CMMC Reform Task Force Update

CMMC Reform Task Force Update

Bottom Line Up Front

On July 13, 2026, the Department of War (DoW) suspended the roll-out of CMMC Phase 2.  Phase 2 was originally set to take effect November 10, 2026.  CMMC Phase 2 would have added a variety of new requirements, including the introduction of third-party C3PAO certification as a condition of contract award.  

PLEASE NOTE: The Phase 1 self-assessments remain mandatory.  DoW did not suspend the entire CMMC program; DoW simply “paused” the effective date for CMMC Phase 2. 

Although Phase 2 is suspended, existing certifications retain their full value, and the fundamental FAR and DFARS cybersecurity obligations are unchanged and must still be met by defense contractors. Peak InfoSec continues conducting CMMC Level 2 Mock and Certification Assessments.

If you would like to schedule a Mock or Certification Assessment, or to schedule consulting assitance, please contact us!

Details

The announcement came without warning.  For many defense contractors preparing for the November 10, 2026 deadline, it also raised more questions than it answered. On July 13, 2026, DoW Chief Information Officer (CIO) Kirsten Davies signed a policy memorandum (publication case 26-P-1023) pausing Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program and launching a 60-day, top-to-bottom review.  That review will be conducted by the “CMMC Review Task Force”.

This is not a rollback of CMMC. It is not a reprieve from cybersecurity obligations. Understanding exactly what changed—and what did not—is essential for every contractor in the Defense Industrial Base.

The suspension of CMMC Phase 2 is a speed bump, not a stop sign. The underlying legal framework—32 C.F.R. Part 170, FAR and DFARS cybersecurity clauses, and SPRS obligations—remains in force. Organizations that maintain compliance momentum, accurate documentation, and a defensible SPRS score will be better positioned regardless of how the CMMC program is ultimately reformed.

Why Was phase 2 suspended?

According to DoW, the driving forces behind the suspension were:

  1. Rebuilding the Arsenal of Freedom;
  2. Elevating an empaowering the acquisition workforce to rapidly deliver capability;
  3. Maximizing acquisition flexibility through reduced regulations and process;
  4. Developing high performance systems through rigorous enterprise technical execution excellence; and
  5. Improving lifecyscle risk management.

What Is the CMMC Phase 2 Suspension?

The suspension of CMMC Phase 2 specifically pauses the requirement for defense contractors who handle Controlled Unclassified Information (CUI) to obtain a CMMC Level 2 certification from an accredited C3PAO as a condition of contract award.  This requirement had been scheduled to take effect on November 10, 2026. Along with Phase 2, all pending and future CMMC implementation milestones—including Phases 3 and 4—are suspended until further notice.

The CMMC Reform Task Force, reporting to the DoW CIO, has been charged with recommending revisions to the CMMC program within 60 days.  The CMMC Reform Task Force issued a Request for Information to solicit from stakeholders recommended changes to the CMMC program.  Industry stakeholders are invited to submit responses through August 14, 2026.  As discussed in more detail, below, Peak InfoSec has submitted our recommendations to the CMMC Reform Task Force, and we encourage others to submit their own recommendations (or to copy ours).

What Does the CMMC Phase 2 Suspension Not Change?

The suspension is a policy memo—not a regulatory amendment. Several critical requirements remain fully in effect:

  • Phase 1 self-assessment and self-attestation went into effect in November 2025 and remain unchanged. DFARS 204.7503(b) still requires contracting officers to verify CMMC status in SPRS prior to contract award.
  • DFARS 252.204-7012 remains fully operative, including the 72-hour incident reporting requirement to DIBNet and mandatory flow down to subcontractors.
  • NIST SP 800-171 compliance continues to be required for all contractors handling Controlled Unclassified Information (CUI).
  • Annual SPRS affirmations must still be submitted by a named senior Affirming Official and are subject to enforcement under the Department of Justice’s Civil Cyber-Fraud Initiative and other programs.
  • Voluntary C3PAO assessments remain available and valid. The Cyber AB confirmed on July 13, 2026, that C3PAOs remain authorized to conduct CMMC Level 2 Certification Assessments, issue CMMC Level 2 certifications, and record the certifications in CMMC eMASS for publication to SPRS.

