Skip to content

CMMC Phase 2 Is Suspended. What Should a Supplier Do Now?

By Donovan Brown
August 19, 2026
15 sections
CMMC Phase 2 Is Suspended. What Should a Supplier Do Now?

The CMMC Phase 2 suspension changed when you are assessed, not whether you must comply. DFARS 252.204-7012 is untouched. Here is how a defense supplier should spend the pause.

01

Introduction

On 13 July 2026 the Department of War suspended the CMMC Phase 2 transition and stood up a reform task force. Two conversations promptly started inside defense suppliers across Texas. One was compliance is cancelled. The other was buy an assessment before the window shuts. Both are wrong, and both cost real money.

The suspension changed when you get assessed, not whether you have to comply. DFARS 252.204-7012 is untouched, so if that clause is in your contract, your NIST SP 800-171 obligations are live today exactly as they were on 12 July. What the pause hands you is time.

02

What the Department actually suspended

The action is narrow, and the narrowness matters more than the headline:

  • Third-party and government-led assessment mandates are paused. Requiring activities may designate only Level 1 (Self) or Level 2 (Self) in new procurements.
  • Level 2 (C3PAO) and Level 3 (DIBCAC) may not be designated while the suspension is in effect.
  • No waivers are being granted under the program during the review.
  • Open solicitations are being amended, and contracting officers were directed to strip suspended levels from existing contracts by modification, generally before the next option exercise.
  • A reform task force is running a 60-day review, with an industry request for information that closed in August 2026.

The Department's own memo described the program as imposing what it called significant and often prohibitive burdens on contractors, naming small businesses specifically. That framing tells you the review is genuine, not that the requirement is going away.

03

Why this is not a rule change

This is the structural point most of the market is missing. The suspension is an executive action, implemented through Department memoranda directing how requiring activities and contracting officers behave. Nobody amended 32 CFR Part 170 and nobody withdrew the DFARS clause, so nothing has to be re-noticed or re-published for the mandates to return. A memo can restart what a memo paused, which means treating this as a permanent repeal bets a contract vehicle on the durability of an internal policy decision. For the framework in plain language, see our explainer on what CMMC 2.0 actually is.

04

What did not change at all

Everything below is as binding today as it was on 12 July:

  • DFARS 252.204-7012, including the safeguarding requirement and 72-hour cyber incident reporting.
  • NIST SP 800-171 implementation across all 110 security requirements for systems that process, store, or transmit CUI. Our NIST 800-171 compliance overview walks the families.
  • SPRS score submission and maintenance. Your posted score is still the number the government sees.
  • Annual affirmations by a senior official, which carry real legal weight because an affirmation is a representation to the government.
  • Flowdown under DFARS 252.204-7021, which sits in paragraph (f) and applies when a subcontractor will process, store, or transmit FCI or CUI on its own systems.

Read that list with False Claims Act exposure in mind. The assessment would have caught an inaccurate score; the affirmation is what creates liability. The suspension removed the first and left the second intact, so self-assessment honesty matters more now, not less.

05

The two failure modes to avoid

Treating the pause as a repeal

Programs get shelved. Budget moves. The engineer carrying the SSP gets pulled to a revenue project. Eighteen months later the requirement returns on a compressed timeline, and you are competing for assessment capacity against everyone else who also stopped.

Panic-buying an assessment

Other suppliers are rushing to lock in a C3PAO engagement as insurance. Consider what you are buying: the Department currently cannot designate Level 2 (C3PAO), so no contract today requires that certificate, and the task force may change the assessment construct itself. The right posture sits between the two, which is to build the substance and defer the ceremony.

06

Rev 2 still governs, and upgrading can hurt you

Here is a trap that catches sophisticated teams. CMMC Level 2 is assessed against NIST SP 800-171 Revision 2 and the SP 800-171A assessment guide dated June 2018. NIST withdrew both on 14 May 2024, but they remain binding for CMMC because the program rule incorporates them by fixed-date reference. So a contractor who sees Rev 2 marked withdrawn and rebuilds around Revision 3 can end up failing on requirements Rev 3 dropped or reworded. Rev 3 is not a superset, and changing the anchor reference would take rulemaking that has not happened.

