
On July 13, 2026, the Pentagon suspended Phase 2 of the Cybersecurity Maturity Model Certification program — the phase that would have required third-party C3PAO assessments across contracts involving controlled unclassified information starting November 10, 2026. Within a day, half the defense industrial base had decided CMMC is dead.
It is not. And the gap between those two readings is where contractors are about to hurt themselves.
Nothing was rescinded. 32 CFR Part 170 is still codified. Your DFARS clauses did not evaporate from your contracts overnight. The self-assessment you affirmed in the Supplier Performance Risk System is still a representation to the federal government, and the Department of Justice is still settling False Claims Act cases over exactly that representation — one of them less than four weeks before this memo landed.
> WHAT ACTUALLY HAPPENED
DoD Chief Information Officer Kirsten Davies signed the suspension memo — CIO CMMC Reform Memo 26-P-1023 — announced July 13 alongside Under Secretary of Defense for Acquisition and Sustainment Michael Duffey. It suspends all pending and future CMMC milestones until further notice and stands up a CMMC Reform Task Force reporting to the CIO.
The suspension is narrow in its legal effect and enormous in its practical one. What stopped is the mandatory C3PAO certification requirement that was scheduled to start appearing in solicitations on November 10. What continues is everything DoD was already using to police cybersecurity: self-assessments against NIST SP 800-171 Revision 2, and select government-led DIBCAC assessments.
That distinction matters legally. As Wiley noted in its client alert, the pause delays only the mandatory C3PAO assessment. Rolling back the program itself would require amending both the Program Rule and the DFARS Rule — formal notice-and-comment rulemaking, not a memo. Until that happens, the regulations on the books are the regulations that apply to you.
> WHY THE MATH DID NOT MATH
The suspension was not ideological. It was arithmetic, and the arithmetic had been obvious to anyone tracking the assessor ecosystem for two years.
The Capacity Gap That Killed Phase 2
Roughly one hundred assessor organizations were expected to certify more than one hundred thousand companies inside a fixed contractual window. At the observed throughput, the queue clears sometime in the next decade. Davies said it plainly.
So the math just simply doesn't math for small to medium-sized businesses to even get compliant by the transition date.
The assessor pipeline was growing — just nowhere near fast enough. The ecosystem added roughly fifteen C3PAOs and one hundred eighty certified assessors across four months. At that rate, closing a six-figure assessment backlog is not a scheduling problem. It is a category error.
CMMC Assessor Ecosystem Growth vs. a 100,000-Company Backlog
Davies' memo framed the consequence as a national security problem rather than a compliance one: prohibitive costs, severe assessment-capacity shortages, and complex regulatory timelines were, in her words, actively forcing new entrants and small businesses to opt out of defense contracts entirely. SBA Administrator Kelly Loeffler called CMMC compliance an untenable barrier pushing firms out of the industrial base.
If you are running a small defense supplier, the actionable read is this: the program did not get suspended because the threat went away. It got suspended because the delivery mechanism priced out the suppliers DoD needs. Whatever replaces it will be cheaper to demonstrate — not weaker in what it demands of your actual security posture.
> WHAT IS STILL LEGALLY BINDING
Here is the part the celebratory LinkedIn posts skipped. If you hold a contract with a CMMC or safeguarding clause today, this is your unchanged obligation set.

A suspended assessment is not a suspended obligation. Nobody stopped requiring the controls — they stopped requiring someone else to come check.
There is a second-order effect worth naming. Removing the third-party assessor removes the friendly party who would have caught your overstated score before DoD did. For the next year or more, the only entities validating your SPRS number are DIBCAC — and plaintiffs' counsel working on contingency.
> THE FALSE CLAIMS ACT DID NOT PAUSE
The Civil Cyber-Fraud Initiative, launched by DOJ in October 2021, targets contractors who knowingly misrepresent their cybersecurity compliance. It is not a DoD program. A DoD CIO memo cannot suspend it, and 2026 has been its most active year on record.
On June 18, 2026 — twenty-five days before the Phase 2 suspension — DOJ announced that Huntsville-based LOGZONE Inc. would pay $507,144 to resolve allegations it failed to meet cybersecurity requirements in Navy contracts. The detail that should stop you cold: LOGZONE had reported a perfect self-assessment score of 110. A subsequent government assessment scored it at -170.
