TL;DR: On July 13, 2026, the Department of War (formerly the Department of Defense) announced an immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements that were scheduled to trigger third-party assessment mandates on November 10, 2026. Secretary of War Pete Hegseth's memo cites prohibitive compliance costs on small defense firms and a severe C3PAO capacity shortage: over 100,000 Defense Industrial Base (DIB) businesses needing third-party assessment against roughly 100 available certified assessors. A 60-day, top-to-bottom CMMC reform task force review is underway. Phase 1 self-assessment requirements that took effect November 2025 remain in force, and the underlying DFARS 252.204-7012 obligation to safeguard Controlled Unclassified Information (CUI) under NIST SP 800-171 is unchanged. For NC's 350-plus defense manufacturers and tier-2 and tier-3 subcontractors across the Piedmont Triad, this is a real cost reprieve, but it is not a green light to defer security investment. This post is the correct-reading playbook.
Key takeaway: The suspension is a pause on external certification, not a pause on the security controls themselves. DFARS 7012 still requires NIST SP 800-171 controls, contracts still require SPRS self-assessment scoring, and cyber insurance renewals still ask about maturity. The right response is to redirect the C3PAO budget into the controls themselves and be ready when the pause ends.
Are you a NC defense contractor uncertain what still applies after the CMMC Phase 2 suspension? Contact Preferred Data Corporation for a same-week defense contractor cybersecurity review. BBB A+ rated. On-site within 200 miles of High Point. Call (336) 886-3282.
What Exactly Did the Pentagon Suspend on July 13, 2026?
The Department of War's July 13, 2026 announcement suspends the Phase 2 third-party assessment mandate under the CMMC program. The suspension is immediate and open-ended pending a 60-day task force review.
Three concrete facts every NC defense contractor should treat as confirmed:
- Phase 2 third-party assessment requirement is paused. The November 10, 2026 date at which CMMC Level 2 contracts would have required a C3PAO-issued certification is no longer in force. Contracting officers will not enforce a Phase 2 certification requirement while the pause is in effect.
- Phase 1 self-assessment remains in force. The November 2025 Phase 1 requirement that contractors handling Federal Contract Information (FCI) at CMMC Level 1 and Controlled Unclassified Information (CUI) at CMMC Level 2 submit annual self-assessments is unchanged.
- DFARS 252.204-7012 is completely unchanged. The underlying contract clause that requires NIST SP 800-171 control implementation, Supplier Performance Risk System (SPRS) score submission, and CUI safeguarding is a separate federal acquisition regulation. It was not part of the CMMC rulemaking and is not affected by the suspension.
The 60-day task force review will produce recommendations on the future of the CMMC program. Outcomes range from a modified CMMC that scales C3PAO capacity, to a fully self-attested model that pushes assessment obligations onto DIB companies themselves, to something new entirely. NC defense contractors should plan for both a modified CMMC and a self-attested model, because the task force could recommend either.
Key takeaway: Read the memo carefully. What is paused: the C3PAO third-party certification requirement and its cost. What is not paused: your existing contractual obligation to implement NIST 800-171 controls, to submit SPRS scores, and to safeguard CUI. If you were already doing the security work, keep doing it. If you were only doing the security work to prepare for the C3PAO audit, this is your window to reset around the actual security value.
Why Did the Pentagon Suspend Phase 2 Now?
The suspension has a stated cost rationale and an unstated capacity rationale. Both matter for NC defense contractors trying to model what comes next.
Three specific drivers of the July 13 suspension:
- C3PAO capacity gap of ~1,000:1. With 100,000-plus DIB companies needing Level 2 certification and roughly 100 accredited C3PAOs available, the math never worked. A single C3PAO can typically deliver 8-20 full assessments per year. Even at 20, capacity would have covered 2 percent of the need by November 10.
- Small business cost pressure. Full C3PAO assessments run $50,000 to $250,000 per site, plus the internal remediation cost, plus annual surveillance. For a 25-person NC precision-machining shop with a single tier-3 subcontract, that ratio was budget-breaking.
- Alignment with the Acquisition Transformation System. Secretary Hegseth has framed the pause as consistent with a broader Department of War initiative to eliminate bureaucracy that keeps small firms out of the defense industrial base. The suspension is the first concrete implementation of that framing.
Industry reaction has been mixed. Trade groups representing large primes and existing C3PAOs have expressed concern that the pause undermines the industrial-base security posture. Trade groups representing small and mid-market DIB companies have expressed relief that the November 10 cliff is off the calendar. Both readings are legitimate; NC defense contractors sit in the second group.
What Still Applies to NC Defense Contractors After the Suspension?
The suspension removes the third-party certification requirement. It does not remove the underlying security obligations. Every NC defense contractor should re-read their existing contracts and confirm what obligations remain.
