Cybersecurity
CMMC Phase 2 Is Suspended: What Does That Actually Mean for Hampton Roads Contractors?
DoD suspended CMMC Phase 2 on July 13, 2026, pending a 60-day reform review. Phase 1 self-assessments, SPRS score submission, and DFARS 252.204-7012 obligations are still in force for Hampton Roads defense contractors. Here is what Newport News Shipbuilding subcontractors and the wider DIB still have to do.
On July 13, 2026, the Department of War suspended CMMC Phase 2, the requirement that would have forced third-party cybersecurity assessments on contracts involving Controlled Unclassified Information starting November 10, 2026. If you’re a subcontractor feeding parts, engineering services, or IT support into Newport News Shipbuilding, Naval Station Norfolk, Joint Base Langley-Eustis, or JEB Little Creek, and you read that sentence and felt a wave of relief, hold on. Phase 1 is still in force. Your DFARS 252.204-7012 obligations did not move. Your SPRS score still matters. What got suspended is the audit mandate, not the underlying requirement to protect CUI.
That distinction carries more weight here than in most of the country. Hampton Roads holds one of the densest defense industrial base subcontractor populations anywhere: shipyard suppliers clustered around Newport News, machine shops and logistics providers in Chesapeake and Suffolk, IT and engineering firms serving the Langley footprint in Hampton, port and maritime logistics operators tied to Portsmouth and the wider harbor. Here is what actually happened, what you still owe DoD this month, and why “paused” is not the same word as “over.”
What to Do Right Now, in Order of Priority
If you read nothing else, read this. Three things:
First, don’t let your SPRS score go stale. If you have not run a self-assessment in the last 12 months, that is your most exposed gap regardless of which CMMC phase is active.
Second, keep building toward Level 2 if your contracts involve CUI. The controls are not going away. See the CMMC readiness checklist for what to have documented before any assessment, self or third-party.
Third, watch the Reform Task Force output. The RFI comment period closes August 14, 2026, and the task force report is due within 60 days of the July 13 announcement. Expect a revised timeline to follow, not an immediate one.
Everything below explains why, in more detail than you probably need this week but will need eventually.
What CMMC Phase 2 Suspended Actually Changes for Hampton Roads Defense Contractors
Newport News Shipbuilding is the largest industrial employer in Virginia, and its subcontractor base runs deep through Newport News and the wider Peninsula. Naval Station Norfolk is the largest naval base in the world, sitting alongside a dense contractor footprint in Norfolk. JEB Little Creek-Fort Story anchors a second cluster of DIB vendors on the Virginia Beach side. Add Joint Base Langley-Eustis in Hampton and the Port of Virginia’s maritime logistics traffic running through Portsmouth, Suffolk, and Chesapeake, and you get a region where a large share of small and mid-size businesses carry a DFARS 252.204-7012 clause somewhere in their contract stack, whether they think of themselves as a “defense contractor” or not.
That density is exactly why DoD cited the assessor shortage as its reason for suspending Phase 2: too many contractors, not enough C3PAOs to audit them. It also means more Hampton Roads businesses have direct exposure to this suspension than almost any other region in the country, and more of them are guessing at what it actually requires of them this month.
What Actually Happened? Plain-English Summary
DoD Chief Information Officer Kirsten Davies signed a memo suspending CMMC Phase 2, the tier that would have required certified third-party assessment organizations (C3PAOs) to formally audit contractors handling prioritized or critical CUI. Phase 3 and Phase 4, the later stages of full CMMC rollout, are suspended along with it.
The stated reason is a math problem, and Davies put it bluntly at the announcement: something north of 100,000 companies in the defense industrial base would eventually need a third-party assessment, and roughly 100 certified assessors existed to do the work. Small Business Administration data cited by DoD put the aggregate cost of rolling out future CMMC phases at more than $7 billion annually across small and mid-size businesses. Davies described the current framework as forcing “innovative new entrants and small businesses to opt out” of DoD contracts entirely.
In place of the C3PAO mandate, DoD stood up a CMMC Reform Task Force under the CIO’s office, pulling in Acquisition and Sustainment, Research and Engineering, Legislative Affairs, and legal counsel. The task force has 60 days to recommend a framework that, in DoD’s own language, “prioritizes speed to capability, lowers barriers for small, medium, and non-traditional businesses, and replaces prohibitive, third-party compliance models with scalable, realistic security measures.” A public request for information closes August 14, 2026, and industry comment is expected to shape whatever comes next.
None of that changes what CMMC exists to do. It changes how DoD plans to verify that you are doing it.
What Requirements Are Still in Force and Cannot Be Ignored?
