Threat & Compliance · Updated August 22, 2026
CMMC Phase 2 is paused. Here is what defense contractors should do in the next 90 days.
On July 13, 2026 the Department of War suspended CMMC Phase 2 and stood up a 60-day Reform Task Force. The suspension changed the third-party assessment schedule. It did not repeal 32 CFR Part 170, waive DFARS 252.204-7012, or move the annual SPRS affirmation. This is what actually changed, what still applies, and the 90-day plan we are running with our Pacific defense clients.
Published August 21, 2026 · Updated August 22, 2026 · Cyberuptive Team · Honolulu
What actually happened on July 13, 2026?
On July 13, 2026 the Department of War issued two coordinated memoranda. DoD CIO Kirsten Davies signed the policy memorandum (Memo 26-P-1023, reported by Inside Defense) suspending CMMC Phase 2 implementation and chartering a 60-day CMMC Reform Task Force. Under Secretary of Defense for Acquisition and Sustainment Michael Duffey signed the companion implementation memorandum instructing program managers on how to execute the pause across active procurements.
The Department of War CIO CMMC portal is unambiguous: the November 10, 2026 Phase 2 milestone will not occur on that date, all pending and future CMMC implementation milestones are held in abeyance, and Phase 1 self-assessment requirements remain in force. The scoped legal analyses from Latham & Watkins, Squire Patton Boggs, and Crowell & Moring converge on the same read.
The Duffey memorandum, quoted at length in the Latham analysis, directs that during the suspension period “[p]rogram Managers and requiring activities must only include the need for CMMC Level 1 (Self) or Level 2 (Self) assessments in procurement request and requirement documents.” The suspension bars program offices from designating both Level 2 (C3PAO) and Level 3 (DIBCAC) assessments during the review. Existing solicitations that contain those designations must be amended “as soon as practicable.”
Alongside the memoranda, the Department opened a public Request for Information: Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base: posted on SAM.gov. Comments closed at 12:00 p.m. Eastern on August 14, 2026 per SBA Office of Advocacy. The task force is chartered to synthesize the record and submit findings and recommendations within 60 days.
The dates that matter
| Date | Event |
|---|---|
| Dec 16, 2024 | 32 CFR Part 170 (CMMC Program final rule) effective. |
| Nov 10, 2025 | CMMC Phase 1 began. Level 1 (Self) and Level 2 (Self) requirements applicable in new solicitations. |
| Jul 13, 2026 | DoW CIO Memo 26-P-1023 and Duffey implementation memo suspend Phase 2. CMMC Reform Task Force chartered. RFI opens on SAM.gov. |
| Aug 14, 2026 | CMMC Reform Task Force RFI public comment period closes (12:00 p.m. ET). |
| Nov 10, 2026 | Originally scheduled Phase 2 effective date, will not occur on that date. |
| TBD | CMMC Reform Task Force report and any revised guidance. No published restart date for Phase 2. |
What still applies during the pause
The suspension is narrowly scoped to CMMC Phase 2 assessment designations. Every other layer of the CUI-safeguarding regime keeps operating:
| Requirement | Status during the suspension |
|---|---|
| 32 CFR Part 170 (CMMC Program rule) | In force. Not repealed by the July 13 memoranda. |
| NIST SP 800-171 Rev 2 (110 controls, Level 2 baseline) | In force. Underlying safeguarding standard for CUI. |
| DFARS 252.204-7012 (safeguarding + 72-hour incident reporting) | In force. Adequate security under (b), cyber-incident reporting under (c), and subcontractor flow-down under (m) all continue. |
| DFARS 252.204-7019 / 7020 (Basic and High assessments in SPRS) | In force. Annual SPRS score submission and DIBCAC High assessments where contractually required. |
| Phase 1 Level 1 (Self) and Level 2 (Self) | In force. Program offices may still require self-assessments in new procurements. |
| Annual senior-official affirmation (32 CFR 170) | In force. Affirming officials still owe an annual attestation of continued compliance. |
| Existing contract clauses requiring C3PAO or DIBCAC | Follow the contract. A program-level suspension does not automatically modify signed clauses. |
| DOJ Civil Cyber-Fraud Initiative (FCA) | Active. FY 2025 recoveries hit a record $6.8B including cybersecurity fraud settlements. |
Why the pause happened: the cost math
The Reform Task Force did not arrive from nowhere. The Small Business Administration’s Office of Advocacy and downstream analyses have converged on a compliance cost model that made CMMC 2.0 Level 2 hard to absorb for the small end of the defense industrial base. Practitioner-reported ranges from the SBA analysis, summarized by Secureframe among others, sit around $388,600 in total compliance cost per certification for a small firm on a self-assessment pathway and up to $593,800 per certification for a firm requiring a C3PAO third-party assessment. Those figures include gap remediation, tooling, professional services, documentation, and the assessment fee itself: not just the C3PAO invoice.
