If you support a defense contractor, the rules you spent a year preparing for just moved under your feet. On July 13, 2026, the Pentagon suspended Phase 2 of the Cybersecurity Maturity Model Certification program and handed a 60-day review to a new CMMC Reform Task Force. Plenty of contractors read that as a reprieve. It is not one. The obligation to protect controlled information never went anywhere, and the contract clauses that carry the legal teeth are still in force.
TL;DR
- What it is. CMMC compliance is documented proof that a defense contractor meets the cybersecurity controls required to handle federal contract information and controlled unclassified information.
- What changed. In July 2026 the Pentagon paused Phase 2, so third-party Level 2 assessments are not being enforced while a 60-day review runs.
- What did not. DFARS 252.204-7012, NIST SP 800-171, Phase 1 self-assessments, and False Claims Act exposure all still apply.
What CMMC Compliance Means
CMMC stands for Cybersecurity Maturity Model Certification. It is the Department of Defense mechanism for verifying that companies in the defense industrial base protect two kinds of sensitive government data: federal contract information (FCI) and controlled unclassified information (CUI). If your client wins DoD work and that work involves either data type, CMMC applies to them, and by extension to whoever runs their IT.
The program maps directly onto an existing standard. Level 1 covers the 15 basic safeguards in FAR 52.204-21. Level 2 aligns with the 110 controls in NIST SP 800-171 Revision 2. Level 3 layers on a subset of NIST SP 800-172 for the highest-value programs. So CMMC is not a new rulebook. It is an enforcement wrapper around requirements that defense contractors have been bound by contract to meet since the DFARS clause landed in 2017. Most existing content treats CMMC as a standalone acronym. It sits inside a wider family of controls, and it helps to see it that way. Our cybersecurity frameworks list for MSPs shows how 800-171 lines up against SOC 2, ISO 27001, and the NIST CSF, which matters when a client asks why they are being asked to do the same thing three times.
The reason CMMC gets attention that other frameworks do not is the assessment. For years, contractors self-attested to 800-171 and moved on. CMMC was built to close the gap between what contractors claimed and what they had running. That is the piece the July 2026 pause touched, and the piece worth understanding in detail.
Who Needs CMMC Compliance
The short answer: any company in the defense supply chain that handles FCI or CUI, and everyone who supports their IT. That is broader than it sounds. The Department of Defense puts the defense industrial base at more than 220,000 companies, and the requirement flows downhill. A prime contractor holding a CUI contract has to push the same protection obligations to its subcontractors, so a small machine shop three tiers below the prime can inherit Level 2 requirements without ever speaking to the government directly.
Two data types draw the line. Federal contract information is the routine, non-public information generated under a contract, and it triggers Level 1. Controlled unclassified information is the sensitive category, things like technical drawings, specifications, and data covered by ITAR or export control, and it triggers Level 2. A contractor that cannot say for certain which data it holds cannot scope its own compliance, and that uncertainty is common enough that scoping is usually the first real project, not the paperwork at the end.
For an MSP, the trigger is simpler. If a client falls into either bucket and you run any part of the environment that stores, processes, or transmits that data, you are in scope with them. There is no version of this where the provider sits outside the boundary.
What Changed in July 2026: The Phase 2 Pause
On July 13, 2026, the Department of War issued a memorandum ordering an immediate suspension of the Phase 2 rollout. Phase 2 was the step that would have required contractors handling CUI to pass a third-party assessment from a certified assessor, known as a C3PAO, before winning Level 2 work. That transition had been scheduled for November 10, 2026. A CMMC Reform Task Force now has 60 days to review the program, and the department opened a public request for information alongside the pause.
Reporting from Federal News Network and Breaking Defense confirmed the memo the day it dropped, and client alerts from WilmerHale, Morrison Foerster, and Jenner & Block landed within a week. The legal read was consistent across all of them. As compliance attorney Marc Snyderman summarized it for the defense community, suspension is not repeal. Here is what the pause did not touch:
- DFARS 252.204-7012. The clause requiring 800-171 implementation and 72-hour incident reporting stays in every affected contract.
