CMMC Phase II Is Suspended. Your Security Obligations Are Not.

The Pentagon has suspended the third-party audit rollout for its defense-contractor cybersecurity program - four months before audits were due to become the default. What actually changed, what did not, and what to do while the reform window is open: in plain English, verified against the primary documents.

By Andy Potanin, President, UDX · July 14, 2026

The Thirty-Second Version

CMMC - the Cybersecurity Maturity Model Certification - is the Pentagon's system for making defense contractors prove they protect two kinds of sensitive but unclassified information: Federal Contract Information (FCI, the routine paperwork of doing government business) and Controlled Unclassified Information (CUI, the technical data that actually matters to an adversary). Contractors have been self-assessing against these rules since November 2025. The next step - scheduled for November 10, 2026, four months from now - would have required most contractors handling CUI to pass an audit by an accredited outside assessor before they could win contracts. That coming requirement is what just went away.

On July 13, 2026, the Department of War - the renamed Department of Defense - announced the immediate suspension of CMMC Phase II, the stage of the rollout that would have made those third-party audits the default. Two memos carry the action, both cleared under case number 26-P-1023: a reform directive signed by Chief Information Officer Kirsten Davies, and an implementation memo signed by Under Secretary for Acquisition and Sustainment Michael Duffey ordering contracting officers to strip audit requirements out of active solicitations. A CMMC Reform Task Force now has 60 days to redesign the program, informed by a public comment window that closes August 14, 2026.

What changed: you no longer have to hire an outside auditor to prove your cybersecurity. What did not change: you still have to do the cybersecurity, prove it internally, and sign your name to it under False Claims Act liability. Davies put the intent plainly at the Pentagon briefing, per Breaking Defense: "We are not reducing cybersecurity through this measure. We are reducing the red tape." Her memo closes harder: "We will not defeat our adversaries with compliance checklists." Everything below is the detail behind those two sentences - and where the risk actually moved.

Implementing Suspension of CMMC Phase 2 · Attachment 1 cleared for open publication · 26-P-1023

"During the period of suspension, Program Managers and requiring activities must only include the need for CMMC Level 1 (Self) or Level 2 (Self) assessments in procurement request and requirement documents. Program Managers and requiring activities may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period."

"[Contracting officers] must issue a corresponding solicitation amendment as soon as practicable… For existing contracts… remove them via modification prior to the exercise of the next option period."

"…no waivers shall be granted during the review of the program. This directive is effective immediately."

the operative language, quoted from the signed memo - self-assessment is now the only path a contracting officer may designate

Even by procurement standards, that language is dense. A decoder:

Program Managers and requiring activities - the government offices that decide what a contract must require before anyone buys anything. They write the requirements; contracting officers execute them.

Level 1 (Self) and Level 2 (Self) - you assess your own systems and post the result to the Pentagon's supplier database. Level 1 covers 15 basic practices for routine contract information; Level 2 covers all 110 NIST SP 800-171 controls for CUI.

Level 2 (C3PAO) - the suspended path: an audit by a Certified Third-Party Assessment Organization, an accredited private assessment firm.

Level 3 (DIBCAC) - the other suspended path: an audit by the government's own assessors, the Defense Industrial Base Cybersecurity Assessment Center, reserved for the most sensitive programs.

Solicitation amendment - a formal edit to an open bid. If a solicitation you are bidding on carried an audit requirement, it is being edited out - and "as soon as practicable" is contracting language for "immediately, allowing for the paperwork."

Modification prior to the next option period - existing contracts renew in blocks called options. The audit requirement comes out at the next renewal or administrative update, not through mid-performance surgery.

No waivers - during the review, nobody can be put back onto the audit path, even voluntarily. The suspension has no exceptions in either direction.

What Was Planned, and What Is Left

CMMC was never a single switch. It is a four-phase schedule, written into federal regulation (32 CFR Part 170, the program rule, and DFARS 252.204-7021, the contract clause), that gradually tightened how contractors prove compliance. Phase 1 has been running since November 10, 2025: new solicitations require contractors to assess themselves and post the results. Phase 2, due November 10, 2026, was the teeth - it would have made an audit by an accredited third-party assessor (a "C3PAO") the default for contracts touching CUI, with the government's own audit team (DIBCAC) handling the most critical programs in later phases.

PhasePlanned startWhat it requiredStatus today
Phase 1Nov 10, 2025Self-assessments in new solicitationsActive. Unchanged.
Phase 2Nov 10, 2026Third-party audits become the default for CUI contractsSuspended.
Phase 3Nov 10, 2027Audits extend to contract option exercises; government audits for critical programsSuspended (depends on Phase 2)
Phase 4Nov 10, 2028Full coverage in all applicable contractsUnder review.

