Two things are true at once right now, and the gap between them is where small shops get hurt.
The first: the Pentagon really did suspend a major piece of CMMC on July 13, and it's the biggest change to the program since enforcement started. The second: if you handle Federal Contract Information and you're at Level 1, your obligations are identical to what they were in June.
Most of the coverage has been written for companies with a compliance officer and a $200,000 assessment budget on hold. This one's written for the shop with 14 people, a bookkeeper who also does IT scheduling, and a prime who sends letters.
Exactly what the memo did
On July 13, 2026, the Department of Defense (the Department's 2026 memoranda are issued under the Department of War name) announced the immediate suspension of the transition to CMMC Phase 2, which was scheduled for November 10, 2026. The announcement came from CIO Kirsten Davies and Under Secretary for Acquisition and Sustainment Michael Duffey, and it froze all pending and future CMMC implementation milestones until further notice.
A CMMC Reform Task Force was stood up to run a 60-day top-to-bottom review and report findings on or about September 13, 2026. Alongside it, the Department posted a request for information asking industry about cost drivers, administrative burden, and which NIST SP 800-171 controls actually deliver meaningful risk reduction.
The operational detail that most summaries buried: a follow-on memo directed contracting officers to actively remove Level 2 C3PAO and Level 3 requirements that are already sitting in live documents. Solicitations get amended as soon as practicable. Existing contracts get amended before the next option period or at the next scheduled administrative modification.
That's an unwind, not just a pause on new work. If you've been staring at a solicitation with a C3PAO requirement in it, that requirement is coming out.
What stayed in force
Here's the same question run against a Level 1 shop's actual obligations.
| WHAT | STATUS AFTER JULY 13 |
|---|---|
| The 15 requirements in FAR 52.204-21 | Unchanged. Contract term since 2016. |
| Level 1 annual self-assessment | Unchanged. Still required. |
| SPRS entry and senior official affirmation | Unchanged. Still legally binding. |
| Pass/fail scoring, no POA&Ms at Level 1 | Unchanged. |
| CMMC Phase 1 | Live since Nov 10, 2025. Still live. |
| Self-assessment clauses in new contracts | Programs can still include them, and do. |
| DFARS 252.204-7012 | Unaffected. |
| C3PAO certification at Level 2 | Suspended. |
| DIBCAC assessment at Level 3 | Suspended. |
| Phases 2, 3, and 4 | Suspended until further notice. |
Every suspended row involves somebody outside your company showing up to verify. Every unchanged row is something you do yourself. That's the whole pattern, and it's not a coincidence.
Why Level 1 was never the problem
The reasoning behind the suspension is worth reading carefully, because it tells you where this lands.
Davies cited SBA data suggesting future CMMC phases could cost small and mid-sized businesses more than $7 billion annually, with individual compliance bills approaching $600,000. She pointed at a capacity mismatch: north of 100,000 companies in the defense industrial base needing third-party assessments, against roughly 100 approved assessment organizations to perform them. Her line was that the math just simply doesn't math. A March 2026 GAO report had already warned the requirements risked pushing small businesses out of the industrial base. The SBA endorsed the suspension publicly.
Read the components of that argument:
- $600,000 per company is what a Level 2 certification engagement can run at the high end. It's consultants, remediation, and the C3PAO's fee.
- 100 assessment organizations for 100,000 companies is a queue problem that only exists if an outside party has to do the assessing.
- The task force's charge, in the memo's own framing, is to lower barriers for small, medium, and non-traditional businesses and to replace prohibitive third-party compliance models with scalable, realistic security measures.
Level 1 already is the scalable, realistic version. Fifteen requirements, no assessor, no queue, no five-figure fee. The thing the Department paused is the opposite of the thing you're being asked to do.
The three things that don't care about the pause
Your prime. Primes spent the last year building supplier requirements around CMMC posture, and many started checking SPRS status before the rule made them. A prime's supplier requirement is a commercial term in your agreement with them. It doesn't expire because the Pentagon opened a review. If your prime asks for your Level 1 status in September and you send back a link to a news article, you're going to have a hard conversation.
