Phase I self-assessments remain active. Mandatory C3PAO and DIBCAC assessment designations are suspended during the reform review. However, organizations must continue to protect FCI and CUI, and the risk of unsupported compliance representations still applies.
Key takeaway
The government paused the contractual phase-in of Phase II certification requirements. It did not repeal the CMMC program, suspend FAR or DFARS safeguarding clauses, or eliminate potential False Claims Act exposure for knowingly inaccurate cybersecurity representations.
At a glance
Still active
Suspended during review
Still required
Phase I, including Level 1 and Level 2 self-assessment designations where required.
Phase II transition and mandatory Level 2 (C3PAO) or Level 3 (DIBCAC) designations during the review period.
Applicable FAR and DFARS duties, NIST SP 800-171 Rev. 2 implementation, incident reporting, flow-down and accurate representations.
What happened
On July 13, 2026, the U.S. Department of War announced the immediate suspension of the transition to CMMC Phase II, which had been scheduled for November 10, 2026. Pending and future CMMC implementation milestones were placed on hold while a CMMC Reform Task Force conducts a 60-day, top-to-bottom review of the program.
The Department did not announce a replacement date for Phase II. All Phase I self-assessment requirements remain in place, and the interim approach continues to use Level 1 and Level 2 self-assessments, together with select government-led assessments.
Why Phase II was suspended
The Department stated that the current implementation approach was creating costs, delays and barriers that could restrict participation in the Defense Industrial Base, particularly for small, medium-sized and non-traditional suppliers. The review is intended to preserve a meaningful cybersecurity baseline while making the program more scalable and better aligned with speed-to-capability and operational resilience objectives.
- Cost and administrative burden: The government cited prohibitive compliance costs and complex regulatory timelines as barriers to entry and continued participation.
- Assessment capacity: The reform memorandum identified shortages in third-party assessment capacity as a constraint on implementation at scale.
- Operational resilience: The government wants future requirements to show clearer, measurable security and resilience outcomes rather than relying primarily on administrative compliance.
- Small-business participation: The review is intended to reduce barriers for small and non-traditional businesses without removing the obligation to safeguard federal information.
What the government plans to do during the suspension
The suspension is an active reform period, not an inactive waiting period. The Department has established a CMMC Reform Task Force and issued a public Request for Information to gather industry evidence and recommendations.
1
Conduct a 60-day review
The Task Force will review the certification model from end to end and provide recommendations to the Department CIO. Further implementation guidance is expected after the review.
Collect and analyze industry feedback
The public RFI asks suppliers to identify cost drivers, administrative burdens, high-value controls, low-value requirements, self-assessment challenges, commercial cybersecurity capabilities and reforms that could improve operational resilience.
3
Maintain an interim cybersecurity baseline
The Department will continue using NIST SP 800-171 Rev. 2 self-assessments and select government-led assessments. DFARS 252.204-7012 and other applicable cybersecurity clauses remain in force.
4
Amend affected procurement documents
Active solicitations containing Level 2 (C3PAO) or Level 3 (DIBCAC) requirements are to be amended. Existing contracts are to be modified at the next appropriate administrative point. No Phase II waivers will be issued during the review.
What changes during the suspension
Program managers and requiring activities may designate only CMMC Level 1 (Self) or CMMC Level 2 (Self) during the review period. They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments in new procurement requirements during this period.
- Active solicitations: Requirements packages containing Level 2 (C3PAO) or Level 3 (DIBCAC) must be amended, followed by a corresponding solicitation amendment as soon as practicable.
- Existing contracts and agreements: Affected certification assessment requirements are to be removed through modification before the next option period or during the next scheduled administrative modification.
- New requirements: Level 1 self-assessments may be used for FCI and Level 2 self-assessments may be used for CUI. Additional cybersecurity protections may still be required when supported by law and regulation.
What does not change
The suspension does not remove the underlying obligation to safeguard government information. The applicable solicitation, contract, subcontract and flow-down clauses remain the controlling source for each supplier.
- Phase I remains in force: Level 1 and Level 2 self-assessment requirements remain available and enforceable where included in a solicitation or contract.
- FCI safeguarding remains required: FAR 52.204-21 continues to establish minimum safeguards for covered contractor information systems that process, store or transmit FCI.
- CUI protection remains required: DFARS 252.204-7012 remains in effect, including applicable NIST SP 800-171 Rev. 2 implementation, cyber-incident reporting, preservation and flow-down obligations.