One line in the implementation memo makes this operational, not theoretical: contracting officers "must issue a corresponding solicitation amendment as soon as practicable," and existing contracts lose the audit requirement "prior to the exercise of the next option period." If you are mid-bid on a solicitation that carried a third-party audit requirement, expect an amendment - not eventually, but now.

The three certification levels survive; only the audit paths are frozen. Level 1 covers contractors that handle only FCI: an annual self-assessment against 15 basic safeguarding practices from the federal acquisition rules. Level 2 covers CUI: all 110 security requirements of NIST SP 800-171, self-assessed every three years - or audited, which is the part now suspended. Level 3, for the most sensitive programs, adds 24 requirements from NIST SP 800-172 and a government-led audit; also suspended. A contractor that falls short can hold a "conditional" status - a minimum score of 88 out of 110 with a written fix-it plan (a POA&M) that must close within 180 days.

Two things about the plumbing did not move. Every status, self-assessed or not, still requires an annual affirmation of continuous compliance in SPRS - the Pentagon's supplier database - signed by a named senior official. And primes must still flow the requirement down: any subcontractor that will touch FCI or CUI must hold the appropriate CMMC status, suspension or no suspension.

What Did Not Change

This is the part most of the commentary is muddling, so here it is as a checklist. The audit is gone for now. The obligations the audit was checking are not. Most of them predate CMMC entirely - they come from DFARS 252.204-7012, a contract clause that has required this protection for nearly a decade - its current form dates to a 2016 rule with full implementation required by the end of 2017 - and that both July 13 memos explicitly reaffirm.

RequirementPlain EnglishStatus
DFARS 252.204-7012Protect covered defense information; report breaches to the Pentagon within 72 hours; preserve forensic images for 90 daysFully in force
NIST SP 800-171 Rev 2All 110 security controls for CUIFully required, via self-assessment and select government-led assessments
SPRS score + annual affirmationPost your score; a named officer signs yearly that it is trueStill required
FedRAMP Moderate cloud for CUIAny cloud service touching CUI must meet the federal cloud security baseline (or its documented equivalent)Unchanged
FIPS-validated encryptionCryptography must use government-validated modules, not just "we use TLS"Unchanged
Third-party (C3PAO) auditsThe outside assessment for Level 2Suspended - cannot be designated during the review
Government (DIBCAC) auditsThe government-led assessment for Level 3Suspended

One line from Truvisory's analysis is worth stealing: the gate moved, the bar didn't. The diagram below is the whole story in one picture.

UDX diagram showing CMMC assessment paths that changed on July 13 versus the five security requirements that did not change
The whole announcement in one picture: the proof paths changed - self-assessment is the only active one - while every underlying requirement stays exactly where it was.

Three Rulebooks People Confuse

Every conversation about this topic eventually tangles three different regimes, so it is worth being precise about who each one tests. CMMC tests the defense contractor's own systems. FedRAMP tests the cloud provider's service - it is how the government decides whether AWS, Azure, or a SaaS product is safe for federal data. SOC 2 is neither: it is a voluntary commercial report, issued under accounting-profession rules, that companies use to reassure business customers. It has no federal standing at all. A structural grievance underneath all of this - one the reform task force will hear plenty about - is that the defense world runs its contractor rules on NIST SP 800-171 while the rest of the federal cloud world, FedRAMP included, runs on the larger NIST SP 800-53 catalog. The two are related - 800-171 was derived from the 800-53 moderate baseline and tailored for contractor systems - but a company serving both markets ends up living in two compliance universes at once, and paying for both.

What welds the first two together is a single sentence in DFARS 7012: any cloud service used to store, process, or transmit CUI must meet the FedRAMP Moderate baseline or its equivalent. "Equivalent" is not a vibe - a December 2023 Department CIO memo hardened it to mean 100 percent of the roughly 325-control Moderate baseline, assessed by a FedRAMP-recognized third-party assessor, with a complete body of evidence available on request. There is no partial credit and no fix-it-later path to equivalency. In practice, "equivalent" means "did all the work of authorization without the marketplace listing." The July 13 suspension did not touch any of this.

And SOC 2? It genuinely helps - access control, logging, vendor management, and incident-response process cover maybe 40 to 50 percent of the implementation work, as compliance-comparison guides like the Defense Compliance Report's conclude. But SOC 2 says nothing about government-validated encryption, CUI marking and handling, SPRS scores, signed affirmations, or restricting access to US persons. Holding a SOC 2 report does not satisfy CMMC. It shortens the trip; it is not the destination.

The Trap Most Small Contractors Miss

Here is the sleeper issue that catches small defense contractors, and the suspension did nothing to defuse it. If an outside IT provider - a managed service provider, an MSP - touches your CUI environment, then under CMMC scoping rules that provider becomes part of your assessment scope, and so do the tools they use on your systems: the remote-management agent, the monitoring platform, the backup service, the ticketing system. Each of those tools is itself a cloud service touching your environment, which drags it under the same FedRAMP Moderate equivalency wire described above - a point MSP-focused analyses like Techvera's have been hammering for a year.

