CMMC Phase 2 Suspension: The Compliance Pause That Raised Contractor Risk
On July 13, 2026 the Department of War announced it was suspending CMMC Phase 2 “immediately,” months before third-party certification was due to become mandatory for Level 2 contractors on November 10. Read quickly, it sounds like relief: no C3PAO assessment, no mandatory certification, and a 60-day review by a new CMMC Reform Task Force.
What the pause actually did was remove the independent verification. It did not remove the obligations, and it did not remove the enforcement. Those are still very much live.
That leaves self-attestation as the main compliance touchpoint for most contractors, at the same moment DOJ’s Civil Cyber-Fraud Initiative is scaling up. A “reprieve” that removes third-party verification doesn’t lower the legal risk. It concentrates it in the one place a contractor can get things wrong: the number they type into SPRS. (That is our read, assembled from the sources below; no single one of them makes this argument on its own.)
What actually changed
The suspension comes with a 60-day review by the CMMC Reform Task Force. The Department’s stated reason is that CMMC imposed “prohibitive compliance costs and bureaucratic burdens” and, per Small Business Administration data, was pushing companies out of the defense industrial base. CIO Kirsten A. Davies announced it, citing Under Secretary Michael Duffey and Secretary Pete Hegseth’s “Acquisition Transformation System” directives as the driver.
The mechanics are worth being precise about. Phase 2, scheduled for November 10, would have made third-party C3PAO certification mandatory for applicable Level 2 contracts. One thing to confirm rather than assume: DLA Piper’s alert folds the government-led DIBCAC Level 3 assessments into Phase 2, while DefenseScoop’s reporting puts those in a later phase (Phase 3, targeted for November 2027), with Phase 4 as full implementation. It doesn’t change the headline, since all future phases were suspended, but contractors should check the phase mapping against their own contract.
What stayed live is the part most readers skip. During the interim the Department keeps enforcing NIST SP 800-171 Rev 2 through self-assessments and “select government-led assessments.” Still in force:
- FAR 52.204-21 (basic safeguarding of covered contractor information)
- DFARS 252.204-7012, including cyber incident reporting
- The full set of 110 NIST SP 800-171 Rev 2 controls
- SPRS self-assessment reporting
- The annual affirmation (32 C.F.R. § 170.22)
The Task Force will take in industry feedback from a public RFI (responses were due August 14) and deliver a report on “realistic, scalable security measures” within 60 days. The RFI asked about cost drivers, administrative burden, which of the 800-171 controls actually reduce risk, and whether commercial security tools and managed services should count in place of separate assessments. Davies did not rule out cancelling the program entirely.
Her arithmetic for the pause: future phases could cost small and mid-size businesses more than $7 billion a year, against more than 100,000 DIB companies needing assessments and roughly 100 approved assessors. A March 2026 GAO report (GAO-26-107955) found the standards could be too difficult and costly for some small businesses.
Scores up, confidence down
The most useful data point isn’t from the government. It’s a Merrill Research survey commissioned by CyberSheath, a CMMC managed-services vendor, reported by Washington Technology. Read it as directional, not official, but the shape is hard to miss:
- Average SPRS scores hit a five-year high of +51, up from +33 in 2025. (2025 was the first year with a positive average; a perfect NIST SP 800-171 score is 110.)
- Confidence in score accuracy fell hard: 65% said they were “extremely or very confident” their score was accurate, down from 89% the year before.
- 1% said they were “completely prepared” for CMMC certification, unchanged from 2025.
So contractors are reporting better scores while also saying they’re less sure those scores are right, and almost nobody claims to be ready for certification. High self-reported compliance plus low confidence plus near-zero readiness is the combination that gets an enforcement agency’s attention.
CyberSheath CEO Emil Sayegh’s argument, in the same piece: reform should keep “objective, verifiable assurance that protections are actually in place and working,” because verification and accountability are what keep self-reported compliance honest.
Where the risk moves: the False Claims Act
The False Claims Act is where the suspension’s risk actually lands. This section leans on DLA Piper’s alert and DOJ’s FY2025 False Claims Act fact sheet.
CMMC and DFARS certifications, meaning the annual affirmations and the SPRS self-assessment scores, are legal certifications. A false one, made knowingly or with reckless disregard, can trigger liability under 31 U.S.C. § 3729: treble damages, per-claim civil penalties, and qui tam relator suits (relators collect 15–25%). The affirmation obligates a senior “affirming official” to attest that the organization “has implemented and will maintain” all applicable controls, at award, annually, and after POA&M closeout. DFARS 252.204-7020(d) separately requires SPRS self-reporting of NIST SP 800-171 compliance.
DLA Piper’s warning is direct: with independent verification paused, “the accuracy of contractor self-assessments and affirmations submitted to SPRS may receive increased attention during the suspension period.”