- Phase 1 self-assessments. Level 1 and Level 2 self-assessments introduced on November 10, 2025 remain mandatory, and contractors still need a current SPRS score to win new awards.
- False Claims Act exposure. A false or stale affirmation of compliance is still a fraud risk, and the Department of Justice has been pursuing those cases.
The request for information is the part MSPs should read closely. The Department of War asked for input on cost drivers, on which 800-171 controls deliver meaningful risk reduction, and on whether it should recognize commercial cybersecurity tools and managed services in lieu of a separate assessment. That last question points straight at the managed-services model. If the reformed program gives credit for a properly run managed security stack, the MSPs that can document their controls will have a commercial edge. Nobody knows the outcome yet, which is the point of watching it rather than standing down.
The Three CMMC Levels, Compared
Most of the confusion around CMMC comes from mixing up the levels. Each one maps to a data type, a control set, and a way of proving you meet it.
| Level | Data protected | Control basis | How it is verified |
|---|---|---|---|
| Level 1 | Federal contract information (FCI) | 15 basic safeguards (FAR 52.204-21) | Annual self-assessment, submitted to SPRS |
| Level 2 | Controlled unclassified information (CUI) | 110 controls (NIST SP 800-171 Rev 2) | Self-assessment now; third-party C3PAO assessment was the Phase 2 plan, currently paused |
| Level 3 | CUI on the highest-priority programs | Level 2 plus a subset of NIST SP 800-172 | Government-led DIBCAC assessment |
The vast majority of contractors land at Level 1 or Level 2. If a client only handles FCI, Level 1 is a self-assessment they can complete without an outside auditor. The moment CUI enters their environment, they are in Level 2 territory, and that is where the cost and the documentation burden climb.
The Assessment Path and Your SPRS Score
Every level runs through the Supplier Performance Risk System. A contractor scores their environment against the applicable controls, submits the result to SPRS, and a senior official affirms it annually. That SPRS score is now a gate: no current score, no new DoD contract. This did not change with the pause.
The scoring is unforgiving. Level 2 starts at 110 and subtracts points for every control that is not fully met, so a single missing multifactor authentication requirement can drop a score by five points. Controls you have not finished go into a plan of action and milestones, a POA&M, with a hard 180-day window to close them. Some controls cannot be POA&M'd at all and must be in place before you can claim a passing score.
Phase 2 would have added an independent check on top of the self-score for Level 2 CUI work. That check comes from a C3PAO, a third-party assessor accredited through the Cyber AB, and there are only a few dozen of them for a base of hundreds of thousands of contractors. The backlog math was part of why the program drew fire, and part of why the pause happened. Level 3 was always different: it runs through a government-led DIBCAC assessment rather than a commercial one, and the pause did not change that path either.
During the pause, the third-party check is not being enforced, but the self-assessment and affirmation still run through SPRS exactly as before. For an MSP, the practical takeaway is that a client's SPRS score reflects the environment you help run. If your documentation is thin, their score is soft, and a false affirmation built on your gaps is a legal problem that lands on the contractor first, then rolls back to the provider who signed off on the controls.
What CMMC Compliance Costs
Cost is the reason the program is under review, and the numbers explain why. A Level 1 self-assessment typically runs $5,000 to $15,000 in preparation and internal time. Level 2 is a different order of magnitude. Preparation to meet all 110 controls ranges from $50,000 to well over $500,000 depending on how far the environment sits from the standard, and a third-party C3PAO assessment, when it was required, added $50,000 to $150,000 on top. Ongoing maintenance runs another 10 to 20 percent of the initial spend every year.
The biggest cost lever is scope. A contractor that lets CUI spread across its whole network has to protect the whole network. One that isolates CUI into a defined enclave, a segmented environment with controlled access, only has to assess and secure that enclave. Scoping the boundary down is the single move that turns a $500,000 Level 2 project into something a small business can survive, and it is where an MSP earns its keep long before an assessor shows up.