CMMC is not one requirement. It is a layered set of obligations, and the July 13 announcement only touched one layer: the schedule for rolling Level 2 third-party assessments into new contracts. Here is what did not move, and what is most likely to get an auditor’s attention or trigger a False Claims Act problem if you treat it as optional.

Still required, unchanged by the pause:
- CMMC Phase 1, Level 1 self-assessment against 15 basic safeguarding practices for contractors handling Federal Contract Information, with annual affirmation.
- NIST SP 800-171 Rev 2, the 110 security controls that any contract with DFARS 252.204-7012 has required since well before CMMC existed.
- SPRS score submission and affirmation. DFARS 252.204-7020 requires contractors handling CUI to have a current NIST SP 800-171 assessment score in the Supplier Performance Risk System, regardless of CMMC’s rollout status.
- 72-hour incident reporting, the DFARS 252.204-7012 obligation to report covered cyber incidents to DoD within 72 hours of discovery.
- Existing contract clauses. If DFARS 252.204-7021 with a specific CMMC level is already written into your contract, that clause holds unless your contracting officer modifies it.
Paused as of July 13, 2026:
- Phase 2 rollout, the schedule that would have started requiring Level 2 C3PAO third-party assessments in new contracts on November 10, 2026.
- Phase 3 and Phase 4 milestones, later-stage requirements, including Level 3 government-led assessments, frozen along with Phase 2.
The detail behind those two lists matters as much as the lists themselves.
Shipyard prime contractors flow DFARS 252.204-7012 down through their subcontractor base as a matter of course, so a machine shop in Suffolk or an engineering firm in Portsmouth working under a Newport News Shipbuilding subcontract is bound by 7012 whether or not the prime ever mentions CMMC by name. This clause predates CMMC and does not depend on it.
CMMC Phase 1 took effect in November 2025, with annual self-assessment scores affirmed by a senior company official. If your SPRS score is stale, inflated, or missing supporting evidence, that is a live exposure today, not a future one.
FAR 52.204-21 basic safeguarding. For contractors handling Federal Contract Information rather than CUI, the 15 basic safeguarding practices remain a contract condition regardless of anything happening with CMMC Phase 2.
Legal guidance following the suspension has been consistent on one point worth repeating: failing to actually implement the substantive security requirements underneath Level 1 or Level 2, even while the third-party audit mandate is paused, can expose a contractor to breach of contract or False Claims Act liability. The audit went away. The underlying legal duty to protect CUI did not.
Why the Confusion Is Understandable
Headlines compress. “DoD suspends CMMC” reads like the whole program stopped. What actually happened is narrower: DoD paused the next step in a multi-year rollout, while leaving the compliance obligations that predate CMMC, and that CMMC was built to formalize, exactly where they were. NIST SP 800-171 has applied to CUI-handling DoD contractors since DFARS 252.204-7012 took effect in 2017. CMMC’s job was to add teeth via mandatory assessment. The assessment mandate’s expansion paused. The underlying standard did not.
For contractors in Hampton Roads working shipbuilding support, base operations, or defense manufacturing contracts, this distinction is the difference between “we can stand down” and “we keep doing what we were already supposed to be doing.” It is the latter.
What Does the 60-Day Review Mean, and When Will We Know More?
Four dates are confirmed as of this writing, and everything past them is not:
- July 13, 2026: DoD announces immediate suspension of the CMMC Phase 2 rollout, which was set to require Level 2 C3PAO third-party assessments in new contracts starting that November. Phases 3 and 4 are frozen alongside it, and DoD stands up the CMMC Reform Task Force.
- November 10, 2026: the date Phase 2 was originally set to take effect. This date is now suspended, not simply delayed. No new effective date has been published.
- August 14, 2026: deadline for the public RFI comment period, giving Defense Industrial Base stakeholders a formal channel to weigh in on the reform review before the task force finalizes its recommendations.
- Mid-September 2026 (approximate): the Reform Task Force’s report to the DoD Chief Information Officer is due within 60 days of the July 13 announcement. That is a reporting deadline, not a schedule republication date. A report being delivered does not automatically mean a new rollout timeline is published the same day.
That gives DoD a rough window for announcing what replaces the current C3PAO-heavy model, though a formal rulemaking process, if one is required, will take longer than the review itself.
Read that timeline for what it is: an internal deadline for a report, not a guaranteed date for a new rule. DoD has suspended Phase 2 before finalizing what comes next, which is exactly why contractors who assume the destination will look like Phase 1 forever are making an unverified bet. The stated goals, lowering the barrier for small businesses and replacing “prohibitive, third-party compliance models” with something more scalable, suggest the eventual framework will still require you to prove your security posture. It just may not require a $50,000 to $100,000 outside audit to do it.
