On July 13, 2026, the Department of War (the Pentagon’s new name following last year’s rebrand) suspended Phase 2 of the CMMC program — the phase that would have made third-party C3PAO certification mandatory starting November 10, 2026. The stated reasons: assessor capacity hasn’t scaled to meet demand, and compliance costs are, in the department’s own words, “structurally incompatible” with the current timeline.
If you’ve been sprinting toward a November certification, you can exhale — a little. But don’t put the program down. DFARS clause 252.204-7012 is still fully in force, which means contractors handling CUI must still:
- Implement all 110 NIST SP 800-171 controls.
- Report cyber incidents rapidly.
- Complete self-assessments for Levels 1 and 2.
- File annual affirmations through DoD’s Supplier Performance Risk System (SPRS).
A 60-day reform task force is rewriting the rulebook
Within days of the pause, the Department of War’s CIO stood up a CMMC Reform Task Force to conduct a top-to-bottom review of the program. Its charter names five priorities: rebuilding defense capabilities, empowering the acquisition workforce, cutting regulatory burden, improving technical execution, and strengthening lifecycle risk management. Translation: expect proposals aimed at making the program less painful for small and mid-sized contractors, without gutting the security bar.
- Jul 13, 2026Phase 2 suspended — mandatory C3PAO certification postponed indefinitely.
- Jul 20, 2026Reform Task Force chartered, RFI opened for industry input on reducing compliance burden.
- Aug 14, 2026RFI comment period closed — input gathered from small, mid-size, and non-traditional defense contractors.
- Mid-Sep 2026 (expected)Task force recommendations due to DoW leadership.
- Mid-Oct 2026 (earliest)Formal determinations on program changes — any real changes still require rulemaking, not just a memo.
CUI rules are expanding far beyond the Pentagon
While CMMC dominates the headlines, the more consequential move this summer may be the FAR Council’s June 23, 2026 proposed rule — part of the broader “FAR overhaul” — which extends CUI safeguarding and NIST SP 800-171 obligations to civilian agencies (GSA, VA, DHS, and others) for the first time. If your contracts touch any federal agency, not just DoD, this is the rule to watch.
The proposal also upgrades the security baseline from NIST SP 800-171 Revision 2 to Revision 3 — a meaningful lift involving restructured control families and new parameters. The public comment period closed July 23, 2026; a final rule is expected to follow in the coming months.
| Requirement | Before | Proposed |
|---|---|---|
| Incident reporting window | 8 hours | 72 hours |
| Security baseline | NIST SP 800-171 Rev. 2 | NIST SP 800-171 Rev. 3 |
| Applies to | DoD contractors only | DoD + civilian agencies (GSA, VA, DHS, etc.) |
| Incident trigger | Includes “suspected” incidents | Confirmed incidents only |
| CUI identification | Contractor’s burden to determine | New SF form, government identifies |
What to do this week
No fire drills — just the habits that keep you audit-ready no matter how the rulemaking lands.
- Keep your SPRS score current. Self-assessments and annual affirmations are still mandatory — don’t let the pause become an excuse to let this lapse.
- Start a Rev. 3 gap assessment. The control changes are real work — get ahead of it instead of scrambling when the final rule lands.
- Check your prime’s flowdown language. Several primes are holding subcontractors to CMMC-level requirements contractually, regardless of the federal pause.
- Watch for the Task Force recommendations in mid-September. We’ll break down what they mean for you the week they drop.
Quick hits
- Jul 2026Cyber AB town halls reinforce the message.Both June and July recaps urge contractors to stop treating November 10 as a hard deadline.
- Jul 2026Primes are staying the course.Some large primes are telling suppliers the pause doesn’t change contractual flowdown expectations — plan accordingly.
- Jun 2026Assessor eligibility widens.New Tier 3 equivalence pathways mean US citizenship is no longer a strict requirement to become a CMMC Level 2 assessor.
Not sure where your organization stands?
CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.