Those figures fall hard on small businesses, which make up a large share of the defense supply chain. The pause and the request for information are, in part, a response to years of contractors on r/CMMC and government-contracting forums documenting this pain in detail. For MSPs serving that market, cost control is not a nice-to-have. It is the difference between a client staying in the defense market and walking away from it.
Where MSPs Fit: Shared Responsibility
Here is the rule that trips up both contractors and their providers. Using a cloud service or a managed service does not automatically satisfy a control. The Department of War has been explicit: the contractor must validate that the provider truly implements the control, document who owns what in a shared responsibility matrix, and confirm the configuration is switched on. If your MSP touches a client's systems, stores their data, supports their users, or administers their cloud tenant, you are inside their compliance boundary whether or not anyone wrote it down.
That creates concrete obligations. A multi-tenant environment has to keep one client's CUI separated from another's, so a flat management plane across your whole book of business is a finding waiting to happen. Administrative activity in a client environment has to be logged and the logs retained. Access has to be restricted to need-to-know. These are the same controls a mature security program runs anyway, which is why the cleanest path is a documented, consistent stack rather than a per-client patchwork. Our MSP security stack guide walks through the layers that map to 800-171 in practice.
Tooling is where this gets real. Meeting 800-171 means asset inventory, endpoint management, centralized logging, access control, and evidence you can hand an assessor. Flamingo is an AI-native all-in-one MSP and IT platform built to run those functions from one place, with native PSA included and without the vendor lock-in that makes a compliance stack expensive to change later. It is not a compliance certificate, and no platform is. It is a way to implement and document the controls once instead of stitching them across eight tools and hoping the evidence lines up. Affordable and portable matters here, because the client who cannot afford the stack is the client who leaves the defense market.
Evidence is the currency an assessor deals in, and it is where thin managed-services setups fall apart. Saying multifactor authentication is on does not count. A screenshot of the policy, a configuration export, and a log showing it enforced does. Every one of the 110 Level 2 controls needs that kind of artifact, and pulling it together after the fact is far more expensive than capturing it as you go. An MSP that generates evidence continuously, from a platform that logs and reports centrally, hands the client an assessment package instead of a scramble.
This is also where the July RFI turns into an opportunity rather than a headache. If the reformed program credits well-run managed services against assessment requirements, the providers who already document their controls will be positioned to sell that as a service, not absorb it as a cost. The MSPs treating the pause as a chance to get their evidence house in order are the ones who benefit if the rules shift that way.
Choosing which MSP carries a defense client also becomes a due-diligence question in both directions. A contractor should be asking their provider hard questions about logging, separation, and documentation before signing. The prompts in our guide to questions to ask an MSP before signing a contract map cleanly onto what a CMMC assessor will later want to see.
What To Do During the Pause
The worst move an MSP can make right now is treating the pause as a stop order. The task force has 60 days, the RFI closes on its own timeline, and the underlying obligations never lifted. Momentum is cheaper to keep than to rebuild.
- Keep implementing 800-171. Every control you finish now is a control that counts under whatever the reformed program looks like, and it protects the client today.
- Tighten the paperwork. A current system security plan, a live POA&M, and an accurate SPRS score are the artifacts that survive any version of CMMC.
- Lock the shared responsibility matrix. Write down which controls you own, which the client owns, and which you split, then hand the client evidence they can affirm honestly.
Watch the task force and the RFI, because the managed-services question inside it could reshape how MSP-delivered security gets credited. The contractors who kept building through the pause will be the ones ready to win work the day the rules settle. The ones who exhaled and stopped will be explaining a soft SPRS score to a contracting officer who did not get the memo about relaxing.
Compliance is where security starts, not where it stops. The pause changed the deadline. It did not change the job.
Marketing Manager
Ohayo! I'm Kristina, and I'm doing good things with content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
