The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · capital allocation, not applicability

Should I Stop CMMC Compliance? What to Cut, What to Keep, and What Restarting Costs

Last updated:

Last verified: against primary regulatory and operational sources.

By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Regulatory facts verified against primary sources on August 14, 2026

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with, endorsed by, or sponsored by the Department of War, the Department of Defense, DCMA DIBCAC, NIST, the Cyber AB, or any U.S. government agency.


Should I stop CMMC compliance? No — not wholesale. Defer or reprice deadline-driven third-party assessment spend unless a live instrument still requires it. Keep the safeguards, incident response, assessment records, SPRS entries, and affirmations your controlling instrument still requires. The Department of War suspended CMMC Phase II on July 13, 2026 and prohibited new Level 2 (C3PAO) and Level 3 (DIBCAC) designations during the review. It left Phase I self-assessment requirements and DFARS 252.204-7012 in force. The suspension documents did not revoke existing CMMC statuses, and the Cyber AB stated two days later that C3PAO Level 2 certification assessments remained operational and available.

Here is the public cost comparison that settles the first argument without pretending to settle your invoice: the Small Business Administration estimated approximately $593,800 for a small firm requiring third-party assessment and $388,600 for a small firm eligible for self-assessment. The difference is $205,200, or 34.6% of the higher estimate. The self-assessment estimate is 65.4% of the third-party estimate.

That is not an official audit-versus-implementation allocation, and it is not permission to cut 34.6% across the board. SBA published two path totals, not one contractor's line-item budget. What the comparison does prove is harder to dismiss: removing the third-party path does not remove most of the public cost estimate. The ledger below tells you which actual invoice lines can move.

The rest of this page is the line-item version: twenty specific expenses, each with a verdict, the authority behind it, and the restart exposure if you cut it and the requirement returns. Plus one development almost nobody covering the suspension has connected to the same budget meeting — a separate federal CUI rulemaking proposal published three weeks before the pause that would use NIST SP 800-171 Revision 3, not Revision 2, for federal contracts involving CUI if finalized as proposed.


The 60-second version

Four verdicts. Every CMMC expense you have falls into one of them.

Verdict — What it means — Typical examples
VerdictWhat it meansTypical examples
CONTINUEA live clause, rule, contract, or operating need still requires it. Stopping creates contractual, regulatory, or security exposure.Applicable NIST SP 800-171 Rev. 2 safeguards, SSP maintenance, accurate SPRS records, annual affirmation, incident reporting
VERIFY IN WRITINGThe answer depends on a document only you can read. Do not guess in either direction.A signed contract that still names Level 2 (C3PAO); a prime flow-down; the clause package in your award
DEFER OR REPRICEThe expense was priced against the suspended November 10, 2026 trigger rather than a live requirement or operating need.Assessment rush fees, scheduling premiums, Level 3 preparation not named in a live instrument, unused modules
DO NOT BUY YETYou do not know your level, scope, data path, or assessment type. Buying now means buying blind.A generic “CMMC compliance package”; an enclave selected before CUI scoping

This page is for: the owner, CFO, controller, IT director, or compliance lead holding invoices, renewals, and a signed engagement, being asked “why is this still in the budget?”

This page is not for: someone still working out whether CMMC applies at all. That is a different question with a different answer. Start with Do I Still Need CMMC? and come back once you know your level and clause. For a clean comparison of the assessment types, use our CMMC Levels guide.

Before you cancel anything, open the controlling document and write down four fields: the clause package, the required CMMC status, the next award or option date, and whether the promised amendment or modification has actually issued. That five-minute step will resolve more than another hour of headlines.

This page is not legal, contractual, cybersecurity, procurement, or compliance advice. The clause in your instrument and the data in your systems set your requirement. Not a checklist. Not this page.


Should I stop CMMC compliance? The number that settles the first argument

Answer capsule: A contractor should not stop CMMC compliance wholesale solely because of the July 13, 2026 Phase II suspension. The suspension stopped new Department designations of Level 2 (C3PAO) and Level 3 (DIBCAC) during the review; it did not erase Phase I self-assessment requirements, DFARS 252.204-7012, existing contract language, or private subcontract terms. SBA's two published small-business estimates differ by $205,200, but that difference is a public benchmark — not an official line-item allocation and not an automatic savings percentage.

Let's do the arithmetic in public, because it is still useful when it is described honestly.

On July 13, 2026, SBA published two estimates in its suspension release:

  • $593,800 — approximate total compliance cost per CMMC certification for a small firm requiring third-party assessment
  • $388,600 — approximate total compliance cost for a small firm eligible for self-assessment

$593,800 − $388,600 = $205,200.

The difference is 34.6% of the higher estimate. The self-assessment estimate is 65.4% of the higher estimate.

Here is the boundary that matters: SBA did not publish a line-item model showing that $205,200 is “the audit” and $388,600 is “the implementation.” The release does not establish that the two populations have identical levels, scopes, starting maturity, environments, or cost categories. The subtraction is our computation on two published estimates. It is not SBA's finding about your budget.

What the comparison supports is narrower and stronger: a self-assessment path still carried approximately two-thirds of the higher public estimate. The third-party assessment was never the whole bill. It was just the most visible bill.

So when your CFO asks whether the July announcement means you can stop spending, the answer is yes — on the specific deadline-driven and third-party-assessment expenses that no live document still requires. It is not yes to a flat 34.6% cut. Use the ledger below, then use your own contract and invoices.

For the broader cost model — assessment fees, implementation, enclaves, managed services, and recurring work — see our CMMC Level 2 cost guide.


The honest part: some of what you were paying for bought a deadline

Here is what most pages covering this suspension will not tell you, because it costs the people who write them money to say it.

A real slice of your CMMC budget was buying a date, not security. Expedite fees to be assessment-ready by November 10. Premium consulting hours priced against a hard deadline. A scheduling deposit to hold a scarce assessor slot in a market that had 110 authorized C3PAOs in the Cyber AB's July 15 snapshot. Evidence packaging designed to survive an assessor's sampling rather than to actually run your network. Level 3 preparation for a phase that had not arrived. A GRC platform seat count sized for an audit you were about to have.

