On July 13, 2026, the Department of Defense suspended CMMC Phase 2 and put every milestone after it in abeyance until further notice. The third-party assessment requirement that was supposed to start appearing in contracts on November 10 is on hold, and a reform task force is due to report back around the middle of this month.
A lot of defense contractors read that as permission to stop. This article argues the opposite, and then gives you the 90 days of work anyway. It covers what actually changed versus what still binds you, what a C3PAO assessment inspects, and a week-by-week roadmap through scoping, remediation, and a mock assessment. If you were mid-preparation when the news broke and your leadership is asking whether to keep spending, this is the piece to hand them.
What actually happened to CMMC Level 2 certification in July 2026?
The Department's CIO issued a memo titled "Removing Barriers to Defense Industrial Base Expansion," suspending the next phase with immediate effect and standing up a CMMC Reform Task Force to run a 60-day review. Federal News Network reported that the memo halts pending and future milestones while Phase 1 stays in force. Program managers may now designate only the Level 1 or Level 2 self-assessment options. They may not designate the C3PAO or DIBCAC equivalents.
Solicitations that already carried those designations are being amended to strip them, and existing contracts get modified before the next option period. Analysis from Latham & Watkins lays out the mechanics. Meanwhile the Department published an RFI asking industry which requirements cost the most and deliver the least, with responses closing on August 14. The SBA Office of Advocacy summarised the questions, and the notice itself sits on SAM.gov.
Read the stated intent carefully. Officials were explicit that this removes verification bureaucracy rather than the standard itself. As one put it at the announcement, "We are not relaxing any standards by any means", per Breaking Defense. The bar did not move. The referee left the field. Cybersecurity Maturity Model Certification remains the program of record; what lapsed is the schedule for enforcing it.
What still binds a defense contractor right now?
Everything underneath CMMC. DFARS 252.204-7012 still requires you to implement NIST SP 800-171 Rev. 2 if you handle CUI. Phase 1 requirements have applied since November 2025. Your Supplier Performance Risk System score is still a representation you made to the government, your annual affirmation is still due, and Level 2 self-assessments remain a condition of award on applicable DoD contracts.

The False Claims Act is entirely untouched, and that is the part contractors keep underweighting. Defense firms handling CUI have settled cybersecurity misrepresentation cases in the millions over the past two years, and every one of those turned on a self-reported number that did not match the environment. Removing the assessor does not remove the liability. It moves the liability onto your signature, which is a compliance exposure your cyber insurance almost certainly does not cover.
Government-led assessments also continue, and the Department has said it will keep enforcing the baseline through contractor attestation and selected reviews. CMMC compliance is therefore still a live obligation, just one you now attest to yourself. So does your prime's flowdown, which is contractual and does not care what the Pentagon announced. Primes are checking subcontractors on their own schedule, and a supply chain question from a prime is not answered by citing a suspension memo.
Why keep preparing when the requirement is paused?
Because the work and the certificate are different things. Roughly 110 controls of hardening, documentation, and monitoring is what protects controlled unclassified information on your network. The C3PAO assessment is just someone confirming you did it, and CMMC certification is the receipt. Suspending the confirmation does not make the underlying exposure go away, and adversaries did not pause anything on July 13.
The commercial argument is stronger still. Contractors that hold a Level 2 certificate or can demonstrate real assessment readiness will differentiate on it during the pause, because primes are still asking and the answer is still binary. When the requirement returns, and the task force language points toward reform rather than repeal, capacity will be the constraint. Every contractor who stopped in July competes for C3PAO availability with every contractor who did not.
There is also a practical asymmetry. Preparation and implementation take six to twelve months of preparation for a mid-size firm, and full CMMC Level 2 readiness is rarely faster. If you stop now and the program restarts in a year with a compressed runway, you will be doing the same work under worse conditions. Our CMMC preparation engagements have not slowed since July, and the reason clients give is consistently the same one: they would rather be early than eligible-on-paper.