  • Build to Rev 2. Map to Rev 3 in a separate column if you like, but do not retire a Rev 2 control because Rev 3 no longer lists it.
  • Assess against 800-171A (June 2018), whose objectives, not the top-level control text, are what a verdict is written against. A requirement is met only when every objective is met.

Our CMMC vs NIST CSF comparison shows where the two diverge.

07

Use the pause to scope the enclave properly

Scoping is where the money is, and it is almost always done badly under deadline pressure. A supplier racing a date declares the whole network in scope because that beats proving what is out, then pays to secure and document systems that never touched CUI.

  • Find the CUI first, not the systems. Trace actual deliverables, drawings, and specifications: where they enter, rest, and leave.
  • Draw a boundary you can defend with evidence, then enforce it technically rather than by policy statement.
  • Classify honestly. CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets carry different obligations.
  • Shrink before you spend. Every host legitimately moved out permanently cuts cost, evidence burden, and audit surface.

Our CUI field guide for CMMC covers marking, handling, and boundary decisions, and the CMMC self-assessment tool gives you a baseline in minutes.

08

Build the SSP, then a remediation plan you can defend

A System Security Plan describes a real system a stranger has to be able to follow. Most fail because they describe an intended architecture rather than the one that exists.

  • Write it against the deployed configuration. If the SSP says conditional access enforces MFA on all remote sessions, the policy screenshot has to match.
  • Name owners, not departments. Assessors ask who does this, and how often.
  • Version it. An SSP with no change history is one nobody maintains.

Then write an honest Plan of Action and Milestones. The pull toward inflating a SPRS score is strong, and the suspension strengthens it because the external check went away. An affirmation resting on a score you cannot substantiate is the fact pattern that turns a security gap into a fraud allegation. Our CMMC self-assessment guide walks the scoring methodology, and the compliance gap analysis calculator sequences the findings.

09

Deploy access control for real, not on paper

Access control and authentication are where paper compliance and deployed reality diverge most. Two items deserve the pause time:

  • MFA everywhere it is required, including the awkward places. Remote access and privileged accounts are obvious. Legacy applications, service accounts, vendor VPN tunnels, and the ERP that predates modern identity are where the gaps live. A written MFA policy is the start, not the finish.
  • Privileged access that is actually least privilege. Standing domain admin on daily-driver workstations is one of the most common findings in defense supply chain environments. Privileged access management removes standing rights, brokers elevation, and produces the session records assessors ask for. Our PAM service covers the rollout.

Both satisfy a cluster of 800-171 requirements, and both are among the controls most likely to stop an intrusion before it becomes a reportable incident.

10

Run a restore test, not a backup report

Almost every supplier can produce a green backup dashboard. Far fewer can produce a dated record of a restore a human actually performed and verified.

  • Restore a real CUI-bearing system to a clean target and confirm the data is usable, not just that files copied.
  • Time it against what your contract and business can tolerate.
  • Verify the copy an attacker cannot reach, immutable or offline, with credentials separate from production.
  • Record who did it, when, and what broke. The failures are the valuable part.

We cover the mechanics under backup and recovery and disaster recovery, and our first 72 hours guide maps the ransomware sequence.

11

Stop paying for controls CUI never required

A meaningful share of defense compliance spending goes to protections the regulation never asked for, sold on fear. CUI is unclassified, and that single fact eliminates a long list of expenses:

  • No SCIF. A sensitive compartmented information facility protects classified material.
  • No TEMPEST countermeasures, shielded rooms, or emanations testing.
  • No GSA-approved security container. A locked office or lockable cabinet with controlled keys satisfies physical protection for CUI documents.
  • No NSA-listed high-security shredder. A commercial cross-cut shredder meeting the destruction standard is sufficient.
  • GCC High is not universally mandatory. What forces a sovereign or restricted cloud is ITAR or other export-controlled data, not CUI as a category, and many suppliers meet the requirement in properly configured commercial Microsoft 365. Where export control does apply, our ITAR compliance service addresses it.

