On July 13, 2026 the Department of War suspended CMMC Phase 2, pausing the third-party (C3PAO) certification milestone that was set for November 10, 2026. This is a pause in assessments, not a pause in your underlying obligations. If you handle CUI, the work you owe hasn't changed.
Book a 15-minute review →The suspension is narrowly scoped. What paused is the requirement for a Certified Third-Party Assessment Organization (C3PAO) to certify you before contract award. What did NOT pause: DFARS 252.204-7012 (safeguarding covered defense information and 72-hour incident reporting), NIST SP 800-171 Rev 2 implementation, your Phase 1 self-assessment, your SPRS score posting, and annual affirmations. Those remain firmly in force.
The DoD created a CMMC Reform Task Force to conduct a 60-day review, reporting back around mid-September 2026, and the driver it cited was compliance cost and small-business attrition in the defense industrial base. In other words: the expensive part got paused because it was too expensive for small contractors - not because the security requirements went away. CMMC could return in a revised, streamlined form.
What this means for you practically: keep your self-assessment current, keep your SPRS submission accurate, maintain your DFARS 252.204-7012 safeguarding obligations, and keep your scoping, SSP, and evidence work moving. None of it becomes wasted effort - a future government-led or third-party assessment will still be measured against the same 110 NIST SP 800-171 controls.
MDRwatchdog fits this moment exactly. We turn the monitoring you already run into your self-assessment evidence - control matrix, SSP, POA&M, and a live SPRS score - at a fraction of what a full consultant-led engagement costs. The forcing function changed; the readiness work didn't, and staying ready is now cheaper than scrambling later. This is not legal advice; confirm your specific obligations with your contracting officer and counsel.
No. CMMC Phase 2 is suspended pending a 60-day review, not canceled or repealed. The 32 CFR Part 170 rule remains in place, and CMMC could return in a revised form. Phase 1 self-assessment requirements remain in effect.
Yes. DFARS 252.204-7012 and NIST SP 800-171 Rev 2 are unaffected by the suspension. You must still implement the 110 controls, self-assess, post your SPRS score, and report incidents within 72 hours.
No. Self-assessment, SPRS scoring, and DFARS safeguarding are all still live, and any future assessment will measure against the same 110 controls. Preparation work carries forward - it does not become wasted effort.
The CMMC Reform Task Force is expected to report around mid-September 2026. Because the suspension is an administrative action, the program can be changed again the same way. Watch official DoD/DoW channels and confirm contract-specific requirements with your contracting officer.
MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).