August 5, 2026

    CMMC Phase 2 Is Paused, Not Cancelled. Here's What That Actually Means for You

    If you sell to, or contract with, the Department of Defense, you've probably recently heard some version of: "CMMC is dead." "It's cancelled." "We don't have to worry about this anymore."

    None of that is true, and treating it as true could cost your organization a lot more than the price of a certification.

    Here's what actually happened, what it means for your compliance obligations right now, and how to use this window to your advantage instead of letting it lull you into a false sense of security.

    Is CMMC Cancelled? No. Here's What Actually Got Paused

    On July 13, the Department of Defense announced an approximately 60-day suspension of the CMMC Level 2 third-party certification requirement. This piece of the process, known as C3PAO assessment, was set to become mandatory in new contracts starting this November.

    That's it. That's the pause.

    The DoD is using this window as a task force period to evaluate whether the current Level 2 third-party assessment approach is still the right path forward. Any significant change to that approach would still have to go through a lengthy federal rulemaking process — meaning this isn't something that can be undone or replaced overnight, regardless of how the announcement gets summarized in a LinkedIn post.

    What's paused is the validation mechanism. What's not paused is everything CMMC was built to validate in the first place.

    Do I Still Need to Comply with DFARS 7012 and NIST 800-171?

    This is the part that gets lost in the noise, and it's important to put into perspective: CMMC certification was never the source of your security requirements. It's the check.

    The actual requirements — DFARS 252.204-7012 and NIST SP 800-171 — have been in place for years, independent of CMMC, and are still fully in force. If your contracts require you to protect Controlled Unclassified Information (CUI), you are still required to:

    • Meet the 110 security controls in NIST 800-171
    • Maintain an accurate System Security Plan and Plan of Action & Milestones
    • Submit and maintain your score, with supporting evidence, in the Supplier Performance Risk System (SPRS)

    None of that goes away during the pause. If anything, it becomes more important, because the third-party stamp of approval that used to back up your self-attestation isn't there right now, which means your own evidence needs to hold up on its own.

    Enforcement hasn't paused either. The Department of Justice can still pursue False Claims Act violations against companies that misrepresent their compliance status, and DIBCAC medium and high assessments are still happening. Penalties for a false attestation can be severe, and in some cases may exceed a company's total revenue. There have been recent, real DOJ settlements involving companies that self-reported a perfect score while their actual environment scored well below zero.

    One more wrinkle: a pause from the DoD doesn't bind prime contractors. Many primes flow CMMC requirements down to their subcontractors as a condition of the subcontract, entirely independent of what the DoD requires directly. If your customer is a business that sells to the government rather than the government itself, this pause may mean nothing at all to their contractual obligations. It's worth asking, plainly: is your customer the DoD, or are they upstream of the DoD?

    Frameworks Will Keep Shifting, But NIST Is Your Anchor

    CMMC as a label is relatively new and, frankly, more recognizable than the regulation underneath it. DFARS 7012 has quietly existed for years, doing the actual work of setting the bar. CMMC is simply the mechanism for checking whether organizations are meeting that bar.

    That distinction matters more with every news cycle like this one. Compliance frameworks and certification programs are political and administrative constructs: they can be paused, restructured, or renamed depending on what a task force deems appropriate. What they're built on top of, in this case NIST 800-171, is far more stable and far less likely to move.

    If you find yourself unsure what a given announcement actually changes, the reliable move is to go back to the underlying standard rather than the headline. In this case: has NIST 800-171 changed? No. Has DFARS 7012 changed? No. Then your obligations haven't changed, whatever else is happening around the edges.

    Expect more noise before this settles. There are CMMC-focused conferences this fall that will likely generate their own share of speculation, and the DoD's task force review is expected to produce an update by mid-September. Some of that could mean adjusted assessment costs, revised timelines, or other procedural changes. What it's very unlikely to mean is the disappearance of the underlying security requirements themselves.

    CMMC Checklist-1

    Why a SIEM Still Matters

    The window between now and mid-September isn't a reason to wait. It's actually the best time you'll get to build the logging, detection, and a trail that makes your self-assessment defensible, before anyone is checking.

    Organizations that treat this as "we can relax" will be behind when assessments resume, and they'll be exposed to DIBCAC review and False Claims Act risk in the meantime with no certification to point to if questions come up. Organizations that treat this as "we finally have breathing room to get ahead of it" will walk into whatever comes next in a materially stronger position: closer to assessment-ready, with clearer evidence, and without the scramble.

    That's why your SIEM still matters. Blumira gives manufacturers the SIEM, the log retention, and the documented response trail that makes a self-assessment credible — not just submitted.

    • Centralized, 1-year of hot log storage, a core piece of demonstrating you can actually produce evidence, not just assert a score. If someone asks you to produce logs from two months ago, can you get there in minutes?
    • Coverage mapped to real detection needs, so you're not guessing at whether your current tooling actually supports the controls you're attesting to.
    • A clearer picture of your security posture, so your SPRS score reflects your actual environment and not a best guess. That score is exactly what regulators and prime contractors will be looking at.

    The smartest use of this window is closing the gap between where your environment stands and where your attestation says it stands, before someone else checks for you.

    Frequently Asked Questions

    Is CMMC cancelled? No. The DoD has paused the Level 2 third-party certification (C3PAO assessment) requirement for approximately 60 days while a task force evaluates the process. The underlying security requirements have not been cancelled.

    Do I still have to comply with NIST 800-171 during the CMMC pause? Yes. NIST 800-171 and DFARS 7012 exist independently of CMMC and remain fully in force. CMMC certification is the validation step; it was never the source of the requirement itself.

    Can I stop submitting my SPRS score during the pause? No. You're still required to submit your self-assessment score to the Supplier Performance Risk System (SPRS) along with supporting evidence, even without a third-party assessor involved.

    What happens if I ignore the pause and don't stay compliant? You remain exposed to DIBCAC assessments and False Claims Act enforcement from the Department of Justice. Penalties for a false attestation can be severe, and there are documented cases of companies facing major consequences for self-reported scores that didn't match their actual environment.

    Do prime contractors still require CMMC from subcontractors during the pause? Many do. The DoD pause applies to what the government itself requires, but prime contractors can independently choose to keep CMMC requirements in their subcontracts. If your customer isn't the DoD directly, ask whether their own contract terms have changed — the DoD's pause may not affect them at all.

    When will CMMC Phase 2 resume? The DoD's task force review is expected to produce an update around mid-September 2026, though any structural changes to the assessment process would still require federal rulemaking, which takes considerably longer.

    Have questions about how CMMC may apply to your environment? Talk to your Blumira team today! We're happy to walk through what's changed, what hasn't, and where to focus next.

    More from the blog

    View All Posts