Every dollar moved from theatre to real controls improves both your SPRS score and your posture.

12

Your prime is the real near-term deadline

Primes do not wait for the Department. Expect questionnaires, requests for your SPRS score and affirmation status, and sometimes a readiness commitment by the prime's chosen date. A supplier who can hand over a current SSP, a credible POA&M, and a substantiated score is commercially far stronger than one who says the program is paused. That is the best near-term case for doing the work now, whether you are a precision manufacturer or an engineering firm.

13

Where to Start

If you do nothing else with the window, do these six things in order:

  • 1. Confirm which clauses you hold. Note whether 252.204-7012 and 252.204-7021 appear in each active contract, and watch for modifications removing suspended levels.
  • 2. Locate your CUI, not your systems. Everything downstream depends on getting this right.
  • 3. Draw and enforce the enclave boundary, shrinking it as far as the evidence supports.
  • 4. Score yourself honestly against Rev 2 using the 800-171A objectives, and update SPRS to match reality.
  • 5. Close access control and recovery gaps first. MFA, privileged access, and a verified restore test buy the most risk reduction per dollar.
  • 6. Put a named owner and a review cadence on the SSP and POA&M so the program outlives whoever wrote it.

For an outside read before committing budget, a free IT assessment is the fastest option. Our CMMC compliance services and security assessments cover scoping through evidence collection, and fractional security leadership supplies the governance layer the affirmation requirement assumes you have. LayerLogix brings 20+ years of experience and 100% Texas-based support, with business-hours support and after-hours emergency response backed by automated 24/7 monitoring.

14

Frequently Asked Questions

Does the CMMC suspension mean I can stop working on compliance?

No. The suspension pauses third-party and government-led assessment mandates only. DFARS 252.204-7012 is untouched, so your NIST SP 800-171 obligations, SPRS score submission, annual affirmation, and 72-hour incident reporting continue as before. What changed is when you are assessed, not whether you must comply.

Should I schedule a C3PAO assessment now to get ahead?

Generally no. During the suspension the Department cannot designate Level 2 (C3PAO) or Level 3 (DIBCAC), so no current contract requires that certificate and no waivers are granted. The task force may also change the assessment construct. Spend the window on scoping, your SSP, and real controls.

Can the suspension be reversed without new rulemaking?

Yes, and this is the key planning assumption. It was implemented through Department memoranda, which makes it an executive action rather than a regulatory change. Because 32 CFR Part 170 and the DFARS clauses were never amended, the assessment mandates can restart without any notice-and-comment rulemaking process.

Should I upgrade my program from NIST 800-171 Rev 2 to Rev 3?

Not as a replacement. CMMC Level 2 is assessed against Rev 2 and the June 2018 SP 800-171A guide, both incorporated by fixed-date reference even though NIST withdrew them on 14 May 2024. Rebuilding around Rev 3 can make you fail on requirements Rev 3 dropped. Build to Rev 2 and treat Rev 3 as a mapping exercise.

Do I need GCC High and a SCIF to handle CUI?

No to both. CUI is unclassified, so a SCIF, TEMPEST countermeasures, a GSA-approved container, and an NSA-listed shredder are not required. GCC High is not universally mandatory either. What actually forces a restricted government cloud is ITAR or other export-controlled data, and many suppliers meet the requirement in properly configured commercial Microsoft 365.

15

Geographic Coverage

LayerLogix supports defense suppliers, machine shops, and engineering firms across Texas from our headquarters at 2001 Timberloch Place in The Woodlands and our Round Rock office. We deliver CMMC and NIST 800-171 work through CMMC compliance in Houston and Clear Lake near the Johnson Space Center, across North Texas in Fort Worth and the wider DFW metroplex, and throughout the northern Houston suburbs from The Woodlands. Call 713-571-2390 in Greater Houston, 214-617-2370 in DFW, or 512-829-1981 in Austin.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call