No — CMMC is not cancelled. On July 13, 2026, DoD suspended CMMC Phase 2 (the third-party C3PAO certification mandate) and opened a 60-day review. That's a pause, not a repeal. The certification is suspended; the security standard behind it is not. If you handle government data, you still owe a self-assessment, a current SPRS score, and compliance with NIST 800-171 and DFARS 252.204-7012 — today.
If you're a small contractor who just heard "CMMC got suspended" and started wondering whether the last year of work was for nothing — take a breath. The honest version is more useful than the rumor, and it's genuinely good news for small business: the single most expensive, most-feared piece got paused, while the part that actually makes you secure stayed exactly where it was.
On July 13, 2026, DoD CIO Kirsten Davies signed a memo suspending CMMC Phase 2 — the requirement that many contractors pass an independent C3PAO third-party certification (the mandate that was set to begin November 10, 2026). DoD stood up a 60-day CMMC reform task force to review the whole program.
The reason is the exact complaint small business has been making for years: roughly 100,000+ defense firms would need audits from only about 100 approved assessors, at a cost the SBA said could exceed half a million dollars per company. As one official put it, "the math just simply doesn't math" for small and mid-size businesses. So DoD hit pause to rework it.
This is the part that matters, because a lot of stale advice online now reads wrong. Here's the clean split:
| Requirement | Status now |
|---|---|
| Level 2 C3PAO third-party certification (was Nov 10, 2026) | Suspended |
| Level 3 DIBCAC government assessment | Suspended |
| NIST SP 800-171 (the 110-control security standard) | Still required |
| Level 1 & Level 2 self-assessments | Still required |
| SPRS score (DFARS 252.204-7019/-7020) | Still required |
| DFARS 252.204-7012 (safeguarding + 72-hr incident reporting) | Still required |
If you handle Federal Contract Information (FCI), you owe a Level 1 self-assessment. If you handle Controlled Unclassified Information (CUI), you owe NIST 800-171, a Level 2 self-assessment, and a current SPRS score. None of that paused. And this matters: a false or inflated SPRS score still carries False Claims Act liability — the suspension did not lower your legal exposure one bit. If anything, self-attesting honestly matters more now, because self-assessment is carrying the whole weight during the review.
The review is on a clock. The task force has ~60 days to gather feedback plus 15 to write recommendations. Two dates to watch:
We keep a running CMMC Reform Tracker with the timeline and what each milestone means, and we surface every official development in MMO — the CMMC Pulse feed. Bookmark whichever you'll actually check.
This is the best time in years to get compliant: you do the real 800-171 work and self-attest, without paying $30k–$100k for a certification audit that isn't currently required. Two free ways to start — see exactly where you stand, or follow the honest step-by-step.
No. DoD suspended CMMC Phase 2 (the C3PAO certification mandate) on July 13, 2026 and opened a 60-day review. It's paused, not repealed. NIST 800-171 self-assessment, DFARS 252.204-7012, and SPRS scoring remain in effect — the certification is suspended, the standard is not.
The self-assessment is. Level 1 (self) if you handle FCI, or NIST 800-171 + Level 2 (self) + an SPRS score if you handle CUI. What's suspended is the requirement to pass an independent C3PAO certification audit.
Not currently. During the suspension, program managers may designate only Level 1 (self) or Level 2 (self) — not a Level 2 C3PAO or Level 3 assessment. Paying for a formal cert audit now is premature for most, though the 800-171 work is still worth doing.
No. NIST 800-171 is unchanged and still enforced through DFARS and self-assessment. A false SPRS score still carries False Claims Act liability. Keep building — you'll be ahead when a revised rule lands (likely late 2026 or 2027).
The RFI closes August 14, 2026, and a recommendations report is expected around late September 2026. Outcomes could range from tweaks to an overhaul, likely followed by a revised rule.