The Department of War Just Paused CMMC Phase II. Read This Before You Slow Down.
The November 10 third-party assessment deadline is gone for now. Your obligation to protect federal data is not.
Weeks ago, with the November 10 deadline still looming, we called CMMC the gatekeeper for government contractors and told you to be ready. This week, the gate swung open, at least for now.
If you spent the past year and a real slice of your budget getting ready for a C3PAO assessment, you woke up this week to a different rulebook. On July 13, the Department of War (DoW, the renamed Department of Defense) suspended CMMC Phase II, the milestone that would have forced third-party certification into contracts starting November 10. A 60-day reform review is now running, and department leaders would not promise the program survives it.
Here is the trap. The headline reads like relief, and plenty of contractors are already treating it as a green light to stop. That reading will cost some of them a contract, and it could cost a few of them a False Claims Act investigation. The deadline moved but the duty to secure your data did not.
What actually changed on July 13
Pentagon Chief Information Officer Kirsten Davies announced an immediate suspension of CMMC Phase II, the phase that introduced mandatory assessments by a Certified Third-Party Assessor Organization for companies handling Controlled Unclassified Information. Phase III, the Level 3 government-led assessments slated for November 2027, and full implementation after it are suspended as well. Pending and future CMMC milestones already written into solicitations are on hold. In her signed memo, Davies argued that holding to the old deadlines was “jeopardizing our ability to field capabilities to our warfighters.”
Davies did not frame this as a retreat from security. Cybersecurity stays a priority, she told reporters; the paperwork is what is going away. “We are not reducing cybersecurity through this measure. We are reducing the red tape,” she said. The problem was arithmetic nobody could solve on the current timeline. About 100,000 businesses in the Defense Industrial Base still needed an assessment, and only about 100 assessors were authorized to conduct them, which in Davies’ words meant the math just simply doesn’t make sense for small firms trying to certify by November 10. The Small Business Administration had already warned that compliance costs were pushing capable companies out of defense work entirely.
A new CMMC Reform Task Force will run a top-to-bottom review and deliver findings within 60 days. Acquisition and Sustainment undersecretary Michael Duffey said the decision lets the department maintain a strict security baseline while removing paralyzing costs. Alongside the review, the department posted a Request for Information asking contractors which costs are crushing them and which security controls deliver real risk reduction. When reporters asked whether the whole program could be scrapped, leadership left the door open.
The timeline, start to now
2020 The Pentagon launches CMMC to verify contractor cybersecurity instead of trusting self-attestation alone.
2021 The program is paused and reworked into CMMC 2.0, trimming five maturity levels down to three.
Nov 10, 2025 Phase I takes effect. Contracts begin requiring Level 1 and Level 2 self-assessments and annual affirmations.
Jul 13, 2026 The pause. Phase II is suspended. A 60-day reform review and a public RFI begin. Phase I self-assessment stays in force.
~Sep 2026 The Reform Task Force report is due. Expect a redesigned framework, a new timeline, or a decision on the program’s future.
Nov 10, 2026 The original Phase II date (suspended). Mandatory C3PAO certification will not switch on as planned.
What did not change, and this is the part people miss
The certification mechanism is under review. The security baseline underneath it is untouched. If you handle CUI or Federal Contract Information, every obligation that governed you last week still governs you today.

The Department of Justice has not paused anything either. Its Civil Cyber-Fraud Initiative already uses the False Claims Act to pursue contractors who misrepresent their cyber posture, and legal analysts expect that scrutiny to reach inaccurate Phase I self-assessments next. A self-assessment is a claim you are making to the government. Sign one that your systems cannot back up, and the missing C3PAO auditor becomes the least of your problems.
Three contractors, three very different mornings
THE ONE WHO PAID UP FRONT
A 140-person aerospace machining shop booked its C3PAO assessment in the spring and had already sunk six figures into remediation and prep. The pause does not refund that. It also does not waste it. Every control this shop implemented still satisfies its DFARS 7012 duty, still strengthens its Phase I score, and still positions it ahead of competitors when the framework returns in some form. The smart move is to bank the readiness, not unwind it.
THE SMALL SUB ABOUT TO WALK AWAY
A 12-person specialty supplier had run the numbers and decided a Level 2 certification made no financial sense. It was preparing to let its defense contracts lapse. The pause is exactly the reprieve this company needed, and keeping these organizations in the game is precisely what the DOW was looking to achieve by reviewing the requirements. This supplier gets to stay in the base, keep supplying, and use the review window to close its self-assessment gaps at a manageable pace instead of exiting the market.
THE PRIME THAT NEVER GOT THE MEMO
A mid-tier prime had written CMMC readiness into its own subcontractor requirements. The government pausing Phase II does not rewrite that prime’s flow-down terms. Subs who assume the pressure is off may find their prime still gating the next award on demonstrated compliance. Read your contract language, not just the press release.
What disciplined contractors do with a 60-day window
A pause is a gift only to the companies that use it. Run your NIST 800-171 self-assessment now and document the score honestly, because it is still contractually live and still auditable. Keep the evidence organized so you can defend it under government scrutiny. A C3PAO mock assessment is still worth doing to validate that score without committing to formal certification. And submit real feedback to the RFI, since this is the rare moment the Defense Industrial Base gets to shape the rule it will live under.
Compliance in GovCon is a moving target by design. DCAA, DFARS, and CMMC all shift on their own schedules, and the contractors who survive the whiplash are the ones who treat compliance as an operating habit rather than a scramble before a deadline. Build the discipline into daily operations and a suspended deadline becomes a head start instead of a reset.
Compliance discipline does not get to take a pause
While the CMMC certification mechanism sits under review, your DCAA timekeeping and labor-tracking obligations keep running every single day. AutoTime Solutions is built to keep that side of your compliance defensible, accurate, and audit-ready, so a shifting cybersecurity rule is never the thing that puts your contracts at risk.
This article is provided for general information and does not constitute legal or compliance advice. Confirm your specific obligations against your contract terms and, where appropriate, qualified counsel.