The commercial editions of the tools most MSPs run do not meet that bar. So a small contractor can do everything right inside its own walls - enclave, encryption, policies, training - and still be non-compliant because its IT vendor's remote-access tool is an ordinary commercial SaaS. If you outsource IT and you handle CUI, the first question to your provider is not "are you good at security." It is "which of your tools meet FedRAMP Moderate or equivalent, and can you show me." Expect a pause on the phone. MSPs that can answer it are structurally scarce, and during the review window they are the partner worth locking in.

UDX diagram of the three compliance regimes: CMMC tests the contractor, FedRAMP tests the cloud provider, SOC 2 is a voluntary commercial attestation, linked by the DFARS 7012 cloud requirement
Three regimes, one load-bearing wire: DFARS 7012 fuses CMMC to FedRAMP for any cloud touching CUI - and an MSP's tools inherit the requirement. SOC 2 sits outside the federal system entirely.

What a Defensible Self-Assessment Looks Like

With the audit paths frozen, self-assessment is not a loophole - it is the compliance model, and it produces real artifacts. A defensible Level 2 self-assessment means: a System Security Plan (SSP) describing how each of the 110 controls is actually implemented; a numeric score posted to SPRS; a POA&M for anything unfinished; a library of evidence - configurations, logs, screenshots, policies - that backs every "met" answer; and the signed annual affirmation. Software can automate most of the preparation: compliance platforms such as Vanta, Drata, Secureframe, Ignyte, and FutureFeed connect to your cloud accounts and continuously collect evidence, generate the SSP, and track the score, for a four- to five-figure annual subscription depending on tier per industry roundups. What software cannot do is be the assessor of record or sign the affirmation. A human does that, and the next section is about what that signature now carries.

The economics explain why the Pentagon blinked. A first-cycle third-party audit engagement commonly ran $50,000 to $200,000 before anyone fixed anything, and the capacity math was broken: CIO Davies told reporters there are "over 100,000 DIB businesses" that still needed an assessment and "somewhere in the neighborhood of 100, maybe a little over 100 assessors… So the math just simply doesn't math." Her count checks out - the accreditation body reported 107 authorized assessment firms operating as of its June town hall - and cumulative Level 2 certificates, though climbing every month from January's 773, were still in the low four digits by mid-2026, against a population the department itself puts above 100,000. The SBA's statement endorsing the suspension cited all-in compliance costs "approaching as much as $600,000" for small firms. Against that, a defensible self-assessment stack - a compliance platform, a government-cloud workspace for CUI (Microsoft's GCC High tier is the common route, commonly cited around $60 to $95 per user per month for licensing - though the one-time tenant migration and CUI configuration work is the real line item, typically a five- to six-figure project), FIPS-configured endpoints, and a quarterly internal review by someone who did not build the tooling - is a fraction of the cost, and every dollar of it goes into actual security rather than assessment fees.

Where the Risk Went: Your Signature

Removing the auditor does not remove liability. It concentrates it. Under the program rule, the annual affirmation is signed by a named senior official, and a false affirmation on a federal contract is precisely what the False Claims Act exists to punish - a law with enough teeth, and enough recent enforcement history, that it gets its own section below. The operational question comes first: how does an honest company end up signing something false?

Two failure modes drive nearly all of these cases. The first is scope failure: your compliance dashboard only sees the systems you connected to it. If CUI actually flows through something nobody onboarded - a shared drive, a contractor's laptop, an aging file server, a chat channel - the report says all-green while reality is non-compliant. That gap between the dashboard and the truth is what gets prosecuted. The second is interpretation failure: software can prove multi-factor authentication is switched on; it cannot tell you whether the list of people authorized to see CUI is actually correct, or whether the offboarding process really revoked access every time. Those are human judgments, and they are the reason a self-assessment needs a skeptical internal reviewer, not just a well-configured tool.

The scale of the temptation is documented. CyberSheath's State of the DIB report found 69 percent of defense contractors claiming compliance through self-assessment while, in the contractors CyberSheath assessed, roughly 1 percent were genuinely audit-ready. That 68-point gap did not disappear on July 13. It just lost its external check - which means the honest operators need their internal one to be real.

The False Claims Act, in Plain English

The law behind all of this deserves its own explanation, because it is older, blunter, and more personal than most compliance frameworks. The False Claims Act was signed by Abraham Lincoln in 1863 to punish Civil War procurement fraud, and its core idea has not changed: submitting a false claim for government money is a federal offense that costs you three times the government's damages plus a penalty for every false claim. The modern reach comes from how courts read "claim" - every invoice under a defense contract counts, and an invoice can be false if the company was ignoring a material contract requirement when it billed. A signed cybersecurity affirmation asserts exactly such a requirement. Sign that your 110 controls are implemented when they are not, and every invoice that follows is potentially a false claim.

