← Back to list

CMMC Phase II Is Suspended. Your Obligations Aren’t.

If you run security or compliance at a defense contractor, you probably exhaled on July 13th. The Department of War suspended CMMC Phase II…

Keith Foster · 2026-07-28 12:08 · 0 claps · 3.0 min read
#cmmc-compliance #cmmc-certification #cmmc-assessment
Open on Medium ↗

CMMC Phase II Is Suspended. Your Obligations Aren’t.

If you run security or compliance at a defense contractor, you probably exhaled on July 13th. The Department of War suspended CMMC Phase II — the rule that would have forced most Level 2 contractors through a mandatory third-party (C3PAO) assessment starting this November — and kicked off a 60-day review of the whole program. The Small Business Administration cheered it as relief for small businesses. The November cliff you’d been white-knuckling toward? Gone, for now.

Here’s the kicker: that relief is a trap if you treat it as permission to stop.

Let me be blunt about what actually happened, because the headlines blurred it. (All of this is as of late July 2026 — this is a moving target, so verify the current status before you make a decision on it.)

What changed: the near-term mandate for third-party certification is paused. Nobody is going to fail an assessment this November, because that assessment requirement isn’t in force right now. The immediate pressure is off.

What did not change — at all: your underlying legal obligations. DFARS 252.204–7012 still lives in your contracts. NIST SP 800–171 still defines the 110 controls you’re expected to implement. You are still required to protect Controlled Unclassified Information. You still owe an accurate SPRS score based on a real self-assessment. And a reformed program is widely expected to come back after the review.

Read that again. The certification check got postponed. The homework didn’t. If a contract obligated you to protect CUI on July 12th, it obligates you on the day you’re reading this.

Think of the suspension as a snooze button, not a cancellation. The alarm is still set — you just bought yourself a little more sleep. And you know exactly how the snooze-button story ends for the people who roll over and pull the covers back up: they wake up late, panicked, and scrambling.

That’s the real risk here. Not the November that isn’t coming — the next deadline that will. The contractors who stand down entirely, lay off the readiness effort, and let their System Security Plan go stale are going to face a worse scramble when the reformed rule lands, on a shorter clock, with a thinner runway. Standing up 800–171 compliance from cold takes six to twelve months. You do not want to start that clock the day the new deadline is announced.

The teams who’ll win treat this pause as found time, not time off. Here’s the play:

Keep your homework current. Your SSP and POA&M should describe reality, not aspiration. Use the breathing room to close real gaps instead of documenting fake ones. The goal is simple: be genuinely ready to be assessed at any time, so whenever the rule returns, it’s a non-event.

Fix the expensive stuff now, calmly. The controls everyone crams at the last minute — asset inventory, access control, logging and monitoring, incident response — are exactly the ones that take real engineering time. Do them now, without a gun to your head, and you’ll do them better and cheaper.

Turn compliance from a fire drill into a background process. This is the mindset shift that matters. Point-in-time compliance — sprinting to “pass,” then letting everything decay until the next audit — is the most expensive and least secure way to do this. Continuous readiness, where your evidence is always current and your posture is always defensible, costs less over time and actually protects you. The assessment stops being an event you dread and becomes a snapshot of a thing that’s already true.

Here’s the part most compliance vendors won’t tell you: “always ready” used to be too expensive for a small contractor to maintain. Keeping an SSP current, collecting evidence continuously, tracking a POA&M in real time — that was a full-time job you couldn’t afford.

It isn’t anymore. The same automation wave everyone’s nervous about — AI agents, continuous monitoring, automated evidence collection — is exactly what makes continuous compliance affordable for a ten-person shop. The tooling finally caught up to the requirement. The contractors who pair this pause with the right automation won’t just survive the next rule change; they’ll barely feel it.

The suspension didn’t lower the bar. It just handed you a rare, unpanicked window to get over it properly. Don’t spend it hitting snooze.

Originally published at https://cognitivefortify.substack.com on July 28, 2026.


메타데이터
post_id
0db5a12d3e14
slug
cmmc-phase-ii-is-suspended-your-obligations-arent-0db5a12d3e14
url
https://medium.com/@ke_foster/cmmc-phase-ii-is-suspended-your-obligations-arent-0db5a12d3e14
canonical_url
https://medium.com/@ke_foster/cmmc-phase-ii-is-suspended-your-obligations-arent-0db5a12d3e14
author_url
https://medium.com/@ke_foster
status
ok
fetched_at
2026-08-09 11:07:28