By Hayley Steele, Associate Director of Market Intelligence & Strategic Programming, MassMEP
On July 13, 2026, the Department of Defense announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect November 10, 2026. For manufacturers who have been working toward certification, the phones started ringing. What does this mean? Do we stop? Do we wait? Do we start over?
The short answer: keep going.
The suspension does not eliminate your cybersecurity obligations. It does not repeal the CMMC program rule. It does not release you from the requirements already embedded in your contracts. What it does is pause the November deadline for Phase II third-party assessments by Certified Third-Party Assessment Organizations (C3PAOs), and it launches a 60-day review of the program by a newly formed CMMC Reform Task Force.
Phase I self-assessments, SPRS scores, and all DFARS safeguarding requirements remain fully in force. If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), those obligations did not change on July 13.
Why the Suspension Happened
The DoD CIO cited two core problems. First, the compliance cost burden on small and mid-size manufacturers in the defense supply chain. SBA data projected future CMMC phases could cost small businesses more than $7 billion annually. Second, an assessor shortage that made the certification timeline functionally impossible at scale, with more than 100,000 companies needing assessments and roughly 100 authorized C3PAOs available to conduct them.
The goal of the review is to reform the program, not end it. Officials have not ruled out ending it entirely, but the direction of the suspension is toward fixing the process, not abandoning the requirement for cybersecurity protection of defense information. That distinction matters for how manufacturers should respond.
What This Means for Massachusetts Manufacturers
Massachusetts has a significant defense supply chain. Manufacturers across the Commonwealth, from prime suppliers to sub-tier contractors, have been working to understand and meet CMMC requirements. The suspension gives additional time. It does not give permission to stop.
The manufacturers who will be best positioned when Phase II does take effect, in whatever form the reform task force recommends, are the ones who used this window to continue the work. Gap assessments completed now are not wasted. System Security Plans developed now are not wasted. The documentation, the controls, the internal processes built toward CMMC compliance are the same work that protects your contracts and your data today, regardless of where the certification timeline lands.
Stopping because the deadline moved is the costliest thing a manufacturer can do. The False Claims Act risk that comes with certifying CMMC compliance while not actually meeting cybersecurity obligations did not go away with Phase II. The contractual requirements in existing DFARS clauses did not go away. The cyber threats targeting the defense industrial base did not go away.
What You Will Learn on August 12
MassMEP and Synagex are hosting a one-hour information session on August 12, 2026, at 11:00 a.m. to cut through the noise and give manufacturers a clear picture of where things stand and what to do next.
Whether you are already working through a gap assessment or just beginning your CMMC journey, this session is designed to meet you where you are. The agenda covers:
- What the July 13 announcement means, and what it does not
- Why continuing your CMMC preparation is still the right move
- How the suspension affects manufacturers at different stages of CMMC readiness
- Next steps based on what we know today
The session closes with a live Q&A with CMMC experts. This is one hour with people who have been working in this space every day and can answer your specific questions directly.
The Window Is Open. Use It.
The 60-day reform review is underway. The public RFI comment deadline is August 14, one day after our session. The task force will report its findings and recommendations shortly after. What comes next is not yet known.
What is known: manufacturers who stay the course on cybersecurity preparedness are protected regardless of where the policy lands. Those who step back and wait are exposed.
Register for the August 12 information session here and come with your questions.