What is a C3PAO assessment and how does the assessment process work?
A C3PAO assessment is a formal assessment performed by a Certified Third-Party Assessment Organization, authorised under the CMMC Accreditation Body, of whether your environment meets CMMC Level 2 practices. A CMMC Level 2 assessment is the only route to certification for most DoD contracts involving CUI, and CMMC Level 2 requires every applicable objective to be evidenced rather than asserted. The assessor tests the 110 NIST SP 800-171 controls, which decompose into 320 assessment objectives, and each objective is scored MET, NOT MET, or NOT APPLICABLE.
The assessment process runs in three parts: planning, where scope and evidence expectations get agreed; the active assessment itself, where the team examines artefacts, interviews staff, and tests configurations; and reporting, where assessment findings are delivered and uploaded. Nothing about it is adversarial, and experienced C3PAOs will tell you the failures they see are almost never technical. They are documentary.
The distinction that matters for CMMC Level 2 compliance is evidence versus intent. Saying you review audit logs is not evidence. A ticket showing who reviewed which log on which date, against a documented procedure, is. That gap between policy and proof is what the next three months of work closes, and it is how you measure your security posture against CMMC rather than against a policy binder.
Days 1 to 30: how do you scope the assessment boundary and review your SSP?
Start with data flow, not with tooling. Map where CUI enters your environment, where it lives, where it moves, and where it leaves. That map defines what is in scope, and scoping errors are the single most expensive mistake in this whole exercise because they scope in systems that could have been excluded.
.webp)
Then check the SSP against reality. A system security plan that describes an architecture you decommissioned last year is worse than no plan, because it tells an assessor your documentation is not maintained. Walk each of the 110 requirements and mark what the SSP claims, what is actually implemented, and where the evidence lives. Most contractors discover a third of their controls are implemented but undocumented.
Close the month with a gap assessment that produces a ranked list rather than a narrative. Also confirm your scoping level, because defense contractors handling federal contract information only need the entry tier, while firms that handle CUI need CMMC Level 2. Getting that wrong in either direction wastes a quarter. The NIST 800-171 to CMMC mapping we published walks the control crosswalk in detail.
Days 31 to 60: how do you close the gaps?
Sequence remediation by score impact and by whether an item can even be deferred. Certain one-point requirements are deemed fundamental to CUI protection and must be fully implemented before assessment; they cannot be deferred. Do those first regardless of effort, because a deferral containing one of them fails you outright.
Then work the families where findings cluster. Audit and accountability is the perennial one: firms collect logs and never demonstrate review. System and communications protection is the second, usually boundary protection and encryption of CUI in transit. Access control and configuration management fill out most remaining gaps. None of this is exotic engineering. It is finishing work that got deprioritised.
Update the SSP as you go rather than at the end. Every control you remediate changes the document, and a month of accumulated edits reconstructed from memory in week twelve is how errors get introduced. Where a fix depends on a vendor or a cloud migration, log it as a risk with an owner and a date, and make sure your supply chain risk management view covers external service providers holding CUI on your behalf.
Days 61 to 90: what does a rehearsal prove?
A mock assessment is a dress rehearsal run to the real scoring rules by someone outside your organisation. That last clause is the whole value. Internal readiness reviews consistently over-score, because the people who built the control are the worst judges of whether an outsider would accept the evidence.
.webp)
Run it as an adversarial evidence exercise. Give the reviewer the SSP, ask them to pick twenty objectives at random, and require artefacts within an hour. If your team is searching shared drives, you are not ready no matter what the score says, because a C3PAO works to a schedule and unproduced evidence is a finding.
Use the remaining weeks on the findings and on assembling the evidence package: policies, procedures, network diagrams, audit log samples, training records, incident records. The goal of a readiness assessment is not a number. It is a folder someone else can navigate. That is also what a prime's security questionnaire wants, so the work pays for itself even before you schedule your assessment.
What drives the assessment cost?