The law's sharpest feature is who gets to enforce it. Under the qui tam provisions, a private person - almost always a current or former employee - can file suit on the government's behalf and keep a share of whatever is recovered, typically 15 to 30 percent. That is why the Aerojet Rocketdyne settlement should be read carefully: the $9 million case was filed by the company's own former senior director of cybersecurity. The person most likely to know that your System Security Plan is fiction is the person the law pays to say so.

And the enforcement machinery is organized, not incidental. The Department of Justice launched its Civil Cyber-Fraud Initiative in 2021 specifically to apply the False Claims Act to cybersecurity misrepresentations on federal contracts, and it recovered more than $52 million across nine cybersecurity matters in fiscal 2025, inside a record $6.8 billion False Claims Act year. The suspension arguably increases this exposure rather than reducing it: with no third-party assessor in the middle, the affirmation stands alone, and so does the person who signed it.

What to Do Before August 14

If you run a small defense contractor - and we write this as a small business in the defense space ourselves - the suspension is a genuine window, and it has a clock on it. First, answer the RFI on SAM.gov: responses are due August 14, 2026, and the Reform Task Force writing the program's next iteration is explicitly synthesizing that feedback. If compliance costs have shaped your bid decisions, this is the one moment your experience is being solicited. Second, redeploy the audit line item - the $50,000-plus you had parked for a C3PAO engagement - into the security work itself: the CUI enclave, the evidence automation, the incident-response runbook that can actually hit a 72-hour reporting deadline. Third, plan capital as if some audit requirement returns. The CMMC clause remains in the DFARS, with the program's phased rollout mapped through late 2028; the review could revive audits, replace them, or scrap them, and betting the company on "scrapped" is speculation, not strategy.

If you were already in the audit pipeline - assessment scheduled, or even passed - the work is not wasted. Nothing in the memos revokes a certification already recorded; statuses keep their validity period, contracting officers simply cannot require one while the review runs. The readiness work behind it is exactly the security posture the interim regime still demands, a completed third-party assessment remains a differentiator with primes whose own terms may still ask for it, and if some audit requirement returns from the task force, you will be standing where everyone else has to get to. Pause the engagement if it has not started; do not unwind the preparation.

One more note for the comment window: weigh the incentives behind the commentary you read. Much of the loudest criticism of the suspension comes from firms that sell assessments, and much of the loudest celebration from firms that sell the software that replaces them. The primary documents are three pages each. Read them first, then the takes.

Watch your primes, too. Nothing stops Lockheed, RTX, or Northrop from keeping third-party assessment requirements in their own subcontract terms - their risk teams and cyber insurers liked the independent attestation before the Pentagon required it. The government gate is suspended; a contractual gate in your flowdown terms may not be. Read the next amendment carefully before assuming your audit obligation vanished with the memo.

For the engineering leaders inside these firms, the roadmap simply does not change: multi-factor authentication everywhere, least privilege enforced, government-validated encryption in transit and at rest, centralized logging with real retention, the CUI enclave, and a System Security Plan maintained as living documentation rather than a binder nobody opens. Defer the audit scheduling and the pre-audit paperwork surge. Defer nothing else.

The Bottom Line

The July 13 memos removed the auditor, not the architecture. Four things actually changed: contracting officers can no longer require third-party or government-led CMMC assessments during the review; active solicitations carrying those requirements are being amended and existing contracts modified at their next option; no waivers will be granted while the review runs; and a task force will recommend the program's next shape within 60 days, informed by comments due August 14. Everything else - the 110 controls, the 72-hour breach reporting, the federal-baseline cloud requirement, the validated encryption, the signed annual affirmation with False Claims Act exposure attached - is exactly where it was on July 12.

For most small and mid-size defense contractors this is a real reprieve on cost and a real opening to bid work that felt walled off. It is not a reprieve on the security work, and it is emphatically not an invitation to attest to compliance you do not have - the enforcement record suggests the opposite trade is now in effect: less friction up front, more personal exposure on the signature. Build the enclave. Automate the evidence. Sign only what you can defend.

If you want a second set of eyes on your scope - the systems your dashboard does not see, the MSP tools that inherit requirements, the affirmation you are about to sign - that is work we do. Start the conversation below.

This article is analysis, not legal advice. Consult qualified counsel and your contracting officer for guidance on specific solicitations. Primary sources: the Department of War release, the reform memo and implementation memo (both PDF), the Department CIO's CMMC page, and the RFI on SAM.gov. We read them so you can check us.

"

Talk to an Expert

Connect with our diverse group of UDX experts that can help you implement successful DevOps practices within your organization.