Status current as of 3 September 2026. See the publishing note at the end of this document before scheduling.
CMMC Level 2 compliance still requires all 110 security controls from NIST SP 800-171 across 14 control families, and the July 2026 suspension changed how that gets verified rather than whether it applies. On 13 July the Department of War suspended Phase II, which would have made third-party certification a condition of award starting 10 November 2026, and froze the later implementation milestones with it. What did not move: 32 CFR Part 170 remains in effect, DFARS safeguarding obligations remain in effect, and self-assessments with annual affirmation in SPRS remain mandatory. The practical result is that the signature carrying the legal weight is now yours rather than an assessor’s, which narrows your exposure to certification cost and widens it under the False Claims Act. We recommend you separate certification spend from control implementation spend immediately, because those two budget lines are about to be treated very differently and most organizations have been running them as one project.
Overview
- Suspended is not repealed. The verification mechanism paused. The underlying security requirements did not.
- Self-assessment is now the operative check. That moves False Claims Act exposure onto your own attestation rather than reducing it.
- Your prime contract still binds you. A flow-down clause does not care what a Pentagon memo said.
- Scoping still decides the cost. Where controlled unclassified information lives determines the size of everything that follows.
- The pause has an end date attached. The reform task force reports in mid-September 2026, and pausing your program is a bet on an outcome nobody has seen.
The 5 Why’s
This is written for IT and compliance leads at defense suppliers, subcontractors, and non-traditional vendors that handle federal contract information or controlled unclassified information. The typical organization here has between one hundred and a few thousand employees, sells to a prime rather than directly to the government, and has spent the past two years building toward a certification requirement that just moved.
Regional concentration matters for how urgent this feels. Suppliers around Central Florida’s simulation and training cluster, the Charleston federal IT and aerospace base, and the New Jersey manufacturing corridor all sit in supply chains where prime contractors have already written flow-down requirements into subcontracts. Those obligations are contractual, and a contract does not update itself when a department memo issues.
The trigger for most organizations right now is confusion. A team that budgeted for a C3PAO assessment in late 2026 has been told the requirement is suspended, and leadership is asking whether the spend can stop. That question is reasonable and the answer is more specific than yes or no.
The consequence of answering it wrong runs in both directions. Continue spending on assessment logistics that may never be required and you waste money. Halt the program wholesale and you lose remediation progress, staff, and the defensibility of the SPRS score you are still legally required to maintain.
CMMC 2.0 Readiness After the Rules Moved
The program has changed shape twice in under a year, and the organizations handling it best are the ones that separated the security work from the certification work before they had to.
Phase 1 took effect on 10 November 2025, putting Level 1 and Level 2 self-assessment requirements into applicable solicitations, with senior official affirmation submitted through the Supplier Performance Risk System. Phase II was scheduled for 10 November 2026 and would have required assessment by a Certified Third-Party Assessment Organization for applicable Level 2 contracts. On 13 July 2026 that transition was suspended, along with the pending Phase III and Phase IV milestones, and a CMMC Reform Task Force was directed to conduct a 60-day review. During the suspension, contracting officers may include only Level 1 or Level 2 self-assessment requirements, and existing contracts carrying Phase II requirements are to have them removed by modification.
The stated reasoning was capacity and cost. Department leadership pointed to the arithmetic problem of roughly a hundred authorized assessment organizations against a defense industrial base of well over a hundred thousand companies, alongside small business cost estimates that a March 2026 GAO report had already flagged as a risk to supplier participation.
None of that touches the control set. Level 2 still means the 110 requirements in NIST SP 800-171, a system security plan that describes how each is implemented, a plan of action for anything not yet met, and a score submitted and affirmed in SPRS. That work is the same work it was in June, which is why we scope it inside broader cybersecurity services rather than as a certification project with an end date.
The change that deserves the most attention is where liability sits. With third-party verification paused, the government relies on your self-attestation, and an inaccurate or unsupported SPRS score submitted by a senior official is exactly the kind of representation that generates False Claims Act cases. Several defense bar analyses published after the suspension made this point directly: the pause reduces assessment burden and does not reduce, and may increase, enforcement exposure.
What Changed in July 2026, and What Did Not?
What changed is the verification mechanism and the timeline. What did not change is every substantive obligation you already had.
Changed: the 10 November 2026 transition to mandatory third-party assessment is suspended until further notice, Phases III and IV are frozen alongside it, contracting officers are limited to self-assessment requirements during the pause, and contracts already carrying Phase II requirements are to be modified to remove them.
Unchanged: 32 CFR Part 170 remains the governing program rule. DFARS safeguarding obligations for covered defense information remain. Annual self-assessment and senior official affirmation in SPRS remain mandatory. The 110 NIST SP 800-171 controls remain the standard. Incident reporting obligations remain. And the government-wide CUI rulemaking moving through the broader FAR overhaul is unaffected by any of this.

