The short answer
The Department’s July 13, 2026 announcement suspended the planned expansion of CMMC Phase II, which had been scheduled to begin November 10, 2026. It did not cancel CMMC, erase Phase I, or waive cybersecurity duties already imposed by a solicitation, contract, subcontract, or other applicable requirement.
For a small or midsized defense contractor, the practical response is not “stop CMMC.” It is:
- identify which clauses and flow-downs actually govern each opportunity and active contract;
- keep required safeguards and incident-response duties operating;
- maintain truthful, reproducible assessment evidence; and
- avoid expensive certification-only work until the required assessment path is clear.
This article explains the current public position as of September 21, 2026. It is practical cybersecurity guidance, not legal advice. Contracting officers and qualified counsel should resolve contract-specific ambiguity.
What the Department paused—and what it did not
The official July 13 Department release announced the immediate suspension of Phase II requirements and a comprehensive review of CMMC. Phase II would have expanded use of Level 2 C3PAO assessments beginning November 10, 2026. The same release said Phase I self-assessment requirements remained in effect and emphasized that the change did not remove the obligation to protect federal information.
As of September 21, 2026, HostBreach has not located a later official public announcement that replaces that July direction with a new Phase II start date or final reform design. Do not infer a new deadline from commentary or from the passage of the announced review period. Check current official guidance and the exact acquisition documents that apply to your organization.
The distinction matters because CMMC is only one layer of the contractor cybersecurity picture. The current CMMC program rule in 32 CFR part 170 defines the program, assessment levels, scope concepts, and phased implementation framework. Contract clauses determine what a contractor must do for a specific award.
Five duties that may still apply during the Phase II pause
1. Follow the clauses in the solicitation, contract, and flow-down—not a headline
Build an obligations register for every relevant opportunity and active contract. At a minimum, record:
- the solicitation or contract number;
- the clauses and provisions included;
- the CMMC level or status stated, if any;
- whether the work involves Federal Contract Information (FCI), Controlled Unclassified Information (CUI), covered defense information, or operationally critical support;
- the contractor systems expected to handle that information;
- subcontractor and external-service-provider dependencies; and
- the contracting officer or prime-contractor questions that remain unresolved.
This prevents two opposite mistakes: continuing to fund an assessment path that no longer applies to the opportunity, or assuming the Phase II pause removed duties that remain in the contract.
The current DFARS 252.204-7021 text requires a contractor, when the clause and a specified level are included, to maintain the required CMMC status for systems used in performance that process, store, or transmit FCI or CUI. It also addresses annual affirmations, reporting, and subcontract flow-downs. Whether those terms bind your company depends on the acquisition document—not on the fact that the clause exists online.
HostBreach recommendation: treat the contract matrix as the first page of the readiness plan. Label each item “confirmed,” “assumed,” or “needs written clarification.” Do not let a vendor proposal quietly convert an assumption into a requirement.
2. Protect covered defense information under DFARS 252.204-7012 when it applies
DFARS 252.204-7012 remains a separate safeguarding and cyber-incident-reporting clause. For covered contractor information systems, it requires adequate security and, in the circumstances described by the clause, implementation of the applicable NIST SP 800-171 security requirements.
The clause also contains operational duties that are easy to overlook during a policy transition:
- review certain incidents for evidence of compromise;
- rapidly report covered cyber incidents to DoD—defined by the clause as within 72 hours of discovery;
- preserve specified system images and relevant monitoring or packet-capture data for at least 90 days after the report;
- submit malicious software to DC3 when directed by the clause; and
- provide additional information or equipment if DoD requests it for forensic analysis.
Those duties do not turn on whether a C3PAO assessment is currently required for the next award.
HostBreach recommendation: test the reporting process before an incident. Confirm who can decide that an event is reportable, who can access the reporting portal, who preserves evidence, how counsel and leadership are notified, and how the team meets the 72-hour window without guessing.
3. Keep Phase I and any current self-assessment obligations accurate
The July announcement preserved Phase I. The program rule and DFARS 252.204-7021 describe self-assessment results, current CMMC status, CMMC unique identifiers, and annual affirmations when those requirements apply to a contract.
A self-assessment is not a paperwork substitute for implementation. It should be supportable by the actual environment, the System Security Plan (SSP), and evidence that authorized personnel can reproduce and explain. If the system, provider, data flow, or boundary changes, determine whether the assessment and affirmation still reflect reality.
The CMMC rule currently incorporates NIST SP 800-171 Revision 2 for Level 2. NIST has published later revisions, but the applicable standard is the one required by the governing rule and contract. Do not silently remap an assessment to a different revision because a newer publication exists.
