The honest answer: the CMMC third-party certification requirement is paused as of July 2026, but if you handle CUI you are still required to implement NIST SP 800-171, self-assess, post a SPRS score, and safeguard covered defense information under DFARS 252.204-7012. The audit paused; the obligation did not.
Book a 15-minute review →It helps to separate two things people lump together. The 'CMMC certification' - a C3PAO verifying your compliance before award - is what the Department of War suspended on July 13, 2026, pending a 60-day reform review. The underlying cybersecurity requirements - NIST SP 800-171 Rev 2, DFARS 252.204-7012 safeguarding and 72-hour incident reporting, DFARS 252.204-7019/7020 self-assessment and SPRS posting - were explicitly left in full force.
So if you're a defense contractor or subcontractor handling CUI: yes, you still have real, current, contractual obligations. Primes must still meet them and flow them down. Your SPRS score still conditions award under DFARS 252.204-7019. What changed is that a third party isn't currently required to certify you before you win work.
The strategic read: this is a pause, not a repeal, and it's administratively reversible. A future assessment - government-led or a revised third-party model - will still measure against the same 110 controls. Contractors who keep their self-assessment, SSP, and evidence current are protected whichever way the reform lands; those who stop are betting the program never returns.
MDRwatchdog keeps your self-assessment evidence current from live monitoring, so you stay ready regardless of what the task force decides. Readiness and evidence, not certification, and not legal advice - confirm your contract-specific requirements with your contracting officer.
The third-party certification is paused as of July 2026. But NIST SP 800-171 implementation, self-assessment, SPRS posting, and DFARS 252.204-7012 safeguarding remain required for contractors handling CUI.
Yes. DFARS 252.204-7012 flow-down remains active, and primes must still meet current obligations and flow them to subcontractors. Ask your prime whether they are amending flow-down terms in light of the suspension.
Yes. The suspension is a pause pending a 60-day review, and CMMC could return in a revised or streamlined form. The underlying rule (32 CFR Part 170) remains in place.
MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).