Compliance
Why Phase II paused, according to the announcement
CMMC Phase II was suspended on 13 July 2026, and the reason given matters for how you plan.
The stated rationale was cost and burden. The Department of War pointed to prohibitive compliance costs and bureaucratic requirements, and to the risk of pushing small and mid-sized businesses out of the defense industrial base entirely. It sits alongside a wider push to streamline acquisition. A CMMC Reform Task Force was established to review the program, with industry input and a report to the CIO.
That is worth stating plainly, because a lot of commentary — ours included, earlier — reached for capacity as the explanation. Assessment capacity is a real constraint, and GAO reported 92 authorized C3PAO organizations as of December 2025 against a defense industrial base of well over 100,000 firms. But the announcement does not give capacity as the reason, and we should not present our inference as the Department’s stated case.
What did not change:
- DFARS 252.204-7012 still applies.
- NIST SP 800-171 still applies.
- Phase I self-assessment, SPRS scores and annual affirmations continue unchanged.
So the obligations are live and the verification is paused. If you supply the defense industrial base, this is a window to close real gaps at your own pace rather than against someone else’s date — and the outcome of the task force review is the thing worth watching, because it may change what Level 2 requires rather than merely when.
More updates
-
Backups rarely fail in a ransomware event. Recovery does.
The backup job is green. The restore is what breaks — usually on recovery order, an encrypted backup server, or a restore time nobody measured.
-
Your contract decides the assessment. Scope decides the effort.
About $593,800 with a third-party assessment, or $388,600 self-assessed. Which applies is set by your contract's requirement, not by how you are configured.
-
MFA is not the finish line it used to be
Modern attacks do not defeat multi-factor authentication. They wait for it — through prompt fatigue and stolen session tokens.