That deadline is suspended. The premium attached to it is not currently buying you award access unless a live contract, subcontract, solicitation, or private term still makes it relevant. If you were paying for speed alone, you can stop paying for speed without pretending the underlying work evaporated.

We are an independent trade publication that routes readers to provider categories. Telling you to cut spend is against our own commercial interest. We are telling you anyway, because the alternative — joining the chorus of “don't stop, keep buying” — is not analysis. It is a reflex, and mostly it comes from people who invoice you.

Now the pivot, and it is the entire argument of this page.

Underneath that deadline was work that had nothing to do with the deadline. Knowing where your CUI actually lives. Access control. Multifactor authentication. Logging. A System Security Plan that describes the system you actually run instead of the one you wish you ran. An SPRS record that matches reality. None of that was created by the November date. None of it disappeared when the date did. And every plausible outcome of the current review — a return of certification, a narrower return, or a replacement model built around self-assessment and government validation — is fed by the same evidence.

That is why the ledger below has four verdicts instead of two. “Stop” and “keep” is not enough resolution to spend against.

And if this page isn't for you, we'd rather you left now. If you handle Federal Contract Information (FCI) only, with no Controlled Unclassified Information (CUI) anywhere in your environment and no prime asking for more, the story is much smaller than the headlines suggest, and this is not the six-figure decision driving the fear. Go to our CMMC Level 1 self-assessment checklist and stop reading this.

Definitions, once, then we use them freely. FCI (Federal Contract Information) is non-public information provided by or generated for the Government under a contract, excluding information the Government makes public and simple transactional information. CUI (Controlled Unclassified Information) is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls, excluding classified information. C3PAO (CMMC Third-Party Assessment Organization) is an authorized organization that performs formal CMMC Level 2 certification assessments. DIBCAC is the Defense Industrial Base Cybersecurity Assessment Center, the government organization that performs Level 3 and other government-led assessments. SPRS is the Supplier Performance Risk System, where applicable NIST SP 800-171 assessment records, CMMC self-assessment results, CMMC statuses, identifiers, and affirmations are stored or reflected. RPO/RP means Registered Practitioner Organization or Registered Practitioner — readiness and advisory help, not the formal certification decision. MSSP (Managed Security Service Provider) operates security controls on your behalf. GRC platform means governance, risk, and compliance software used to manage evidence and control mappings. CUI enclave is a segmented environment built to hold CUI in a smaller assessment boundary.


Which CMMC costs can I stop paying? The Spend Triage Ledger

Answer capsule: After the July 13, 2026 suspension, CMMC expenses divide into four categories: work a live instrument or operating need still requires, work whose status depends on a contract document, work priced only against the suspended November 10, 2026 trigger, and work that should not be purchased before scope is known. Phase I self-assessment requirements remain in place. New Level 2 (C3PAO) and Level 3 (DIBCAC) designations are paused, but C3PAO Level 2 certification assessments remain operational and available, and the suspension documents did not revoke existing statuses.

We assembled this table on August 14, 2026 by reading the July 13 implementation procedures, the codified DFARS clauses at Acquisition.gov, 32 CFR Part 170, Class Deviation 2026-O0025, official SPRS guidance, the Cyber AB's program documents, and the June 23 proposed FAR rule side by side, then mapping each surviving authority to the line items that actually appear on a defense contractor's invoice.

This is an invoice-level synthesis, not a regulatory label. The verdict column is our editorial judgment. The authority column tells you what that judgment rests on.

