Estimated reading time: 4-5 minutes
On July 13, 2026, the Department of Defense announced the immediate suspension of CMMC Level 2 Phase II requirements, including the planned November 10, 2026 transition. The suspension does not mean that CMMC has disappeared. Contractors still have obligations to protect federal data. DFARS 252.204-7012 still matters. NIST SP 800-171 Rev. 2 still matters for contractors handling Controlled Unclassified Information.
What changed is the timing and enforcement path for the next phase of CMMC implementation. During the suspension period, DoD guidance says program managers and requiring activities may only designate CMMC Level 1 Self or CMMC Level 2 Self assessment requirements. They may not designate CMMC Level 2 C3PAO assessments or CMMC Level 3 DIBCAC assessments during this period.
That distinction matters. The government has paused the more burdensome third-party certification ramp-up, but it has not told contractors to stop protecting defense information.
Why DoD Hit Pause
DoD described the suspension as part of a broader review aimed at reducing barriers for small, medium, and non-traditional businesses. The Department said the current program had created prohibitive compliance costs and bureaucratic burdens, and it specifically cited recent data, including reports from the Small Business Administration, showing that CMMC compliance was pushing innovative companies out of the Defense Industrial Base.
SBA’s own statement was even more direct. SBA said the suspension followed months of engagement between DoD, SBA, and small business stakeholders. It also said small businesses warned that the current CMMC framework imposed costly burdens on small contractors that are essential to growing the Defense Industrial Base.
In other words, this was not just a cybersecurity policy decision. It was also an industrial-base decision. DoD appears to be asking whether the CMMC certification structure, especially the third-party assessment requirement, was becoming a barrier to competition, innovation, and supplier participation.
CMMC Level 2 Grant Program Proposal Was a Warning Sign
The suspension also comes shortly after Senate Armed Services Committee language that would create a CMMC grant program for small businesses and nontraditional contractors. That proposal would provide grants of up to $100,000, with total program funding capped at $50 million, to offset direct costs associated with a CMMC Level 2 third-party assessment.
That proposed grant program is not law yet. Contractors should not treat it as available funding. But it is an important signal.
Congress was already recognizing that CMMC Level 2 assessment costs could keep small businesses from competing for DoD work. The proposed grant would focus on the direct cost of the C3PAO assessment, not necessarily the full cost of building, documenting, and maintaining a compliant cybersecurity program. That matters because a grant might help with the assessment bill, but it would not automatically solve every readiness gap. Contractors may still need to address system security plans, access control, incident response, documentation, training, vendor management, and evidence collection before an assessment is worthwhile.
The C3PAO Price Tag Became Part of the Policy Problem
For many small businesses, the Level 2 third-party assessment requirement was the pressure point. Coley GCS previously noted that C3PAO evaluation costs alone can often run from tens of thousands of dollars into six figures depending on company size and complexity. SBA’s July 13 statement put the broader cost concern in even sharper terms, estimating total compliance costs at approximately $593,800 per CMMC certification for small firms requiring third-party assessment.
Those numbers help explain why DoD suspended Phase II. The issue was not simply that cybersecurity is expensive. The issue was whether the certification structure was becoming too expensive, too fast, and too dependent on limited assessor capacity. SBA said Phase II would have required more than 120,000 small Defense Industrial Base businesses to seek compliance through a system supported by only about 100 approved assessors. SBA warned that rushing the process could increase assessment costs, delay certification, and lock otherwise qualified suppliers out of defense contracting.
That is the heart of the suspension decision: DoD is trying to preserve cybersecurity requirements while reconsidering whether the certification process itself is creating too much friction for the companies the government needs in the defense supply chain.
What Contractors Should Do Now
Contractors should not confuse a pause in Phase II with permission to stand down. DoD’s implementation memo says baseline compliance with NIST SP 800-171 Rev. 2 will continue through CMMC Level 1 and Level 2 self-assessments and select government-led assessments. Small businesses should use this pause to get practical.
First, confirm whether your company handles Federal Contract Information or Controlled Unclassified Information. That determines whether Level 1 or Level 2 requirements are likely to matter.
Second, separate cybersecurity implementation from assessment cost. The C3PAO review may be paused, but the underlying security work may still be required by contract.
Third, keep your documentation current. A self-assessment is only useful if your system security plan, score, policies, procedures, and evidence are organized enough to support the position you are taking.
Fourth, watch both tracks: DoD’s 60-day review and the Senate CMMC grant proposal. The review may reshape the certification model, while the grant proposal may affect future funding support for small businesses if it survives the NDAA process.
Need Help Understanding the Contract Impact?
Coley GCS helps contractors understand how federal acquisition and compliance changes affect opportunity pursuit, contract readiness, and long-term positioning. If your company is pursuing DoD work, managing a GSA MAS Contract, preparing for a GWAC or IDIQ opportunity, or deciding whether defense work is worth the compliance investment, now is the time to review your path forward.
The best posture is balanced: do not panic, but do not pause all preparation. CMMC Phase II may be suspended, but the government’s expectation that contractors protect federal data remains very much alive.

0 Comments