CMMC Phase II Suspended: What MSPs Need to Know
8 mins read

CMMC Phase II Suspended: What MSPs Need to Know

Key Points

  • The Department of War suspended CMMC Phase II requirements, but organizations must still comply with NIST SP 800-171, DFARS, and other existing federal security obligations.
  • The suspension pauses C3PAO certification requirements but does not eliminate self-assessments, SPRS score reporting, annual affirmations, or Controlled Unclassified Information (CUI) protection requirements.
  • MSPs should continue remediation efforts, validate SPRS submissions, maintain audit evidence, and confirm which systems process Federal Contract Information (FCI) or CUI.
  • Organizations remain responsible for accurate compliance attestations, and unsupported claims may create contractual, administrative, or False Claims Act (FCA) liability.

On July 13, 2026, the Department of War (DoW) published a release, “Forging the Arsenal of Freedom,” announcing an immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements. If you support clients in the defense industrial base (DIB), the network of companies that supply the DoW, you have probably fielded a version of this question all week, “Does this mean compliance is over?”

It does not.

A CMMC Reform Task Force now has 60 days to report back, using feedback gathered through a public Request for Information (RFI), the government’s formal process for collecting industry input before it changes a rule. However, reviews like this tend to run long, and that exact date isn’t guaranteed.

Why the Department suspended CMMC Phase II

The Department’s stated reason, per the release, is Secretary Pete Hegseth’s Acquisition Transformation System (ATS) directive, which prioritizes speed to capability and lower compliance costs for small, medium, and non-traditional businesses. The release cites Small Business Administration (SBA) data showing compliance costs were pushing companies out of the DIB. DoW Chief Information Officer (CIO) Kirsten A. Davies is quoted directly making that case.

There is also a simpler math problem behind this. By most estimates circulating since the announcement, well over 100,000 companies needed a third-party assessment against roughly 100 accredited assessors, making the original timeline nearly impossible to meet.

What the suspension changes

Phase II is suspended. This is the requirement for certified third-party assessments through a C3PAO (a CMMC Third-Party Assessment Organization, an accredited outside firm) or a review by DIBCAC (the Defense Industrial Base Cybersecurity Assessment Center, the Department’s own assessment arm). Any pending or future CMMC milestones are paused too.

In the interim, the Department will keep enforcing compliance through NIST SP 800-171 Rev 2 self-assessments (the federal standard listing the 110 security controls required to protect sensitive defense data) and what the release calls “select government-led assessments.” These will likely land mostly at the prime contractor level, further up the supply chain than most MSP clients. It reads as a reminder that the Department still has authority to look under the hood, more than a new audit program.

The requirements that are still in effect

Phase I self-assessment requirements are still fully in effect: FAR (Federal Acquisition Regulation) 52.204-21, covering basic safeguarding of Federal Contract Information (FCI), and DFARS (Defense Federal Acquisition Regulation Supplement) 252.204-7012, requiring safeguarding of Controlled Unclassified Information (CUI), cyber incident reporting, and implementation of all 110 NIST SP 800-171 controls. The release states plainly that the suspension “does not eliminate the requirement for companies to protect federal data.”

Also unaffected: Supplier Performance Risk System (SPRS) score entries, annual affirmations, International Traffic in Arms Regulations (ITAR) requirements, remediation plans, system security plans, and subcontractor flowdowns. CUI itself is a broad category, and ITAR is one of many standards underneath it. CMMC tried to bundle all of these into a single certification, and that bundling is what got paused. The requirements underneath it are all still in place.

Where the compliance risk exists

The suspension removed a verification step, but it did not remove the underlying obligation. What is gone, for now, is the third party that would have checked your work before a problem surfaced.

An inaccurate self-assessment or an unsupported affirmation can still create contractual, administrative, and False Claims Act (FCA) exposure, a federal law that holds a business, and often the individual who signed off, personally liable for knowingly defrauding government programs. Contracts already flow this requirement from primes to subcontractors, and that clause is likely to shift from proving a completed audit to something closer to, “Submit your self-attestation, and we reserve the right to audit you later.” Lying on it, especially after accepting government funds, can carry civil and criminal consequences. It is already public record that multiple DIB companies have been prosecuted under the False Claims Act for compliance claims that did not hold up.

Practical steps for MSPs

  • Keep remediation plans moving; this news is not a reason to pause them.
  • Check that SPRS scores and annual affirmations still reflect your client’s actual environment.
  • Confirm scope, such as which client systems touch CUI or FCI, and which of those you manage directly.
  • Keep evidence current, including audit trails, patch compliance records, and access logs, in case a prime contractor review comes up.
  • Tell clients plainly that suspended is not the same as resolved.

How NinjaOne supports CMMC and FedRAMP compliance

FedRAMP (the Federal Risk and Authorization Management Program, which governs which software platforms are approved to handle federal data) is not the same program as CMMC, and this suspension does not touch it. However, showing an assessor your platform already runs on FedRAMP-authorized infrastructure tends to simplify that conversation. NinjaOne is the only FedRAMP Moderate-authorized RMM (remote monitoring and management) platform on the market today.

Underneath all of it, NinjaOne helps MSPs operationalize and demonstrate the technical controls NIST SP 800-171 asks for: patch automation, role-based access control (RBAC), multi-factor authentication (MFA), and centralized reporting across every client environment you manage.

Every business in the defense industrial base remains legally accountable for producing its compliance record on request: logs, audit trails, and the self-attestation behind its SPRS score, whether or not a third-party assessor shows up to check it. That’s exactly why a platform built to keep that proof current and ready matters right now.


PakarPBN

A Private Blog Network (PBN) is a collection of websites that are controlled by a single individual or organization and used primarily to build backlinks to a “money site” in order to influence its ranking in search engines such as Google. The core idea behind a PBN is based on the importance of backlinks in Google’s ranking algorithm. Since Google views backlinks as signals of authority and trust, some website owners attempt to artificially create these signals through a controlled network of sites.

In a typical PBN setup, the owner acquires expired or aged domains that already have existing authority, backlinks, and history. These domains are rebuilt with new content and hosted separately, often using different IP addresses, hosting providers, themes, and ownership details to make them appear unrelated. Within the content published on these sites, links are strategically placed that point to the main website the owner wants to rank higher. By doing this, the owner attempts to pass link equity (also known as “link juice”) from the PBN sites to the target website.

The purpose of a PBN is to give the impression that the target website is naturally earning links from multiple independent sources. If done effectively, this can temporarily improve keyword rankings, increase organic visibility, and drive more traffic from search results.

Jasa Backlink

Download Anime Batch

Leave a Reply

Your email address will not be published. Required fields are marked *