DoD Suspends CMMC Phase 2; Reform Task Force RFI Responses Due August 14
On July 13, 2026, the Department of War (formerly DoD) CIO suspended CMMC Phase 2 requirements, which had been scheduled to take effect November 10, 2026, and stood up a CMMC Reform Task Force to deliver reform recommendations within roughly 60 days. A companion Request for Information posted to SAM.gov seeks defense industrial base input on compliance cost drivers, control effectiveness, self-attestation, and commercial cybersecurity capabilities, with responses due by email no later than 12:00 pm ET on Friday, August 14, 2026. Phase 1 obligations, the Level 1 and Level 2 self-assessment and affirmation requirements flowing through DFARS 252.204-7021 since November 10, 2025, remain in effect.
Key Analytics
Impact Analysis
The suspension pauses the mandate for third-party C3PAO assessments but relaxes nothing that is already in force: contractors must still self-assess against NIST SP 800-171 Rev 2, keep SPRS scores accurate, file annual affirmations, and meet DFARS 252.204-7012 safeguarding and incident reporting obligations, all of which carry False Claims Act exposure. The task force review could reshape or reinstate third-party assessment requirements, so treat in-flight certification investments as risk decisions rather than sunk costs; assessment capacity may tighten sharply if the mandate returns in revised form. The RFI window is a rare opportunity to put your organization's cost and burden data on the record before the rules are rewritten. As of August 2026, no replacement timeline for Phase 2 or later phases has been announced.
Recommended Actions
- Submit RFI comments by 12:00 pm ET on August 14, 2026, documenting your specific compliance cost drivers and which NIST 800-171 controls deliver measurable risk reduction
- Maintain Phase 1 compliance without interruption: accurate SPRS scores, current self-assessments, and annual affirmations under DFARS 252.204-7021 remain enforceable
- Weigh re-booking risk before canceling scheduled C3PAO assessments, since assessment capacity may tighten again if third-party requirements return after the review
- Track the CMMC Reform Task Force's recommendations, expected roughly 60 days from the July 13 announcement, before revising certification budgets or timelines
- Brief leadership that the suspension is a pause pending review, not a repeal, and that DFARS 252.204-7012 safeguarding and incident reporting obligations continue unchanged
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›RFI submission drafting with specific cost drivers and control effectiveness evidence
- ›Phase 1 continuity check across SPRS accuracy, self-assessment currency, and affirmations
- ›Re-booking risk analysis before canceling or deferring a scheduled C3PAO assessment
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 50 to 115 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.