CMMC & Compliance

Is CMMC Cancelled? What the July 2026 Suspension Actually Means

No. CMMC is not cancelled.

It is suspended in part, under review in whole, and still legally on the books. Those are three different things, and the difference is worth real money to you.

Here is what actually happened, what you still owe today, and what I would do in the next three weeks.

What actually happened on July 13, 2026

Two memoranda came out that day. One from the Department of War’s Chief Information Officer, one from the Under Secretary of Defense for Acquisition and Sustainment.

Together they suspended the Phase II assessment mandate — the requirement that you obtain an independent third-party assessment from a C3PAO as a condition of contract award.

That is the specific thing that stopped. The November 10, 2026 date you have been counting down to no longer applies.

A CMMC Reform Task Force was stood up at the same time and directed to run a top-to-bottom 60-day review. The RFI window for industry input closed on August 14. The task force is expected to report around September 13, 2026.

So as I write this in late August, we are in the gap: comments are in, the report is not out, and nobody — including anyone telling you otherwise on LinkedIn — knows the shape of what comes next.

Suspended is not cancelled, and the distinction is legal

Both the 32 CFR rule and the 48 CFR (DFARS) rule remain in force. Nothing was rescinded. Nothing was repealed.

A suspension is the Department declining to enforce a specific mechanism while it reconsiders that mechanism. The underlying regulation is still sitting there. It can be un-suspended, amended, or replaced — but it did not disappear, and neither did your obligations under it.

I have watched three separate contractors this month treat “suspended” as “over.” That is a mistake that shows up later as a failed audit or a False Claims Act problem, not as a savings.

What you still owe, today, with no change whatsoever

This is the part the headlines got wrong.

  • DFARS 252.204-7012 remains fully operative, including the 72-hour cyber incident reporting requirement
  • FAR 52.204-21 still applies to anyone touching Federal Contract Information
  • All 110 NIST SP 800-171 Rev. 2 controls remain the standard for Level 2
  • Self-assessments remain required for contract eligibility
  • SPRS score submission continues
  • Annual affirmation by a named affirming official continues
  • Flow-down to your subcontractors continues
  • DIBCAC can still audit you

Read that list again. The certification process was paused. The security requirements were not touched.

If you handle CUI, your obligations this morning are identical to your obligations on July 12.

The False Claims Act risk did not pause

This is the piece I most want small contractors to hear.

Every affirmation you have submitted is a representation to the government. If your SPRS score overstates your actual control implementation, that exposure is live right now — during the suspension, not after it.

The suspension removed an assessment gate. It did not remove liability for having told the government something untrue. If anything, a period where nobody is coming to check makes the temptation worse and the eventual discovery uglier.

If your posted score is optimistic, fix the score or fix the controls. Do not wait for the task force.

What happens to your existing contracts and solicitations

Concrete guidance came with the memos:

Solicitations that carry Level 2 or Level 3 requirements are to be amended “as soon as possible.”

Contracts already awarded get modified to remove the suspended requirements before the next option period or the next scheduled administrative modification.

What this means practically: do not assume your contract officer has done this yet. Go look at your active solicitations and awards. If a CMMC certification requirement is still sitting in there unamended, that is a conversation to start now rather than discover at option exercise.

I would put that on this week’s list. It is a fifteen-minute review that occasionally saves a bid.

Where you stand depends on where you were

The suspension does not mean the same thing to every contractor. Four situations, four different answers.

You had not started. Best case, oddly. You get a window with no gate and no deadline pressure, and the work you do now — scope, SSP, honest SPRS score — is valid under every outcome on the table. Start.

You were mid-preparation. Keep going, but stop buying. Remediation and documentation hold their value. Anything you were about to purchase specifically to satisfy an assessor can wait until September.

You had an assessment booked. Talk to your C3PAO. The mandate that made it a condition of award is suspended; the assessment itself is not illegal, and there are reasons a prime relationship might still want it. But do not pay for a gate that nobody is currently checking unless someone specific is asking you to.

You are already certified. Nothing is taken away from you. You are ahead, and if assessment returns in any form you are not scrambling. Keep your affirmations current.

You are a subcontractor. Watch your primes. Flow-down obligations did not change, and a prime’s own contract language may still require things of you that the Department has stopped requiring of the prime. Your obligation lives in your subcontract, not in the memo.

What the task force is actually weighing

The public signal so far points at a tension between assurance and burden — whether third-party assessment survives in some form, gets replaced by expanded self-assessment, or becomes risk-tiered so that only higher-sensitivity programs draw an external assessor.

The stated motivation was cost and small-business access. The phrase that got quoted around the announcement was that the math simply did not work for the industrial base at the scale being asked.

That framing matters for you. If the reform lands where the framing points, the small-contractor path gets cheaper and more self-directed, not laxer. The documentation burden is the thing most likely to be trimmed. The 800-171 controls are the thing least likely to move.

What I would do between now and September 13

Not “wait.” Waiting is the expensive option, because the work that survives every possible outcome is the work you would be doing anyway.

1. Confirm your scope. Know exactly which systems touch CUI. If you have never drawn that boundary deliberately, that single decision drives more of your eventual cost than any other choice you will make. I wrote about why scoping determines your entire budget — it is the highest-leverage hour you can spend.

2. Make your SPRS score true. Not high. True. Then work the gap.

3. Write the SSP properly. Every reform outcome on the table still requires a System Security Plan. There is no version of this where documented controls stop mattering.

4. Keep your POA&M honest and dated. Contemporaneous records are what protect you if the enforcement posture tightens later.

5. Read your contracts. As above.

6. Do not buy a certification right now. The gate is suspended. Anyone selling you urgency this month is selling you their own pipeline.

The honest summary

CMMC is not cancelled. One expensive gate was suspended while the Department figures out whether that gate was worth what it cost. Everything that actually protects defense information is still required, still enforceable, and still yours to demonstrate.

If you were behind on July 12, you are still behind. You just got a quieter window in which to catch up — and a genuine opportunity, because the contractors who use this window will be the ones ready on day one of whatever replaces Phase II.

For the July announcement itself and the immediate reaction, I covered that here: CMMC Isn’t Dead. It’s Changing.

Where to start

If you are not sure which of those five situations you are actually in, the CMMC readiness quiz takes two minutes and will tell you.

The CMMC guide walks the whole path for small defense contractors. And if you are FCI-only and Level 1 is your ceiling, the Level 1 packet is free — this quiet window is a good time to simply get it done.

I’m Ken Haynes. I run CyberCloudAI — CMMC readiness, fractional CISO leadership, and AI tooling for defense contractors. This is general information about a fast-moving regulatory situation, not legal advice; check the current state of the rules and your own contracts before acting.


Discover more from CyberCloudAI.tech

Subscribe to get the latest posts sent to your email.

Scroll to Top