The Department of War (“DOW”) suspended Cybersecurity Maturity Model Certification (“CMMC”) Phase 2 requirements, scheduled to take effect on November 10, 2026, for at least 60 days while a newly established “CMMC Reform Task Force” undertakes a comprehensive review of the program. Importantly, the suspension pauses only DOW’s mechanism for verifying contractor compliance with existing, mandatory cybersecurity controls—it does not pause or eliminate a contractor’s obligation to implement and maintain the controls required under FAR 52.204-21 and DFARS 252.204-7012.
CMMC Refresher
The final CMMC programmatic rule took effect on November 10, 2025. Finalization of that rule kicked off DOW’s phased implementation of the CMMC program. Phase 1 began with DOW including the self-assessment requirements for CMMC Level 1 (Self) or CMMC Level 2 (Self) in DOW solicitations as a condition for award and in contracts as a condition for the exercise of an option or extension to the period of performance:
- CMMC Level 1 (Self): CMMC Level 1, which covers basic safeguarding of Federal Contract Information (“FCI”), requires defense contractors to perform an annual self-assessment of their compliance with the 15 security controls required by FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, to secure FCI processed, stored, or transmitted on their information systems.
- CMMC Level 2 (Self): CMMC Level 2, which covers broad protection of Controlled Unclassified Information (“CUI”), requires defense contractors to perform a self-assessment every three years of their compliance with the 110 security controls in NIST SP 800-171 rev. 2 (as required by DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting) to secure CUI processed, stored, or transmitted on their information systems.
Phase 2 would require contractors to obtain third-party assessments conducted by Certified Third-Party Assessment Organizations (“C3PAOs”) to verify contractors’ implementation and maintenance of the NIST SP 800-171 rev. 2 security controls—i.e., to verify contractors’ reported CMMC Level 2 (Self) assessment scores.
DOW’s July 13, 2026 memoranda (see here and here), however, suspended (i.e., temporarily paused) that transition. But compliance with FAR 52.204-21 and DFARS 252.204-7012 isn’t suspended.
What the Suspension Does and Does Not Do
The suspension bars DOW agencies from including CMMC Level 2 (C3PAO) (and the higher-tiered CMMC Level 3 (DIBCAC)) assessment requirements in solicitations and contracts during the 60-day review period. For active solicitations that include CMMC Level 2 (C3PAO) or CMMC Level 3 (DIBCAC), agencies must issue amendments “explicitly removing” the requirements “as soon as practicable.”[1] For existing contracts and agreements containing CMMC Level 2 (C3PAO) or CMMC Level 3 (DIBCAC), contracting officers must “remove them via modification prior to the exercise of the next option period or during the next scheduled administrative modification.”[2]
Nor does the suspension pause CMMC Level 1 and Level 2 self-assessment requirements. DOW agencies will still include these as part of DOW solicitations, contract awards, and contract modifications/extensions. Because these requirements remain active, contractors must still post Level 1 and Level 2 self-assessment results in the Supplier Performance Risk System (“SPRS”) and affirm compliance annually. Necessarily, contractors must ensure compliance with the underlying cybersecurity controls required by FAR 52.204-21 or DFARS 252.204-7012—clauses that implement NIST SP 800-171 rev. 2 controls for FCI (15 controls) and CUI (110 controls).
Why False Claims Act Risk Remains
False Claims Act (“FCA”) risk remains notwithstanding DOW’s pause of Phase 2. This is because FAR 52.204-21 started to become a requirement of nearly all FAR-based solicitations and contracts in 2016. DFARS 252.204-7012, which must be included in all defense solicitations and contracts except those solely for the acquisition of COTS items,[3] set December 31, 2017 as the deadline for contractors to have implemented the NIST SP 800-171 rev. 2 controls.[4] These cybersecurity clauses have been a requirement of defense contracts for years.
Under the FCA’s “implied certification” theory of liability, every time a contractor submits an invoice for payment to the government under a contract that includes either or both of these clauses, the contractor is “impliedly certifying” compliance with these material contract terms.[5] If the contractor is not in compliance, however, then—under this legal theory—the contractor has submitted a “false claim” to the government.
