On July 13, 2026, the Department of War suspended Phase 2 of the CMMC rollout, pulling the November 10, 2026 date off the calendar and standing up a reform task force to run a 60-day review. If you run a small defense contractor, you probably read that as breathing room. It is not. The suspension paused one thing: the requirement to hold a third-party CMMC Level 2 certificate as a condition of award. It paused no security control, no contract clause, and no scoring duty you already carry. DFARS 252.204-7012 is untouched. Phase 1 self-assessment obligations from November 2025 are untouched. Your SPRS score is still the number a contracting officer looks at. The firms that get hurt here are the ones that hear “paused” and stop.
The 5 Things This Article Settles
- A suspended deadline is not a repealed rule. CMMC Phase 2 assessments are on hold, but the underlying NIST 800-171 control set that those assessments would have measured remains a contractual obligation today.
- Your SPRS score did not freeze. Contracting officers still read it, still weigh it, and a stale or inflated score is now more exposed, not less, because nothing external is coming to correct it.
- Prime contractor flow-downs live in contract law, not in the memo. A DoD suspension does not amend a subcontract you already signed. If your prime wrote a certification requirement into your agreement, that requirement is still yours.
- Remediation momentum is the real casualty. Most small firms lose ground during a pause because the internal budget conversation reopens, and the plan of action drifts with nobody watching the calendar.
- The restart will be faster than the original ramp. Reform work is already underway, and the firms that treated the pause as build time will meet the new date from a standing start.
This piece is written for owners, compliance officers, and general counsel at defense contractors in the 10 to 500 employee range, the firms with real CUI exposure and no dedicated compliance department. If you are earlier than that and still working out whether any of this applies to you, our breakdown of what CMMC compliance actually covers is the better starting point.
Why the CMMC Phase 2 Assessments Pause Is Not a Reprieve
The CMMC Phase 2 assessments pause removed a verification mechanism while leaving every substantive security obligation in force, which means your legal exposure did not fall and in one respect it rose. We have spent the past few weeks on calls with contractors who assumed the opposite, and the conversation follows the same arc every time: relief, then a slow realization that nothing in their actual contract changed.
What the suspension did and did not touch
The memo suspends the phased introduction of mandatory third-party assessment. In practice, that means contracting agencies were directed to amend active solicitations and strip CMMC Level 2 and Level 3 requirements as soon as practicable. Read narrowly, that is a procurement instruction. It tells contracting officers what they may condition an award on. It says nothing about the safeguarding obligations already written into your existing awards.
The case for reading it more broadly is worth stating fairly. Some counsel argue that a suspension of the certification regime signals the department’s own doubt about the control baseline, and that aggressive spending against a framework under active review is poor stewardship of a small firm’s cash. That view has weight, and the task force exists precisely because the cost math drew serious objection from small business advocates. The counterargument is narrower and, in our reading, stronger: DFARS 252.204-7012 was in force before CMMC existed and it survives CMMC’s revision. The clause requires adequate security on covered contractor information systems and 72-hour cyber incident reporting. No memo suspended that clause. A firm that stands down its controls is not hedging against an uncertain rule, it is breaching a certain one.
The verification gap cuts against you
Here is the part that gets missed. Third-party assessment is a burden, but it is also a shield. A C3PAO certificate is independent evidence that a qualified party looked at your environment and agreed with your position. Without it, your compliance posture rests entirely on your own attestation, and a self-attestation is a representation to the government. If it turns out to be wrong, the exposure runs through the False Claims Act, not through a failed audit you can remediate. The assessment regime that felt like a cost center was also the thing that put a second signature next to yours.
The reform is a revision, not a retreat
The task force was given 60 days and a public request for information. Suspension pending review is the standard shape of a rule being rebuilt, not withdrawn. Small business advocates who pushed for the pause asked for a proportionate framework, not the absence of one. Our read is that Level 1 and the self-assessment path emerge close to intact, and the argument lands on scoping, assessment cost, and how far certification flows down to subcontractors. If you want the timeline context, we track it in our piece on when CMMC actually becomes required.
5 Risks Small Firms Miss After the CMMC Phase 2 Assessments Pause
The risks that surface after a CMMC Phase 2 assessments pause are mostly quiet ones, because none of them announce themselves with a failed audit. Each one below is something we have watched play out inside real contractor environments in the weeks since the announcement.
Risk 1: Treating a paused deadline as a cancelled obligation
This is the expensive one. A contractor stands down the remediation project, releases the outside help, and reassigns the internal owner. Six weeks later the reform lands with a new date, and the firm restarts from a position worse than where it stopped, because staff turned over and the documented evidence went stale. Our team has seen firms lose a full quarter of progress this way. The controls you already implemented do not decay, but the artifacts that prove them do: access reviews go unsigned, log retention lapses, and the system security plan stops matching the network it describes.
Risk 2: Letting the SPRS score go stale or indefensible
Your Supplier Performance Risk System score is a self-posted number reflecting your NIST 800-171 implementation, and it is the single figure a contracting officer is most likely to pull. Validate that the score you posted is accurate and defensible right now, and if it is not, correct it. A score posted eighteen months ago against an environment that has since migrated to a new tenant is not a small paperwork problem. It is a live representation to the government that no longer matches reality, and the pause did nothing to soften it. If you are unclear where your firm sits in the tier structure, our breakdown of the CMMC levels maps score to level plainly.
Risk 3: Assuming the memo overrides your prime contractor
It does not, and this catches subcontractors constantly. A DoD memo directs government contracting officers. It does not amend a private subcontract between you and a prime. If your prime flowed a certification requirement down to you in a signed agreement, that obligation sits in contract law and stays until the prime agrees to change it. Some primes are already issuing relief. Others are holding the requirement because their own risk posture has not moved. The action here is direct: read your active subcontracts, find the flow-down language, and ask your prime in writing what their position is. Do not infer it. Our guidance on who actually needs CMMC certification walks the prime and subcontractor split in more detail.
