMC 2.0 update is a genuine regulatory reversal, but it is also being widely misread. Contractors reading headlines about “CMMC suspended” are correct in the narrow sense (Phase 2 mandatory third-party certification is on hold) and dangerously wrong in the broader sense (nothing about the actual cybersecurity obligations changed). The Alabama defense contractor that paid $507,144 to the DoJ on June 18, less than a month before the suspension announcement, did so under exactly the enforcement regime that still governs today.

For Orange County defense contractors trying to make sense of this: the smart move is not to pause compliance spending. The smart move is to redirect it. Instead of focusing on C3PAO audit preparation, focus on making sure the SPRS score you sign is one you can defend under FCA scrutiny. Instead of chasing certification checkboxes, focus on building the genuine security posture that both the DFARS clauses and the Civil Cyber-Fraud Initiative expect you to have. The mechanism for verification changed. The requirement for real security did not.

The Task Force reports around mid-September. DFARS rulemaking will take longer. In the meantime, the contractors continuing serious cybersecurity work are the ones who will be ready for whatever CMMC 2.5 or CMMC 3.0 ultimately looks like. The contractors treating this as a permission slip to slow down will discover, likely the hard way, that the enforcement mechanism they were worried about was never the primary risk. The primary risk is, and remains, self-attested representations that do not match operational reality.

Find out where your SPRS score, NIST 800-171 posture, and FCA exposure actually stand.

Intelecis has been helping Orange County defense contractors implement NIST 800-171 controls and defend their SPRS scores since well before CMMC 2.0 was finalized. NSA-Accredited, with documented experience across DFARS 252.204-7012, the full NIST 800-171 control set, and the SPRS scoring methodology. Book a free security assessment and we will show you, in writing, exactly where your compliance and enforcement risk actually stands after the July 13 suspension.

Get Your Free CMMC Assessment →

📞 949-266-2088 · Fullerton, CA · NSA-Accredited · Serving OC since 2010

Related reading:
CMMC Compliance Services for OC Defense Contractors ·
NIST 800-171 vs CMMC: The Difference That Can Make or Break Your DoD Contract ·
CMMC Self-Assessment vs C3PAO Audit: What Contractors Are Getting Wrong ·
CMMC Enforcement Timeline 2026: What DoD Subs Need to Know ·
Schedule Your Free CMMC Assessment