FCA risk remains not only under the implied certification theory but also (more obviously) due to the requirement that contractors must still affirm compliance with FAR 52.204-21 annually (for CMMC Level 1 (Self)) and DFARS 252.204-7012 (for CMMC Level 2 (Self)) in SPRS.
Likewise, the July 13 DOW memorandums confirm continued enforcement of “compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessments and select Government-led assessments.”[6] How the government intends to go about these “select Government-led” assessments during the 60-day suspension isn’t clear. What is clear, however, is that someone, at some point, will review your entity’s certification of compliance: The only question is whether that someone will be a third-party, DIBCAC, or the Department of Justice (“DOJ”).
For example, just last month, an Alabama defense contractor agreed to settle FCA allegations that the contractor knowingly failed to implement the NIST SP 800-171 controls, as required by its contracts with the Navy. Notably, the contractor’s failure to implement the NIST controls was discovered during a Defense Industrial Base Cybersecurity Assessment (“DIBCA”) and not due to whistleblower involvement like several other recent DOJ Civil-Cyber Fraud Initiative settlements.
In the Alabama settlement, the contractor submitted a perfect self-assessment score of 110 for its implementation of NIST SP 800-171 in SPRS. Three years later, DIBCAC assessed the contractor’s compliance and determined its actual score as -170; significantly lower than what the contractor certified. As a result, the government alleged the contractor had knowingly failed to implement the required security controls, giving rise to FCA liability. The settlement is the latest for the Civil Cyber Fraud Initiative, which netted over $52 million in in 2025 alone.
Next Steps
DOW has issued a request for information (“RFI”) to industry, seeking feedback on “practical strategies” to inform the CMMC Reform Task Force. Responses are due by 12:00 pm EDT on August 14, 2026.
Further, while DOW is hitting pause on CMMC Phase 2, just last month the FAR Council issued a proposed rule that would require nondefense contractors that process, store, or transmits CUI on their information systems to comply with NIST SP 800-171 rev. 3. Thus, assuming the proposed rule is adopted, both defense and nondefense contractors will be required to safeguard CUI under the NIST standards.
Takeaways
- Contractors are still required to safeguard FCI and CUI in accordance with FAR 52.204-21 and DFARS 252.204-7012, respectively. DOW solicitations and contracts will continue to include CMMC Level 1 (Self) and CMMC Level 2 (Self) as conditions of award and contract performance, meaning contractors must still report their self-assessment scores in SPRS and annually certify compliance.
- Contractors can expect DOW to amend “active” solicitations to remove CMMC Level 2 (C3PAO) and CMMC Level 3 (DIBCAC) requirements and to modify existing contracts containing these requirements “prior to the exercise of the next option period or during the next scheduled administrative modification.” The memorandums do not address the timing of these activities within the context of the 60-day review period.
[1] DOW, Memorandum re: Implementing Department of War Chief Information Officer’s Suspension of the Advancement to [CMMC] Phase 2 Requirements (July 13, 2026).
[2] Id.
[3] DFARS 204.7304(c).
[4] DFARS 252.204-7012(b)(2)(ii)(A).
[5] Universal Health Servs., Inc. v. United States ex rel. Escobar, 579 U.S. 176, 187 (2016)
[6] DOW, Memorandum re: Implementing Suspension of the Advancement to [CMMC] Phase 2 Requirements (July 13, 2026) & DOW, Memorandum re: Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of [CMMC] Requirements (July 13, 2026).
- Partner
Kelsey Hayes is a partner in the firm’s Construction & Project Development practice group. She regularly, and successfully, litigates bid protests, claims, and disputes before the U.S. Government Accountability Office ...
- Partner
As a partner in the firm’s Construction and Project Development and Appellate Practice Groups, Mike specializes in Federal procurement disputes from informal negotiations through appeals. Mike’s knowledge of the Federal ...
- Partner
David Timm is a member of the firm’s Construction & Project Development practice group. He represents contractors and companies in complex disputes, claims, and bid protests involving federal, state, and local government ...
Federal, state, and local governments spend billions of dollars each year on goods and services for their citizens. Our federal government contracts team has a 25-year track record of helping businesses solve problems and achieve their goals in the areas of construction and government contracts. Here, they share their insights as well as important updates.