Expense line — What it buys — Verdict — Authority or decision rule — Restart exposure if you cut it
Expense lineWhat it buysVerdictAuthority or decision ruleRestart exposure if you cut it
NIST SP 800-171 Revision 2 implementationThe 110 Level 2 security requirements across 14 requirement familiesCONTINUE where applicableDFARS 252.204-7012 still requires the applicable safeguards where incorporated; CMMC Level 2 remains tied to Rev. 2 under 32 CFR Part 170Controls drift, evidence disappears, and reimplementation rarely costs less than maintenance
System Security Plan maintenanceThe description of the system you actually operateCONTINUEThe SSP requirement is one of the Level 2 requirements that cannot be placed on a POA&M for Conditional Status under 32 CFR 170.21Rewriting a stale SSP while under an award or assessment clock is more expensive than keeping it current
POA&M closureRemediation of known gapsCONTINUEConditional Level 2 requires at least 88 of 110 points, excludes six specified requirements from the POA&M, and gives 180 days to close a valid POA&MOpen gaps become harder to defend as systems and personnel change
SPRS assessment, status, and affirmation accuracyA current government record that matches the applicable clause packageCONTINUE where applicableCodified 252.204-7019/-7020, 252.204-7021, and official SPRS workflows create different record duties; the instrument determines which one appliesCorrecting an inaccurate record under award or enforcement scrutiny is worse than maintaining it
Annual affirmation by the Affirming OfficialContinued currency of the CMMC statusCONTINUE where CMMC applies32 CFR 170.22 and DFARS 252.204-7021 require annual affirmationA stale affirmation can make a status non-current; a knowingly false representation can create enforcement exposure
72-hour cyber-incident reporting capabilityA functioning response path when a covered incident occursCONTINUE where 252.204-7012 appliesDFARS 252.204-7012 remains in effectYou cannot build a credible reporting and preservation process during the incident
FedRAMP Moderate-equivalent cloud for covered defense informationCompliant cloud handling where the clause appliesCONTINUE where applicableDFARS 252.204-7012 requires an external cloud provider handling covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline and related clause dutiesReverse migration followed by a second migration is one of the costliest cuts on this list
Level 1 annual self-assessment and affirmationCurrent Level 1 (Self) status for FCI systemsCONTINUE where Level 1 is requiredLevel 1 uses 15 basic safeguarding requirements, permits no POA&M, and requires annual assessment and affirmationLow implementation burden compared with the eligibility damage from letting the status lapse
Flow-down managementThe correct requirement in subcontracts and other instrumentsCONTINUE where applicableDFARS 252.204-7021 and 32 CFR 170.23 require the appropriate CMMC level to flow down when a subcontractor will process, store, or transmit FCI or CUIRe-papering a supply chain after award is slow and commercially painful
MSP or MSSP operating live controlsAccess, logging, patching, monitoring, response, or other actual operationsCONTINUE, or transition deliberatelyNo rule requires a specific provider, but abrupt cancellation can create a real control failureTransition cost plus the operational gap you created
Existing Final CMMC Level 2 status upkeepA current status you already earnedCONTINUE if you rely on itThe suspension documents did not revoke achieved statuses; Final Level 2 statuses have three-year currency subject to annual affirmations and continued complianceLetting it go stale can force a new assessment before you can rely on it again
Signed contract that still names Level 2 (C3PAO) or Level 3Contract performance and status eligibilityVERIFY IN WRITINGContracting officers were directed to remove those requirements by modification before the next option or during the next scheduled administrative modification; the change is not automaticActing on a government memo that never changed your executed instrument
Active solicitation that still names Level 2 (C3PAO) or Level 3Bid eligibilityVERIFY IN WRITINGActive solicitations were to be amended as soon as practicable; your bid changes only when the amendment issuesA bid strategy based on an amendment that never arrived
The clause package actually in your awardEvery downstream dutyVERIFY IN WRITINGCodified DFARS text and the current Part 240 class-deviation package coexist; older and newer instruments may not use the same provisions and clausesBuying or cancelling against the wrong legal package entirely
Legacy NIST SP 800-171 DoD Assessment work under 252.204-7019/-7020A Basic, Medium, or High assessment record and summary scoreVERIFY IN WRITINGThe codified clauses remain published. Newer instruments under Class Deviation 2026-O0025 may instead use the Part 240 package, including 252.240-7997 for government Medium/High assessmentsMissing a live pre-award or option requirement because someone told you the old clauses “went away”
C3PAO assessment booked only for the former November 10 gateA formal Level 2 certification assessmentDEFER OR REPRICE, subject to your agreementNew DoW Level 2 (C3PAO) designations are prohibited during the review, but C3PAO Level 2 certification assessments remain operational and available, and a live private or contractual trigger can still matterPrivate cancellation fees, lost slot value, and later queue re-entry
Assessment rush or expedite premiumSpeedDEFER OR REPRICEThe federal date that created the premium is suspendedUsually the cleanest cut on the page unless a separate deadline survives
Level 3 or February 2021 SP 800-172 preparation not named in a live instrumentWork for a Level 3 trigger that is not presently in your documentsDEFER OR REPRICENew Level 3 designations are prohibited during the review. CMMC Level 3 still incorporates 24 selected requirements from the February 2021 SP 800-172, not NIST's later replacement publicationThe underlying Level 2 work carries forward; speculative enhanced work may not
Unused GRC platform seats or modulesShelfwareDEFER, DOWNGRADE, OR REPRICENo CMMC authority requires a particular software product. The requirement is implemented safeguards, current documentation, and supportable evidenceExport and retention planning before cancellation; lock-in if you wait
A generic “CMMC compliance package” bought before scopingThe wrong thing, expensivelyDO NOT BUY YETYou cannot select the right environment, provider category, or evidence workflow before identifying the instrument, level, CUI path, and assessment typeThis is the most avoidable spend on the list

One caution about this table. It sorts expenses, not contracts. A class deviation tells contracting officers which text to use; it does not silently rewrite an executed award. Every VERIFY IN WRITING row exists because the honest answer depends on a document sitting in your file, not on anything we or anyone else can publish. Open it.

You've found your rows. Now sequence them.

Most contractors at this point don't have a motivation problem — they have a sequencing problem. They're about to buy the right thing at the wrong time, or the wrong category at any time. Readiness, managed security, evidence workflow, enclave deployment, and formal assessment are five different jobs, and the suspension changed the priority order among them.

See who to hire first or map my situation to the right provider category — high-level inputs only. Resolve the job before anyone talks to you about a quote.

The Find My CMMC Path tool is an educational routing tool. It does not determine compliance, interpret your contract, or guarantee certification.

Do not submit CUI, drawings, technical data, export-controlled content, contract files, or sensitive contract details.


What CMMC work can I not stop? The clause that says so

Answer capsule: The July 13, 2026 memoranda direct Department contracting personnel; they do not amend 32 CFR Part 170, silently rewrite an executed contract, or cancel private subcontract terms. Where incorporated, DFARS 252.204-7012 safeguarding and 72-hour incident reporting continue. Phase I self-assessments, applicable SPRS records, and annual affirmations also continue under the CMMC clause package. The Department said it would enforce the baseline during the review through self-assessments and select government-led assessments.

The reason the “keep” column is so long is that much of it predates the suspension, and some of it predates CMMC.

DFARS 252.204-7012 required covered contractors to implement the applicable NIST SP 800-171 safeguards no later than December 31, 2017 and established the 72-hour incident-reporting duty. CMMC's acquisition clauses took effect on November 10, 2025. CMMC did not create the underlying 7012 safeguards. It added status, assessment, affirmation, and award mechanics around them. The new Level 2 (C3PAO) and Level 3 designations are what the July procedures stopped.

There is also a version-control trap here that can make a technically sophisticated contractor spend against the wrong document.

NIST now lists SP 800-171 Revision 2 as superseded by Revision 3 and lists the February 2021 SP 800-172 as superseded by a later revision. CMMC did not automatically move with NIST's catalog. 32 CFR Part 170 still ties Level 2 to the 110 requirements in SP 800-171 Revision 2 across 14 requirement families and Level 3 to those 110 requirements plus 24 selected requirements from the February 2021 SP 800-172. For CMMC, Revision 3 is not controlling unless DoD changes the controlling rule, clause, or instrument.

Here is the part that should get a senior executive's attention.

Your signature is carrying more weight than it did in June

Before the suspension, a contractor with an optimistic self-assessment expected a future third-party gate on many Phase II awards. Under that model, a C3PAO could find the gap between the posted record and the running network before a later award relied on the status.

That procurement gate is gone for new Department Level 2 (C3PAO) designations during the review. Government-led assessments continue, and C3PAO Level 2 certification assessments remain operational and available, so independent validation did not disappear. But the contractor's own assessment record and annual affirmation now carry more of the immediate procurement burden for the self-assessment paths the Department left in place. A lower compliance burden is not a license for a looser representation.

This is not theoretical, and it is not old news.

