CMMC Phase 2 is suspended. What a DLA supplier still owes.
The Department of War suspended CMMC Phase 2 assessment requirements on 13 July 2026, and a lot of DLA suppliers have read that as "the cybersecurity rules are off." They are not. DIBBSFlow reviewed the suspension memo coverage and the underlying DFARS clauses on 26 August 2026: what stopped is the third-party certification assessment that was due to start appearing in contracts on 10 November 2026. What continues, unchanged, is every self-assessment, every SPRS score, and every safeguarding obligation you already had. If you sell on DIBBS, the practical answer is that your obligations today are the same as your obligations in June.
What actually changed on 13 July?
The Department of War suspended Phase 2 of the CMMC implementation timeline and stood up a CMMC Reform Task Force to run a 60-day review, taking industry feedback through a public request for information. Reporting on the decision points to cost data from the Small Business Administration showing that compliance expense was pushing smaller companies out of the defense industrial base, which is the same pressure DLA suppliers have been describing for two years.
The task force is expected to report on or about 13 September 2026. Until it does, nothing about the suspension is final, and nothing about your current contracts has changed.
What is suspended?
One thing: the certification assessment performed by somebody other than you.
- Level 2 certification assessments by a C3PAO are suspended.
- Level 3 assessments by DIBCAC are suspended.
- The phase-in of those requirements into new contracts, scheduled to begin 10 November 2026, is on hold.
If you were budgeting for a third-party assessment this autumn to stay eligible for work, that specific spend is paused. That is the whole of the relief.
What still applies?
This is the part being misread, so it is worth being plain. Phase 1 is not suspended. The clauses already in your contracts are not suspended.
- DFARS 252.204-7012. You remain contractually obligated to safeguard covered defense information, to implement NIST SP 800-171 as adequate security, to report cyber incidents to DIBNet within 72 hours, and to flow the clause down to your subcontractors.
- DFARS 252.204-7019 and 252.204-7020. Self-assessment, posting your score in SPRS, and providing the government access for its own assessment all continue. 7019 still conditions award on having a current assessment score in SPRS.
- Level 1 self-assessment and annual affirmation for federal contract information. Still required.
- Level 2 self-assessment and annual affirmation for controlled unclassified information. Still required. It is the third-party verification of that self-assessment that stopped, not the self-assessment.
The accuracy expectation on your SPRS score and your annual affirmation is exactly what it was before 13 July. An affirmation is a statement to the government, and the Department of Justice has been treating inaccurate cybersecurity representations as actionable. A pause on somebody checking your work is not a pause on the work being true.
Which level applies to a DIBBS supplier?
Almost every company holding a DLA contract handles federal contract information, which is information provided by or generated for the government under a contract and not intended for public release. Purchase orders, delivery schedules, and shipping instructions all qualify. That puts most DIBBS suppliers in scope for Level 1 at minimum.
The line that catches machine shops and distributors is the next one up. Controlled unclassified information arrives with technical data: the drawings, specifications, and technical data packages you pull to quote a part. If you are requesting drawings through cFolders or TDMT, or holding export-controlled technical data, you are handling a category that carries the higher obligation. Many suppliers who think of themselves as Level 1 are storing Level 2 material in a shared drive because that is where the drawings landed.
Worth separating two things that get conflated in the same conversation: JCP certification governs your access to export-controlled technical data, and CMMC governs how you protect information once you have it. They are different regimes with different gates. Passing one says nothing about the other.
What should you do before the task force reports?
Nothing dramatic, and nothing you can safely skip.
- Check whether your SPRS score is current. If award eligibility depends on it and it has lapsed, that is a live problem today and has nothing to do with the suspension.
- Find out where technical data actually lives in your business. Not where policy says it lives. Drawings pulled for a quote three years ago are still somewhere.
- Do not cancel remediation work you had already scoped. The requirement did not go away and the review may narrow it rather than remove it. Work already done is not wasted.
- Do reconsider the timing of a third-party assessment if that was booked purely for the 10 November date. That date is no longer live.
- Submit to the RFI if the cost burden is real for you. The review is explicitly taking industry input, and small suppliers are the population the cost data was about.
What happens after 13 September?
Unknown, honestly. The task force could recommend narrowing which contracts carry the requirement, changing the assessment mechanism, adjusting thresholds for smaller suppliers, or restarting the phase-in on a later schedule. Anyone telling you which of those will happen is guessing.
What is predictable is the shape of the risk. Suspensions of this kind tend to end with a revised requirement rather than no requirement, and the companies that treated the pause as a cancellation are the ones that scramble. Keep your self-assessment honest and your score current, and whatever comes back is an adjustment rather than a restart.
Where DIBBSFlow fits, and does not
DIBBSFlow is not CMMC certified, does not assess or certify anyone, and does not provide legal or compliance advice. This page is a plain-language summary of public sources, written because DLA suppliers kept asking and the honest answers were scattered across law-firm alerts. For a determination about your own contracts, your contracting officer and your counsel are the right and only authorities.
What DIBBSFlow does is separate: showing you which DIBBS work fits your business, what the recorded market around it looks like, and where you stand in it.
Frequently asked questions
Is CMMC cancelled?
No. The Department of War suspended Phase 2 assessment requirements on 13 July 2026 pending a 60-day review. Phase 1 self-assessment obligations, SPRS scores, annual affirmations, and DFARS 252.204-7012 all remain in effect.
Do I still need a Level 1 self-assessment?
Yes. Level 1 self-assessment and annual affirmation for federal contract information were not suspended. If you hold a DLA contract, you almost certainly handle federal contract information.
Do I still need to keep my SPRS score current?
Yes. DFARS 252.204-7019 and 252.204-7020 are unaffected, and 7019 still conditions award on a current assessment score in SPRS. A lapsed score can cost you eligibility regardless of the suspension.
What was actually suspended?
Third-party certification assessments: Level 2 assessments by a C3PAO and Level 3 assessments by DIBCAC, plus the phase-in of those requirements into contracts that had been scheduled to begin 10 November 2026.
Does a DIBBS machine shop handle controlled unclassified information?
Often yes, through technical data. Drawings, specifications, and technical data packages pulled through cFolders or TDMT can carry that category. Where the drawings are stored is usually the question that decides the answer.
When will we know what happens next?
The CMMC Reform Task Force is expected to report on or about 13 September 2026. Nothing is final until it does.
Sources
All accessed 26 August 2026. This page summarizes public reporting and the cited DFARS clauses. It is not legal advice.
- Latham & Watkins, "What Defense Contractors Should Know About DOD's Suspension of CMMC Phase 2"
- DLA Piper, "Department of War suspends CMMC Phase 2 assessment requirements: Top points for defense contractors"
- WilmerHale, "Pentagon Suspends CMMC Phase 2 Requirements and Launches Review of Cybersecurity Certification Program"
- Crowell & Moring, "Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review"
- Federal News Network, "Pentagon suspends CMMC phase two requirements, launches review of program"
- DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021
- NIST SP 800-171
Start with one five-character CAGE code. DIBBSFlow will confirm the scope, available source context, and next step before analysis begins.