The Pentagon Paused CMMC. It Did Not Pause Your Obligations.
A recap of the July 2026 Cyber AB Town Hall: the Phase 2 suspension, the Reform Task Force, and what defense contractors should read into the quiet.
A lot of contractors read the July 13 news as a reprieve. The Pentagon suspended CMMC Phase 2, the November 10 third-party certification requirement came off the table, and inboxes across the defense base exhaled. The July 2026 Cyber AB Town Hall, held July 28, spent most of an hour arguing that the exhale is a mistake.
Cyber AB CEO Matt Travis kept returning to one distinction. The Department of War paused a verification mechanism. It did not pause the requirement that mechanism was built to verify. If you walk away with a single sentence from that session, make it that one.
What the Department of War actually did
On July 13, DoW Chief Information Officer Kirsten Davies and Undersecretary for Acquisition and Sustainment Michael Duffey jointly announced two actions. First, an immediate and indefinite pause of CMMC Phase 2, the set of requirements scheduled to take effect November 10, 2026. That pause also pulls back the Level 2 C3PAO certification language that had already found its way into some live solicitations. Second, a comprehensive review of the program, aligned to Secretary Hegseth’s Arsenal of Freedom initiative, run through a new CMMC Reform Task Force and a public Request for Information.
The framing from the Pentagon was cost and speed. Officials pointed to Small Business Administration figures suggesting future CMMC phases could cost small and midsize firms more than $7 billion annually, and to a gap between roughly 100 authorized assessors and the tens of thousands of companies that would eventually need one. The RFI is open, and industry responses are due August 14, 2026.
What did not change, item by item
The Cyber AB was emphatic that the program itself is still running. Only the Phase 2 contractual requirements are on hold. As of the Town Hall, all of the following remain in effect: DFARS 252.204-7012 obligations, which still require conformity to NIST SP 800-171 for anyone with that clause in a contract. C3PAOs are still performing Level 2 assessments. eMASS and SPRS are still processing certifications. The Program Office is staffed. DIBCAC is still assessing both C3PAOs and contractors. DCSA is still running Tier 3 background investigations and FOCI screening. Training providers and the exam pipeline are untouched.
Existing Level 2 certifications carry over. Based on what the Cyber AB knew at the session, there is no expected change to their three-year validity. A certificate you already hold still counts.
Put plainly, the plumbing is intact. The only thing that moved is whether a contract can force you through a third-party assessment to win the award. That is a real change for procurement teams. It is close to no change at all for your security obligations.

The Reform Task Force, and when to expect answers
The review sits inside the DoW’s Office of the CIO and will be led by Acting Deputy CIO J. Aaron Bishop. The task force has a 60-day window to work, plus roughly 15 days to write up recommendations for Davies and Duffey. Travis did the arithmetic out loud: expect recommendations around early October 2026 if the schedule holds.
It is organized in four tiers, and the Cyber AB has been told it will be invited into Tier 4, though no formal contact had happened by the Town Hall. Travis relayed that Davies has signaled she wants the task force and industry to do the work without a predetermined outcome. The Cyber AB and the CyberEF both plan to respond to the RFI and publish their responses, the same posture they took during the 32 CFR and 48 CFR rulemaking. He was careful to label the Cyber AB’s read on the reform drivers as interpretation of what it is hearing from Pentagon and SBA officials, not official DoW positions.
Why “suspended” is not “canceled”
Travis spent real time on the legal scaffolding, and it is the part contractors betting on repeal should sit with. CUI protection does not originate with CMMC. It traces to Executive Order 13556, signed in 2010, which tasks the executive branch with safeguarding Controlled Unclassified Information. The National Archives and Records Administration acts as executive agent and charges NIST with writing the technical standard, which is NIST SP 800-171. Agencies enforce it through the DFARS and the FAR. Pausing CMMC does not touch any link in that chain.