Recent Cyber False Claims Act Settlements
The Affirmation Trap
The FCA hook is not the control gap — it is the signature. When a senior official affirms a SPRS score, that affirmation becomes a representation the government relies on to award. A control you never implemented is a compliance finding. A score you affirmed while knowing it was wrong is a false claim, with treble damages and per-claim penalties attached. The suspension of Phase 2 does not touch that exposure. It arguably widens it, because self-attestation is now the primary mechanism for longer than anyone planned.
The practical takeaway for the next twelve months: treat your SPRS score as a sworn statement rather than a planning artifact. If your current score assumes controls that are still on a roadmap, correct the score now — a downward revision costs you competitive position, while an unrevised overstatement costs you a qui tam suit. We made a version of this argument when your audit passes and you are still exposed, and the logic is identical here.
> WHAT COMES BACK, AND WHEN
The CMMC Reform Task Force must deliver findings and recommendations within 60 days of the July 13 announcement — putting the report around mid-September 2026. It is drawing on a public request for information with responses due August 14.
The RFI questions tell you where this is heading. DoD is asking industry which NIST SP 800-171 Rev. 2 controls actually deliver meaningful risk reduction, what the real cost drivers and administrative burdens are, how companies already use commercial security tooling and managed services, and how the department might give credit for those existing investments in a revised framework.
Read against the questions being asked, the likely shape of CMMC 3.0 is a smaller set of high-value controls, broader acceptance of evidence generated by tooling you already operate, and reciprocity for assessments you have already passed. That is a rationalization of the program, not a repeal of it. Anyone reading this as permission to stand down is reading it against the plain text of the RFI.
There is also a timing floor. Any substantive change requires amendments to both 32 CFR Part 170 and the DFARS rule, which means proposed rule, comment period, and final rule. Even on an aggressive schedule that is a multi-quarter process. A realistic planning assumption: recommendations in the fall, proposed rulemaking in 2027, and requirements landing in solicitations after that — with your existing obligations running continuously the entire time.
> WHAT TO DO IN THE NEXT 90 DAYS
When we wrote CMMC: The Reckoning in November 2025, the story was that the rule had finally gone live and roughly half a percent of the industrial base was ready. Nine months later, DoD looked at the same ratio and blinked. The requirement did not turn out to be wrong. The delivery model turned out to be unbuildable at the scale of a 100,000-company supply chain.
The contractors who come out of this ahead are the ones who separate the two. Keep building the security program, because the adversary that motivated CMMC did not take a 60-day pause. Stop buying certification theater priced against a deadline that no longer exists. That is not a contradiction — it is the whole lesson.
The Illumenati // Boutique GRC for the AI-First Era // illumen.io
> SOURCES
- [01]DOD halts cybersecurity requirements for CMMC Phase 2: “The math just simply doesn’t math”— DefenseScoop
- [02]Pentagon suspends CMMC phase two requirements, launches review of program— Federal News Network
- [03]DOD Pauses CMMC 2.0 Implementation: A Big Deal with Little Immediate Impact— Wiley Rein LLP
- [04]Department of War Suspends CMMC Phase II — But Compliance Obligations Remain, As Does Enforcement Risk— Jenner & Block LLP
- [05]DOD suspends CMMC Phase 2, launches 60-day “reform” review— Washington Technology
- [06]DoW Requests Information for CMMC Reform Task Force— SBA Office of Advocacy
- [07]DOJ Reaches $507,144 Settlement with Defense Contractor, Signals Increased FCA Scrutiny of Cybersecurity Self-Assessments— Sidley False Claims Act Blog
- [08]Defense contractor settles cybersecurity False Claims Act allegations— DefenseScoop
- [09]Cybersecurity-Related Enforcement Under the False Claims Act: New Settlements, Same Lessons— Mintz
- [10]CMMC Affirmation Trap: FCA Exposure for Defense Contractors and Acquirers— Holland & Knight
- [11]CMMC Ecosystem by the Numbers: Inside the CyberAB Marketplace— Secureframe