The practical picture differs depending on where you sit in the supply chain. Organizations contracting directly with the department can read the memo and adjust. Subcontractors cannot, because their obligations arrive through flow-down clauses in a prime’s subcontract, and those clauses remain in force until the prime amends them. Some primes will move quickly and some will not, and a few have their own security requirements that exceed CMMC and were never contingent on it. Organizations already holding a Level 2 certification are in a different position again, since a certification obtained is not withdrawn by a pause in requiring new ones.
What we recommend you do about it:
- Read your actual contracts rather than the headlines. Flow-down clauses, not memoranda, determine what you owe your prime today.
- Ask your prime in writing what they intend to do. Their answer, documented, is what protects you if the position shifts later.
- Keep the SPRS score current and defensible. It remains a required representation and it is now the primary thing the government is relying on.
- Verify the score against evidence before the next affirmation. A number nobody can substantiate is the exposure that grew, not shrank, in July.
- Watch for the mechanisms that would make this real. A class deviation, a DFARS change, or an amendment to 32 CFR Part 170 would constitute actual regulatory change. A memo can be reversed as easily as it was issued.
Should You Pause Your CMMC Level 2 Program?
Pause the certification logistics. Do not pause the control implementation. Those are two budget lines that most organizations have been running as one project with one name, and the ability to tell them apart is the difference between a sensible cost decision and an accidental security rollback.
Certification logistics means the things that exist only because a third-party assessment was coming: the C3PAO engagement fee, assessment scheduling, readiness reviews priced against an assessment date, and travel. Those can reasonably be deferred while the requirement is suspended. Control implementation means multi-factor authentication, access control, audit logging, media protection, incident response, configuration management, and the rest of the 110. Those remain legally required, they are what the SPRS score represents, and they are what your prime’s flow-down obligates.

This calculus shifts for organizations that were nearly ready. If your assessment was booked and your remediation was substantially complete, finishing carries a real option value: certification obtained now is not withdrawn later, assessor capacity is the constraint everyone expects to bind again if the requirement returns, and a completed assessment removes the question from future bids. Organizations still early in remediation face the opposite math and should focus entirely on 800-171 implementation rather than on assessment readiness. There is also a staffing dimension that budget conversations tend to miss: security staff hired against a November 2026 deadline will be reassigned or will leave during a pause, and rebuilding that capability later costs more than retaining it through the review.
What we recommend you do about it:
- Split the budget lines this quarter. Certification-specific spend in one, control implementation in another. If you cannot separate them, that itself is a finding.
- Continue 800-171 remediation without interruption. It is required independently of CMMC and it is what your score represents.
- Finish if you are close. A completed assessment is durable and assessor capacity will constrain everyone again if the requirement returns.
- Retain the team through the review period. Reconstituting a compliance capability costs more than carrying it.
- Keep your plan of action live. Open items with owners and dates are the evidence that a self-attested score is being managed rather than asserted.
What Does CMMC Level 2 Readiness Actually Require?
A defined boundary, the 110 controls implemented inside it, documentation that shows how, and a score you can defend line by line. Scoping comes first because it determines the cost of everything after it.
The scoping question is where controlled unclassified information enters your environment, where it lives, who touches it, and what systems it crosses. Email, file transfer, engineering applications, cloud storage, endpoints, and backups all commonly hold it. Every system inside that boundary carries the full control set and the recurring evidence burden that comes with it, so the difference between a carefully scoped enclave and an entire corporate network is the difference between a manageable program and an expensive one. Organizations that skip straight to purchasing tools before defining the boundary reliably spend more and cover less, which is why our CMMC compliance services work starts with data flow before it touches technology.

The right approach depends on how the environment is built. Organizations with cleanly separable work can move controlled information into a dedicated enclave, often on a government community cloud tenant, and keep the assessed boundary small. Organizations where that data crosses shared engineering, manufacturing, or clinical systems cannot separate cleanly and have to bring more of the estate into scope, which changes the budget significantly and should be modeled before commitments are made. Under the assessment path as it stood before the suspension, a conditional status required meeting at least 88 of the 110 requirements with remaining items closed inside 180 days. That threshold is a useful planning target regardless of how verification ends up working, because it describes a program that is substantially complete rather than aspirational.
What we recommend you do about it:
- Map the data flow before buying anything. Where CUI enters, resides, and exits determines your boundary, and the boundary determines your cost.
- Enclave it if you can. A small assessed environment is cheaper to build, cheaper to evidence, and cheaper to maintain every year afterward.
- Write the system security plan as you implement, not afterward. Reconstructing documentation from memory is where programs lose months.
- Treat the plan of action as a live document. Owners, dates, and closure evidence, reviewed on a cadence.
- Assume your score will be examined. Build the evidence file as though someone will ask you to substantiate every control, because the enforcement risk did not pause.
CMMC Expertise from Matt Rosenthal
In 30 years working with regulated organizations, I have watched more compliance budgets wasted on tooling bought before scoping than on anything else. What I have seen firsthand with CMMC is companies buying platforms to cover an environment nobody had drawn a boundary around, then discovering the assessed scope included systems that never needed to be in it. Our team maps where controlled information actually flows before we recommend a single control, because the boundary decides the cost of the entire program. The July suspension changed the verification, not the work.
What to Do in the Next Sixty Days
The suspension gave defense suppliers something they have not had in two years, which is time without a certification deadline attached. The organizations that use it well will spend it on the parts of the program that were always going to matter: a defensible boundary, implemented controls, documentation that matches reality, and a SPRS score backed by evidence. The organizations that treat it as permission to stop will find themselves rebuilding a capability under a compressed timeline if the requirement returns, and carrying self-attestation risk in the meantime with a program nobody is maintaining.
Start by separating your budget lines, because every other decision depends on knowing which spend was about certification and which was about security. Then verify your current SPRS score against actual evidence, control by control, since that number is now the primary representation the government is relying on and the one most likely to be examined. Then continue remediation on the controls you have open, and keep the plan of action current with owners and dates.
CMMC Level 2 compliance in its current form asks you to attest to something rather than prove it to an assessor. That is less expensive and more legally exposed, and it rewards organizations that can substantiate what they claimed. Watch for the reform task force recommendations and for any class deviation or rule amendment that follows, since those are the mechanisms that would signal genuine change rather than a paused timeline.
If you cannot currently substantiate your SPRS score with evidence for each control, that is the gap worth closing while the pressure is off. Contact Mindcore to request a CMMC scoping and readiness review.