Then there is Congress. Section 1648 of the FY2020 National Defense Authorization Act directed the Secretary of Defense to build a consistent framework for defense industrial base cybersecurity, and it explicitly requires a process for third-party independent assessment and certification. That is public law. It has not been amended or withdrawn. A task force can recommend a lot of things, but it cannot repeal a statute. The Cyber AB’s own July 15 statement called third-party verification indispensable and framed a Level 2 certification as the best insurance policy against False Claims Act risk. Read against Section 1648, that is not spin. It is a reasonable bet on where this lands.
The terminology fix that reframes the whole debate
The sharpest moment was a vocabulary correction. Travis pushed back on the phrase “CMMC implementation,” which he called inaccurate and everywhere. There is no such thing. Contractors implement the security requirements of NIST SP 800-171. CMMC is only the verification that you did. The cost of building your security program and the cost of hiring a C3PAO to check it are two different line items, and blurring them makes CMMC look more expensive and more burdensome than it is.
Sit with what that means during a pause. If CMMC was only ever the check on the work, then pausing CMMC pauses the check, not the work. The 800-171 controls, the system security plan, the plan of action and milestones, the honest SPRS score: all of that was your obligation before Phase 2 and stays your obligation now. The suspension removed the proctor from the exam. It did not cancel the exam.
What contractors on the floor are actually saying
An industry panel of three certified organizations, moderated by the CyberEF’s Mike Snyder, made the abstract concrete. Amanda Webb of Level 1 Fasteners noted that many of her suppliers still are not certified, so the pause buys her supply chain some breathing room to get ready. Whitney Palacios, CISO at BigBear.ai, said her security posture did not shift an inch on July 13, because DFARS 7012 never went anywhere, and that her primes and government customers keep asking about CMMC status regardless of the pause. Alison Giddens of Win-Tech said her flowdown obligations are unchanged, and she has started pushing back up her own chain for clarity on CUI markings rather than assuming her sub-tiers have it handled.
Three different vantage points, one shared conclusion. The demand signal for real cybersecurity did not disappear when the mandate paused. It just stopped being the government’s job to enforce on a calendar, and started being a question your customers ask directly.
Q&A worth flagging
A few answers from the session have immediate operational value:
Verifying a subcontractor’s Level 2 status: request a SPRS PDF export directly from them. That is a verifiable record, and a stronger check than a certificate handed over by the contractor.
Subcontractor self-assessments: still required. If DFARS 7012 is in the contract, the Level 2 self-assessment obligation stands. The pause hit C3PAO certification requirements, not the self-assessment or the underlying 800-171 conformity.
FedRAMP 20x: does not currently meet CMMC or DFARS 7012 requirements, per Travis. FedRAMP Rev 4 and Rev 5 remain accepted, though those authorizations are expected to sunset at the end of the calendar year, with updated policy anticipated by then. Written guidance to C3PAOs is expected to follow.
Pursuing CCP or CCA certification: no reason to pause. Existing C3PAO certifications should not be affected. And the value of a Level 2 certification during the pause, in Travis’s framing, comes down to two things that did not change: it is the strongest protection against False Claims Act exposure, and it still opens doors with primes who keep asking.
Where that leaves DIB contractors
Do not dismantle anything. The remediation work you were doing for 800-171 holds its value under every outcome the task force could produce, because the standard underneath it is set by a 2010 executive order and a 2020 statute, not by a November deadline.
Keep your SPRS score honest and your evidence current. With third-party assessments paused, self-attestation carries more weight, not less, and a false score is the same False Claims Act liability it always was.
Answer the RFI by August 14 if you have real cost or implementation data. Early October is when recommendations are expected, and the DIB’s input shapes them.
Ask your primes where they stand rather than waiting for a signal. Most are holding flowdown steady because their own contract risk did not change, and silence is not permission to stop.
The Pentagon gave the defense base a pause. The Cyber AB spent an hour explaining that a pause is not a pardon. The contractors who keep building through the quiet are the ones who will be ready no matter what early October brings.
Primary source: CMMC.com, July 2026 Cyber AB Town Hall Recap (July 29, 2026). Additional reporting: DefenseScoop, U.S. SBA Office of Advocacy, the Cyber AB, and Government Contracts Law. Links embedded throughout.