On June 18, 2026 — three and a half weeks before the suspension — the Justice Department announced that LOGZONE, Inc., a logistics services provider in Huntsville, Alabama, agreed to pay $507,144 to resolve False Claims Act allegations involving two Navy contracts. According to DOJ, from May 2021 to March 2025 the company allegedly failed to implement certain NIST SP 800-171 controls. When the Defense Contract Management Agency assessed the company's implementation, the result was a score of −170, against a possible range of −203 to 110. The settlement included $253,572 in restitution, and DOJ stated that the claims were allegations only and there had been no determination of liability.

Read the range again. The scale runs from −203 to 110. A score of −170 sits near the bottom of what is arithmetically possible.

Two things matter about this case for your decision right now:

DOJ says the issues were identified when DCMA assessed the company's implementation. Select government-led assessments are exactly what the Department said would continue during the suspension. The validation mechanism that surfaced this problem survived.

The alleged conduct ran through March 2025 and settled in June 2026. Enforcement operates on a multi-year lag. A record entered this quarter can matter long after the current review concludes.

We are not suggesting this outcome is typical, and this was not a CMMC enforcement case — it was a civil False Claims Act settlement about contractual cybersecurity requirements, NIST SP 800-171 implementation, and a government assessment score. That is precisely why it belongs here. The suspension did not suspend the False Claims Act, DFARS 252.204-7012, or the risk created by a government record that does not match the running environment. If you want the second case on the public record, our applicability page covers the MORSECORP settlement in detail, including the reported gap between the posted score and the later calculation.

Is your posted record defensible today?

If there is daylight between what SPRS says and what is actually running, closing that gap is the highest-value work available during this window — and it is work you would need under every outcome that leaves the underlying safeguarding duty in your instrument. It is also, notably, work that usually costs less than rebuilding a neglected program under an award clock.

See what a defensible self-assessment requires — our free readiness checklist, organized across the 14 NIST SP 800-171 Revision 2 requirement families.


Five parties who can still make this work matter

Answer capsule: The July 13 memoranda bind Department program managers, requiring activities, and contracting personnel. They do not automatically amend an executed contract, a private subcontract, a government assessment notice, or federal enforcement law. Four actors can affect a current obligation or its enforcement today; the FAR Council can change the future government-wide CUI baseline through a final rule and later contract incorporation.

A memorandum to government personnel is not a release. Here is who is left.

1. Your own contract. Contracting officers were directed to remove suspended Level 2 (C3PAO) and Level 3 requirements by modification before the next option exercise or during the next scheduled administrative modification. That language creates a real interval between Department policy and the words still sitting in your award. Until the modification issues, the clause in your contract is the clause in your contract.

2. Your prime. DFARS 252.204-7021 requires the appropriate level to flow down when a subcontractor will process, store, or transmit FCI or CUI. The memoranda direct Department personnel — they do not rewrite a private subcontract. Your prime may amend the requirement, maintain it under a private supplier standard, or ask for different evidence. Confirm the position in writing rather than relying on any published summary, including ours.

3. DIBCAC and other authorized government assessors. The Department's interim enforcement language keeps select government-led assessments running. Independent verification did not disappear. It narrowed to assessments the Government selects, and the published suspension documents do not explain how every target will be chosen.

4. The Department of Justice. Annual affirmations and other contractual representations remain subject to the ordinary enforcement framework. The Civil Cyber-Fraud Initiative and the LOGZONE resolution show why accuracy still matters. The suspension is not an immunity document.

5. The FAR Council. This one does not create a current duty by proposal alone. It does belong in the same capital-allocation discussion because it points toward a broader federal CUI baseline built on Revision 3 if finalized and incorporated.

The two clocks are running in opposite directions

Three weeks before the Department paused new CMMC Phase II designations, the FAR Council proposed a broader CUI framework for federal contracts involving CUI.

On June 23, 2026, the FAR Council published a proposed rule at 91 FR 37550 under FAR Case 2026-001. The proposal consolidates the earlier FAR Case 2017-016 CUI rulemaking into the Revolutionary FAR Overhaul, proposes new FAR 52.240-6 and 52.240-7, and would use NIST SP 800-171 Revision 3 for covered contractor systems handling CUI. Comments closed July 23, 2026.

Dimension — Department of War — July 13, 2026 — FAR Council proposal — June 23, 2026
DimensionDepartment of War — July 13, 2026FAR Council proposal — June 23, 2026
ActionSuspended new Phase II Level 2 (C3PAO), Level 3, and later implementation milestones during review; kept Phase I self-assessmentsProposed a government-wide contract framework for safeguarding CUI
InstrumentCIO memorandum and attached implementation proceduresProposed rule under FAR Case 2026-001, 91 FR 37550
Security baselineCMMC Level 2 remains NIST SP 800-171 Revision 2Proposed FAR 52.240-7 would require NIST SP 800-171 Revision 3 when the CUI clause applies
Enhanced requirementsCMMC Level 3 remains 24 selected requirements from the February 2021 SP 800-172Agencies could identify SP 800-172 requirements for a critical program or high-value asset
Incident reportingDFARS 252.204-7012 remains at 72 hours where incorporatedProposed CUI-incident reporting is 72 hours from discovery
Clause vehicleDFARS 252.204-7021 / 252.204-7025 and the applicable deviation packageProposed FAR 52.240-6, FAR 52.240-7, and a contract-specific CUI form
ScopeDepartment contracts and subcontracts carrying the applicable CMMC requirementFederal solicitations and contracts in which CUI will be involved, excluding COTS-only acquisitions and subject to the proposal's prescriptions
Current legal effectImmediate Department acquisition direction; executed instruments still require amendments or modificationsNone as a final rule. It remains a proposal as of August 14, 2026
How obligations would attachThrough the applicable solicitation, clause, status designation, and contract actionThrough the proposed provision, clause, and CUI form when included in a solicitation or contract — not through a CMMC-style four-phase schedule

What this means in plain terms: one part of the federal government paused new third-party and government-led CMMC designations. Another part proposed a broader contractual CUI baseline using a newer NIST revision. If you dismantle a functioning Revision 2 program now, one plausible outcome is rebuilding it against Revision 3 later — after paying once to unwind what you already had.

