CMMC20X
Policy record

The Phase 2 Suspension: What the Record Says

What the July 13 CMMC documents changed, left in place, and left unresolved.

StatusCurrent
Last reviewed
Research lanesCurrent intervention
Claim registerC-12 · C-15

Current through August 13, 2026. This record describes the Department's published interim posture; it is not legal advice or a prediction of the Task Force outcome.

On July 13, 2026, the Department of War suspended the CMMC phased implementation schedule, including the planned November 10 transition to Phase 2. It also opened a 60-day review and a public request for information.

The announcement created two kinds of confusion at once. Some readers treated it as the end of CMMC. Others treated it as a delay with no operational effect. The published documents support neither reading.

What the Department directed

The implementation attachment is specific:

  1. The pending and future phase milestones are held in abeyance. During the suspension, requiring activities may designate only Level 1 (Self) or Level 2 (Self). They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC).
  2. Active solicitations are to be amended. Where a requirements package included Level 2 (C3PAO) or Level 3 (DIBCAC), the responsible officials must initiate amendments removing those designations.
  3. Existing contracts are to be modified on a defined schedule. The attachment directs removal before the next option exercise or during the next scheduled administrative modification.
  4. Waiver procedures are suspended during the review. The interim posture no longer permits the designations that would have required those waivers.
  5. The Department will use self-assessments and selected Government-led assessments. That is the stated verification posture while the review is underway.

Those are implementation instructions, not a small change to a date on a calendar.

What the same record keeps in place

The Department’s release and current CMMC page say that Phase 1 self-assessment requirements remain in place. The implementation attachment also says the cybersecurity requirements in DFARS 252.204-7012 remain effective.

That distinction matters. The July action changes which CMMC assessment designations may be used during the review. It does not tell suppliers to stop safeguarding covered defense information, and it does not turn a self-assessment into a claim that needs no support.

The official record is therefore narrower than either slogan:

The July documents changed The July documents retained
The phased implementation schedule Phase 1 self-assessment requirements
Use of Level 2 (C3PAO) and Level 3 (DIBCAC) designations during the suspension Applicable safeguarding obligations, including DFARS 252.204-7012
Affected solicitation and contract language Level 1 (Self), Level 2 (Self), and selected Government-led review
The near-term verification posture The requirement to protect covered Government information

Contract applicability depends on the actual solicitation, contract, data, and system. This publication does not provide legal advice; suppliers should read their own instruments and obtain qualified counsel where necessary.

What the suspension does not answer

The interim posture resolves an implementation problem. It does not resolve the enduring assurance problem: how a large, heterogeneous supplier base can produce security claims that are current, scoped, supportable, and independently verifiable without recreating an unaffordable document exercise.

That is where CMMC 20X takes a position. Preserve the security outcome. Make the evidence source-linked and portable. Refresh it when systems materially change. Use independent human attention where uncertainty and consequence demand it. Test new verification methods before giving them program effect.

The suspension is a current intervention. The CMMC 20X Blueprint is the larger operating argument, and the evidence profile shows what one inspectable implementation could look like.

Trace the claim

Sources and revision history.

Primary and governing sources

  1. 01Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II RequirementsU.S. Department of War
  2. 02Implementing Suspension of CMMC Phase IIDepartment of War Chief Information Officer
  3. 03Cybersecurity Maturity Model CertificationDepartment of War Chief Information Officer
  4. 04DFARS 252.204-7012Acquisition.gov
  5. 05DFARS 252.204-7019Acquisition.gov
  6. 0632 CFR part 170Electronic Code of Federal Regulations

Corrections and material revisions

  1. Rebuilt around the official release, implementation attachment, current program page, and acquisition clauses. Removed unsupported enforcement characterizations, disputed-capacity commentary, and language that overstated the legal effect of the memo.

See an error or a source we missed? Send a correction. Material changes are recorded here rather than silently overwritten.

Place this moment in the larger argument.

Current policy can change quickly. The Blueprint states the enduring CMMC 20X position; the RFI shows how Deep Fathom applies it to the Department’s current decisions.