- Government oversight continues: The Department may conduct select government-led assessments during the interim period.
- The CMMC ecosystem remains operational: The Cyber AB states that voluntary C3PAO Level 2 assessments, training, examinations, professional services and assessment processing remain available.
The False Claims Act risk does not pause
The False Claims Act (FCA) is a separate federal enforcement mechanism. The Department of Justice uses it to pursue government contractors and grant recipients that knowingly misrepresent cybersecurity practices, knowingly fail to meet material contractual cybersecurity requirements, or knowingly fail to satisfy required incident-monitoring and reporting obligations.
Important legal distinction
A cybersecurity gap does not automatically create False Claims Act liability. The principal risk arises when an organization knowingly submits or maintains a false or unsupported representation that is material to a government payment, contract award or continued performance. This section is general information and is not legal advice.
During the suspension, exposure can still arise from activities such as:
- Unsupported self-assessment scores or affirmations: Submitting or maintaining an SPRS score, CMMC affirmation or related representation that is not supported by the actual environment and available evidence.
- Misstating NIST SP 800-171 implementation: Representing that required controls are implemented when material practices are absent, ineffective or materially different from the documented SSP.
- Ignoring known contractual gaps: Continuing to claim compliance or submit invoices while knowingly failing to meet material FAR or DFARS cybersecurity obligations.
- Incident-reporting failures: Knowingly failing to report or preserve information relating to a cyber incident when the contract requires it.
- Inaccurate third-party or flow-down representations: Failing to apply required clauses to subcontractors or relying on unsupported supplier assurances for systems that handle covered information.
Recent Justice Department actions show that cybersecurity-related FCA enforcement is not theoretical. Multiple defense contractors have resolved allegations of misrepresenting cybersecurity compliance through settlements reaching into the millions of dollars, underscoring that self-assessment accuracy carries real legal exposure.
What the pause means for certification plans
The appropriate response depends on the organization’s contracts, customer expectations, readiness level and business objectives. The announcement should not be treated as an automatic instruction to cancel planned work.
1
If a C3PAO assessment was planned only because of Phase II
Review the affected solicitation, contract or subcontract and obtain written confirmation of any amendment or modification before changing the assessment schedule.
If a prime contractor or customer expects independent assurance
Confirm whether that requirement remains in the commercial or subcontract relationship. A government implementation suspension does not automatically rewrite every customer commitment.
3
If the organization is close to assessment-ready
A voluntary C3PAO assessment remains available. The decision to proceed should reflect customer demand, competitive value, risk tolerance, budget and uncertainty about the final reform outcome.
4
If the organization is still building its program
Continue implementing safeguards, validating the self-assessment, closing material gaps and maintaining evidence. Delaying core security work may increase future cost, disruption and representation risk.
What suppliers should do now
- Confirm requirements in writing: Identify the CMMC, FAR, DFARS, prime-contractor and subcontract clauses applicable to each opportunity and contract. Do not rely solely on public announcements.
- Validate every representation: Ensure self-assessment scores, affirmations and customer statements are supported by current evidence and accurately reflect the environment.
- Maintain the security baseline: Keep the CUI scope, asset inventory, data flows, SSP, POA&M and supporting procedures current.
- Continue risk-based remediation: Close material gaps, govern exceptions and document decisions, owners, milestones and evidence of completion.
- Preserve assessment evidence: Maintain policies, procedures, configurations, logs, access reviews, training records, supplier records and technical test results.
- Escalate material issues: Where a representation may be inaccurate or a material contractual requirement may not be met, involve appropriate legal, contracts and cybersecurity leadership promptly.
- Monitor reform activity: Track the Task Force review, RFI outcomes, official implementation guidance and any solicitation or contract amendments that affect timing or obligations.
Contract check
Do not assume that a public announcement has already changed your contract or subcontract. Confirm the applicable amendment or modification in writing before changing a compliance, reporting or assessment commitment.
How SAOG Cyber can help
SAOG Cyber helps aerospace and defence suppliers maintain a practical, evidence-based readiness program during the reform period. Support can include:
- validating CUI scope, self-assessment scores, SSPs, POA&Ms and supporting evidence;
- prioritizing remediation and maintaining an assessment-ready evidence package;
- supporting decisions on whether to proceed with, defer or reschedule a voluntary C3PAO assessment; and
- monitoring official program changes and translating them into clear actions for leadership and delivery teams.
The objective is to preserve cybersecurity, contractual accuracy and market readiness while avoiding unsupported assumptions during a period of policy change.