On July 13, 2026, the Department of War suspended CMMC Phase 2, the stage that would have required third-party assessments for contractors handling controlled unclassified information starting November 10, and stood up a reform task force with 60 days to recommend fixes (war.gov release, Jul 13, 2026). If you run a small defense contractor, the temptation is to read this as a reprieve and reassign the budget. That reading will cost you.
Why the math forced a pause
The suspension was arithmetic, not mercy. More than 100,000 defense-industrial-base companies needed assessments, and roughly 100 approved assessor organizations existed to perform them (Breaking Defense, Jul 2026). Projections cited in the department's reasoning put future-phase compliance costs above $7 billion a year across the base, with individual bills for some businesses approaching $600,000 (Federal News Network, Jul 2026). A bottleneck that severe does not process a hundred thousand companies by November. Something had to give, and the assessment mandate gave first.
What did not change
Read the release carefully, because the list of things that survived is longer than the list of things that paused:
- All 110 security controls in NIST SP 800-171 still apply to anyone holding CUI.
- DFARS 252.204-7012 is still in your contracts.
- SPRS score submissions and annual affirmations are still required; Phase 1 self-assessment continues in force.
- False Claims Act exposure for misstating your SPRS score did not pause and will not.
In other words: the requirement to be secure survived. What paused is the requirement to pay a third party to watch you prove it.
The move: remediate at self-assessment prices
Here is the asymmetry worth acting on. Right now, closing your NIST 800-171 gaps is a self-paced project you control: your own POA&M, your own timeline, your own (honest) SPRS score. If the task force reinstates a certification requirement (and a task force created to reform a program rarely recommends deleting it), remediation becomes a scheduled event with a scarce assessor on the clock and every other contractor in the queue ahead of you. Same work, worse prices, worse leverage.
The 60-day review window is exactly long enough to finish what most small shops have left: the unimplemented controls everyone defers (FIPS-validated encryption, audit-log review, multifactor on everything that touches CUI), a POA&M that reflects reality, and an SPRS score you could defend under oath. That last phrasing is deliberate. The Department of Justice has already used the False Claims Act against contractors whose posture didn't match their paperwork, and nothing in the July 13 release touches that liability.
What we don't know yet
Honest unknowns: whether the task force recommends a lighter certification tier for small businesses, whether the November 10 date slips a quarter or a year, and whether the roughly 100 assessor organizations expand fast enough to matter. Anyone who tells you they know the shape of the replacement is guessing. The recommendation lands with the department's CIO on roughly a 60-day clock from July 13; plan to re-read your position in mid-September.
The checklist
If CUI touches your systems, this window has four jobs: pull your current SPRS score and check it against reality; finish the deferred 800-171 controls while it's a self-paced project; document everything as if an assessor arrives in Q1; and file the September task-force report in your calendar now. We are a newly formed firm building our own compliance posture from zero, and we'd rather build it once, correctly, in the cheap window. That is the whole argument.