On July 13, 2026, the Small Business Administration announced that the Department of War suspended CMMC Phase II requirements, the third-party and self-assessment certification tier originally scheduled to take effect November 10, 2026. The suspension followed sustained pushback from the small-business contractor community over compliance costs SBA estimated at roughly $593,800 per third-party certification, against a pool of only about 100 approved assessors serving more than 120,000 affected businesses.
A CMMC Reform Task Force now has 60 days to deliver recommendations, with Phase I self-assessment and existing DFARS 252.204-7012 safeguarding obligations remaining fully enforceable throughout. Contractors should not read this suspension as reduced compliance pressure: it coincides with proposed FAR Part 40 supply-chain security rulemaking and a documented rise in False Claims Act cybersecurity enforcement activity, signaling a shift in enforcement mechanism rather than a retreat from enforcement itself.
The actionable takeaway for Defense Industrial Base contractors is to redirect near-term compliance resources toward verifying the accuracy of existing Phase I self-assessments and SPRS scores now, since false attestation exposure does not depend on Phase II being in effect.
Key Finding: The Department of War's suspension of CMMC Phase II is not a retreat from cybersecurity enforcement in the Defense Industrial Base but a recalibration, arriving alongside proposed FAR Part 40 supply-chain rulemaking and rising False Claims Act cybersecurity enforcement activity—meaning contractors that treat the suspension as reduced compliance risk are likely to be caught unprepared by the mechanisms replacing it.
On July 13, 2026, the Small Business Administration announced that the Department of War had suspended CMMC Phase II requirements, the certification tier that would have required Defense Industrial Base contractors to undergo either third-party assessment or self-assessment depending on the sensitivity of information they handle. Phase II had originally been scheduled to take effect November 10, 2026. The suspension followed sustained pushback from the small-business contractor community centered on compliance cost: SBA estimated the cost of third-party certification at approximately $593,800 per firm, and self-assessment-eligible compliance at approximately $388,600, figures assessed against a certification infrastructure that SBA noted included only around 100 approved third-party assessment organizations available to serve more than 120,000 affected small businesses across the DIB.
In response, the Department of War established a CMMC Reform Task Force, tasked with delivering recommendations within 60 days of the suspension announcement, placing expected completion around mid-September 2026. The Task Force is soliciting industry feedback through a public Request for Information, with responses due by August 14, 2026. During this review period, Phase II implementation remains on hold in its entirety. Critically, this suspension does not extend to Phase I self-assessment requirements or to the safeguarding obligations already established under DFARS clause 252.204-7012, both of which remain fully in force and enforceable for covered contractors throughout the review period.
The suspension has not occurred in isolation. It coincides with a wave of newly proposed federal rulemaking activity, including a proposed FAR Part 40 rule that would consolidate supply-chain and information-security requirements across federal procurement more broadly, alongside additional proposed rulemaking addressing Controlled Unclassified Information handling, Foreign Ownership, Control, or Influence (FOCI) considerations, and quantum-readiness requirements—developments covered in detail by Government Contracts Navigator and Inside Government Contracts in analysis published July 21–22, 2026. Separately, and running on a parallel track, Eye on Enforcement has documented a connection between cybersecurity compliance failures and the current administration's broader False Claims Act fraud-enforcement priorities, under which inaccurate cybersecurity attestations submitted to the federal government can independently trigger fraud liability regardless of the certification framework nominally in effect at the time. Federal News Network's coverage of contractor reaction to the suspension reflects a mixture of relief over near-term cost avoidance and uncertainty about what compliance framework will ultimately take Phase II's place.
Contractors should not treat the Phase II suspension as license to deprioritize cybersecurity documentation work. Existing DFARS 7012 safeguarding requirements and Phase I self-assessment and Supplier Performance Risk System (SPRS) scoring obligations remain fully enforceable, and inaccurate self-attestations submitted under these existing frameworks represent an increasingly live and independent source of False Claims Act exposure, separate from whatever happens to Phase II going forward.
The suspension changes near-term certification timelines in ways relevant to business development and proposal planning, removing an imminent Phase II deadline that many firms had been actively preparing for. However, the parallel FAR Part 40 rulemaking signals a longer-term consolidation of supply-chain security requirements across federal procurement more broadly, which will likely reintroduce comparable compliance burden in a different regulatory form once finalized, rather than representing a lasting reduction in overall requirements.
The convergence of a compliance-relief action, the CMMC Phase II suspension, occurring at the same time as an enforcement-intensification trend under False Claims Act priorities illustrates a broader federal pattern worth tracking: a shift away from prescriptive, certification-based compliance regimes and toward outcome-based liability exposure, where the government relies on after-the-fact fraud enforcement against inaccurate attestations rather than upfront certification gatekeeping. This pattern has implications extending beyond CMMC specifically, relevant to how compliance, legal, and security functions across the DIB should be structured to work together going forward.
Immediate Term: Defense Industrial Base contractors—particularly small and mid-sized firms that had already begun Phase II preparation activities—should redirect compliance resources toward auditing the accuracy of their existing Phase I self-assessments and current SPRS submissions. This redirection is warranted specifically because False Claims Act liability attaches to inaccurate attestations under currently enforceable frameworks regardless of whether Phase II is in effect, meaning the suspension does not reduce this specific category of exposure even though it removes a near-term certification deadline.
Short Term: Contractors and their compliance functions should closely monitor two parallel developments: the CMMC Reform Task Force's 60-day review output, expected around mid-September 2026, which will likely shape what framework ultimately replaces or modifies Phase II, and the proposed FAR Part 40 rulemaking docket, which may establish supply-chain security requirements that apply more broadly across federal procurement independent of the CMMC program specifically. Firms that had allocated budget toward Phase II certification preparation should consider whether that budget is better positioned toward attestation-accuracy auditing in the interim, given the more immediate enforcement exposure that work addresses.
Long Term: This recalibration suggests that DIB contractors should plan compliance programs around a continuous attestation-accuracy discipline rather than around discrete, one-time certification milestones. As enforcement mechanisms shift from prescriptive certification gatekeeping toward outcome-based fraud liability, the operational skill set required shifts correspondingly—from managing a fixed certification timeline toward maintaining ongoing documentation accuracy and cross-functional coordination between security, legal, and compliance teams capable of responding to enforcement actions that may arise independent of any specific certification deadline.
Actions are organized by organizational security maturity, centered on redirecting compliance effort toward attestation accuracy rather than the suspended certification timeline.
Institutional Note: Institutional stakeholders across all maturity levels should treat the current suspension period as a planning window rather than a compliance pause, given that the underlying enforcement exposure through existing frameworks has not been suspended alongside Phase II.
The suspension of CMMC Phase II illustrates a pattern increasingly familiar across federal cybersecurity policy: relief from one compliance mechanism rarely means relief from the underlying risk it was designed to address. As enforcement pressure shifts from upfront certification toward after-the-fact attestation accountability, Defense Industrial Base contractors that read this moment as a pause rather than a redirection are the ones most likely to be caught unprepared when the next mechanism takes shape.
Institutional resilience here is less about tracking a single certification deadline and more about building the continuous attestation discipline that outlasts whichever specific framework is currently in force.