01 — COMPLIANCE POSTURE BRIEF

CMMC after the suspension: what software vendors still owe

On 13 July 2026, the Phase 2 requirement for mandatory certification by an authorized third-party assessment organization was suspended by DoD CIO Memo 26-P-1023. No replacement date has been published.

Two readings of that are common and both are wrong. It is not the end of CMMC, and it is not permission to stop. What was suspended is one step — who confirms your posture. What was not suspended is the posture itself: DFARS 252.204-7012 still obliges adequate security by reference to NIST SP 800-171, the separate self-assessment requirement is still in force, and the 72-hour cyber incident reporting obligation is untouched.

The practical consequence is narrower and more awkward than either reading. You have lost the date you were planning against and kept every obligation you were planning to meet. An applicable Department of War solicitation can still specify a certified assessment on its own terms, and a prime can still flow the requirement down by contract, so the gate moved from a calendar to the document in front of you — which is harder to see coming, not easier.

What is inside

  • What the 13 July 2026 suspension actually paused — and the much larger set of obligations it left standing.
  • Level 1 or Level 2: the data question that decides which one you are in.
  • Where the 110 requirements actually consume engineering time, and the one that is not a requirement at all.
  • Scoping — the architectural decision that sets the price of everything downstream.
  • Why conditional status is narrower than vendors read it as.
  • A five-step sequence ordered by your pipeline, now that there is no government date to work back from.

Where it comes from

Drawn from the public federal record — DoD CIO Memo 26-P-1023, the Federal Register, the Department of War's own CMMC program materials, the current clause text on acquisition.gov, and fedramp.gov for the baselines the external cloud service requirement points at. Six pages. No vendor pitch, and no company's self-attested compliance claim presented as a verified fact.

GovExpress is a diagnostic. We are not an assessor, a C3PAO, a 3PAO, or a certification body, and nothing in the brief certifies anything. It is informational and is not legal advice.

02 — COMMON QUESTIONS
Is there a CMMC certification deadline?

Not at present. The Phase 2 requirement for mandatory certification by an authorized third-party assessment organization was suspended on 13 July 2026 by DoD CIO Memo 26-P-1023, and no replacement date has been published. NIST SP 800-171 obligations under DFARS 252.204-7012 continue to apply, the separate self-assessment requirement is still in force, and an applicable Department of War solicitation can still specify a certified assessment on its own terms.

Does this apply if we are only a subcontractor?

CMMC requirements flow down. A prime carrying a Level 2 obligation is required to pass the applicable requirement to subcontractors handling the same information, which is why the requirement usually arrives as a supply-chain questionnaire rather than as a solicitation.

Why do you ask for a work email?

The brief is written for people evaluating defense work on behalf of a company, and a work address is how we keep the list to that audience. We send a confirmation link first and only deliver the brief once you click it, so the address is verified before anything is sent. If your company does not have its own mail domain yet, email us and we will send it across directly.