Is CMMC Going Away? What the Phase 2 Suspension Actually Changed

Nick Sally · Certified CMMC Registered Practitioner · July 25, 2026

The announcement hit my desk at 4:45 on a Monday afternoon, July 13, 2026. By that evening I’d read the press release, the CIO memos, and the RFI, and watched the CIO’s video twice. The next morning I sanity-checked my read with a certified assessor I work with.

Short version: the Department of War suspended CMMC Phase 2. The November 10, 2026 switch to mandatory third-party assessments is off. And almost everything you actually owe is still owed.

What got suspended

The implementation memo is blunt in a way press releases never are: “The upcoming November 2026 transition to Phase 2 of CMMC implementation is suspended.” Program managers “may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period.”

It goes further than most people noticed. Contracting officers are directed to strip C3PAO requirements out of active solicitations by amendment, and out of existing contracts at the next modification. The third-party assessment industry didn’t get paused so much as unplugged.

What’s still required

Same memo, same page:

“During this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments. The cybersecurity requirements outlined in the clause at DFARS 252.204-7012 . . . remain in effect.”
  • NIST SP 800-171 Rev 2: all 110 requirements, still contractually yours under DFARS 252.204-7012. That clause has been in defense contracts since 2017.
  • Self-assessments: solicitations keep carrying CMMC Level 1 (Self) and Level 2 (Self) requirements. The memo says those are the ONLY designations allowed right now.
  • Your SPRS score, per DFARS 252.204-7019, plus the annual affirmation a senior official signs by name.
  • Government-led assessments. DIBCAC didn’t go anywhere, and DFARS 252.204-7020 is still the government’s ticket into your environment.

So is CMMC going away?

My honest read: the checklist got a stay of execution and the requirement didn’t move an inch. The department stood up a reform task force and published an RFI asking industry which controls are burdensome and which ones actually improve security. I read that as a compressed control set coming, probably sitting closer to plain NIST 800-171. That’s a prediction, so hold me to it loosely.

Here’s the thing about the panic and the celebration both: we’ve run this experiment before. From 2017 on, DFARS 7012 required all 110 controls on the honor system. Everyone claimed a great score. Very few were actually there. CMMC exists BECAUSE the honor system failed.

Now we’re back on the honor system, with 2 differences. DIBCAC still audits, and DOJ has built a settlement rhythm under the False Claims Act (a $507,144 example from June 2026). The government stopped scheduling your test and kept grading it.

If you were racing the November deadline, you just got handed time. Frankly, the smartest move I’ve seen all month is the owner who used it to make their self-assessment true instead of closing the browser tab.

Doing this work in Microsoft 365 GCC High? CMMC for Microsoft 365 is the reference this blog sits on top of: pre-written SSP language, policies, and GCC High configuration steps for all 320 assessment objectives. $997 once. Preview Control 3.1.1 free →