Contractual obligations that are unchanged by the July 13 suspension:
- DFARS 252.204-7012. Requires adequate security for CUI aligned to NIST SP 800-171 (Rev 2 or Rev 3 depending on contract vintage), 72-hour cyber incident reporting to DoD via the DIBNet portal, and cooperation with damage assessment.
- DFARS 252.204-7019 and 7020. Require SPRS score submission and NIST SP 800-171 assessment methodology adherence at the required level (basic self-assessment, medium government-conducted, or high government-conducted).
- DFARS 252.204-7021. The CMMC clause itself. The clause still exists in contracts; the suspension is at the enforcement level, not the clause level.
- NIST SP 800-171 controls (110 controls in Rev 2, expanded set in Rev 3). Access control, awareness training, audit, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, system and information integrity.
- Federal Acquisition Regulation FAR 52.204-21. Basic FCI safeguarding at CMMC Level 1 equivalent. Applies to any FCI in your possession.
- Cyber insurance policy language. Defense-industry cyber policies typically incorporate NIST SP 800-171 posture as an underwriting criterion. That does not change because Phase 2 paused.
The practical effect for a typical NC defense subcontractor: you still need to run access control, audit logging, encryption, incident response, and vendor risk management to the NIST SP 800-171 standard. You no longer need to pay a C3PAO $50,000 to $250,000 to certify that you do. That is a real dollar reprieve.
How Should NC Defense Contractors Redirect the Freed Budget?
The freed C3PAO budget is a rare opportunity to close the gap between "we have controls on paper" and "we have controls that actually work." Smart NC defense contractors will redirect that dollar into the controls themselves.
Comparison: Where NC defense-contractor budget was going pre-suspension vs post-suspension smart reallocation.
| Line Item | Pre-Suspension Plan | Post-Suspension Smart Reallocation |
|---|---|---|
| C3PAO assessment | $50K-$250K | $0 (paused) |
| Pre-assessment gap analysis | $10K-$40K | Keep at $10K (still needed for SPRS accuracy) |
| Remediation projects | $30K-$150K | Increase to $60K-$200K (fund the actual controls) |
| 24/7 SOC / MDR | $30K-$80K annual | Add $30K-$60K annual (this is where NIST 800-171 lives) |
| Endpoint MFA + EDR | Often deferred | Fund fully (~$80-$150 per endpoint) |
| Vulnerability management | Often manual | Fund tooling (~$15K-$40K annual) |
| Incident response retainer | Rarely funded | Fund a $10K-$25K retainer with a defined SLA |
| CUI enclave / GCC High | Deferred pending certification | Complete migration during pause window |
The right-hand column is the "same total budget, better security outcome" plan. NC defense contractors who execute it during the 60-day pause will emerge from the task force review in a stronger posture than they would have been in under the original November 10 timeline, and they will do it with less dollar spend on paperwork and more on controls.
This is exactly the CUI-safeguarding program Preferred Data delivers as part of our Managed IT Services and Cybersecurity practice for NC defense manufacturers, precision machining shops, aerospace subcontractors, and defense-adjacent professional-services firms.
What Should NC Defense Contractors Do in the Next 60 Days?
The task force has 60 days. The right posture for a NC defense contractor is to use that window to complete a set of concrete deliverables that will pay off regardless of the task force's recommendation.
PDC's 60-day post-suspension execution plan for NC defense contractors:
- Weeks 1-2: Re-baseline the SPRS score. Run a fresh NIST SP 800-171 self-assessment against your actual environment (not a paper environment). Submit an updated SPRS score. If your prior score was inflated by a "we plan to have this by November" attitude, correct it now.
- Weeks 2-4: Complete the CUI inventory. Identify every location CUI touches: file shares, email, ERP, laptops, mobile devices, contractor workstations. If you cannot enumerate it, you cannot protect it, and no amount of C3PAO reprieve saves you from a real incident.
- Weeks 3-6: Deploy the top-10 unfunded controls. MFA on privileged accounts (AC-2), FIPS 140-2 or 140-3 encryption at rest and in transit (SC-13), full-fleet EDR (SI-3), 90-day log retention with alerting (AU-6), documented incident response plan with contact list (IR-6), 24/7 monitoring for CUI systems (SI-4), vendor risk management for subcontractors (SR-3), user awareness training with phishing simulations (AT-2), quarterly vulnerability scans with remediation SLA (RA-5), and privileged access management (AC-6).
- Weeks 5-8: Fund the CUI enclave (GCC High or equivalent). For NC defense contractors still working CUI in commercial Microsoft 365 or Google Workspace, the pause is your window to migrate to a compliant enclave without a certification deadline breathing down your neck.
- Weeks 7-8: Wait for the task force recommendation. Do not defer the security work waiting for the recommendation. The recommendation will either preserve NIST SP 800-171 (in which case you are ready) or replace it with a self-attested model (in which case your NIST 800-171 work maps directly to the new attestation).
Why NC Defense Contractors Should Not Read This as "We Can Stop"
The wrong reading of the suspension is "we can defer cybersecurity spend." That reading has three concrete costs.
