On July 13, 2026, the Department of War suspended Phase 2 of CMMC, effective immediately, pending a 60 day review. The Small Business Administration publicly backed the decision the same day.
Read that second sentence again, because it is the part that matters for the organizations we exist to serve.
Why did the SBA welcome a pause in a cybersecurity program?
Because the program was pushing small suppliers out of defense work.
The arithmetic was never survivable. Roughly 100,000 companies in the defense industrial base needed third party assessments, and there are roughly 100 approved assessors to perform them. One official summarized it as the math simply not adding up. The SBA Administrator described the framework as an untenable barrier for small businesses.
That is not a cybersecurity objection. It is an access objection, and it is the same one we hear constantly from the shops and small manufacturers who call us. They were not refusing to protect controlled information. They could not reach the front of a queue that was never built to hold them.
So is the pressure off?
No, and this is where a lot of small contractors are about to make an expensive mistake.
The Department paused the assessment. It did not touch the obligation. In its own words it will keep enforcing compliance with NIST SP 800-171 through self assessments and select government led assessments.
Which means, if you handle controlled unclassified information under a defense contract:
- DFARS 252.204-7012 is still in your contract and still binding
- NIST SP 800-171 Rev 2, all 110 requirements, is still the standard
- Your self assessment is still required
- Your score still gets posted, and a named official at your company still signs it
The auditor left the room. The homework did not.
What actually changed for a small contractor?
One thing, and it is worth understanding precisely: the outside expert who would have reviewed your work before the government saw it is gone for now.
For a large prime with a compliance department, that is an inconvenience. For a small contractor without one, it is the whole problem. You are now signing an attestation about a technical standard with 110 requirements, and nobody independent is checking your reading of it first.
That is not a reason to panic. It is a reason to get an honest look at where you stand from someone who has read the standard properly.
Is this not a good moment to just wait?
It is the most tempting question in the room, so it deserves a straight answer. No.
The last time CMMC was paused, in 2021, a great many organizations treated it as permission to stop. Years later a great many of those same organizations were still struggling with the foundational NIST 800-171 requirements. The pause ended. The requirements returned. Those organizations were exactly as far behind as when they started, with less runway and a harder deadline.
The review runs 60 days from July 13, which points to a decision somewhere around the middle of September. That is a genuine window. It is only useful to the contractors who treat it as build time.
What is the Cyber Grants Alliance doing about it?
The same thing we were doing before the announcement, because the reason we exist did not change this week.
Our CMMC Gap Assessment Grant provides an in-kind assessment against all 110 NIST SP 800-171 requirements for qualifying defense contractors. Not a scan, not a questionnaire, not a checklist you fill in yourself. An assessment of where your organization actually stands, delivered as work rather than as an invoice, so that being small is not the thing that decides whether you get to see the truth about your own posture.
The pause makes that more useful, not less. The self assessment is now the artifact carrying all the weight, and the organizations least able to reach an assessor are the ones now most exposed by signing one blind.
What should a small defense contractor do in the next 60 days?
- Do not stop. Your DFARS obligation is live regardless of what the task force recommends.
- Get an honest baseline against all 110 requirements. Guessing is now a signed guess.
- Do not book third party certification right now. That is the one thing genuinely deferred.
- Put the effort into closing real gaps instead, because every plausible version of the future asks for the same underlying controls.
- Watch September.
Frequently asked questions
Is CMMC cancelled?
No. Phase 2, the third party certification requirement scheduled for November 10, 2026, is paused pending a 60 day review. The requirement to protect controlled defense information under DFARS 252.204-7012 and comply with NIST SP 800-171 remains in force.
Does the pause mean small contractors can stop preparing?
No. Self assessments remain required, and the officer who signs the attestation carries that responsibility personally. The pause removed the third party reviewer, not the requirement.
Can a small contractor still be assessed by the government?
Yes. The Department explicitly retained select government led assessments.
Who qualifies for the CMMC Gap Assessment Grant?
Qualifying defense contractors. Eligibility and the application are on our grant page.
When will we know what happens next?
The CMMC Reform Task Force is expected to report within 60 days of July 13, 2026, which points to roughly mid September.
Where this leaves you
A deadline moved. A standard did not. And the organizations with the least room to absorb either were the ones the pause was meant to protect.
If you are a small defense contractor who has been quietly hoping this would go away, it did not. But the thing standing between you and a clear picture of where you stand is smaller than you think.