Now the discipline, because this matters more than the point: the FAR CUI text is a proposed rule. It is not law. It can change before any final rule publishes, and no final rule had published as of August 14, 2026. We are not telling you to implement Revision 3 today for CMMC. For CMMC Level 2, Revision 2 remains controlling until DoD changes the governing rule, clause, or instrument.

We are telling you something narrower and more useful: the July pause is not the only federal development that belongs in your cybersecurity budget. The proposal does not justify speculative spending. It does make dismantling a working CUI program a harder decision to defend.

Which category should hold this work while the rules move?

The answer changes depending on whether your next twelve months are about implementation, evidence, environment, or verification — and the suspension shifted that priority order for most contractors handling CUI.

Compare CMMC provider categories — what a C3PAO, an RPO, an MSSP, a GRC platform, and a CUI enclave each actually do, and which problem each one solves.


If you're a subcontractor, the answer is probably different

Answer capsule: The July 2026 memoranda direct Department personnel and do not automatically amend an executed subcontract. Under 32 CFR 170.23, the required flow-down depends on the prime requirement and the information the subcontractor will handle. A Level 2 (Self) prime ordinarily flows Level 2 (Self) to a subcontractor handling CUI; a Level 2 (C3PAO) prime ordinarily flows Level 2 (C3PAO); and a Level 3 prime ordinarily flows at least Level 2 (C3PAO), absent other Government guidance. The signed subcontract still controls until it is changed through the process it requires.

If you are a sub, this section matters more to your budget than anything else on this page. Relief does not travel downhill by headline.

Three rules we would hold to:

Silence is not relief. A prime who has not changed the requirement in writing has not released you from it.

“Under review” is the same as silence for budgeting purposes. Keep the current written requirement in your plan until the prime gives you a definite answer.

If multiple primes share one environment, the strictest live requirement tends to set that environment's posture. Separately scoped systems can support different requirements. One flat network usually cannot be treated as Level 1 for one customer and Level 2 for another while the same CUI crosses it.

Some primes also impose supplier questionnaires, portal evidence, or cybersecurity terms that are independent of the federal CMMC phase schedule. Those obligations live in the subcontract, supplier terms, and portal instructions. The July memoranda did not erase them. Verify the actual source before you keep paying — or before you stop.

Send this to your prime today

Copy it. Change the brackets. Send it before you cancel a single line item.

Subject: Confirmation of current CMMC requirement — [contract / subcontract / opportunity number]

Following the July 13, 2026 suspension of CMMC Phase II, we are confirming our obligations under this agreement so that we can plan accurately. Could you please confirm in writing:

  1. The exact CMMC status required of us — Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), Level 3, or another stated requirement.
  2. The subcontract provision, flow-down clause, or prime-contract requirement that establishes it.
  3. Whether our systems are expected to process, store, or transmit FCI, CUI, or both.
  4. Whether any amendment or modification since July 13, 2026 has changed this requirement.
  5. The evidence you require from us, and by when.
  6. Whether you intend to maintain this requirement irrespective of the Department's current designation policy.

We will not transmit CUI, drawings, technical data, or sensitive contract material by ordinary email. Please identify a protected channel if any response requires that content.

Question six is the one that matters for your budget, and it is the one contractors forget to ask. A prime that intends to hold the line regardless of the Department's policy has just told you your spend decision, and it did not come from a memo.

A good answer names the status, the assessment type, the clause or provision, the data basis, and a date. “Everyone needs Level 2” is not an answer — it is a prompt to ask again, politely, in writing.

For the full prime/sub boundary analysis, see our CMMC flow-down requirements guide.


What stopping actually costs if the requirement comes back

Answer capsule: The cost of pausing the wrong CMMC work is not just a future assessment fee. It is the cost of rebuilding an environment, evidence base, personnel knowledge, and documentation set that were already paid for. The Cyber AB's July 15, 2026 snapshot listed 110 authorized C3PAOs, more than 1,000 CCAs, and nearly 2,000 organizations with Final Level 2 status. C3PAO Level 2 certification assessments remain operational and available. If procurement demand returns broadly, deferred contractors can re-enter a finite market at the same time.

There are three separate costs of stopping, and only one of them is obvious on an invoice.

Cost one: the queue. In its July 15, 2026 statement, the Cyber AB reported 110 authorized C3PAOs, more than 1,000 Certified CMMC Assessors, and nearly 2,000 organizations holding Final Level 2 status. That is a dated snapshot, not a live count — verify current listings in the Cyber AB Marketplace, and see our Cyber AB Marketplace guide for why counts in secondary coverage vary. The Cyber AB also said C3PAO assessments remained operational and available. The suspension removed new Department designations; it did not mothball the ecosystem.

If third-party certification returns as a broad procurement gate, demand can reconcentrate quickly. A contractor that maintained scope, controls, evidence, and documentation enters that market differently from one that dismantled all four.

Cost two: decay. This is the one nobody prices. Controls drift. Staff turn over. The person who knew where the CUI actually flowed leaves. An SSP that was accurate in March can describe a system that no longer exists by December. Unwinding and rebuilding a CUI enclave can cost more than maintaining one because you pay for migration twice and absorb operational disruption twice.

Cost three: the self-assessment benchmark. SBA's public estimate for a small firm eligible for self-assessment was $388,60065.4% of its third-party-path estimate. That does not make $388,600 your implementation bill, and it does not make $205,200 your automatic savings. It does show why “the assessment was paused” and “the cost disappeared” are not the same sentence.

What could actually happen next

Three scenarios. All three are our editorial reading of the published documents, not predictions, and the controlling documents establish none of them.

Certification returns substantially as written. The task force recommends adjustments rather than replacement. Contractors that maintained current controls, evidence, scope, and documentation are ahead. A current Level 2 status remains a usable procurement and subcontracting asset where a buyer accepts or requires it.

Certification returns narrowly. Third-party assessment applies to a smaller set — higher-sensitivity CUI, specific programs, or specific tiers — with self-assessment and government-led validation elsewhere. Your implementation and evidence still carry; deferring an untriggered assessment was the correct cut.

The model is replaced. The Department builds a different validation model around self-assessment, government selection, existing commercial capabilities, or some combination. In that world, the quality of your own record and evidence does not become less important.

