CMMC 2.0: What Changed on July 13, 2026
The Audit Requirement Is Suspended. The Security Obligation Is Not.
BLUF: Tens of thousands of defense contractors have spent the last two years preparing for mandatory third-party audits under CMMC 2.0. On July 13, 2026, the Department of War released a memo pausing the requirement for a CMMC Level 2 third-party audit, in order to keep compliance expenses from straining smaller contractors' budgets. Trade groups such as the NDIA welcomed the pause. C3PAO audits are on hold, but the underlying NIST requirements remain in place, and this suspension lessens audit friction without removing the responsibility of companies that handle CUI data.
Introduction
The Department of War has suspended CMMC Phase 2. The mandatory requirement for defense contractors to secure Level 2 third-party certification through a C3PAO is now suspended until further notice.
Financial and operational hurdles have hit small and mid-sized DoW contractors hard enough that many said they would leave the industry rather than absorb the compliance overhead into their budgets. This suspension provides temporary relief to many small and mid-size defense contractors while the DoW re-evaluates its approach and enforcement.
Current CMMC Enforcement Status
Figure 1. CMMC enforcement status as of July 2026: Level 1 and Level 2 self-assessment remain active and mandatory, while C3PAO third-party audits and DIBCAC government audits are suspended.
Direct Impact on Active Solicitations and Contracts
Pivoting away from third-party audits temporarily changes how contractors prove compliance. It does not drop the security requirements themselves. Contracting officers must remove Phase 2 third-party assessment requirements from open solicitations. Existing contracts with active C3PAO clauses require formal modification before program offices can exercise option periods. Pending awards now rely on CMMC Level 1 and Level 2 self-assessment. The official CMMC waiver workflow is frozen while leadership builds a revised framework.
Baseline Compliance Requirements Still Standing
Pausing third-party audits removes external certification friction. It gives zero relief from the legal duty to protect sensitive defense data. Contractors still carry full responsibility for securing their networks.
Figure 2. What paused with the July 13, 2026 suspension memo versus what remains mandatory and enforced: NIST SP 800-171 Rev 2, DFARS 252.204-7012, SPRS score postings, and False Claims Act liability all continue unchanged.
What Comes Next? The 60-Day Strategic Review
A newly formed CMMC Reform Task Force has allocated 60 days to review the CMMC 2.0 program. The primary goal is to align cybersecurity enforcement with acquisition speed and eliminate unnecessary barriers for nontraditional, small businesses and new entrants without an existing FedRAMP or ISO footprint. Alongside the pause, the Pentagon has issued a Request for Information. It is most interested in cost drivers and whether commercial alternatives could replace redundant controls. Per the Office of Advocacy, the public comment period closes August 14, 2026.
Figure 3. Key dates in the CMMC Reform Task Force's 60-day strategic review, from the July 13, 2026 suspension memo through the August 14, 2026 public comment deadline and a revised framework still to be issued.
Recommended Actions for Defense Contractors
Defense contractors should focus on the following:
Maintain compliance. Contractors should maintain cybersecurity budgets and remediation timelines through the review period. The core baseline has not changed: NIST SP 800-171 Rev 2, DFARS 252.204-7012, and SPRS score requirements remain mandatory. Continuous technical validation and internal hygiene are still required.
Manage security baseline integrity. The shift focuses responsibility on self-assessment integrity. Without third-party auditing, inaccurate self-attestations go directly into government database entries, creating extra exposure under the Department of Justice's Civil Cyber-Fraud Initiative and the False Claims Act. Re-evaluate current SPRS entries, System Security Plans, and active Plans of Action and Milestones for accuracy.
Review active solicitations and contracts. Verify that pending solicitations and existing contracts have removed C3PAO requirements per official Pentagon directives before option periods are exercised.
Engage with public feedback. Submit hard cost data and specific examples of redundant controls to the Task Force during its 60-day review.
Conclusion: Modernization Beyond the Audit Pause
The DoW's decision to freeze Phase 2 offers breathing room for small and mid-sized defense contractors, but it is a pause on administrative friction, not an exemption from cybersecurity duty. The mandates of NIST SP 800-171 Rev 2 and accurate SPRS score posting remain active and enforceable.
Without a current need for third-party assessments to validate security controls, compliance integrity rests entirely with the DoW contractor, and inaccurate SPRS postings remain enforceable under the Department of Justice's Civil Cyber-Fraud Initiative and False Claims Act liability.
Contractors should treat this review window as an opportunity to sharpen their baseline security and internal records, and to actively submit feedback to the CMMC Reform Task Force.
Getting Started with ACC3 International
ACC3 International helps defense contractors track CMMC compliance obligations through periods of regulatory change. Contact ACC3 International to discuss how the July 13, 2026 suspension affects your active solicitations, contracts, and SPRS posture.
References
Office of Advocacy. (2026, July 20). DoW requests information for CMMC reform task force. U.S. Small Business Administration. https://advocacy.sba.gov/2026/07/20/dow-requests-information-for-cmmc-reform-
Office of Industrial Base Growth. (2026, July 13). Forging the arsenal of freedom. U.S. Department of Defense. https://business.defense.gov/engage/news/article/4542563/forging-the-arsenal-of-freedom-
Office of the Chief Information Officer. (2026). Implementing the suspension of the advancement to CMMC Phase II requirements [Memorandum]. U.S. Department of Defense. https://dodcio.defense.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf
Ross, R., & Pillitteri, V. (2024). Protecting controlled unclassified information in nonfederal systems and organizations (NIST Special Publication 800-171, Revision 3). National Institute of Standards and Technology. https://doi.org/10.6028/nist.sp.800-171r3
U.S. Department of Justice. (2021, October 6). Deputy Attorney General Lisa O. Monaco announces new Civil Cyber-Fraud Initiative [Press release]. https://www.justice.gov/archives/opa/pr/deputy-attorney-general-lisa-o-monaco-announces-new-civil-cyber-fraud-initiative
U.S. Small Business Administration. (2026, July 13). SBA commends U.S. Department of War's suspension of CMMC Phase II for small defense contractors [Press release]. https://www.sba.gov/article/2026/07/13/sba-commends-us-department-wars-suspension-cmmc-phase-ii-small-defense-contractors