The assessment fee is the small part. C3PAO engagement pricing for a mid-size contractor typically runs into the low tens of thousands, varying with scope, and it is quoted against the boundary you defined in month one. Remediation, tooling, and staff time are the real CMMC Level 2 cost, and they commonly run several multiples of the assessment itself.
The biggest cost driver is boundary size. Every additional system, site, and user inside scope adds objectives to test and evidence to produce. Contractors who enclave CUI into a defined environment pay substantially less than those who leave it distributed across a general-purpose network, and that architectural decision is worth more than any tool you buy.
The second driver is documentation debt. If your policies were written for an ISO review in 2019 and never mapped to these requirements, someone is rewriting them, and consultants bill for it. Doing that work internally during a suspension, when nobody is holding a deadline over you, is the cheapest version of it you will ever get.
What happens with POA&Ms, conditional status, and eligibility?
Under the rules as written, a plan of action can carry a limited set of non-critical items and gets you a conditional status if you score at least 88 of 110. You then have 180 days to close every item through a closeout assessment. Miss that window and the status terminates automatically, taking contract eligibility with it.
Treat conditional status as a fallback rather than a plan. It is designed for organisations that are genuinely close, and it converts a compliance problem into a countdown with a hard failure mode. Firms that enter assessment intending to defer their way through tend to find the 180 days evaporate against the same constraints that produced the gaps.
Nothing about Level 3 changes this either, since DIBCAC assessments are frozen on the same memo. The suspension does not change the arithmetic; it just moves the date. Whatever emerges from the reform review, the underlying scoring model in CMMC 2.0 has survived every revision since the original CMMC 1.0 framework, and betting on it disappearing is a poor risk assessment.
Frequently asked questions about C3PAO scheduling during the pause
Can I still book an assessment? Yes. C3PAOs remain authorised and are still conducting Level 2 certification assessments. If you hold a slot, most C3PAOs advise keeping it rather than releasing a date you will want back.
Does a certificate still mean anything? Commercially, yes. Primes evaluating subcontractors are still asking, and a completed CMMC assessment answers a question your competitors are currently answering with a memo reference.
Should I tell my prime we are pausing? Only if you want the conversation that follows. Flowdown obligations sit in your subcontract, and the current CMMC requirements in live DoD contracts are unchanged for anything already awarded.
What should we watch for? The task force report, expected around mid-September, and whatever rulemaking follows it. Assessments for Level 2 could return on a revised schedule, a revised standard, or both, and DoD has not indicated which. Any change to the standard requires new rulemaking, which takes months at minimum.
Get an honest read on where you stand
Our CMMC Readiness Checklist walks a defense contractor through boundary definition, SSP review, and the evidence expectations for each control family, in the order an assessor works. It is built for a program manager to run without a consultant in the room.

VisioneerIT prepares contractors in the defense industrial base the way an assessor reads them, control by control, evidence first. If you want to know what a rehearsal would find before you commit to a date, talk to our team.
Key things to remember
- The next phase was suspended on July 13, 2026, along with all later milestones. Program managers may designate only the self-attested tiers while the review runs.
- What was suspended is the verification, not the standard. DFARS 252.204-7012, NIST SP 800-171 Rev. 2, SPRS scoring, and annual affirmations all still apply.
- False Claims Act exposure is unchanged, and with the assessor gone the risk shifts onto your own attestation.
- Primes do not follow Pentagon memos. Subcontract flowdown is contractual and still binds you.
- Scope first. Map CUI data flow before touching tooling, because boundary errors are the most expensive mistake available.
- Fix the fundamental one-point requirements before anything else. They cannot be deferred at all.
- Have someone external run the rehearsal. Internal reviews over-score, consistently.
- Boundary size and documentation debt drive cost far more than the assessment fee does.
- Conditional status needs 88 of 110 and closes in 180 days or terminates. Treat it as a fallback, not a strategy.
- Capacity is the reason to keep going. Everyone who stopped in July will be competing for the same assessor calendars when this restarts.

