Home/The Wire/CMMC Phase II Just Got Suspended: Here's What Defense Contractors Should Do Right Now
The Wire

CMMC Phase II Just Got Suspended: Here's What Defense Contractors Should Do Right Now

CMMC Phase II Just Got Suspended: Here's What Defense Contractors Should Do Right Now

On July 13, 2026, the Pentagon announced a significant update that has left much of the defense industrial base in a state of flux: the suspension of CMMC Phase II requirements. For defense contractors and mid-market manufacturers throughout Pennsylvania, this news might feel like a reprieve. However, viewing this 60-day review period as a stand down order would be a strategic mistake.

The suspension pauses the mandatory move toward third-party CMMC certifications, but it does not erase the underlying cybersecurity requirements that govern your ability to win and hold Department of Defense contracts.

At Splashwire, we have guided organizations through regulatory shifts for over 25 years. We understand that while the acronyms may change, the mission of safeguarding covered defense information remains constant. Here is what the Phase II suspension means for your operations and the steps you should take today to maintain your competitive edge.

Understanding the July 2026 Suspension

The Department has initiated a 60-day CMMC reform review. During this window, the transition to mandatory Level 2 third-party assessments and Level 3 government-led assessments is on hold.

For many Pennsylvania manufacturers, this specifically impacts upcoming solicitations. If you were preparing for a contract that required a C3PAO certification by late 2026, you can expect those requirements to be amended. Programs are currently directed to utilize CMMC Level 1 Self or CMMC Level 2 Self designations instead.

The Critical Distinction: Compliance vs. Certification

It is vital to distinguish between compliance and certification. The CMMC Phase II suspension is a pause on the certification mechanism: how the government verifies your security. It is not a suspension of the compliance requirements themselves.

The underlying mandate, NIST SP 800-171 Rev. 2, remains in force. If your contract includes the DFARS 252.204-7012 clause, your obligation to implement the required security controls has not changed.

Why NIST SP 800-171 Rev. 2 Still Matters

While the CMMC framework is being refined, the Department continues to use the Supplier Performance Risk System as the primary tool for evaluating contractor risk.

For Pennsylvania defense contractors, maintaining an accurate and high SPRS score is still one of the most effective ways to demonstrate audit readiness. The government has stated that it will continue to enforce NIST SP 800-171 Rev. 2 through:

  • Self-assessments: Annual affirmations signed by a senior company official.
  • DIBCAC reviews: Targeted government-led audits for high-priority programs.
  • False Claims Act enforcement: Increased scrutiny on the accuracy of self-reported scores.

In short, the pause on Phase II does not mean a pause on security. It simply shifts the burden of proof back to your internal teams and your IT solutions partners.

Action Plan: What to Do During the 60-Day Review

Do not wait for the review period to end before taking action. Use this time to harden your environment and ensure that your documentation reflects your actual security posture.

1. Conduct a Gap Analysis Against Rev. 2

If you have not recently audited your systems against the assessment objectives in NIST SP 800-171A Rev. 2, now is the time. Focus on high-impact areas like access control, incident response, and phishing resistance.

2. Update Your System Security Plan

The System Security Plan is the foundational document of your CMMC compliance journey. It must accurately describe how each required control is implemented within your environment. A stagnant SSP is a red flag during any government-led assessment.

3. Refine Your Plan of Action and Milestones

For any controls not yet fully implemented, ensure your POA&Ms are realistic and time-bound. The 60-day suspension provides a window to close these gaps without the immediate pressure of a third-party auditor's visit.

4. Leverage Strategic Leadership

Navigating these changes requires more than technical fixes. It requires executive oversight. Many mid-market manufacturers need executive technology leadership to align cybersecurity investments with business goals.

Augment vs. Outsource: Choosing Your Path

As the landscape shifts, Pennsylvania contractors often face a choice: should they augment their current staff or outsource their cybersecurity needs entirely?

  • Augmentation: This approach brings specialized cybersecurity consulting alongside your internal IT team. It is often ideal for organizations that have a strong baseline but need expert guidance on specific NIST controls, SPRS scoring, or audit readiness.
  • Outsourced managed services: For many manufacturers, the complexity of 24x7 monitoring, incident response, and continuous compliance is too great to manage internally. Managed IT operations provide a scalable way to ensure that security keeps pace with evolving threats while you focus on production.

Regardless of the path you choose, the goal is the same: simplifying how technology is consumed and enhancing how it is experienced. Cybersecurity should not be a barrier to your growth. It should be the foundation of it.

The Splashwire Approach to Government Solutions

We see the current suspension not as a reason to slow down, but as an opportunity for our clients to get ahead. While the rest of the industry waits for the 60-day review to conclude, proactive contractors are solidifying their positions.

Our team specializes in providing strategic services that go beyond simple help desk support. We act as your guide through the complexities of:

  • Security risk assessments: Keeping your practices up to date with the latest NIST revisions.
  • Audit readiness: Preparing your team and your documentation for whenever certification requirements return.
  • vCIO/vCISO services: Providing the executive leadership needed to navigate federal regulations.
  • Compliance and risk management: Aligning controls, policies, documentation, and operational practices so your environment is defensible.

Do Not Let the Suspension Stall Your Progress

The July 13 announcement is a tactical change, not a change in the Department's ultimate strategy. The protection of controlled unclassified information remains a top priority, and the contractors who remain committed to CMMC compliance will be positioned for critical contract opportunities in the years to come.

Is your organization ready for a self-assessment affirmation? Are your SPRS scores accurate and defensible?

Do not leave your compliance to chance.

Talk to an Expert about a comprehensive CMMC readiness assessment. We will help you navigate this interim period, secure your environment, and position your organization for success when the 60-day review concludes.

Back to The Wire