What changed
2026-07-31 13:41 UTC → 2026-08-04 22:06 UTC ·
added
removed
The On 13 July 2026 the Department of Defense announced on 13 July 2026 an immediate pause suspension of the Cybersecurity Maturity Model Certification (CMMC) CMMC Phase II requirement that obliges third‑party assessments assessment requirement for Level 2 contracts. The suspension was limited to pause removes the external‑auditor step; all other obligations – Certified Third‑Party Assessor Organization (C3PAO) audit while leaving Phase I self‑assessment, compliance with DFARS 252.204‑7012, NIST SP 800‑171 Rev 2 controls, 72‑hour incident reporting, annual SPRS score updates and false‑claim liability – remained in force. Program managers were directed to amend or delete the suspended clauses from active solicitations. A clarification issued on 28 July confirmed the narrow scope of reiterated that only the pause external‑auditor step is on hold and reiterated confirmed a 60‑day review task force aimed at aligning CMMC with the DoD’s acquisition transformation strategy. goals. The notice highlighted that more than 100,000 small and medium‑size defense contractors face certification costs that can approach $600,000 per firm. By the end of July, industry observers same week, analysts noted that managed service providers serving these contractors must continue the same security duties, remediation work, validate SPRS submissions and preserve audit evidence, and that the regulatory uncertainty is spurring interest in AI‑driven compliance tools. Analysts cautioned that while the certification timeline is delayed, DoD officials, including CIO Kirsten Davies and Undersecretary Michael Duffey, highlighted the underlying security risk does not diminish. The DoD’s high compliance cost—estimated at $7 billion annually for roughly 100,000 firms—and pledged a mid‑September task‑force review will determine whether and how that could reshape the third‑party assessment requirement is reinstated after the 60‑day period. model. Security advisers warned contractors and MSPs not to pause their NIST 800‑171 programs, noting that inaccurate self‑assessments can still trigger False Claims Act penalties of $14,308‑$28,619 per claim plus treble damages.