Key Points
- The Department of War suspended CMMC Phase II requirements, but organizations must still comply with NIST SP 800-171, DFARS, and other existing federal security obligations.
- The suspension pauses C3PAO certification requirements but does not eliminate self-assessments, SPRS score reporting, annual affirmations, or Controlled Unclassified Information (CUI) protection requirements.
- MSPs should continue remediation efforts, validate SPRS submissions, maintain audit evidence, and confirm which systems process Federal Contract Information (FCI) or CUI.
- Organizations remain responsible for accurate compliance attestations, and unsupported claims may create contractual, administrative, or False Claims Act (FCA) liability.
On July 13, 2026, the Department of War (DoW) published a release, “Forging the Arsenal of Freedom,” announcing an immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements. If you support clients in the defense industrial base (DIB), the network of companies that supply the DoW, you have probably fielded a version of this question all week, “Does this mean compliance is over?”
It does not.
A CMMC Reform Task Force now has 60 days to report back, using feedback gathered through a public Request for Information (RFI), the government’s formal process for collecting industry input before it changes a rule. However, reviews like this tend to run long, and that exact date isn’t guaranteed.
Why the Department suspended CMMC Phase II
The Department’s stated reason, per the release, is Secretary Pete Hegseth’s Acquisition Transformation System (ATS) directive, which prioritizes speed to capability and lower compliance costs for small, medium, and non-traditional businesses. The release cites Small Business Administration (SBA) data showing compliance costs were pushing companies out of the DIB. DoW Chief Information Officer (CIO) Kirsten A. Davies is quoted directly making that case.
There is also a simpler math problem behind this. By most estimates circulating since the announcement, well over 100,000 companies needed a third-party assessment against roughly 100 accredited assessors, making the original timeline nearly impossible to meet.
What the suspension changes
Phase II is suspended. This is the requirement for certified third-party assessments through a C3PAO (a CMMC Third-Party Assessment Organization, an accredited outside firm) or a review by DIBCAC (the Defense Industrial Base Cybersecurity Assessment Center, the Department’s own assessment arm). Any pending or future CMMC milestones are paused too.
In the interim, the Department will keep enforcing compliance through NIST SP 800-171 Rev 2 self-assessments (the federal standard listing the 110 security controls required to protect sensitive defense data) and what the release calls “select government-led assessments.” These will likely land mostly at the prime contractor level, further up the supply chain than most MSP clients. It reads as a reminder that the Department still has authority to look under the hood, more than a new audit program.
The requirements that are still in effect
Phase I self-assessment requirements are still fully in effect: FAR (Federal Acquisition Regulation) 52.204-21, covering basic safeguarding of Federal Contract Information (FCI), and DFARS (Defense Federal Acquisition Regulation Supplement) 252.204-7012, requiring safeguarding of Controlled Unclassified Information (CUI), cyber incident reporting, and implementation of all 110 NIST SP 800-171 controls. The release states plainly that the suspension “does not eliminate the requirement for companies to protect federal data.”
Also unaffected: Supplier Performance Risk System (SPRS) score entries, annual affirmations, International Traffic in Arms Regulations (ITAR) requirements, remediation plans, system security plans, and subcontractor flowdowns. CUI itself is a broad category, and ITAR is one of many standards underneath it. CMMC tried to bundle all of these into a single certification, and that bundling is what got paused. The requirements underneath it are all still in place.
Where the compliance risk exists
The suspension removed a verification step, but it did not remove the underlying obligation. What is gone, for now, is the third party that would have checked your work before a problem surfaced.
An inaccurate self-assessment or an unsupported affirmation can still create contractual, administrative, and False Claims Act (FCA) exposure, a federal law that holds a business, and often the individual who signed off, personally liable for knowingly defrauding government programs. Contracts already flow this requirement from primes to subcontractors, and that clause is likely to shift from proving a completed audit to something closer to, “Submit your self-attestation, and we reserve the right to audit you later.” Lying on it, especially after accepting government funds, can carry civil and criminal consequences. It is already public record that multiple DIB companies have been prosecuted under the False Claims Act for compliance claims that did not hold up.
Practical steps for MSPs
- Keep remediation plans moving; this news is not a reason to pause them.
- Check that SPRS scores and annual affirmations still reflect your client’s actual environment.
- Confirm scope, such as which client systems touch CUI or FCI, and which of those you manage directly.
- Keep evidence current, including audit trails, patch compliance records, and access logs, in case a prime contractor review comes up.
- Tell clients plainly that suspended is not the same as resolved.
How NinjaOne supports CMMC and FedRAMP compliance
FedRAMP (the Federal Risk and Authorization Management Program, which governs which software platforms are approved to handle federal data) is not the same program as CMMC, and this suspension does not touch it. However, showing an assessor your platform already runs on FedRAMP-authorized infrastructure tends to simplify that conversation. NinjaOne is the only FedRAMP Moderate-authorized RMM (remote monitoring and management) platform on the market today.
Underneath all of it, NinjaOne helps MSPs operationalize and demonstrate the technical controls NIST SP 800-171 asks for: patch automation, role-based access control (RBAC), multi-factor authentication (MFA), and centralized reporting across every client environment you manage.
Every business in the defense industrial base remains legally accountable for producing its compliance record on request: logs, audit trails, and the self-attestation behind its SPRS score, whether or not a third-party assessor shows up to check it. That’s exactly why a platform built to keep that proof current and ready matters right now.

