Estimated reading time: 5 minutes
On July 13, 2026, the Department of War, formerly the Department of Defense, suspended the rollout of CMMC Phase 2. If you support defense contracts, or you’re an MSP with clients who do, that sentence probably just landed in your inbox from three different directions. Here’s what it actually means, and what it doesn’t.
The short version: the third-party audit got paused. Your compliance obligations didn’t.
What CMMC Phase 2 was supposed to do
What CMMC Phase 2 was supposed to do
CMMC, the Cybersecurity Maturity Model Certification, is the framework the Department uses to confirm that companies handling Controlled Unclassified Information are actually protecting it, not just claiming to. Phase 1 relied on self-assessment. Phase 2 was the next step: bringing in accredited third-party assessors, known as C3PAOs, to formally verify CMMC Level 2 compliance instead of taking a company’s word for it. That requirement was set to begin in earnest on November 10, 2026.
That’s the piece that’s now on hold.
What actually changed on July 13
The Department suspended the transition into Phase 2, meaning the third-party assessment requirement, while it runs a 60-day review of the program. The stated driver is cost and burden, specifically the impact the audit requirement was having on small and mid-sized businesses across the defense industrial base. The goal, per the Department, is to make the program faster and more workable for smaller contractors, not to lower the underlying security bar.
What hasn’t changed, and this is the part that matters
This is where a lot of the reaction online is getting it wrong. A pause on third-party audits is not a pause on the underlying requirements.
DFARS clauses 252.204-7012 and 252.204-7019 are still in force. That means the 110 controls specified in NIST SP 800-171 still apply, and an active SPRS score is still required wherever your contracts call for one. CMMC Level 2 self-assessments remain a contract requirement anywhere they were already required. And the pause does nothing to shield anyone from False Claims Act exposure if a company misrepresents its compliance posture, self-assessed or not.
In plain terms: the outside checkup got delayed. The responsibility to actually be secure did not.
Why this isn’t a green light to relax
CMMC is codified in the Code of Federal Regulations. The current Administration has the authority to delay when and how a rule is implemented. It does not have the authority to cancel the rule outright or rewrite it wholesale. That authority belongs to Congress. So there are a few ways this plays out from here: Phase 2 could resume close to its original timeline once the review wraps, it could get pushed back further, or the Department could come back with a modified approach. Nobody knows yet, and anyone claiming certainty right now is guessing.
There’s also a deadline a lot of contractors will feel before the federal one: your prime’s. Plenty of primes already require evidence of NIST 800-171 implementation, current SPRS scores, and general CMMC readiness from their subcontractors, independent of where the government’s own rollout schedule sits. If Phase 2 slips, those prime-driven expectations don’t automatically slip with it. In many supply chains, the prime is setting a faster clock than the Pentagon is.
What to do with this window
The contractors who come out ahead of a pause like this use the extra runway to close gaps. The ones who come out behind treat it as permission to stop paying attention, and then scramble when the rule resumes on short notice.
A few things worth doing now, while there’s a little breathing room:
- Confirm your written security plan describes what you’re actually doing today, not what you documented a year ago.
- Close out anything still open on your NIST 800-171 gap list instead of letting it sit through the review period.
- Verify that your annual compliance affirmation and SPRS score are both current.
- If you’ve never had an outside party assess your environment, do it now, while it’s a choice instead of a mandate.
Where Cyflare fits
Cyflare didn’t wait for a pause to figure out where our own controls stood. We’re one of roughly 250 organizations worldwide with C3PAO-verified CMMC Level 2 certification, with a perfect 110/110 assessment score. Our SOC runs on CrowdStrike GovCloud, FedRAMP-authorized at the high baseline, with US-only staffing, so partners and clients working toward their own certification inherit real, audited controls instead of starting from a blank page.
Whether you’re an MSP building out a compliance practice for DIB clients or a contractor trying to figure out what actually changed this week, the fastest way to get a straight answer is to talk to someone who’s already been through the audit, not around it.
Get the CMMC Mapping Guide or book a meeting
Cyflare’s CMMC compliance services show exactly how managed security services align to Level 2 requirements, domain by domain.
Frequently Asked Questions
Does the CMMC Phase 2 pause mean I no longer need CMMC Level 2 certification?
No. The pause affects the third-party assessment requirement starting in November. Self-assessment obligations, NIST 800-171 controls, and SPRS reporting all remain in effect.
Will my prime contractor still require CMMC readiness during the pause?
Likely yes. Many primes have already set their own compliance timelines ahead of the federal rollout schedule, and those expectations don’t pause automatically.
Could CMMC Phase 2 be canceled entirely?
Unlikely, and not through this action. CMMC is part of federal regulation, and only Congress has the authority to repeal or fundamentally rewrite it. The Administration can delay implementation, as happened here.
What should I do if I haven’t started my NIST 800-171 gap assessment yet?
Start now. The audit requirement is paused, not the underlying control set, and a 60-day review window is a good time to close gaps before the next version of the rule arrives.
How is Cyflare different from a compliance consultant on this?
Cyflare holds its own C3PAO-verified CMMC Level 2 certification with a perfect 110/110 score, and operates a GovCloud-based SOC. That means partners and clients inherit certified, audited controls rather than working from documentation alone.

