What DoD actually announced
In a July 13 announcement and accompanying memo from DoD Chief Information Officer Kirsten Davies, the department suspended CMMC Phase 2 — the stage that would have made third-party (C3PAO) Level 2 certification a condition of award for applicable CUI contracts beginning November 10, 2026. The suspension is immediate, and it isn't limited to Phase 2: pending and future CMMC implementation milestones, including Phase 3's government-led Level 3 assessments planned for November 2027 and Phase 4's full implementation, are suspended as well. Program managers and contracting officers have been directed to amend solicitations and contracts that already contain the suspended requirements.
In their place, DoD stood up a CMMC Reform Task Force — a cross-functional team spanning the CIO's office, Acquisition and Sustainment, Research and Engineering, and legal — with 60 days to review the program top to bottom and recommend a framework that prioritizes speed, lowers barriers for small and non-traditional businesses, and replaces third-party compliance models with what the department calls scalable, resilient security measures. A public request for information is coming, giving the defense industrial base a direct channel to shape whatever replaces Phase 2.
The stated reasons are cost and capacity. SBA reporting indicated compliance costs were pushing companies out of the defense industrial base entirely. And the assessor math never worked: well over 100,000 companies needed third-party assessments, with only around 100 approved assessment organizations available to conduct them. Officials were candid that the timeline was not achievable for small and mid-sized businesses.
One line from the announcement deserves to be read twice. Davies told reporters: “We are not reducing cybersecurity through this measure. We are reducing the red tape.” The department was explicit that the suspension does not eliminate the legal requirement for contractors to protect federal data. That distinction — verification suspended, obligation intact — is the entire story, and it's the part most of the celebration on LinkedIn this week is missing.
What remains fully in force
The suspension removed one mechanism: the independent audit. Everything the audit was designed to verify is still there.
- Phase 1 self-assessments. The requirements that took effect in November 2025 stay in place. Applicable contracts still require a current CMMC self-assessment, and DoD confirmed programs can continue including self-assessment requirements in new contracts.
- NIST SP 800-171 Rev 2. During the review period, DoD will enforce compliance with the 800-171 standard through self-assessments and select government-led (DIBCAC) assessments. All 110 controls — including media sanitization — remain the baseline.
- DFARS 252.204-7012. The contract clause obligating contractors and subcontractors to safeguard covered defense information predates CMMC by years and is untouched by the suspension.
- SPRS scores. Your self-assessed score still sits in the Supplier Performance Risk System, still gets referenced at award, and still constitutes a representation to the federal government.
- False Claims Act exposure. A false or inflated self-assessment score was fraud before July 13 and is fraud after it. The Department of Justice's cyber-fraud enforcement doesn't require a breach — it's premised on misrepresentation, and the government has been actively prosecuting these cases.
The self-attestation trap
Here's the uncomfortable arithmetic of the suspension. Before July 13, a contractor with an optimistic SPRS score had a forcing function coming: a C3PAO assessor was going to walk through the door before November and sample the evidence. That assessment was expensive and burdensome — but it was also a friendly reader. It would have caught the gap between the score you attested and the program you actually run, before a DOJ investigator or a qui tam relator did.
The suspension removed the friendly reader and kept everything else. Your score still matters at award. The clause that makes it material is still in the contract. The False Claims Act penalty structure still attaches per claim — meaning per invoice, not per contract — with treble damages on top. A small shop billing monthly against a contract awarded on a bad score isn't facing one violation; it's facing one for every invoice it submitted.
So the honest read of July 13 for a compliance owner is not “pencils down.” It's that the burden of proof just shifted entirely onto your own documentation. The evidence a C3PAO would have sampled — policies, records, reconciliation — is now the evidence that defends your attestation if it's ever questioned. Nobody independent is going to validate it for you first.
Primes don't pause
Federal timelines and prime contractor requirements are two different clocks. Large primes spent the last eighteen months building supplier questionnaires, contract amendments, and flowdown requirements around CMMC readiness, because their own award eligibility depends on a compliant supply chain. Some had already begun requiring C3PAO audits ahead of the federal deadline.
Nothing about July 13 obligates a prime to relax those requirements, and the competitive logic points the other way: a subcontractor who can demonstrate a defensible 800-171 program is a lower-risk supplier during a period of regulatory uncertainty, not a higher-risk one. If your CMMC preparation was driven by a prime's supplier requirements rather than the federal calendar, assume those requirements survive until the prime tells you otherwise in writing.
