The CMMC Suspension Is a Memo, Not a Rule

On July 13, 2026, the Department of War (DoW, formerly DoD) suspended CMMC Phase 2 with two memoranda issued under case number 26-P-1023, one from the CIO and one from the undersecretary for acquisition and sustainment. There was no Federal Register notice. 32 C.F.R. Part 170 is unchanged. No DFARS class deviation has been published. The CMMC Program rule and DFARS 252.204-7021 are in force exactly as they were written.

That is the whole story, and it is a strange one. When a regulator wants to change what contractors must do, it runs a rulemaking. It publishes a proposal, takes comment, and amends the Code of Federal Regulations. The process is slow and public because it is meant to be hard to reverse. A memorandum is neither. It changes how the department uses its discretion, and it can be changed back the same way. “A memo can be reversed just as fast,” as Alex Major of McCarter & English put it.

What moved on July 13 was the department’s discretion to designate higher CMMC levels. Program managers may now designate only Level 1 (Self) or Level 2 (Self). They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). Solicitations that already name a higher level have to be amended “as soon as practicable,” and existing contracts have to be modified to strip the C3PAO or DIBCAC requirement before the next option exercise or administrative modification. No waivers during the review.

None of that touches the obligations underneath. NIST SP 800-171 Rev 2 is the interim baseline. DFARS 252.204-7012, with its 72-hour incident reporting, is still in effect. DFARS 252.204-7019 still conditions award on a current SPRS score, and 252.204-7020 still obligates access for government assessments. Phase 1, the self-assessment phase, is a codified condition of award under DFARS 204.7503(b), and it never paused. I wrote about what stays live and where the False Claims Act risk now sits in the earlier post on this suspension, so I will not repeat it here.

CMMC has now been paused twice in about five years. It was paused in 2021 for a review that produced the streamlined three-level CMMC 2.0. In March 2025 the administration’s deregulatory agenda cited the CMMC rule as a “costly Biden Administration regulation” with a $42.26 billion impact. Six months later the rule was finalized without significant changes, which appeared to settle that CMMC was here to stay. Then it was suspended again, months before Phase 2 was due to kick in. Wiley Rein’s alert reads this most clearly: the pause “reflects a concrete step away from the status quo” and “previews at least the possibility of changes to the existing cybersecurity requirements beyond CMMC.”

For a contractor planning a multi-year enclave build, that history is the point. A certification path that has changed course twice is not a stable planning assumption. You cannot treat the target as fixed and plan against it, because the target can move in either direction, fast. That is the difference between “compliance limbo” and a predictability problem. One is a fog that clears. The other is a target that keeps moving.

Plan against the codified text

The practical consequence of memo-not-a-rule is that contracts, not headlines, still control. Major’s client alert makes the case in three lines worth keeping together. Until a class deviation, a DFARS rule, or an amendment to 32 C.F.R. Section 170.3(e) issues, plan against the text as written. Some program offices require C3PAO assessments ahead of the November deadline, so a higher designation can still appear where you would not expect it. And until a modification issues, the clause in your contract is your contract: DFARS 204.7503(c) still bars option exercise unless your required CMMC status is current in SPRS.

The fix for all three is the same and it is boring. Request the modification in writing. Do not treat the memo as self-executing relief.

What a memo means for the build

Three of the things contractors should do with this pause follow directly from its form, and none of them is obvious from the headline.

First, do not dismantle anything. A reformed requirement could return within months, and government-led assessments continue in the interim. Unwinding and rebuilding a CUI enclave costs more than maintaining one. Wiley’s line is blunter: “it is too soon to call these efforts off. CMMC 2.0 is not off the table yet.”

Second, a completed certification still has value, and it may even be the safest place to stand. The Cyber AB’s May 2026 town hall counted 1,391 Final Level 2 certificates issued as of May, and nothing invalidates them. DFARS 252.204-7021(d)(1)(i) requires the stated level “or higher,” so a Level 2 (C3PAO) status satisfies any lesser designation during the suspension. It also remains a differentiator with primes and in M&A diligence.

Third, the paper trail you already created survives the pause and it is discoverable. Starting a C3PAO assessment triggered government notification, and gap assessments documented deficiencies in writing. Those records did not evaporate on July 13. Remediate on a defensible timeline rather than shelving the report. This is the uncomfortable one, because a gap assessment that sat in a drawer looked harmless when certification was coming. It looks different now that the verification mechanism is gone and the review is open.

Two things the memo does not touch

There are two separate tracks still moving, and contractors with a foot in either one get no reprieve from a CMMC Phase 2 pause.

The first is the governmentwide CUI rule. In June 2026 the FAR Council proposed rules that would extend CUI safeguarding and incident reporting requirements to all CUI handled under all federal contracts, folded into a broader FAR overhaul. Wiley’s point is that if that rule goes through, a reduction in CMMC scope “may not offer much relief,” because the requirements just arrive from a different direction. Major is more direct: mixed defense and civilian contractors get nothing from this pause.

The second is the baseline itself. The department tied interim enforcement to NIST SP 800-171 Revision 2, not the Revision 3 published in 2024. Major reads that as breathing room on a Revision 3 transition. I read it the same way, with one caution. Breathing room on a transition is not the same as a transition that will not happen. Budget for Rev 3 while you keep building to Rev 2.

The thing to watch

The CMMC Reform Task Force reports to the CIO with recommendations due roughly mid-September. As of this writing the report has not dropped, so anything said about its contents is a forecast, not a fact. The reason to watch it closely is the same reason the memo matters. If the task force produces a real rulemaking, the program gets a stable legal form again and the predictability problem shrinks. If it produces another memorandum, the target just moved again.

The substantive obligation was never the moving part. NIST 800-171, DFARS 7012, the SPRS scores, and the annual affirmations did not pause. What paused, and what can now be reversed as fast as it was paused, is the certification path on top of them. That split, between the obligation that was always live and the verification that is now optional, is what contractors should price into their planning. The 800-171 baseline never moved, so plan against it. The certification path moved twice, so do not treat it as fixed.

Sources

  1. Wiley Rein LLP — DOD Pauses CMMC 2.0 Implementation: A Big Deal with Little Immediate Impact (July 17, 2026)
  2. McCarter & English, Alex Major — Government Contracts Law: DoD Suspends CMMC Phase 2 (July 2026)
  3. Federal News Network — Pentagon suspends CMMC phase two requirements, launches review (July 13, 2026)
  4. Department of War — DoW Suspends CMMC Phase II Requirements (press release)
  5. DoD Memo 26-P-1023 — Implementing Suspension of CMMC Phase II (procedures)
  6. DoD CIO Memo 26-P-1023 — CMMC Reform Memo (Davies)