If you sell into the defense supply chain, you’ve probably spent the last year bracing for one date: November 10, 2026. That was supposed to be the day Cybersecurity Maturity Model Certification (CMMC) Phase 2 became “real,” when Level 2 third-party certification stopped being a planning exercise and started being a condition of winning contracts. But on July 13, 2026, the Department of Defense (DoD) put that plan on hold. Here’s what was supposed to happen, what the pause actually changes, and—most importantly—what it doesn’t.

What Was Supposed to Happen

CMMC has always been designed to roll out in phases. Phase 1, which began in November 2025, required contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to complete self-assessments against the applicable CMMC level and post their scores to the Supplier Performance Risk System (SPRS). The SPRS system tells would-be government contracting partners what the cybersecurity status is for the organization and provides a competitive advantage against less compliant bidders.

Phase 2 was the next, much bigger step. Starting November 10, 2026, DoD planned to make it standard practice for contracting officers to require that some contractors handling CUI obtain a Level 2 certification not through self-attestation, but through an independent audit conducted by a Certified Third-Party Assessment Organization (C3PAO). In practice, that meant tens of thousands of small and mid-sized defense contractors would have needed to hire outside assessors to formally verify compliance with the 110 security controls in NIST SP 800-171 before they could be awarded or keep certain contracts, with total implementation to all contracts occurring over a multi-year period.

The math behind that requirement, at least according to some contractors in the Defense Industrial Base (DIB), was impactful. According to DoD CIO Kirsten Davies, Small Business Administration data suggested the coming phases could have cost the DIB more than $7 billion a year, with some individual companies facing compliance bills approaching $600,000. (Of course, it should be noted that these companies have been required to comply with the underlying cyber security obligations since 2018, which begs the question of why they have waited!)

More compelling to me, at least, the November 10 date required more than 100,000 companies in the DIB to compete for assessment slots with only around 100 approved C3PAOs nationwide, creating a bottleneck that a March 2026 GAO report had already flagged as a risk that might push small businesses out of the DIB supply chain completely.

What the Pause Actually Does

On July 13, DoD CIO Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey announced an immediate suspension of the transition to Phase 2, along with any pending or future CMMC implementation milestones tied to it. In plain terms: the November 10, 2026 deadline for mandatory C3PAO Level 2 certification is off the table for now.

During the pause, DoD is standing up a CMMC Reform Task Force, pulling in representatives from the CIO’s office, Acquisition and Sustainment, Research and Engineering, Legislative Affairs, Public Affairs, and Legal. That task force, along with public feedback gathered through a formal Request for Information (with comments due by August 14, 2026), is expected to report findings and recommendations within 60 days. The Department has been explicit that this review could lead to the program being revised, narrowed, or even significantly restructured. Everything about Phase 2’s eventual shape is open for reconsideration.

There’s also an immediate, practical consequence for contracts already in the pipeline: DoD has directed that any active solicitations or contracts that already include C3PAO Level 2 or Level 3 assessment requirements must be amended to remove them. During the suspension, contracting officers can only include Level 1 or Level 2 self-assessment requirements, not third-party ones.

What the Pause Does Not Mean

Here’s the part that’s easy to misread: this is a pause on the assessment mechanism, not a pause on cybersecurity compliance itself.

Every substantive obligation that existed before July 13 is still in force. Phase 1 self-assessment requirements, which began in November 2025, are unaffected. Contractors handling CUI are still expected to implement the 110 security controls in NIST SP 800-171, still need to maintain accurate SPRS scores, and are still bound by DFARS 252.204-7012’s safeguarding and rapid incident-reporting requirements. The DoD has said it will continue enforcing cybersecurity compliance during the review period through self-assessments and select government-led assessments.

And importantly to us here at Bracker & Marcus, the Department of Justice’s Civil Cyber-Fraud Initiative, which pursues False Claims Act cases against contractors who misrepresent their compliance, hasn’t gone anywhere either.

So if you’ve been treating CMMC readiness as a box to check only once a C3PAO shows up, this pause is not a license to stop. What’s gone, for now, is the requirement that an outside auditor verify your work before you can win certain awards. What remains is everything the audit was designed to check.

The Bottom Line

This is a pause on the certification mechanism, not a repeal of the security standards. The safest move for contractors is to keep self-assessments current, keep SPRS scores accurate, and keep an eye on the Reform Task Force’s findings, which are due in 60 days, as that will determine what Phase 2 looks like when it eventually returns.

Know a Contractor Who’s Cutting Corners?

Because the underlying compliance obligations have not gone anywhere, contractors who ignore them are still exposed to False Claims Act liability—and so is anyone who knowingly contracts with the government while misrepresenting their cybersecurity posture. Falsely certifying compliance with NIST SP 800-171, DFARS 252.204-7012, or CMMC self-assessment requirements can trigger liability under the False Claims Act, and whistleblowers who report this kind of misconduct may be entitled to a share of any recovery.

If you have direct knowledge of a DIB contractor ignoring its cybersecurity compliance obligations, call Bracker & Marcus at 770-988-5035 for a free, confidential case assessment.