What this means for disposition and 3.8.3
Control 3.8.3 — sanitize or destroy system media containing CUI before disposal or release for reuse — is a five-point control on the NIST 800-171 self-assessment methodology. Five-point controls cannot ride on a POA&M. That was true under the Phase 2 timeline, and it's true under the suspension, because the scoring methodology belongs to 800-171, not to the certification phase that got paused.
Which means the disposition questions didn't change; only who asks them did.
- Can you show what happened to every retired CUI-bearing drive? A serialized certificate of destruction tied to a specific asset, reconcilable against your asset register, is the artifact that answers this — for a self-assessment, a DIBCAC assessment, a prime's questionnaire, or a DOJ inquiry alike.
- Does your destruction method match the media? NIST 800-88 still governs. Overwrite-only approaches still fail for media where Purge or Destroy is warranted, and SSDs still don't sanitize like spinning disks.
- Is there a written SOP behind the records? The policy anchor for 3.8.3 is the first artifact any reviewer — internal or external — asks for.
If anything, disposition evidence gained relative importance on July 13. In a self-attestation regime, contemporaneous third-party records are among the few pieces of your compliance file that don't depend on your own say-so. A destruction certificate from a certified ITAD vendor is independent evidence in a program that just lost its independent check.
Five moves during the review window
- Don't unwind anything. Keep your sanitization SOP, chain-of-custody procedures, and vendor arrangements exactly where they are. The standard they satisfy is still contractual.
- Re-verify your SPRS score against reality. With the third-party check gone, an inflated score has no natural correction mechanism left except enforcement. If 3.8.3 is scored as met, make sure the evidence file proves it.
- Run a serial-number reconciliation. Pull ten retired assets from your register and trace each to a destruction record. That sampling exercise is exactly what assessors perform — and now it's yours to perform on yourself.
- Respond to the RFI when it publishes. The task force is explicitly soliciting industry input on costs and burden. Real numbers from real programs will shape what replaces Phase 2.
- Calendar mid-September. The task force reports back in roughly 60 days. Officials have not ruled out restructuring the program — or ending it. Whatever emerges, the 800-171 baseline underneath it is the safest thing to build on.
CMMC suspension FAQ
Is CMMC cancelled?
No. Phase 2, Phase 3, Phase 4, and pending implementation milestones are suspended while a 60-day review runs. Phase 1 self-assessment requirements remain in force. Officials declined to rule out deeper restructuring — or cancellation — after the review, but as of today the program exists and its first phase is being enforced.
Do I still have to comply with NIST 800-171?
Yes. DoD stated it will continue enforcing NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments during the suspension, and DFARS 252.204-7012 safeguarding obligations are unaffected. The certification mechanism paused; the standard did not.
Should I cancel my scheduled C3PAO assessment?
That's a contract-by-contract call to make with your registered practitioner and counsel — not something this article can decide for you. Factors that cut against cancelling: prime flowdown requirements that haven't changed, the value of an independent validation of your self-attested score, and the possibility that some form of third-party verification returns after the review. Factor that cuts for it: the federal deadline that created the urgency no longer exists. Many contractors are converting scheduled certifications into mock assessments.
What happens after the 60 days?
The CMMC Reform Task Force reports its recommendations to the DoD CIO, informed by RFI responses from industry. The department has signaled the goals: faster paths to capability, lower barriers for small and non-traditional businesses, and security measures that scale without prohibitive third-party cost. What that looks like in contract clauses is genuinely unknown — which is why the durable move is compliance with the underlying standard rather than any particular verification regime.
Does this change anything about how CUI-bearing hardware must be destroyed?
No. CUI on retired hardware is still CUI. NIST 800-88 media sanitization, control 3.8.3, chain of custody, and serialized destruction evidence are all requirements of the standard that remains in force — and they're sampled in self-assessments and DIBCAC assessments, not just C3PAO ones.
YOUR SCORE IS NOW THE AUDIT
Make sure the disposition evidence behind your self-assessment holds up
Our one-page CMMC disposition checklist maps control 3.8.3 to the records a reviewer samples — written SOP, NIST 800-88 method selection, serialized certificates, and asset reconciliation. It was built for C3PAO prep. It works just as well when the reviewer is you.
This article describes the CMMC program status as of July 14, 2026, based on the Department of Defense's July 13 announcement and contemporaneous reporting from Federal News Network, Breaking Defense, and DefenseScoop. The situation is actively developing; verify current requirements against official DoD channels. This is general information, not legal or compliance advice — consult your counsel and registered practitioner for guidance on your specific contracts.