Three cost dimensions of the wrong reading:
- Contractual liability. DFARS 252.204-7012 still requires 72-hour incident reporting to DoD and cooperation with damage assessment. A contractor found in breach of 7012 after a real incident faces contract termination, False Claims Act exposure, and Suspension and Debarment risk. The pause does not change any of that.
- Cyber insurance underwriting. Defense-industry cyber policies increasingly incorporate NIST SP 800-171 posture, SPRS score, and documented control implementation. A contractor whose posture regresses during the pause faces premium increases, sublimit reductions, or non-renewal at their next annual cycle.
- Real incident risk. Chinese Ministry of State Security-linked actors, Russian Foreign Intelligence Service actors, and Iranian Islamic Revolutionary Guard Corps actors do not know about the suspension. They will keep probing defense industrial base companies exactly as they were on July 12. NIST 800-171 exists to prevent those intrusions from succeeding.
The right reading is: the deadline pressure is off, but the operational security expectation is exactly the same as it was two weeks ago. Use the pause to close gaps you had not funded, not to close funding you were spending.
How Does Preferred Data Support NC Defense Contractors Through the Pause?
Preferred Data Corporation has spent 37 years supporting NC defense manufacturers, precision machining shops, aerospace subcontractors, and defense-adjacent professional-services firms through exactly the kind of regulatory whiplash the July 13 suspension represents. Our post-suspension support has four layers.
PDC's four-layer post-suspension support for NC defense contractors:
- SPRS re-baseline. We run a fresh NIST SP 800-171 self-assessment against your actual environment, update your SPRS score, and document the delta from your last submission.
- CUI inventory and enclave migration. We map every location CUI touches and either lock down commercial-tenant handling or migrate to GCC High or a compliant enclave.
- NIST 800-171 control deployment. We fund the top-10 unfunded controls (MFA, EDR, 24/7 SOC, log retention, incident response plan, vendor risk, awareness training, vulnerability management, PAM, encryption).
- Task force readiness monitoring. We track the task force's public communications and re-plan your program as recommendations emerge. Our monthly executive briefing includes the CMMC reform status.
Cost for a typical 25-100 person NC defense contractor: $20,000-$60,000 all-in for the 60-day catch-up program, $2,500-$5,500 per month ongoing for the maintenance program. Compared to a $50,000-$250,000 C3PAO assessment that was budgeted for Q3-Q4 2026, this is a net reduction in first-year spend and a net improvement in security posture.
Frequently Asked Questions
Do I still need to submit a SPRS score after the CMMC Phase 2 suspension?
Yes. SPRS score submission is required under DFARS 252.204-7019 and 7020, which are not part of the CMMC rulemaking and are not affected by the July 13 suspension. If your last submitted score is over 12 months old or based on a paper environment, submit a refreshed score now.
Does the suspension mean CMMC is cancelled?
No. The suspension is a pause on the third-party assessment mandate pending a 60-day task force review. Phase 1 self-assessment requirements from November 2025 remain in force, and DFARS 252.204-7012 CUI safeguarding is unchanged. Outcomes of the review range from a modified CMMC to a fully self-attested model. Plan for both.
Can I stop my C3PAO assessment engagement?
Yes, and most NC defense contractors should. Pause the C3PAO engagement, redirect the freed budget into control implementation and 24/7 monitoring, and be ready to resume if the task force recommends a modified CMMC that keeps some form of third-party assessment.
If my contract already had a Phase 2 clause, is it now unenforceable?
The Phase 2 clause is still in your contract. The enforcement is what was suspended. Contracting officers will not enforce the Phase 2 certification requirement while the pause is in effect. If a contracting officer attempts to enforce, request written guidance citing the July 13, 2026 Department of War memo.
What if we already spent money on a C3PAO gap analysis?
Sunk cost. The gap analysis is still valuable because it maps your NIST SP 800-171 posture. Use it as the baseline for the SPRS re-submission and the control-deployment plan. Do not treat the gap analysis as wasted just because the certification did not follow.
How does this interact with FedRAMP and GCC High?
FedRAMP applies to cloud service providers offering services to federal agencies. GCC High applies to CUI handling in Microsoft's Government Community Cloud High tenant. Neither is directly affected by the CMMC Phase 2 suspension. NC defense contractors still handling CUI in commercial M365 should complete the migration to GCC High or an equivalent enclave during the pause window.
Will cyber insurance premiums drop because of the suspension?
Unlikely. Cyber insurance underwriting focuses on posture and incident history, not on certification status. A contractor with a strong NIST 800-171 posture will price the same whether they had a C3PAO certification or a documented self-assessment. Improve the posture, not the paperwork.
Related Resources
- Cybersecurity Services for NC Defense Contractors
- Managed IT Services
- Manufacturing Industry Solutions
- Contact PDC — request a same-week defense contractor cybersecurity review