Notice what is constant across all three: implemented safeguards, current documentation, and evidence. That is the definition of a low-regret investment. It is also why this page tells you to cut the deadline premium before you cut the running program.

Watch five places: further Department guidance; a revision or rescission of the applicable class deviation; a DFARS rule or clause change; an amendment to 32 CFR Part 170; and the actual amendment, modification, or flow-down that reaches your instrument. Those are the developments that can change the answer you act on. A task-force report by itself does not silently amend a contract.

Right-size the program instead of stopping it.

For most contractors reading this, the correct answer is not “stop” and not “carry on as before.” It is a smaller, cheaper program aimed at the obligations and operating controls that survived — with formal assessment spend deferred until a real trigger exists. That may require a different provider category than the one you are paying today.

Tell us your level, scope, and timeline and we will match you with source-checked CMMC provider options sized to the work you are keeping — not to a date that no longer exists.

Already know the category you need? Request scoped quotes.

Do not submit CUI, drawings, technical data, export-controlled content, contract files, or sensitive contract details.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. This page contains no named provider recommendation.


What to tell your CFO

Answer capsule: A defensible post-suspension budget separates deferrable deadline and formal-assessment spend from the safeguards, records, and operating work a live instrument still requires. It names the authority for each line, states what was verified, and records the date. The July 13 procedures prohibit new Level 2 (C3PAO) and Level 3 designations during the review; they do not erase DFARS 252.204-7012, Phase I self-assessments, applicable SPRS duties, annual affirmations, existing statuses, or unmodified contract language.

You are going to be asked to justify this number. Here is language you can adapt. It is written to survive a board meeting, which means it concedes the cut before it defends the spend.

Post-suspension CMMC budget position — [date]

On July 13, 2026, the Department of War suspended CMMC Phase II, which had been scheduled to begin November 10, 2026. The Department prohibited new Level 2 (C3PAO) and Level 3 (DIBCAC) designations during the review, suspended later implementation milestones, and left Phase I self-assessment requirements in place. A reform task force was directed to report to the Department CIO within 60 days.

What we are reducing. We are deferring or repricing $[amount] previously budgeted for [formal assessment fees / scheduling deposits / expedite premiums / Level 3 preparation / unused software modules]. We verified that no current contract, subcontract, solicitation, option, or private term requires us to retain that spend on the old schedule. [If any live instrument does, state it here instead and identify the written confirmation requested or received.]

What we are continuing, and why. We are maintaining $[amount] for [applicable NIST SP 800-171 Revision 2 implementation / System Security Plan maintenance / POA&M closure / incident response / accurate SPRS records / annual affirmation / live managed controls]. These items arise from the clauses and systems identified in our review, not merely from the suspended Phase II date. The Department stated that it would continue baseline enforcement through self-assessments and select government-led assessments during the review.

How we used the SBA cost figures. SBA published approximate small-business totals of $593,800 for the third-party path and $388,600 for the self-assessment path. The $205,200 difference is a public comparison, not an official line-item allocation and not our automatic savings target. We used our actual invoices and controlling documents to identify the cut.

Risk if we stop the continuing items. Our assessment entries and annual affirmation are formal government records where the CMMC clause applies. In June 2026, the Justice Department announced a $507,144 False Claims Act resolution after a government assessment scored a contractor's NIST SP 800-171 implementation at −170 on a scale from −203 to 110. DOJ stated that the claims were allegations only and there had been no determination of liability. The case was not a CMMC enforcement action, but it demonstrates the exposure created when contractual cybersecurity requirements and the running system diverge.

What we are monitoring. Department task-force recommendations, expected approximately September 11, 2026; further implementation guidance; class-deviation changes; DFARS or 32 CFR amendments; amendments and modifications to our instruments; prime flow-down changes; and the proposed FAR Case 2026-001 CUI rule, which would use NIST SP 800-171 Revision 3 if finalized as proposed and incorporated into an applicable contract.

Next review date: [date]

Fill in your own numbers, delete what does not apply, and keep a copy in the file with the date you verified each fact. A dated, cited memo is what turns “we think we can cut this” into a decision your board can sign off on.


Who should genuinely stop spending — and we mean stop

Answer capsule: Some companies have no present CMMC trigger. 32 CFR 170.3 excludes federal information systems operated on the Government's behalf and acquisitions exclusively for commercially available off-the-shelf items, and frames general applicability for covered acquisitions above the micro-purchase threshold. The rule uses the acquisition, instrument, system, and FCI/CUI data path — not employee count — to determine the requirement.

We would rather disqualify you than sell you something. Four situations where the honest answer is “stop, and document why.”

You have no Department contract, solicitation, subcontract, or other instrument carrying the requirement, and no FCI or CUI touching your systems in contract performance. Not “we might bid someday.” Not “we handle sensitive commercial data.” If there is no live instrument and no contractor system will process, store, or transmit FCI or CUI in performance, do not buy a compliance package against a hypothetical. Document the data path and monitor the pipeline.

The acquisition is exclusively for commercially available off-the-shelf items. Read that carefully. “We sell a commercial product” is a different statement. The exclusion is about the acquisition, and a separate instrument or actual FCI/CUI handling can still create obligations.

You bought software before you scoped. If you are paying for a GRC platform, an enclave, or a managed service selected before anyone mapped where the CUI lives, you may be paying to solve a problem you have not defined. Export your evidence, then decide. Do not renew on autopilot because compliance software feels safer than no compliance software. Software does not satisfy CMMC. Implemented safeguards and supportable evidence do; software is one way to manage them.

You are FCI-only with a clear Level 1 requirement. Fifteen basic safeguarding requirements, an annual self-assessment, no POA&M, and an annual affirmation. That is a real obligation, but it is not a Level 2 build by default. If someone quoted you a Level 2 project without identifying a CUI path or written requirement, get a second opinion. Start with the Level 1 self-assessment checklist.

If one of these describes you, do not buy a CMMC package based on a headline in either direction. Confirm the instrument and the data path first. That is the right answer even though it routes you nowhere and earns us nothing.

For the full applicability analysis — including the paper-only CUI exception, the micro-purchase threshold, and the federal-system carve-out — see Do I Still Need CMMC?.


Is there a real CMMC deadline left?

