Vigilant Cybersecurity

CMMC Weekly Briefing · Jul 13–17, 2026

DoW suspends CMMC Phase 2 and launches a 60-day review

Top story

On Monday, July 13, DoW CIO Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey suspended the CMMC Phase 2 requirements that were scheduled to take effect November 10, 2026. Davies explained the decision to DefenseScoop: "The math just simply doesn't math for small to medium-sized businesses to even get compliant by the transition date." Federal News Network quoted the memo itself: "The current iteration of the Cybersecurity Maturity Model Certification (CMMC) program, while intended to enhance security, imposes significant and often prohibitive burdens on the Defense Industrial Base." A CMMC Reform Task Force now has 60 days to review the program.

Rules and policy

  • What contracts may still require. Latham & Watkins quotes the memo: "[p]rogram Managers and requiring activities must only include the need for CMMC Level 1 (Self) or Level 2 (Self) assessments in procurement request and requirement documents." Why it matters: self-assessments stay in play. Only the third-party requirements are being pulled back.
  • Class Deviation 2026-O0025, Revision 2 (July 16). This revision "provides direction to contracting officers on the suspension of the Cybersecurity Maturity Model Certification Phase 2 implementation." It also temporarily waives the 10 U.S.C. 4663 prohibition for Alibaba Group Holding Limited and Alibaba Group (U.S.). Why it matters: the suspension now reaches contracting officers through the acquisition rules, not just a policy memo.
  • Task force begins work. DefenseScoop reported on July 17 that the task force had already met and "will report to her principal deputy," meaning Davies's. Members come from acquisition and sustainment, intelligence and security, the CIO's office, general counsel, public affairs and legislative affairs, plus the Small Business Administration and the White House. Davies: "We're not going to do a death by 1,000 cuts and just change for the sake of change."

Industry and enforcement

  • The Cyber AB responds. In a July 15 statement, CEO Matthew Travis said the organization was "both surprised and disappointed in yet another momentary pause." He added: "NIST SP 800-171 and DFARS 7012 requirements remain in place and unchanged for most all contractors." Why it matters: the accreditation body read the pause the same way contract lawyers did. The underlying requirements didn't move.
  • Primes tell suppliers to keep going. In a July 16 letter to suppliers, Elbit Systems of America told them to "be prepared to complete a CMMC Level 2 (Self) assessment when required." It added: "This pause is an opportunity to strengthen your program – not a reason to delay it." Why it matters: expect your primes to keep asking for SPRS scores and evidence of progress.

Still on the radar

  • The task force's request for information to industry, which DefenseScoop reported was coming.
  • What happens to Level 2 (C3PAO) and Level 3 (DIBCAC) language already in solicitations and contracts.

Watch list

  • The task force RFI and its response deadline.
  • Contract modifications and solicitation amendments that implement Revision 2.

What to do this week

  • Don't stop your NIST SP 800-171 work. DFARS 252.204-7012 still applies wherever it's in your contract.
  • Keep your SPRS score current and accurate. Self-assessments are still required.
  • If you had a C3PAO assessment scheduled, talk to your assessor before canceling. A certification is still valuable with primes.

Sources

This briefing summarizes public sources for general awareness. It is not legal advice. Check the linked primary sources before acting on any item.

All weekly briefings

Turn the news into a plan

Not sure how this week's changes affect your contracts? A free scoping call is the fastest way to find out.

Schedule a Complimentary Scoping Call

Or reach a practitioner directly: (907) 229-5222 · [email protected]