The FAR clause. FAR 52.204-21 published as a final rule on May 16, 2016 and took effect June 15, 2016. It applies below the simplified acquisition threshold, to commercial-item subcontracts, and to services when FCI is involved. Flowdown is required at any tier. It is not part of the CMMC program rule, it is not what got suspended, and a 60-day program review has no mechanism to remove it. Amending a FAR clause takes its own rulemaking.
Your affirmation. The Level 1 affirmation in SPRS is a statement made by a senior official on behalf of the company. Signing an inaccurate one has never been a paperwork problem - it's an attestation to the government about your security posture, and it carries the exposure that comes with that. The review doesn't retroactively soften an affirmation you already made, and it doesn't lower the bar on one you make next month.
Want to know whether an affirmation you'd sign today would hold up? The free 5-question check samples 5 of the 15 and gives you a grade in about three minutes.
What the task force could actually do
The honest answer is that nobody knows yet, which is exactly why the review exists. But there are only a few shapes this can take, and it's worth walking them.
It comes back mostly intact with new dates. Phase 2 resumes on a later calendar. Level 1 is untouched in this scenario, because Level 1 was never the cost driver anyone complained about.
Third-party certification gets replaced with something lighter. Attestation plus spot audits, a risk-tiered model, government-led assessments for high-value programs only. This is the direction the memo's language points. Level 1 stays a self-assessment, and self-assessment likely becomes more central to the whole program, not less.
The program gets substantially rebuilt. Even here, the FAR clause survives, DFARS 7012 survives, and any replacement still has to answer the question "did this contractor implement basic safeguarding." Whatever form the answer takes, you'll need the same underlying work: individual logins, controlled physical access, a managed boundary, patched systems, sanitized media, and records that show it.
Notice what's constant across all three. The paperwork wrapper might change. The 15 things you actually have to do don't, because they're a contract term and because they're the floor that every version of this program has been built on.
What to do in the next 60 days
Keep going, and stop treating September 13 as a decision point. Your real deadline has never been a government milestone. It's your next award, renewal, or option period, whichever lands first. That date didn't move.
Get your gaps documented now, while it's quiet. Two to four weekends closes a typical small shop's Level 1 gaps. Doing that during a lull beats doing it the week a prime asks. Here are the five gaps that show up most often in shops this size.
Don't let SPRS access lapse. SAM renewal, PIEE registration, and the Cyber Vendor User role approval can eat one to two weeks of pure waiting before you can submit anything. That lead time is the same whether the program is under review or not. The submission walkthrough has the sequence.
Start keeping evidence, if you aren't. Every version of a reformed CMMC will ask you to show your work. The artifacts are cheap to collect as you go and miserable to reconstruct later. Here's what actually counts as evidence.
Answer the RFI. This one's genuinely worth an hour. The Department is asking small businesses what compliance actually costs them and which controls are worth the trouble. Small shops are the constituency the whole review is nominally about, and they're the least likely to file a comment. If you've got a real number - hours lost, dollars spent, a bid you skipped - that's the input the task force says it wants.
Watch what your prime does, not what the Pentagon says. Their letter is the deadline that will actually reach you.
The two dates for the shop wall
Same two as before the suspension, which is the point.
Your next contract event. Award, renewal, or option period - that's when you need a defensible SPRS entry.
Eleven months after you affirm. The reminder to re-assess before your annual affirmation lapses, because an expired affirmation quietly makes you ineligible again.
Add a third if you want: mid-September, to read what the task force says. Just don't make it the day you start.
Where does your shop stand right now?
Five yes/no questions, instant grade, no email required. The headlines changed. Your contract didn't.
Take the free 5-question checkSources: Department of War CIO memo of July 13, 2026 and accompanying press release; Federal News Network and DefenseScoop, July 13, 2026; Crowell & Moring client alert (updated July 14, 2026); WilmerHale client alert, July 20, 2026; Summit 7 program analysis, July 2026; FAR 52.204-21 final rule, 81 Fed. Reg. 30439 (May 16, 2016), effective June 15, 2016; GAO-26-107955 (March 2026).