HostBreach recommendation: maintain an evidence index that ties each claimed implementation to the system boundary, responsible owner, artifact, and last validation date. This makes the self-assessment defensible and reduces the cost of future assessment preparation.
4. Continue the correct flow-downs and supplier checks
The Phase II pause does not make the supply chain disappear. DFARS 252.204-7012 requires the substance of that clause to be included in certain subcontracts or similar contractual instruments involving operationally critical support or covered defense information. DFARS 252.204-7021 contains separate CMMC flow-down language when that clause applies.
Small businesses should review both directions:
- Downstream: What information will your subcontractors receive, what clauses must flow down, and what evidence must be obtained before award?
- Upstream: What did the prime contractor actually flow to you, and does its questionnaire or portal request go beyond the written subcontract?
Do not send CUI to a supplier while the parties are still debating whether the supplier is allowed to receive it. Do not treat a completed questionnaire as proof that the recipient’s environment is authorized for the information.
HostBreach recommendation: connect procurement, program management, security, and legal review before information is released. Record the information category, required protection, approved transfer method, recipient environment, and the contractual basis for the decision.
5. Preserve readiness without buying an assessment you cannot yet justify
The pause creates a budgeting problem, not a reason to abandon security. Some contractors were preparing for a third-party assessment that may no longer be required on the original schedule. Others remain subject to Phase I self-assessment, safeguarding, incident reporting, prime-contractor expectations, or contract-specific CMMC terms.
A defensible middle path is to preserve assessment readiness while sequencing work around confirmed obligations and real risk:
- keep the SSP, scope, asset inventory, and data-flow records current;
- remediate security gaps that matter even if the assessment calendar changes;
- retain evidence in a form that can support a self-assessment or later third-party review;
- delay nonrefundable assessment scheduling until the requirement and timing are supportable; and
- separate security implementation costs from certification-event costs.
This protects option value. If Phase II returns in a revised form, the organization is not rebuilding from zero. If the assessment path changes, the company has still strengthened the systems and processes that protect contract information.
A 30-day decision plan for small defense contractors
Days 1–5: establish the governing facts
Inventory active contracts, options, solicitations, and prime flow-downs. Record applicable clauses, information types, stated CMMC status, and unresolved questions. Ask for written clarification where the document is ambiguous.
Days 6–10: validate scope and information flow
Trace where FCI, CUI, and covered defense information enter, move, and leave the organization. Confirm the people, systems, locations, service providers, and subcontractors that support the work.
Days 11–20: test high-consequence operating duties
Run a tabletop for cyber-incident reporting and evidence preservation. Review access to reporting systems, escalation paths, backups, identity administration, external exposure, and supplier handoffs.
Days 21–30: update the evidence-backed roadmap
Reconcile the SSP, assessment results, scope diagrams, provider responsibilities, and remediation plan. Separate:
- work required by a current contract;
- work needed to make a self-assessment accurate;
- security improvements justified by risk; and
- future certification preparation that depends on policy or acquisition decisions not yet final.
Leadership should leave the month with named owners, dates, dependencies, and a clear explanation of why each expenditure exists.
The HostBreach position
HostBreach is a threat-informed CMMC advisory firm for small and midsized defense contractors. We help organizations determine what applies, define a supportable CUI boundary, assess readiness, prioritize remediation, and build evidence that reflects the operating environment.
Our CMMC Cyber Snapshot and proprietary Cyber Intel Engine provide the outside-in intelligence layer within that work. They do not replace internal validation, determine assessment scope, prove compliance, or establish compromise. HostBreach is not a C3PAO and does not issue CMMC certifications.
If the Phase II pause has left your team unsure what to continue, pause, or validate, start with HostBreach CMMC Advisory. We can help turn contract language, CUI flow, security reality, and evidence into a prioritized readiness plan.
Primary sources
- Department release: Forging the Arsenal of Freedom—Department Suspends CMMC Phase II Requirements (July 13, 2026)
- 32 CFR part 170—Cybersecurity Maturity Model Certification Program
- DFARS 252.204-7012—Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7021—Contractor Compliance With CMMC Level Requirements
- NIST SP 800-171 Revision 2
Source and interpretation note
Prepared September 21, 2026. Official requirements are attributed to the linked Department release, regulations, clauses, and NIST publication. Sections labeled “HostBreach recommendation” and the 30-day plan are HostBreach analysis, not government requirements or a prediction of the CMMC reform outcome. Contractors should verify the latest official guidance and their own acquisition documents before changing compliance commitments.
