Is CMMC Dead?

Is CMMC Dead?

This article reflects publicly available guidance as of July 2026 and is intended for informational purposes, not legal advice. Contract-specific questions should be discussed with qualified legal counsel.

The headline in the ecosystem the past 2 weeks has been that CMMC is “suspended”. If you are like me, your group chat and voicemail lit up, and you probably have somebody in your shop already saying, “See? I told you we didn’t need to bother with any of this.”

Take a breath.

CMMC isn’t dead. The third party assessment is on pause. Your cybersecurity obligations are exactly where they were last week.

That distinction is the whole ballgame, so let’s slow down and walk through it.


What actually happened

On July 13, 2026, the Department of War hit pause on CMMC Phase 2, the piece that was scheduled to switch on November 10, 2026. A reform task force is now reviewing the program, with recommendations expected in about 60 days, and there’s an open comment window for industry feedback. Go leave feedback. I’ve read some really good ideas for improvements.

The reason for the pause? The program was piling “substantial costs and administrative burdens” onto the defense industrial base, especially the small manufacturers who’ve been living in panic mode over deadlines they didn’t have the staff or budget to meet.

If you’ve ever gotten a sky high consultant quote and wondered how a 12-person shop was supposed to afford it, the Department’s explanation likely sounded familiar.

The Good News: If you’ve spent the last year improving your environment, documenting procedures, and collecting evidence, none of that work was wasted. Those improvements still satisfy your contractual obligations today and will almost certainly be needed under whatever replaces the current certification timeline.


Here’s what got suspended (and what didn’t)

Suspended: the third-party assessment. (Level 2 C3PAO assessments. Level 3 DIBCAC assessments.)

Not suspended…not even a little:

  • DFARS 252.204-7012 still requires you to implement all 110 controls of NIST SP 800-171 if you handle CUI.
  • FAR 52.204-21 still requires basic safeguarding for Federal Contract Information.
  • Incident reporting obligations continue.
  • Self-assessments and your SPRS score are still required. In fact, during the suspension, Level 1 and Level 2 self-assessments are the only game in town.

The government didn’t remove the requirement to be secure. It removed, temporarily, the requirement to have a stranger fly in and grade you on it.


The trap nobody’s warning you about

Here’s the part the “CMMC is dead, party’s over” crowd is going to learn the hard way.

When you submit a self-assessment and affirm your SPRS score, you are making a representation to the federal government. If your SPRS score claims controls that haven’t actually been implemented, or that don’t satisfy the requirement as written, you’ve created a different kind of risk. False Claims Act enforcement has increasingly become part of the government’s toolkit when contractors knowingly misrepresent compliance….suspension or not.

The C3PAO going away does not make a padded score safe. If anything, it moves the risk.

Instead of relying on a C3PAO to validate your implementation, you’re relying on your own affirmation. That means every control you’ve marked “MET” should be one you can support with documentation, technical evidence, or a live demonstration if you’re ever asked by the Government.

Sorry, I really am not one of those assessors/consultants that have ever used fear as a way to incentivize contractors to get compliant, but I am afraid that the DoD is going to ramp up on False Claims Act enforcement.

So no, this is not the moment to stop. It’s the moment to make sure what you’ve already claimed is defensible.


What smart contractors are doing right now

If I were sitting across from you, here’s exactly what I’d tell you to do this quarter:

Review your active contracts and solicitations. Some may still reference the original Phase 2 implementation timeline. If you see language tied to the November certification requirement, don’t assume it no longer applies. Talk with your contracting officer or prime contractor before making changes to your compliance plans.

Keep implementing and sustaining your 800-171 controls. Every one of them is still contractually required. Nothing you’ve built is wasted.

Pressure-test your self-assessment. Pull up your SPRS score and ask the uncomfortable question: could you actually show evidence for every control you’re claiming? If the answer is “probably,” assume an assessor would keep asking questions until “probably” became “no.”

Get your documentation and evidence in order. Your SSP, your POA&M, your evidence. They aren’t just “CMMC documents.” They’re simply how you demonstrate compliance with NIST SP 800-171, regardless of if the CMMC program happens to exist.

Don’t cancel your program, you can reschedule the assessment. If you were about to spend money specifically to book a C3PAO before November, you can reasonably pause that line item and reassess. Keep everything else moving.

Watch the 60-day window. The task force reports back this fall. Whether certification returns sooner, later, or in a different form, organizations that stay ready will have options. Organizations that stop now will simply have more catching up to do.

Remember what you’re actually buying. Most of the work involved in CMMC: hardening systems, documenting processes, organizing evidence, and implementing NIST SP 800-171, isn’t “for CMMC.” It’s the work your contracts already require. The certification requirement may have shifted, but the underlying security work hasn’t.


The bottom line

CMMC hasn’t died yet.

The smartest thing you can do in a pause is exactly the thing your competitors won’t, which is to keep going. Stay secure, keep your evidence tight, and make sure every claim in your SPRS score is one you’d stake your contracts on, because you are.

If you’re staring at your self-assessment right now and you’re not 100% sure it would hold up, that’s precisely the conversation I have with clients every day of the week. Can you produce evidence that supports every control you’ve marked “MET”?

Whether certification returns in two months or six, the contractors who keep improving their cybersecurity today won’t be starting over tomorrow.


Have a CMMC question the headlines aren’t answering? Drop it in the comments — I read every one. If you need documentation to meet NIST SP 800-171, check out our compliance engine product at https://cmmccomplianceengine.com

Leave a Reply

Your email address will not be published.

Social Share Buttons and Icons powered by Ultimatelysocial