Home / Guides / Is CMMC Cancelled?

Is CMMC Cancelled? What the July 2026 Suspension Actually Means

Focus: is cmmc cancelled Veteran-run · practitioner guide Updated Jul 19, 2026 ~7 min read
The short answer

No — CMMC is not cancelled. On July 13, 2026, DoD suspended CMMC Phase 2 (the third-party C3PAO certification mandate) and opened a 60-day review. That's a pause, not a repeal. The certification is suspended; the security standard behind it is not. If you handle government data, you still owe a self-assessment, a current SPRS score, and compliance with NIST 800-171 and DFARS 252.204-7012 — today.

If you're a small contractor who just heard "CMMC got suspended" and started wondering whether the last year of work was for nothing — take a breath. The honest version is more useful than the rumor, and it's genuinely good news for small business: the single most expensive, most-feared piece got paused, while the part that actually makes you secure stayed exactly where it was.

What actually happened

On July 13, 2026, DoD CIO Kirsten Davies signed a memo suspending CMMC Phase 2 — the requirement that many contractors pass an independent C3PAO third-party certification (the mandate that was set to begin November 10, 2026). DoD stood up a 60-day CMMC reform task force to review the whole program.

The reason is the exact complaint small business has been making for years: roughly 100,000+ defense firms would need audits from only about 100 approved assessors, at a cost the SBA said could exceed half a million dollars per company. As one official put it, "the math just simply doesn't math" for small and mid-size businesses. So DoD hit pause to rework it.

What's suspended vs. what's still the law

This is the part that matters, because a lot of stale advice online now reads wrong. Here's the clean split:

RequirementStatus now
Level 2 C3PAO third-party certification (was Nov 10, 2026)Suspended
Level 3 DIBCAC government assessmentSuspended
NIST SP 800-171 (the 110-control security standard)Still required
Level 1 & Level 2 self-assessmentsStill required
SPRS score (DFARS 252.204-7019/-7020)Still required
DFARS 252.204-7012 (safeguarding + 72-hr incident reporting)Still required
The one line that captures it The certification is suspended. The standard is not. During the review, a contracting officer can require you to self-assess — Level 1 (self) for FCI or Level 2 (self) for CUI — but cannot require a Level 2 C3PAO certification. The security work is unchanged; only the third-party verification is paused.

So do I still need to do anything? Yes.

If you handle Federal Contract Information (FCI), you owe a Level 1 self-assessment. If you handle Controlled Unclassified Information (CUI), you owe NIST 800-171, a Level 2 self-assessment, and a current SPRS score. None of that paused. And this matters: a false or inflated SPRS score still carries False Claims Act liability — the suspension did not lower your legal exposure one bit. If anything, self-attesting honestly matters more now, because self-assessment is carrying the whole weight during the review.

The trap to avoid Don't read "suspended" as "ignore it." The contractors who freeze all cybersecurity work will be non-compliant today (self-assessment is still required) and unready when a revised rule lands. The ones who keep building their 800-171 posture will be ahead either way. Don't over-buy a C3PAO audit you don't currently need — but don't stop the actual security work.

What happens next

The review is on a clock. The task force has ~60 days to gather feedback plus 15 to write recommendations. Two dates to watch:

We keep a running CMMC Reform Tracker with the timeline and what each milestone means, and we surface every official development in MMO — the CMMC Pulse feed. Bookmark whichever you'll actually check.

The cheapest window in years

Do the standard now — skip the certification cost.

This is the best time in years to get compliant: you do the real 800-171 work and self-attest, without paying $30k–$100k for a certification audit that isn't currently required. Two free ways to start — see exactly where you stand, or follow the honest step-by-step.

Frequently asked questions

Is CMMC cancelled?

No. DoD suspended CMMC Phase 2 (the C3PAO certification mandate) on July 13, 2026 and opened a 60-day review. It's paused, not repealed. NIST 800-171 self-assessment, DFARS 252.204-7012, and SPRS scoring remain in effect — the certification is suspended, the standard is not.

Is CMMC still required in 2026?

The self-assessment is. Level 1 (self) if you handle FCI, or NIST 800-171 + Level 2 (self) + an SPRS score if you handle CUI. What's suspended is the requirement to pass an independent C3PAO certification audit.

Do I still need a C3PAO assessment right now?

Not currently. During the suspension, program managers may designate only Level 1 (self) or Level 2 (self) — not a Level 2 C3PAO or Level 3 assessment. Paying for a formal cert audit now is premature for most, though the 800-171 work is still worth doing.

Should I stop working on CMMC?

No. NIST 800-171 is unchanged and still enforced through DFARS and self-assessment. A false SPRS score still carries False Claims Act liability. Keep building — you'll be ahead when a revised rule lands (likely late 2026 or 2027).

When will we know what happens?

The RFI closes August 14, 2026, and a recommendations report is expected around late September 2026. Outcomes could range from tweaks to an overhaul, likely followed by a revised rule.

Sources — DoD/War Dept release on the Phase II suspension; Federal News Network, DefenseScoop, and National Defense Magazine coverage (July 2026); law-firm alerts confirming NIST 800-171, DFARS 7012, and SPRS remain in force. Status as of July 19, 2026 — we update as the review develops.