08/06/2026
The Pentagon didn't remove your CMMC obligations last week. It suspended one enforcement mechanism and the difference matters if you're a manufacturer running DoD contracts.
On July 13, Department of War CIO Kirsten Davies suspended CMMC Phase II: the third-party C3PAO certification requirement that was set to take effect November 10, 2026. What didn't change: DFARS 252.204-7012, which has required contractors to safeguard covered defense information since 2016, and the Level 1 and Level 2 self-assessment obligations tied to your SPRS score and annual affirmation.
For a shop floor running DoD work, that means this: if you've put time into access controls, backup, documentation, and training this year, none of it was wasted. The standard you were building toward, NIST SP 800-171 Rev 2, is still the standard, still enforced, still what your prime and DoD are checking today.
We're tracking the CMMC Reform Task Force's 60-day review and will tell you plainly what changes, once it's confirmed. Our CMMC readiness team is a good place to start if you want to talk through what this means for your specific contracts:
β https://hubs.li/Q04s1dN30