Some companies see cybersecurity as a cost center. We see things a little different. LEARN MORE >

Our seasoned Chief Information Security Officers bring strategic guidance to your leadership team, helping you right-size your cybersecurity operations.


A full suite of manage solutions from our US-based Security Operations Center (SOC)—staffed 24x7x365 by a full team of experienced analysts.


You can count on our IR team to contain the damage from a cyberattack, investigate the origins of the breach and build better protections for the future.


Why Inversion6

With an abundance of solutions and providers, the task of choosing the right option is critical and can sometimes be overwhelming.

Contact Us
BLOG

CMMC Phase II Suspended?

Here’s what you need to know.

city scape with code above it

Key Takeaways

  • The suspension applies to the certification step, and only the certification step. DFARS clause 252.204-7021 is paused and a 60-day program review is underway.
  • DFARS 252.204-7012 remains fully in force. Contractors still implement the 100 controls of NIST SP 800-171 r2, report incidents within 72 hours and flow down requirements to subcontractors.
  • Phase I requirements remain in place. Contractors must still submit and maintain a self-assessment score in SPRS, and the government retains the right to verify it at any time.
  • Enforcement continues. The Department will enforce NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments during the review period.
  • Prime contractor requirements still stand. Primes flow DFARS 7012 down to subcontractors independent of any government certification timeline.
  • This is a suspension pending review, not a repeal. Keep remediating — closing control gaps carries value regardless of what the task force recommends.

The ongoing saga of CMMC compliance has taken another turn.

On July 13, 2026, the Department of War announced the suspension of CMMC Phase II requirements, which were scheduled to take effect November 10, 2026. The move removes the near-term obligation to pass a Certified Third-Party Assessor Organization (C3PAO) assessment and opens a 60-day review of the program.

For an initiative that has spent years moving from speculation to final rule to phased enforcement, this is a significant development. It's also narrower than the headlines might suggest.

"Bottom line, this suspension applies to the certification step, and only the certification step," said Inversion6 CISO Craig Burland. "Every defense contractor still has to protect CUI, still has to implement NIST 800-171's 100 controls, and still has to stand behind any score they attested to. The work is the same. The audit is what has changed."


What Has Changed

The suspension specifically pauses DFARS clause 252.204-7021 — the requirement to achieve CMMC certification through a C3PAO as a condition of award. A newly established CMMC Reform Task Force will now conduct a comprehensive review of the program, synthesize industry feedback and deliver recommendations to the Department's CIO within 60 days.


What Hasn't Changed

Everything else. Specifically:

  • Safeguarding covered defense information.
    DFARS 252.204-7012 remains fully in force. Contractors and subcontractors are still contractually obligated to implement the 100 controls of NIST SP 800-171 r2, report incidents within 72 hours, and flow down requirements to subcontractors.
  • Reporting self-assessment scores to the government.
    Phase I requirements remain in place and DFARS 7019/7020 pre-date Phase II. That means contractors must still submit and maintain a self-assessment score in SPRS, and the government retains the right to verify it at any time.
  • Enforcement continues.
    During the review period, the Department will enforce compliance with NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments.
  • Prime contractor requirements still stand.
    Primes flow DFARS 7012 down to their subcontractors and increasingly verify it — independent of any government certification timeline.

The Department's own release makes the point directly:

"This action does not eliminate the requirement for companies to protect federal data."


What To Do Now

Keep remediating. A defensible NIST 800-171 posture is the obligation today, and closing control gaps carries value regardless of what the task force recommends.

Contractors who have already invested in a documented System Security Plan, an accurate SPRS score and realistic POA&Ms are holding important assets that will matter under any version of the program.

This is a suspension pending review — not a repeal. The certification requirement could return in its current form, a revised form or something new entirely.

"The smart move here is to treat these 60 days as a head start," said Burland. "The controls were always the destination. The Certification is just proof. Companies that keep closing gaps right now will be ready for whatever comes out of this review — and they'll be more secure in the process."


See how Inversion6 can help you build a solid compliance program, regardless of shifting rules.

LEARN MORE →