Why CMMC Phase 2 Was Paused - And Why Nobody Should Be Surprised
On July 13, 2026, the DoD suspended the mandatory C3PAO assessment requirement for CMMC Level 2. The stated reason: too many contractors, too few assessors, and a $7 billion annual cost estimate the small business community could not absorb. Here is the full picture.
On July 13, 2026, the Department of Defense suspended Phase 2 of the CMMC program - the mandatory third-party C3PAO assessment requirement that was scheduled to take effect November 10, 2026. A CMMC Reform Task Force now has 60 days to review the program and report back to the DoD CIO.
Reactions ranged from relief to frustration to confusion. But for anyone who has worked inside the defense industrial base, the honest reaction is: of course it was.
The Math Never Worked
When the DoD suspended Phase 2, their own CIO used a striking phrase to describe the situation: "the math just simply doesn't math." That is an unusually candid admission from a federal agency, and it points directly to the core problem that has plagued CMMC since the program began in 2019.
Do the math yourself. Even if every C3PAO ran back-to-back assessments 50 weeks a year, the capacity to assess 100,000 contractors simply did not exist. The assessor ecosystem was never built out at the scale the program required. Small businesses were being asked to spend tens of thousands of dollars on assessments for programs they were not sure they would win, with a shortage of assessors that meant scheduling waits of 6 to 12 months or more.
110 Practices Is a Lot for a Machine Shop
CMMC Level 2 maps to all 110 practices from NIST SP 800-171 Rev 2. This is the right standard for protecting Controlled Unclassified Information. The practices are technically sound. But the implementation reality for a 12-person aerospace machining company or a small defense electronics manufacturer is brutal.
These are organizations that may have one IT person, or no dedicated IT person at all. They are being asked to implement and document:
- 22 Access Control practices including MFA for all remote access, wireless access controls, and mobile device management
- 9 Audit and Accountability practices including SIEM-level log retention, alerting, and analysis
- 9 Configuration Management practices including documented baselines for every system
- 16 System and Communications Protection practices including FIPS-validated encryption at rest and in transit
And beyond implementing the controls, they need to document them at a level that satisfies a trained C3PAO assessor. The System Security Plan alone - the master document that describes how all 110 practices are implemented - is a multi-hundred-page deliverable when done properly.
The documentation burden is real. A properly documented CMMC Level 2 implementation includes an SSP, a POA&M, 12 domain-specific policies, network diagrams, evidence packages, and configuration records. Most small businesses do not have the internal resources to produce this without outside help.
A Program That Has Been Revised Since Before It Launched
CMMC was first proposed in 2019. It has since been through: CMMC 1.0, a major restructuring to CMMC 2.0 in 2021, the final rule published in October 2024, Phase 1 implementation in November 2025, and now a Phase 2 suspension in July 2026.
Every revision created uncertainty. Contractors who invested in CMMC 1.0 preparation had to restart when 2.0 changed the structure. Contractors who started preparing for C3PAO assessments are now in limbo waiting for the Reform Task Force report. The cumulative cost of these false starts - consultant fees, infrastructure investments, documentation time - has been significant.
There was also a fundamental gap in implementation guidance. NIST SP 800-171 describes what controls are required. NIST SP 800-171A describes how assessors evaluate them. But for a small manufacturer trying to figure out exactly how to configure their Microsoft 365 tenant to satisfy practice 3.3.2, or how to document their configuration baseline in a way that will pass assessor scrutiny, the official guidance left a lot of room for interpretation - and a lot of room for expensive consultants to fill.
What the 60-Day Review Is Actually Evaluating
The CMMC Reform Task Force is reportedly looking at several structural questions:
- Whether the current assessment model (C3PAO third-party) is the right mechanism for all Level 2 contractors, or whether tiered approaches make more sense
- Whether the scope of practices is appropriately calibrated to the actual CUI risk level of different contractor categories
- How to expand the assessor ecosystem faster - currently a bottleneck that cannot be solved quickly
- Whether shared assessment infrastructure or DoD-sponsored resources could reduce per-contractor costs
A public Request for Information is open until August 14, 2026. Industry comments submitted before that date will inform the Task Force's recommendations.
Where This Leaves the Program
The Phase 2 suspension is not CMMC being canceled. The DoD has been clear that cybersecurity requirements for the defense industrial base are not going away - the question is the mechanism and timeline. The underlying legal basis (DFARS 252.204-7012 and the NIST SP 800-171 obligations it references) remains unchanged. Phase 1 self-assessments and SPRS score submissions are still required.
The most likely outcome from the Task Force review is a revised Phase 2 timeline with some structural adjustments - possibly different assessment tracks for different contractor sizes, possibly phased requirements by CUI sensitivity level, possibly increased DoD support for small businesses. A full cancellation of cybersecurity requirements for CUI-handling contractors is not a realistic outcome.
The pause is on C3PAO assessments, not on NIST 800-171 compliance. If you are a defense contractor handling CUI, you still have contractual obligations. The next post covers exactly what those are - and what happens to contractors who treat the pause as permission to ignore their security posture.
Still Need to Document Your CMMC Controls?
The pause changed the assessment timeline, not the underlying requirements. The Complete Certification Kit gives you the SSP, POA&M, and all 12 domain policies to document your implementation now - before Phase 2 resumes.
View the Certification Kit - $299