Independent estimators including GovBidLab and IBSSCORP have modeled first-year outlays in the $98,000 to $305,000 range for small firms that are not already compliant, with the triennial C3PAO assessment fee alone running $30,000 to $150,000 depending on scope. Combined with an estimated 120,000 small businesses in the CUI-handling supply chain (SBA Office of Advocacy), the aggregate burden is what the task force is examining.
The Reform Task Force RFI asked industry to identify top cost drivers, which controls deliver security value versus overhead, and how commercial cybersecurity tools and managed services can reduce burden. That last framing matters: the direction of travel is not away from safeguarding CUI, it is toward faster and cheaper ways to demonstrate it.
Does the pause reduce False Claims Act risk?
No. On January 16, 2026 the Department of Justice announced that FCA settlements and judgments in fiscal year 2025 exceeded $6.8 billion, the highest single-year total in the statute’s history, and DOJ recovered more than $52 million across nine cybersecurity fraud settlements attributable to the Civil Cyber-Fraud Initiative in its fifth year. Fluet Law tracked a 233% year-over-year jump in Cyber-Fraud Initiative settlements over the prior year.
What triggers cyber-FCA liability has been consistent across cases: false attestations about NIST SP 800-171 posture, misrepresented SPRS scores, exaggerated safeguarding practices in proposals, and gaps between what was claimed and what was configured. None of those exposure vectors was created by CMMC Phase 2, and none of them was closed by the pause. The safest position remains what it was before July 13: keep the SPRS score honest, keep the SSP synchronized with the environment, and treat any material change in scope as a change in scope.
A 90-day playbook for defense contractors
This is the sequence we are running with our Pacific defense clients. It assumes an organization that was tracking toward Phase 2 and now has to reset without losing months of remediation work.
-
Days 1–15 · Confirm which contracts and solicitations are affected.
Pull every active contract, task order, and open solicitation. Identify clauses that call out Level 2 (C3PAO) or Level 3 (DIBCAC). Watch for solicitation amendments removing those requirements, Crowell & Moring flagged bid-protest options where amendments are slow. Document the state of each in a single tracker.
-
Days 1–15 · Re-verify Phase 1 self-assessment posture in SPRS.
Confirm each system that processes, stores, or transmits CUI has a current NIST SP 800-171 Rev 2 basic assessment recorded in SPRS with an active annual affirmation. Update dates. Reconcile any drift between the SPRS entry and the underlying SSP.
-
Days 15–30 · Preserve DFARS 252.204-7012 controls end-to-end.
Adequate security under paragraph (b), 72-hour cyber-incident reporting under paragraph (c), media protection, forensic-imaging capacity, and subcontractor flow-down under paragraph (m). No change. Verify each is operational and evidenced, not merely written.
-
Days 15–45 · Freeze the CUI boundary. Do not shrink it under time pressure.
Document the enclave: systems, SaaS, backups, endpoints, and named users with access. If CUI shows up in personal cloud storage, unmanaged laptops, or shared drives, it is still CUI. False attestations about scope are the fastest path to FCA exposure.
-
Days 30–60 · Keep the SSP and POA&M live.
Update the System Security Plan for every material environment change. Assign an owner and a funded date to every POA&M item. The SSP should be copy-pasteable from the actual environment; assessors, DIBCAC, and primes read it against tickets and configuration.
-
Days 30–90 · Continue the slow remediation tracks.
Identity, MFA on legacy applications, privileged access management, centralized logging, secure configuration baselines, incident response tabletop, backup integrity testing, and vendor-access controls. These are the ones that take months and matter most when Phase 2 restarts on a schedule the task force has not published.