Watch for task force output in September, then for any DFARS or 32 CFR Part 170 rulemaking that follows. Neither has happened yet.
What’s Reasonably Likely, and What Isn’t Confirmed
Based on the stated reasons for the pause, cost burden on small and mid-size contractors and questions about assessor capacity, it is reasonable to expect the task force’s recommendations to touch cost-sharing structures, assessment tiering by contractor size, or assessor capacity requirements. That is informed expectation based on the task force’s public mandate, not a confirmed outcome, and it should be treated that way until DoD publishes findings.
What is not confirmed: any specific date in 2027 or 2028 for Phase 2 to resume, what changes, if any, will apply to the existing control requirements themselves, and whether the resumed timeline will look like the original phased schedule or something restructured. Verify any specific future date you read, including in this article, against the DoD’s official CMMC program page before relying on it for contract planning, and confirm applicability to your specific contracts with a compliance advisor or attorney.
Do I Still Need to Maintain My SPRS Score?
Yes. Nothing in the July 13 memo touches the SPRS submission requirement tied to Phase 1. If your score is not accurate and defensible today, that is worth fixing this month, not after the task force reports back. A contracting officer or a prime running due diligence on a subcontractor can pull your SPRS score at any time, suspension or not.
If you have not validated your score against your actual environment recently, that is the single most useful hour you can spend this week. An inflated score submitted in good faith two years ago and never revisited is a bigger liability than a low score you can explain.
How Does the Suspension Affect Contracts Already in Progress?
If a solicitation or an already-awarded contract specifically named a C3PAO assessment as a requirement, DoD has directed program managers to amend the requirements documents and directed contracting officers to modify awarded contracts, removing the C3PAO language before the next option period or the next scheduled administrative modification.
That is a directive to the contracting workforce, not an automatic change to your paperwork. Two things follow from that. First, if your contract still shows a C3PAO requirement, do not assume it quietly evaporated. Second, get the removal in writing. Email your contracting officer, ask for confirmation of how the suspension affects your specific contract, and keep that confirmation in your file. An ambiguous verbal assurance is not something you want to be relying on eighteen months from now if a new framework reintroduces third-party assessment in a different form.
Contracts that only required Phase 1 self-assessment were never touched by this suspension in the first place.
Should You Slow Down Your CMMC Compliance Work Right Now?
If you are early in a Level 2 program and have not started remediation, this is a reasonable moment to confirm which requirements your actual contracts carry before committing further budget to a C3PAO-specific timeline. That is different from stopping compliance work altogether.
If you are mid-assessment or mid-remediation, the more consistent guidance from legal and compliance advisors since July 13 has been to keep going. You are not building toward a third-party audit that might disappear. You are building toward NIST SP 800-171 implementation that DFARS 252.204-7012 already requires of you, suspension or not. A contractor with a documented System Security Plan, a defensible SPRS score, and 110 controls genuinely implemented is in a stronger competitive position no matter what the Reform Task Force recommends in September. A contractor who paused everything in July will be starting from further behind if the new framework still expects proof of implementation, just delivered differently.
The practical read: treat the C3PAO deadline as removed from your calendar, but keep the security work on it.
Why This Is a Runway, Not a Reprieve
Most contractors treat a compliance deadline like a wall: nothing happens until it is close, then everything happens at once. A paused deadline removes the wall but keeps the distance. The work is the same work. What changed is that you are no longer racing a specific date.
That is exactly the situation where on-demand security leadership earns its cost. A virtual CISO can spend this window building the SSP, closing control gaps, and running the self-assessment cycle at a sustainable pace, instead of the compressed scramble a hard deadline usually forces. When the reform task force publishes new milestones, and it will, contractors who used the pause well show up with a program instead of a panic. Contractors who used the pause to stop show up needing the same 6 to 12 months they would have needed in July, except now on a shorter runway. If you are weighing whether a vCISO fits a smaller shop, see What Is a vCISO?
A composite scenario, built from patterns we see across Hampton Roads defense subcontractors: a 40-person marine engineering firm supporting base operations had a CMMC Level 2 self-assessment roughly 60% complete when the pause hit. Leadership’s first instinct was to shelve the project until “CMMC comes back.” Instead, they kept the gap remediation moving at half the original pace, using the freed-up deadline pressure to fix root-cause issues, a flat network, no MFA on remote access, rather than the fastest workaround. They will likely finish ahead of wherever the new Phase 2 milestone lands, at lower cost than a compressed sprint would have required.
