The ongoing saga of CMMC compliance has taken another turn.
On July 13, 2026, the Department of War announced the suspension of CMMC Phase II requirements, which were scheduled to take effect November 10, 2026. The move removes the near-term obligation to pass a Certified Third-Party Assessor Organization (C3PAO) assessment and opens a 60-day review of the program.
For an initiative that has spent years moving from speculation to final rule to phased enforcement, this is a significant development. It's also narrower than the headlines might suggest.
"Bottom line, this suspension applies to the certification step, and only the certification step," said Inversion6 CISO Craig Burland. "Every defense contractor still has to protect CUI, still has to implement NIST 800-171's 100 controls, and still has to stand behind any score they attested to. The work is the same. The audit is what has changed."
The suspension specifically pauses DFARS clause 252.204-7021 — the requirement to achieve CMMC certification through a C3PAO as a condition of award. A newly established CMMC Reform Task Force will now conduct a comprehensive review of the program, synthesize industry feedback and deliver recommendations to the Department's CIO within 60 days.
Everything else. Specifically:
The Department's own release makes the point directly:
"This action does not eliminate the requirement for companies to protect federal data."
Keep remediating. A defensible NIST 800-171 posture is the obligation today, and closing control gaps carries value regardless of what the task force recommends.
Contractors who have already invested in a documented System Security Plan, an accurate SPRS score and realistic POA&Ms are holding important assets that will matter under any version of the program.
This is a suspension pending review — not a repeal. The certification requirement could return in its current form, a revised form or something new entirely.
"The smart move here is to treat these 60 days as a head start," said Burland. "The controls were always the destination. The Certification is just proof. Companies that keep closing gaps right now will be ready for whatever comes out of this review — and they'll be more secure in the process."