We think about technology like business people, with your productivity and profits top of mind.

Contacts

100 Ashford Center North, Suite 110 Atlanta, GA 30338

285 Elm Street, Suite 101
Cumming, GA 30040

5802 Breckenridge Parkway Suite 104
Tampa, FL 33610

info@eclipse-networks.com

(770) 399-9099

Cybersecurity
best-msp-atlanta-cmmc-phase-2-just-got-suspended-heres-why-you-shouldnt-stop-eclipse-networks

CMMC Phase 2 Just Got Suspended. Here’s Why You Shouldn’t Stop.

If you’re a defense contractor or a supplier in the defense supply chain, you’ve probably heard the news and felt a wave of relief: on July 13, 2026, the Department of Defense suspended CMMC Phase 2, the milestone that would have required third-party certification of your cybersecurity by November 10, 2026. The CMMC Phase 2 suspension is real, and a reform task force is now reviewing the whole program.

But before you tell your team to stand down, understand exactly what got paused and what didn’t. Because the obligation that actually matters is still fully in force, and contractors who treat this as a break are setting themselves up to lose work.

We covered the original rollout in CMMC Compliance Is Now a Contract Requirement. This is the other side of that story: what the pause changes, what it doesn’t, and why the smart move is to keep going.

The CMMC suspension

CMMC, or the Cybersecurity Maturity Model Certification, was designed to do one thing that decades of self-attestation hadn’t: verify that contractors were actually meeting the security requirements they’d been promising to meet. Phase 2 was the teeth. It would have required many contractors handling Controlled Unclassified Information (CUI) to pass an assessment by an accredited third-party organization (a C3PAO) before they could be awarded a contract.

That verification requirement is what’s on hold. On July 13, 2026, the DoD suspended Phase 2, stood up a CMMC Reform Task Force reporting to the DoD Chief Information Officer, and opened a review period expected to run about 60 days. In plain terms: for now, you won’t be required to hire a third-party assessor to certify your Level 2 compliance before winning a contract. WilmerHale’s client alert lays out the mechanics.

What did not change

CMMC was never the source of a security obligation. It was a layer of enforcement built on top of rules that already existed and are still on the books:

  • DFARS 252.204-7012 still requires you to implement the security controls in NIST SP 800-171 if you handle CUI. That clause has been in defense contracts since 2017. It’s untouched.
  • NIST SP 800-171 — all 110 controls — still defines your security baseline. Nothing about the Phase 2 suspension lowers that bar.
  • DFARS 252.204-7019 and 7020 still require you to complete a self-assessment and post a current score in the Supplier Performance Risk System (SPRS), and to affirm it. That score is a live, enforceable data point the government can pull up at any time.

The suspension removed the referee, not the rules. You still have to meet the standards. You still have to score yourself against them. You still have to stand behind that score. As one legal analysis put it, the deadline is gone but the legal obligation isn’t.

Why “we’ll wait and see” is the expensive choice

It’s tempting to read a suspension as permission to slow down, but here’s why that would be a mistake:

  • Your prime contractors aren’t waiting. If you’re a subcontractor, your security requirements don’t come only from the DoD — they flow down through the prime contractor above you. Primes with mature security programs are still writing 800-171 compliance into their subcontracts and still asking for evidence. The government pausing Phase 2 doesn’t release you from what your customer requires to keep doing business with them.
  • A false SPRS score is still legal exposure. Because self-assessment and SPRS reporting remain mandatory, an inflated or stale score is exactly what it was before the suspension: a misrepresentation the government can act on, including under the False Claims Act. The pause on third-party verification arguably makes your self-reported number more scrutinized, not less.
  • The requirement is coming back. A reform task force reviewing the program is not the same as the program going away. When verification returns — in whatever form the review produces — the contractors who kept working the 110 controls will be ready to certify quickly. The ones who stopped will be scrambling, competing for assessor slots, and potentially locked out of awards while they catch up.

Working with Eclipse Networks on CMMC

Treat the CMMC Phase 2 suspension as a schedule change, not a reprieve. The finish line for third-party certification moved. The work required to reach it did not. If you were on track to meet NIST SP 800-171, stay on track. If you were behind, use this extra time to close control gaps, improve your SPRS score, and document your System Security Plan and Plan of Action & Milestones properly.

Contractors who keep building through the pause turn a moment of uncertainty into a competitive edge: when the requirement firms up again, they’re already compliant while competitors are still assessing.

Eclipse Networks helps defense-supply-chain businesses across Georgia and Florida meet NIST SP 800-171, calculate and correct their SPRS scores, and build the security and data protection foundation that CMMC will ultimately verify. If you want a clear-eyed read on where you actually stand against the 110 controls, schedule a consultation — before the deadline comes back on someone else’s timeline.

Author

Dan Weiss

Leave a comment

Your email address will not be published. Required fields are marked *