POA&M Deferral Mechanics, Separate From the Program Timeline
Worth distinguishing from DoD’s phase rollout: a Plan of Action and Milestones is a contractor-level tool, letting you document specific control gaps with a committed remediation date rather than requiring every one of the 110 NIST SP 800-171 controls fully implemented before assessment. The CMMC Program rule restricts which controls, generally lower-severity ones, can be deferred this way; higher-severity or foundational controls typically cannot sit open on a POA&M at assessment time. This mechanism operates independent of whatever DoD does with Phase 2 timing. A well-maintained POA&M is part of readiness regardless of which phase is officially active. See the CMMC Readiness Checklist for how it fits into your broader documentation package.
What Should Hampton Roads Defense Contractors Do This Month?
A few concrete actions, in order of urgency:
Confirm your contract language in writing. If any active solicitation or awarded contract names a C3PAO or Level 2 third-party assessment requirement, ask your contracting officer directly how the suspension applies and get the answer documented.
Validate your SPRS score. If you have not reviewed it in the last twelve months, or if your environment has changed since you submitted it, treat this as due now, not deferred.
Keep DFARS 252.204-7012 work moving. If you are implementing NIST SP 800-171 controls, the suspension changes nothing about that obligation. Continued progress here is what protects you regardless of what framework replaces Phase 2.
Watch the Reform Task Force output in September. Do not build a permanent compliance strategy around the assumption that things stay exactly as they are today.
Do not let “suspended” turn into “we can stop.” The DoD suspended an audit mechanism because it was unworkable at scale, not because CUI stopped needing protection.
Why Helix Stax for CMMC Readiness Right Now
A suspended assessment mandate is exactly the kind of news that gets misread as permission to relax, and that is where contractors lose ground to competitors who read the memo correctly. Helix Stax is a full-stack IT consulting firm working with Hampton Roads defense contractors on cybersecurity compliance: NIST 800-171 gap assessments, SPRS score validation, SSP development, and the practical security work, MFA, logging, segmentation, that DFARS 252.204-7012 still requires whether or not a C3PAO ever shows up.
If you are not sure where your program actually stands after this news, the free Helix Score gives you a directional read in about three minutes. If you want a full picture before deciding what to keep building and what to hold, book the free 60-minute assessment. You walk out knowing exactly which of your obligations moved on July 13, and which ones, the ones that actually carry legal risk, did not move at all.
Read more
Cybersecurity
NIST 800-171 Checklist: The 14 Control Families and How Scoring Works
A working NIST 800-171 checklist covering all 14 control families, the SPRS scoring formula, Rev 2 vs Rev 3 changes, and where NIST SP 800-172 fits. Built for Hampton Roads defense subcontractors.
Cybersecurity
IT Disaster Recovery Plan Template (With RTO/RPO and Site Comparison)
A free IT disaster recovery plan template covering RTO, RPO, hot vs. warm vs. cold site recovery, testing cadence, and how it maps to NIST SP 800-34. Copy it and fill in your own numbers.
Cybersecurity
6 Phishing Email Examples Your Staff Will Actually See (And How to Train Against Them)
Real-world phishing email examples: fake invoices, MFA fatigue, payroll redirects, vendor bank-change scams, and more. What gives each one away, plus how to run simulation training.
Frequently asked questions about Helix Stax managed IT services
No. DoD suspended CMMC Phase 2, meaning the mandatory rollout of third-party (C3PAO) assessments and the Level 3 government-led assessments tied to it. CMMC Phase 1 remains in force: annual self-assessments against the applicable control set, SPRS score submission, and the underlying DFARS 252.204-7012 and NIST SP 800-171 obligations for any contract handling CUI. Nothing about your duty to protect Controlled Unclassified Information changed on July 13, 2026. What changed is how DoD verifies it, and even that is only paused for the length of a 60-day review.
Yes, and for most contractors already mid-process, that is the recommended path. Legal guidance following the suspension has consistently framed this as a speed bump, not a stop sign: contractors with assessments underway are advised to preserve that momentum rather than restart later under whatever framework the Reform Task Force recommends. Voluntary certification also keeps you ahead of competitors who pause everything and then scramble when a revised CMMC framework arrives.
For contracts and solicitations that specified a C3PAO assessment, DoD has directed program managers and contracting officers to amend the requirements documents to remove that specific clause, and to modify already-awarded contracts before the next option period or scheduled administrative modification. That process takes time and depends on your specific contracting office acting on the directive. Until you receive a written modification, do not assume the clause is gone. Confirm the status with your contracting officer in writing and keep the confirmation on file.