Answer capsule: Phase I began November 10, 2025, and its published first-year window runs through November 9, 2026; the July 13 announcement says all Phase I self-assessment requirements remain in place. No replacement Phase II start date has been announced. The task force was directed to report within 60 days of July 13, approximately September 11, 2026. The public RFI closed at noon Eastern on August 14, 2026. Neither event automatically restarts the rollout or changes a contract.

We are not going to manufacture urgency, so here is the honest calendar.

Dates that are real:

  • November 10, 2025 — the CMMC acquisition rule took effect and Phase I began.
  • November 10, 2025 through November 9, 2026 — the Phase I period in the published implementation schedule. The July suspension says Phase I self-assessment requirements remain firmly in place.
  • July 13, 2026 — the Department announced the Phase II suspension and issued the policy and implementation documents.
  • August 14, 2026 at 12:00 p.m. Eastern — the public Request for Information deadline. That window has closed.
  • Approximately September 11, 2026 — 60 calendar days after July 13. The task-force report is due to the Department CIO. A monitoring date, not a contract-change date.
  • November 10, 2026 — the former Phase II start. Suspended. Any page still describing it as the operative start date without the suspension is stale.

Dates that do not exist: a published replacement Phase II start, an automatic resumption date, a final reform model, or a universal date by which every affected contract will be modified.

The deadlines that can cost you money now are yours. Your GRC renewal. Your assessment engagement's cancellation window. Your next option exercise. Your bid amendment deadline. Your prime's response date. Your annual affirmation anniversary. Those dates should drive action this month, and none should be guessed from a headline.


What we actually verified

We think you should know exactly what we read, when, and where the limits are.

Primary and official sources checked on August 14, 2026:

How we label statements on this page:

Statement type — How we treat it
Statement typeHow we treat it
Text in 32 CFR Part 170, the FAR/DFARS, or an official memorandumPresented as the source states it, with the instrument named
A proposed ruleExplicitly labeled as proposed, with its current legal effect separated from what would happen if finalized and incorporated
A NIST publication statusSeparated from the version a regulation or clause still incorporates
A public cost estimateAttributed to the issuing body; arithmetic we performed is identified as ours and not converted into a fake line-item allocation
A live contract, solicitation, subcontract, Marketplace listing, or cancellation termTreated as reader-specific and something the reader must verify
Our recommended actionLabeled as a verdict, framework, scenario, or editorial judgment derived from the verified authorities

What we could not establish for you, and therefore do not pretend to know:

  • Whether your specific solicitation, contract, option, subcontract, or supplier term has actually been amended or modified.
  • Whether your instrument uses the codified DFARS package, the current Part 240 deviation package, or another authorized text.
  • Whether your prime intends to maintain a private requirement regardless of Department designation policy.
  • The live count of authorized C3PAOs at the moment you read this page.
  • Whether your data is FCI, CUI, both, or outside the assessed scope.
  • Whether cancelling, converting, or rescheduling your specific assessment engagement is financially better under its actual terms.
  • Whether a C3PAO or individual assessor has a conflict of interest in your specific engagement.
  • What the CMMC Reform Task Force will recommend, when the Department will act on it, or whether the proposed FAR rule will be finalized as written.

How this was produced: editorial research by The Defense Compliance Report Editorial Team, working from primary government and official program sources. It was not formally reviewed by an outside CMMC Subject Matter Advisor, and no outside reviewer is claimed.


Frequently asked questions

Should I stop CMMC compliance now that Phase II is suspended? No — not wholesale. Defer or reprice work whose only trigger was the suspended November 10, 2026 Phase II date, unless a live contract, subcontract, solicitation, or private term still requires it. Keep the safeguards, assessment records, incident response, SPRS entries, and affirmations your controlling instrument still requires.

Is CMMC Phase I still in effect? Yes. Phase I began November 10, 2025, and the published phase window runs through November 9, 2026. The Department's July 13 announcement says all Phase I self-assessment requirements remain firmly in place while Phase II and later milestones are suspended.

What CMMC costs can I actually cut this month? Assessment rush fees and scheduling premiums priced only against November 10, speculative Level 3 work not named in a live instrument, unused software seats or modules, and generic consulting that cannot be tied to a requirement, control, evidence need, or operating service. Verify private cancellation terms and every signed instrument first.

How much of my CMMC budget was the audit? The public sources do not answer that for your company. SBA published approximate totals of $593,800 for a small firm requiring third-party assessment and $388,600 for a small firm eligible for self-assessment. The $205,200 difference is 34.6% of the higher estimate, but SBA did not label it “the audit,” and it is not an automatic cut percentage.

Is CMMC cancelled? No. New Phase II Level 2 (C3PAO) and Level 3 designations and later milestones were suspended during the review. Phase I self-assessments remain, 32 CFR Part 170 was not repealed, DFARS 252.204-7012 remains in effect, the suspension documents did not revoke existing CMMC statuses, and C3PAO Level 2 certification assessments remain operational and available.

Can I stop paying my CMMC consultant? It depends what the consultant is doing. Work closing verified NIST SP 800-171 Revision 2 gaps, maintaining the SSP, correcting scope, or building supportable evidence can remain useful and required. Work priced only to hit the former November 10 gate can be repriced or deferred. Ask the provider to separate those categories on the next invoice.

Can I cancel my C3PAO assessment? The suspension does not decide your private cancellation rights — the engagement agreement does. Check the deposit, notice window, rescheduling rights, cancellation fee, and any live instrument requiring the status. If you convert the engagement into readiness work, get the conflict analysis in writing: the Cyber AB's Code of Professional Conduct prohibits a C3PAO and its assessment-team members from participating in a Level 2 certification assessment when they served as a consultant preparing that organization for any CMMC assessment within the prior three years. Read our CMMC mock assessment guide before converting the work.

Can I still choose a C3PAO assessment without a new Department designation? Yes. The Cyber AB said on July 15 that C3PAO Level 2 certification assessments remained operational and available. That availability does not make an assessment automatically required for award during the suspension. Decide based on a live customer need, the value of the status, private terms, readiness, cost, and conflict-of-interest rules — not fear that the ecosystem shut down.