 

One critical nuance: the suspension of CMMC Phase 2 applies only to DoW personnel; not your contract with your prime contractor may include additional CMMC-related terms that are still in effect. Several primes have already indicated they will continue requiring C3PAO certifications for their supply chains, regardless of the DoW-level suspension. It is imperative that you confirm, in writing from your prime contractor, any changes to your flow-down requirements before altering any of your CMMC-related plans.

It is worth noting a few additional, important points:

  1. your NIST SP 800-171 implementation costs have already been incurred;
  2. for many businesses, the CMMC Level 2 Certification Assessment costs are a fraction of the NIST SP 800-171 implementation costs;
  3. obtaining third-party certification now carries real strategic advantage when your competitors pause or disengage from the process; and,
  4. we expect significant demand for CMMC Level 2 Certification Assessments to begin in the new year, and encourage you to schedule your assessments as soon as practical to avoid the rush.

 

Contact us to schedule your assessment!

OUR Response to the CMMC Phase 2 suspension

We recognize the disruption this announcement created, and we are responding accordingly.  We also recognize that, for many contractors, third-party certifications hold significant value and they therefore want CMMC Level 2 (C3PAO) assessments and certifications of their information security programs.  Peak InfoSec will continue to conduct CMMC Level 2 (C3PAO) Certification Assessments and issue CMMC Level 2 certifications during the suspension for clients who want to be CMMC Level 2 certified.

We remain available to answer any CMMC status or compliance questions during this period, and are also offering consulting services to select clients so they are better prepared for the next iteration of the CMMC program.

With regard to the DoW CIO’s Request for Information (RFI), Peak InfoSec submitted our response on 3 August 2026.  You can read our response here.

As you will see, we provided suggested recommendations to reduce the burdens of implementing NIST SP 800-171 and getting certified cause.  We also came out in favor of delaying the start of CMMC Phase 2.  In our experience, the vast majority of the Defense Industrial Base would not be ready to have FY2027 contracts mandate CMMC certification by a C3PAO.

What Should You Do If You Choose to Delay Your CMMC Level 2 (C3PAO) Certification Assessment?

If your organization decides to defer its CMMC Level 2 C3PAO certification, do not treat the suspension as permission to stand down from cybersecurity work. Take the following steps:

  1. Confirm customer requirements in writing. Ask your customers whether a CMMC self-assessment meets their subcontract terms. Do not assume relief flows automatically.  Many primes are still requiring third-party certifications of compliance to reduce their own risk.
  2. Continue maintaining and improving your CUI environment. DFARS 252.204-7012 remains fully in effect. Remediate identified gaps on a defensible timeline rather than shelving the findings. Any vulnerabilities in your CUI enclave remain your liability.
  3. Keep your System Security Plan (SSP) current. Continue documenting your system’s CUI compliance. An outdated SSP creates evidentiary gaps that a DIBCAC confirmation assessment or a DOJ investigation will exploit.
  4. Review supporting documentation at least annually. Plans of Action and Milestones (POA&Ms), network diagrams, and policy documents should reflect your current environment.
  5. Conduct your annual self-assessment and submit your SPRS affirmation. This is a legal certification. Ensure every score you submit is defensible with documentation and evidence. False certifications are the explicit target of the Civil Cyber-Fraud Initiative, which carries civil and criminal damages.

If your organization has already initiated a C3PAO assessment, those records document your compliance posture and survive the suspension.

What is the CMMC Reform Task schedule?

Three developments warrant close attention:

  • August 14, 2026: The RFI comment period closes. If CMMC compliance costs affect your organization, submitting a response is one of the few direct channels available to influence the Task Force’s recommendations. Small and midsize contractor voices are currently underrepresented.
  • Mid-September 2026: The CMMC Reform Task Force is expected to deliver its recommendations. Watch for any class deviation, DFARS rule change, or amendment to 32 C.F.R. Part 170—these are the mechanisms that would constitute a genuine regulatory change. The current suspension is a memo, and a memo can be reversed as quickly as it was issued.
  • Mid-October 2026:  The earliest we expect to hear anything formal regarding final determinations.  There is a substantial chance we may not hear anything until late 2026 or early 2027.
  • Ongoing: The government-wide CUI rule, folded into the June 23, 2026, Revolutionary FAR Overhaul rulemaking, is unaffected by the suspension of CMMC Phase 2. Contractors operating across both defense and civilian contracts receive no reprieve from that parallel regulatory track.