Top story
On Monday, July 13, DoW CIO Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey suspended the CMMC Phase 2 requirements that were scheduled to take effect November 10, 2026. Davies explained the decision to DefenseScoop: "The math just simply doesn't math for small to medium-sized businesses to even get compliant by the transition date." Federal News Network quoted the memo itself: "The current iteration of the Cybersecurity Maturity Model Certification (CMMC) program, while intended to enhance security, imposes significant and often prohibitive burdens on the Defense Industrial Base." A CMMC Reform Task Force now has 60 days to review the program.
Rules and policy
- What contracts may still require. Latham & Watkins quotes the memo: "[p]rogram Managers and requiring activities must only include the need for CMMC Level 1 (Self) or Level 2 (Self) assessments in procurement request and requirement documents." Why it matters: self-assessments stay in play. Only the third-party requirements are being pulled back.
- Class Deviation 2026-O0025, Revision 2 (July 16). This revision "provides direction to contracting officers on the suspension of the Cybersecurity Maturity Model Certification Phase 2 implementation." It also temporarily waives the 10 U.S.C. 4663 prohibition for Alibaba Group Holding Limited and Alibaba Group (U.S.). Why it matters: the suspension now reaches contracting officers through the acquisition rules, not just a policy memo.
- Task force begins work. DefenseScoop reported on July 17 that the task force had already met and "will report to her principal deputy," meaning Davies's. Members come from acquisition and sustainment, intelligence and security, the CIO's office, general counsel, public affairs and legislative affairs, plus the Small Business Administration and the White House. Davies: "We're not going to do a death by 1,000 cuts and just change for the sake of change."
Industry and enforcement
- The Cyber AB responds. In a July 15 statement, CEO Matthew Travis said the organization was "both surprised and disappointed in yet another momentary pause." He added: "NIST SP 800-171 and DFARS 7012 requirements remain in place and unchanged for most all contractors." Why it matters: the accreditation body read the pause the same way contract lawyers did. The underlying requirements didn't move.
- Primes tell suppliers to keep going. In a July 16 letter to suppliers, Elbit Systems of America told them to "be prepared to complete a CMMC Level 2 (Self) assessment when required." It added: "This pause is an opportunity to strengthen your program – not a reason to delay it." Why it matters: expect your primes to keep asking for SPRS scores and evidence of progress.
Still on the radar
- The task force's request for information to industry, which DefenseScoop reported was coming.
- What happens to Level 2 (C3PAO) and Level 3 (DIBCAC) language already in solicitations and contracts.
Watch list
- The task force RFI and its response deadline.
- Contract modifications and solicitation amendments that implement Revision 2.
What to do this week
- Don't stop your NIST SP 800-171 work. DFARS 252.204-7012 still applies wherever it's in your contract.
- Keep your SPRS score current and accurate. Self-assessments are still required.
- If you had a C3PAO assessment scheduled, talk to your assessor before canceling. A certification is still valuable with primes.
Sources
- DOD halts cybersecurity requirements for CMMC Phase 2: 'The math just simply doesn't math' (DefenseScoop, July 13, 2026)
- Pentagon suspends CMMC phase two requirements, launches review of program (Federal News Network, July 2026)
- What Defense Contractors Should Know About DoD Suspension of CMMC Phase 2 (Latham & Watkins, July 30, 2026)
- Class deviations list (Defense Pricing, Contracting, and Acquisition Policy)
- Revolutionary FAR Overhaul announcements (Warrant University)
- Pentagon task force to review CMMC hits the ground running (DefenseScoop, July 17, 2026)
- Statement on the Department of War's Suspension of CMMC Phase II Requirements (The Cyber AB, July 15, 2026)
- CMMC Phase II Suspension – Stay the Course (Elbit Systems of America, July 16, 2026)
This briefing summarizes public sources for general awareness. It is not legal advice. Check the linked primary sources before acting on any item.