Do I still need to submit an SPRS score? The answer depends on the clause package. Under codified DFARS 252.204-7019/-7020, a current NIST SP 800-171 DoD Assessment summary-level score may be required in SPRS. Under DFARS 252.204-7021, applicable CMMC self-assessment results, CMMC UIDs, statuses, and annual affirmations are recorded in or reflected through SPRS; Level 1 is not a 110-point numeric score. C3PAO and DIBCAC results move through the CMMC system of record into SPRS. Read the instrument before posting or deleting anything.

Is the annual affirmation still required? Yes, where the CMMC clause applies. 32 CFR 170.22 and DFARS 252.204-7021 require the Affirming Official to complete and maintain a current annual affirmation for each applicable CMMC assessment or status.

Is my existing CMMC Level 2 status still valid? The suspension documents did not revoke achieved statuses. A Final Level 2 status is current for up to three years only while the associated annual affirmation remains current and the organization continues to meet the applicable requirements and scope conditions.

Can my prime still require CMMC from me? Yes. The Department memoranda do not amend an executed subcontract. The federal flow-down rule establishes minimums where it applies, and a prime may also maintain private supplier requirements. Ask for the exact status, clause or term, information basis, and effective date in writing.

Are DIBCAC assessments still happening? The Department said select government-led assessments will continue during the interim. Treat a government assessment notice on its own terms. Do not ignore it because Phase II was suspended.

Does the suspension affect False Claims Act exposure? It does not suspend the False Claims Act or erase contractual cybersecurity representations. In June 2026, DOJ announced a $507,144 resolution after a government assessment scored LOGZONE's NIST SP 800-171 implementation at −170 on a scale from −203 to 110. DOJ stated that the claims were allegations only and there had been no determination of liability. The matter was not a CMMC enforcement case.

Should I switch to NIST SP 800-171 Revision 3 now? Not as a substitute for the CMMC Level 2 baseline. NIST has published Revision 3, but 32 CFR Part 170 still incorporates Revision 2 for CMMC Level 2. Run a version-aware roadmap if Revision 3 is strategically useful, but do not claim that Revision 3 alone satisfies the current CMMC Level 2 requirement.

Which NIST SP 800-172 version controls CMMC Level 3? CMMC Level 3 still uses 24 selected requirements from the February 2021 SP 800-172 in addition to the 110 Level 2 requirements. NIST's later SP 800-172 revision does not automatically change the version incorporated by 32 CFR Part 170.

What is the proposed FAR CUI rule and does it affect my budget? FAR Case 2026-001 is a proposed rule published June 23, 2026 at 91 FR 37550. It would add FAR 52.240-6 and 52.240-7 for federal contracts involving CUI, use NIST SP 800-171 Revision 3, permit agency-selected SP 800-172 requirements for critical programs or high-value assets, and use 72-hour CUI-incident reporting. It is not law as of August 14, 2026. It is a reason to avoid dismantling a useful CUI program, not a reason to claim a new requirement already exists.

My contract still says Level 2 (C3PAO). Am I released? Not automatically. Contracting officers were directed to remove suspended requirements through a modification before the next option exercise or during the next scheduled administrative modification. Ask for the issued modification in writing before changing performance.

What happens around September 11, 2026? The CMMC Reform Task Force report is due to the Department CIO within 60 days of July 13, which lands around September 11. That is a monitoring date. A report can arrive without changing a regulation, clause, contract, subcontract, or assessment engagement.

Will Phase II restart on a set date? No replacement date had been announced as of August 14, 2026. Watch for further Department guidance, class-deviation changes, DFARS or 32 CFR amendments, and the actual amendment or modification that reaches your instrument.

Does company size or employee count exempt us? No employee-count exemption appears in 32 CFR Part 170. Applicability turns on the acquisition, the instrument, the systems, the information handled, and the required status. Employee count may matter to cost, operational scope, or reporting fields; it does not create a CMMC exemption.

Can I get a CMMC waiver during the review? No. The July 13 implementation procedures state that no CMMC waivers will be granted during the review period.

Is it safe to cancel our CUI enclave project? Not without checking scope and operating reality. If the enclave was selected before anyone mapped the CUI path, pause and scope. If it already holds CUI and operates required controls, abrupt cancellation can create a real security and contract-performance gap. Compare the cost of maintaining, downsizing, or migrating before you unwind it.


Where this leaves you

The new audit gate was suspended. The homework wasn't. That is the whole story, and everything above is the detail that tells you which line on your invoice is which.

If you take one action from this page, take this one: open your controlling contract, solicitation, subcontract, or supplier term; find the exact cybersecurity clauses and CMMC status; and write down whether the promised amendment or modification has issued. Five minutes. It converts a national headline into a specific number you can defend to your CFO — and right now that is the only number worth spending against.

Cut the deadline premium. Keep the clause-driven and operational work. Verify anything that touches a signed document. And do not buy anything until you know your scope.

Need help deciding what type of CMMC provider fits the work you are keeping?

Tell us your level, scope, and timeline, and we'll map the job to source-checked CMMC provider options before anyone quotes the wrong project.

Find my CMMC path

Already know the category you need? Request CMMC provider quotes.

Do not submit CUI, drawings, controlled technical information, export-controlled data, contract files, credentials, network diagrams, vulnerability details, or sensitive contract terms.


Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when that relationship is disclosed. Compensation does not control our regulatory analysis, provider-category routing, or Cyber AB status checks. This page contains no named provider recommendation.

Not advice: This article is educational research. It is not legal, contractual, cybersecurity, procurement, or compliance advice. Requirements turn on the controlling instrument, the information handled, system scope, and the facts of performance. Confirm legal and contractual questions with a qualified federal-contracts attorney. Confirm technical scope and readiness with a qualified CMMC professional, and keep any future certification assessment relationship within the Cyber AB conflict-of-interest rules. The contract clause and your data handling set the requirement — not a checklist, and not this page.

Not affiliated: The Defense Compliance Report is not affiliated with, endorsed by, or sponsored by the Department of War, the Department of Defense, DCMA DIBCAC, NIST, the Cyber AB, or any U.S. government agency. We do not issue CMMC statuses, authorize C3PAOs, or guarantee assessment outcomes.

Primary sources cited on this page

Corrections: Found something wrong? Tell us here. · Methodology · Editorial standards