Risk 4: Reopening the budget conversation and losing it
A paused mandate hands every internal skeptic a fresh argument, and compliance spend is the first line item questioned when the forcing function disappears. We watch this happen in real time: a plan of action and milestones that had a funded owner in June becomes an unfunded aspiration in September. The way to hold the line is to reframe the spend away from certification and onto the obligations that never paused. Incident response capability, multifactor enforcement, and CUI boundary definition are DFARS duties with or without CMMC. If your budget case rested on the November date, rebuild it on the clause instead. We broke down where the money actually goes in our look at CMMC assessment cost traps.
Risk 5: Sitting out the reform window
The task force asked for industry input, and most of the questions in the request for information concerned the burden the framework places on smaller firms. This is the rare moment where a contractor’s own cost data can move policy. Firms that stayed quiet during the original rulemaking then spent years absorbing a framework designed around organizations twenty times their size. If your firm has real numbers on what assessment preparation cost you, those numbers are worth more submitted than filed. The second half of this risk is the snapback: when the revised rule arrives, the ramp will be shorter than the original one, because the department has already run the phased approach once.
How Small Firms Should Spend the CMMC Phase 2 Assessments Pause
The right posture during a CMMC Phase 2 assessments pause is to keep building at a steady pace while spending nothing on certification logistics you cannot yet schedule. That distinction is the whole strategy, and it lets you cut real cost without giving up ground.
Keep the control work, defer the assessment logistics
Continue implementing NIST 800-171 controls, maintaining your system security plan, and closing plan of action items. Those feed DFARS obligations directly. What you can reasonably defer is the assessment machinery: C3PAO scheduling deposits, pre-assessment gap engagements booked against a date that no longer exists, and travel. If an assessment is already underway and largely paid for, finishing it is usually the better economics, because a completed assessment is evidence regardless of what the certificate is called after the reform.
Fix your scope before you fix your controls
Most of the cost in any assessment is scope, and scope is the one thing you can shrink without a deadline pressing on you. Contractors routinely treat their entire network as in-scope because nobody has done the work to define where CUI actually lives. Enclaving that data into a defined boundary is the single highest-return project available during a pause, and it is far easier to do calmly than under an audit clock. Our CMMC compliance practice starts almost every engagement here for that reason.
Get your evidence discipline running now
Controls fail assessments less often than evidence does. Build the habit while the pressure is off: quarterly access reviews with signatures, log retention that survives a real query, change records tied to the system security plan, and a named owner for each control family. When the revised rule lands, the firms holding twelve months of clean artifacts will move quickly, and the firms starting fresh will not. Our walkthrough on how to get CMMC certified sequences this work in the order that holds up.
Frequently Asked Questions
Are CMMC Phase 2 assessments cancelled?
No, they are suspended pending a 60-day reform review announced July 13, 2026. The November 10, 2026 implementation date was pulled, but the program was not withdrawn and a task force is actively reworking it. Plan for a revised requirement rather than an absent one.
Does the pause change my DFARS 252.204-7012 obligations?
It does not. That clause operates independently of CMMC and remains fully in force, including the requirement for adequate security on covered systems and cyber incident reporting within 72 hours. Any firm handling covered defense information carries those duties today.
Do I still need to maintain my SPRS score?
Yes. Self-assessment and score posting remain in effect, and your posted score is still what contracting officers reference during award decisions. Confirm the score reflects your current environment, and correct it if your infrastructure has changed since you last posted.
Can my prime contractor still require CMMC certification from me?
Yes. Flow-down requirements written into a signed subcontract are contractual obligations between you and your prime, and a government memo does not amend them. Ask your prime in writing whether they are adjusting the requirement rather than assuming the suspension applies downstream.
Should we stop our CMMC preparation work?
We advise against stopping the control and evidence work, because it satisfies obligations that never paused. Pausing assessment logistics tied to a cancelled date is reasonable. Standing down the underlying security program is what turns a pause into lost ground.
Who You Are Taking Compliance Advice From
Mindcore has spent years inside defense supply chain environments, working alongside small contractors through DFARS implementation, NIST 800-171 gap closure, and the original CMMC ramp. That work is why our read on this suspension is cautious rather than celebratory: we have seen what happens to a firm’s evidence trail when a compliance program goes quiet for two quarters, and it is not a gap that closes quickly. The controls survive the pause. The documentation habit rarely does.
Matt Rosenthal leads Mindcore and has built the firm’s practice around making enterprise-grade security workable for organizations that do not have an enterprise budget behind them. That framing shapes how we approach this moment for defense contractors: the goal is a defensible position you can afford to hold through a rule change, not a certification sprint you fund once and cannot sustain.
Use the Pause to Get Ahead
The suspension of CMMC Phase 2 assessments handed small defense contractors something they have not had since this framework arrived, which is time without a deadline attached to it. What you do with that time decides which side of the restart you land on. The firms that treat it as permission to stop will meet the revised rule with stale documentation, an undefined CUI boundary, and a compliance budget they already surrendered. The firms that treat it as build time will scope their environment properly, get their evidence discipline running, correct their SPRS position, and settle their prime contractor flow-downs in writing. Both groups face the same future date. Only one of them gets to meet it calmly.
Our team works with defense contractors on exactly this problem, sizing a compliance program to a real budget and building it so it holds up whether the rule tightens or loosens. If you want a straight read on where your firm stands and what is worth funding between now and the restart, book a free strategy call and we will walk your scope, your score, and your flow-downs with you.

