CMMC suspension: only self-assessment levels can be written into contracts
On July 13, 2026, alongside the memo suspending Cybersecurity Maturity Model Certification (CMMC) Phase 2, the Department of Defense issued an implementation memo telling program offices and contracting officers what to do with the CMMC requirements already in their solicitations and contracts. Our earlier item covered the suspension and the review. This one covers the contract mechanics, which is where most contractors actually feel the change.
What changed
For the duration of the suspension:
- Program managers and requiring activities may designate only CMMC Level 1 (Self) or CMMC Level 2 (Self) in procurement documents. They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC).
- Active solicitations that already call for a C3PAO or DIBCAC assessment are to be amended to remove that requirement as soon as practicable.
- Existing contracts that contain those requirements are to be modified to remove them, either before the next option period is exercised or at the next scheduled administrative modification.
- Level 2 (Self) continues to mean a self-assessment against the 110 requirements of NIST SP 800-171 Revision 2, with the score posted in the Supplier Performance Risk System (SPRS) and an annual affirmation.
What did not change: the CMMC Program rule at 32 CFR Part 170 and the DFARS 252.204-7021 clause remain on the books as written. The suspension is the department choosing not to designate the higher levels, not a repeal. DFARS 252.204-7012 safeguarding and 72-hour incident reporting obligations continue, and False Claims Act exposure for inaccurate SPRS scores or affirmations is unchanged. DoD has said it will still run select government-led assessments during the pause.
The CMMC Reform Task Force is due to deliver its recommendations to the DoD Chief Information Officer around mid-September 2026, sixty days after the July 13 memos. A public report is expected to follow. Any permanent change to the requirement would then need a class deviation, a DFARS change, or an amendment to the program rule.
What to do now
- Pull every active solicitation, contract, and subcontract that names a CMMC level. Note which ones say C3PAO or DIBCAC and whether an amendment or modification has arrived yet.
- If a modification has not come, ask the contracting officer or prime when it will; do not assume the clause is gone until the paper says so.
- Keep your Level 2 self-assessment, SPRS score, and affirmation current. That is the requirement being enforced right now.
- Treat a scheduled C3PAO assessment as a business decision, not a dead obligation. Many primes still require certification readiness from their supply base.
- Follow CMMC on this site for the task force report and any change to the program rule.