-
Days 60–90 · Decide whether voluntary C3PAO or DIBCAC engagement still makes sense.
The pause blocks program offices from designating Level 2 (C3PAO) or Level 3 (DIBCAC) in new procurements, but existing contract clauses stand and voluntary assessments continue. For most Pacific subs, this is a buyer-signal question rather than a deadline question.
-
Days 60–90 · Archive an RFI response and stay engaged with the task force.
The Reforming CMMC RFI closed August 14, 2026. If you did not comment, document your position for internal record now, cost drivers, controls with real security value, tools and managed services that reduce burden, so you can reengage the moment revised guidance follows the task-force report.
Where Pacific subs still get stuck
The failure modes did not change when the deadline moved. Small defense suppliers in Hawaii and the broader Indo-Pacific consistently trip up in the same places:
- The CUI boundary is aspirational. CUI in personal cloud storage, unmanaged laptops, and shared drives is still CUI. If it is out of scope on paper and in use on Tuesday, the self-assessment is fiction and the SPRS score is a false statement.
- The SSP is a template, not a control. Assessors and primes read the SSP against tickets, configs, and backup jobs. A document that has not been opened since the last proposal is not evidence.
- Shared IT is treated as shared responsibility. A local MSP that patches Windows but cannot produce AU, IA, IR, or MP evidence is not covering DFARS 252.204-7012. The contractor still owns the SPRS score and the affirmation.
- Identity and MFA are the longest remediation track. Privileged access, MFA enforcement on legacy applications, and centralized logging take months to stabilize. The pause is exactly the runway to finish them.
- Subcontractor flow-down under paragraph (m) is under-documented. Primes need to see that CUI-handling subs have their own NIST 800-171 posture and SPRS score. That evidence is the first thing to break under acquisition pressure.
A note for primes
For primes in the Pacific and elsewhere, the message is parallel: use the pause to reduce supplier uncertainty, not to lower the bar. DFARS 252.204-7012(m) flow-down is unchanged. Suppliers that keep moving now will create far less risk when the revised CMMC path solidifies. Suppliers that wait for a perfect final signal will almost certainly compress months of work into an impossible procurement window: and push that risk upstream.
The bottom line
The Department of War suspended the CMMC Phase 2 assessment schedule. It did not suspend the duty to safeguard covered defense information, the annual SPRS affirmation, the DFARS 252.204-7012 incident-reporting clock, or the Civil Cyber-Fraud Initiative. If your business touches Federal Contract Information or Controlled Unclassified Information, the correct strategy in August 2026 is the same one it was in June, freeze the CUI boundary, keep the SPRS score honest, close the identity and logging gaps, and treat the 60-day review window as runway, not exemption.
Related reading
- CMMC Phase 2 pause: what Pacific subcontractors still owe (updated August 2026)
- The CMMC 2.0 timeline for Pacific contractors
- Why Honolulu defense contractors need a Pacific MSSP
- Hawaii MDR and 24/7 SOC coverage
References
- Department of War CIO, CMMC portal (Phase 2 suspended July 13, 2026)
- Inside Defense, Davies and Duffey CMMC suspension memoranda (July 13, 2026)
- Latham & Watkins, What Defense Contractors Should Know About DOD’s Suspension of CMMC Phase 2
- Squire Patton Boggs, Department of Defense suspends CMMC Phase II
- Crowell & Moring, CMMC Phase II Suspended: What Defense Contractors Must Do Now
- DefenseScoop, DOD halts cybersecurity requirements for CMMC Phase 2 (July 13, 2026)
- Federal News Network, Pentagon suspends CMMC Phase 2 requirements, launches review
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (paragraph (m) subcontractor flow-down)
- 89 FR 83092, CMMC Program final rule, 32 CFR Part 170, effective December 16, 2024
- SBA Office of Advocacy, DoW Requests Information for CMMC Reform Task Force
- U.S. Department of Justice, False Claims Act Settlements and Judgments Exceed $6.8B in FY 2025
- Fluet Law, DOJ Cyber-Fraud Settlements Surge 233% in 2025
- Secureframe, CMMC for Small Business (SBA cost analysis: ~$388,600 self-assessment, up to ~$593,800 with C3PAO)