
CMMC Phase 2 Is Paused — But the Cyber Obligation Just Went Government-Wide
Compliance Pulse · Thursday, July 16, 2026
Most contractors read "CMMC Phase 2 suspended" as one word: relief. That reading will cost some of them money. In the same nine-day window the Pentagon paused third-party certification, the FAR Council proposed extending the underlying standard — now NIST 800-171 Revision 3 — to every federal contractor that touches CUI. The obligation did not shrink. It generalized.
The Pentagon Paused the Assessment — Not the Requirement
On July 13, the Department of War suspended CMMC Phase 2 — the third-party C3PAO certification milestone set to begin November 10, 2026 — effective immediately and opened a 60-day reform review. CIO Kirsten Davies was direct: "We are not reducing cybersecurity. We are reducing the red tape."
What did not move is the part that binds. Phase 1 self-assessments, SPRS scores, and annual affirmations stay in force. DFARS 252.204-7012 — safeguard covered defense information, implement NIST 800-171, report incidents within 72 hours, flow the clause down to subs — is untouched. Government-led DIBCAC assessments continue. And DOJ's Civil Cyber-Fraud Initiative keeps building False Claims Act cases on inaccurate self-attestation, no breach required — the June 18 LOGZONE settlement is the reminder, part of more than $80 million recovered since 2021.
Bottom line for DIB contractors: The certification step is paused. The obligation to protect CUI — and to prove it when the government asks — is not.
The Same Standard Just Went Government-Wide
Nine days before the pause, the FAR Council published a proposed rule (FAR Case 2026-001, comments due July 23) that extends CUI safeguarding beyond defense for the first time. Every federal contractor and subcontractor handling CUI — civilian or not, regardless of contract value — would implement NIST 800-171, and the rule moves the bar to Revision 3, not the Revision 2 most programs are built on. New clauses (FAR 52.240-6 and -7), a per-procurement form that finally identifies the CUI a contract covers, 72-hour reporting to CISA, and flow-down to every tier come with it.
Read the two events together and the direction is one movement: the Department of War is rethinking how it verifies the standard while the government extends that standard to everyone.
Bottom line for civilian-agency contractors: The DIB baseline you assumed did not apply to you is becoming your baseline. Revision 2 to Revision 3 is a gap to close now, not after the rule finalizes.
What This Means for Contractors and the Boardroom
Two developments, one direction: the compliance checkpoint is under review while the security obligation expands. Confusing the two is where money leaks — canceled remediation, System Security Plans left to lapse, self-attestations DOJ can later call false. The 60-day review is the cheapest window a contractor gets to close 800-171 gaps before verification resumes or the FAR rule finalizes. The pause is runway, not an exit. The same baseline is generalizing in maritime, where the USCG MTS cyber rule turns one year old today and its plan-and-assessment obligations move from paper to proof.
Security is the asset that keeps you contract-eligible. Compliance only confirms it — and right now, your own self-attestation is the proof the government is checking.
If you hold federal contracts, are you treating the CMMC pause as relief or as runway? And for the shops that sit in both DIB and civilian work, how are you mapping Revision 2 to Revision 3? I'd like your read.