The CMMC pause is breathing room, not amnesty

The Pentagon suspended CMMC Phase 2 and gave a task force 60 days to fix the program. Every underlying obligation survived. What a small defense contractor should do with the window.

JUL 13 · PHASE 2 SUSPENDED 60-DAY TASK FORCE 110 NIST 800-171 CONTROLS REMAIN PAUSED ≠ REPEALED

On July 13, 2026, the Department of War suspended CMMC Phase 2, the stage that would have required third-party assessments for contractors handling controlled unclassified information starting November 10, and stood up a reform task force with 60 days to recommend fixes (war.gov release, Jul 13, 2026). If you run a small defense contractor, the temptation is to read this as a reprieve and reassign the budget. That reading will cost you.

Why the math forced a pause

The suspension was arithmetic, not mercy. More than 100,000 defense-industrial-base companies needed assessments, and roughly 100 approved assessor organizations existed to perform them (Breaking Defense, Jul 2026). Projections cited in the department's reasoning put future-phase compliance costs above $7 billion a year across the base, with individual bills for some businesses approaching $600,000 (Federal News Network, Jul 2026). A bottleneck that severe does not process a hundred thousand companies by November. Something had to give, and the assessment mandate gave first.

What did not change

Read the release carefully, because the list of things that survived is longer than the list of things that paused:

In other words: the requirement to be secure survived. What paused is the requirement to pay a third party to watch you prove it.

The move: remediate at self-assessment prices

Here is the asymmetry worth acting on. Right now, closing your NIST 800-171 gaps is a self-paced project you control: your own POA&M, your own timeline, your own (honest) SPRS score. If the task force reinstates a certification requirement (and a task force created to reform a program rarely recommends deleting it), remediation becomes a scheduled event with a scarce assessor on the clock and every other contractor in the queue ahead of you. Same work, worse prices, worse leverage.

The 60-day review window is exactly long enough to finish what most small shops have left: the unimplemented controls everyone defers (FIPS-validated encryption, audit-log review, multifactor on everything that touches CUI), a POA&M that reflects reality, and an SPRS score you could defend under oath. That last phrasing is deliberate. The Department of Justice has already used the False Claims Act against contractors whose posture didn't match their paperwork, and nothing in the July 13 release touches that liability.

What we don't know yet

Honest unknowns: whether the task force recommends a lighter certification tier for small businesses, whether the November 10 date slips a quarter or a year, and whether the roughly 100 assessor organizations expand fast enough to matter. Anyone who tells you they know the shape of the replacement is guessing. The recommendation lands with the department's CIO on roughly a 60-day clock from July 13; plan to re-read your position in mid-September.

The checklist

If CUI touches your systems, this window has four jobs: pull your current SPRS score and check it against reality; finish the deferred 800-171 controls while it's a self-paced project; document everything as if an assessor arrives in Q1; and file the September task-force report in your calendar now. We are a newly formed firm building our own compliance posture from zero, and we'd rather build it once, correctly, in the cheap window. That is the whole argument.