DOJ’s own numbers back that up. The FY2025 fact sheet reports “over $52 million in nine cybersecurity fraud settlements,” with civil cybersecurity fraud settlements more than tripling in each of the past two years. Two cases map directly onto self-attestation risk:
- MORSECORP Inc. ($4.6 million) submitted “an inaccurate score” for its required security controls and, after a third-party consultant flagged it, “did not promptly update it or notify the government.”
- Health Net/Centene ($11.2 million) “falsely certified compliance with cybersecurity requirements” in a contract.
MORSECORP is the one to remember. An inaccurate SPRS score that gets flagged and then left uncorrected became the basis for a settlement. With third-party verification paused, that SPRS score is the number standing between a contractor and an FCA claim.
The deadlines didn’t pause either
For contractors treating the pause as breathing room, two executive orders dated June 22, 2026 say otherwise.
EO 14412 requires agencies to move high-value assets and high-impact systems to post-quantum cryptography for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. CISA has 270 days to publish guidance on a “cryptographic bill of materials” for automated assessment, and the FAR Council must propose a rule requiring covered contractors to comply by end of 2030 with NIST FIPS including PQC-compliant algorithms. EO 14413 stands up the QC-ADDS quantum computing effort and directs whole-of-government acceleration across quantum computing, sensing, and networking.
Qrypt CTO Denis Mandich, writing in Forbes Councils (opinion, not neutral reporting), put it plainly: the pause “didn’t eliminate the obligation to protect federal data.” What changed is “how compliance may be measured, not whether cybersecurity matters in the quantum era.” The pause “gave no agency permission to wait” on 2030.
What people in the field are saying
Two opinion pieces frame the debate well:
- Lonny Anderson (former NSA CTO, president of BlueVoyant Government Solutions), in DefenseScoop: “CMMC exists because self-assessment, absent verification, is an honor system with a federal contract attached to it.” He argues for an enterprise model that combines formalized independent assessment, continuous external monitoring, and shared remediation support for small suppliers. He also notes the Senate FY2027 NDAA would authorize $50 million in CMMC assessment grants, while cautioning that a one-time subsidy isn’t sustained monitoring.
- Denis Mandich (Qrypt): the pause “transfers the high burden from paperwork to engineering,” which is harder and more resource-intensive.
Both are advocacy, but they point the same direction the reform itself seems to be heading: continuous, verifiable assurance rather than point-in-time attestation. Sayegh’s “objective, verifiable assurance,” Anderson’s “continuous external monitoring,” and EO 14412’s “cryptographic bill of materials” for automated assessment are three ways of saying the same thing.
What to do now
The obligations didn’t pause, so the response can’t either.
- Treat the SPRS score and the affirmation as legal certifications, not paperwork. A senior official is personally attesting, under penalty of the False Claims Act, that controls are implemented and maintained. If a consultant flags a score, correct it. The MORSECORP settlement is what happens when you don’t.
- Confirm your contract’s actual phase mapping. Under existing contracts that already name a Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, whether that requirement is waived is an open question DLA Piper flags but doesn’t settle. Ask the contracting officer.
- Don’t confuse a certification pause with a security pause. DFARS 252.204-7012 incident reporting and the 110 NIST SP 800-171 Rev 2 controls are still live, and the 2030/2031 post-quantum deadlines were untouched by the suspension.
- Read the reform signal. The RFI explicitly asked whether commercial tools and managed services could substitute for separate assessments. If that direction survives, point-in-time certification gives way to continuous monitoring, which rewards organizations that can demonstrate controls rather than assert them.
Bottom line
The CMMC Phase 2 suspension looks like relief and works like a trap for the unprepared. Independent verification is gone, self-attestation is what’s left, and self-attestation is exactly where DOJ’s Civil Cyber-Fraud Initiative is pressing hardest. Contractors who keep their SPRS scores honest, their affirmations defensible, and their incident reporting current will look back on this “pause” as a non-event. Everyone else is running an honor system with a federal contract attached to it.
Sources
- Department of War — “Forging the Arsenal of Freedom”: DoW Suspends CMMC Phase II Requirements (primary)
- DLA Piper — Department of War Suspends CMMC Phase 2 Assessment Requirements: Top Points
- Washington Technology — CMMC’s paradox: scores up, confidence down
- Forbes Councils — Beyond bureaucracy: the CMMC pause won’t change the quantum security deadline
- DefenseScoop — Pausing CMMC cannot mean pausing accountability
- V2 Systems — CMMC update for government contractors, August 2026
- DOJ — False Claims Act Settlements and Judgments, FY2025
- White House — EO 14412: Securing the Nation Against Advanced Cryptographic Attacks
- White House — EO 14413: Ushering in the Next Frontier of Quantum Innovation
- DefenseScoop — DoD halts CMMC Phase 2 cybersecurity requirements (July 13)
- Washington Technology — DoD suspends CMMC Phase 2, launches 60-day reform review