cybersecurity
CMMC Phase 2 Is Suspended: What Does That Actually Mean for Hampton Roads Contractors?
DoD suspended CMMC Phase 2 on July 13, 2026, pending a 60-day reform review. Phase 1 self-assessments, SPRS score submission, and DFARS 252.204-7012 obligations are still in force for Hampton Roads defense contractors. Here is what Newport News Shipbuilding subcontractors and the wider DIB still have to do.
On July 13, 2026, the Department of War suspended CMMC Phase 2, the requirement that would have forced third-party cybersecurity assessments on contracts involving Controlled Unclassified Information starting November 10, 2026. If you’re a subcontractor feeding parts, engineering services, or IT support into Newport News Shipbuilding, Naval Station Norfolk, Joint Base Langley-Eustis, or JEB Little Creek, and you read that sentence and felt a wave of relief, hold on. Phase 1 is still in force. Your DFARS 252.204-7012 obligations did not move. Your SPRS score still matters. What got suspended is the audit mandate, not the underlying requirement to protect CUI.
That distinction carries more weight here than in most of the country. Hampton Roads holds one of the densest defense industrial base subcontractor populations anywhere: shipyard suppliers clustered around Newport News, machine shops and logistics providers in Chesapeake and Suffolk, IT and engineering firms serving the Langley footprint in Hampton, port and maritime logistics operators tied to Portsmouth and the wider harbor. Here is what actually happened, what you still owe DoD this month, and why “paused” is not the same word as “over.”
What CMMC Phase 2 Suspended Actually Changes for Hampton Roads Defense Contractors
Newport News Shipbuilding is the largest industrial employer in Virginia, and its subcontractor base runs deep through Newport News and the wider Peninsula. Naval Station Norfolk is the largest naval base in the world, sitting alongside a dense contractor footprint in Norfolk. JEB Little Creek-Fort Story anchors a second cluster of DIB vendors on the Virginia Beach side. Add Joint Base Langley-Eustis in Hampton and the Port of Virginia’s maritime logistics traffic running through Portsmouth, Suffolk, and Chesapeake, and you get a region where a large share of small and mid-size businesses carry a DFARS 252.204-7012 clause somewhere in their contract stack, whether they think of themselves as a “defense contractor” or not.
That density is exactly why DoD cited the assessor shortage as its reason for suspending Phase 2: too many contractors, not enough C3PAOs to audit them. It also means more Hampton Roads businesses have direct exposure to this suspension than almost any other region in the country, and more of them are guessing at what it actually requires of them this month.
What Actually Happened? Plain-English Summary
DoD Chief Information Officer Kirsten Davies signed a memo suspending CMMC Phase 2, the tier that would have required certified third-party assessment organizations (C3PAOs) to formally audit contractors handling prioritized or critical CUI. Phase 3 and Phase 4, the later stages of full CMMC rollout, are suspended along with it.
The stated reason is a math problem, and Davies put it bluntly at the announcement: something north of 100,000 companies in the defense industrial base would eventually need a third-party assessment, and roughly 100 certified assessors existed to do the work. Small Business Administration data cited by DoD put the aggregate cost of rolling out future CMMC phases at more than $7 billion annually across small and mid-size businesses. Davies described the current framework as forcing “innovative new entrants and small businesses to opt out” of DoD contracts entirely.
In place of the C3PAO mandate, DoD stood up a CMMC Reform Task Force under the CIO’s office, pulling in Acquisition and Sustainment, Research and Engineering, Legislative Affairs, and legal counsel. The task force has 60 days to recommend a framework that, in DoD’s own language, “prioritizes speed to capability, lowers barriers for small, medium, and non-traditional businesses, and replaces prohibitive, third-party compliance models with scalable, realistic security measures.” A public request for information closes August 14, 2026, and industry comment is expected to shape whatever comes next.
None of that changes what CMMC exists to do. It changes how DoD plans to verify that you are doing it.
What Requirements Are Still in Force and Cannot Be Ignored?
Three things did not move, and they are the ones most likely to get an auditor’s attention or trigger a False Claims Act problem if you treat them as optional.

DFARS 252.204-7012. If your contract includes this clause, and most DoD contracts touching CUI do, you are still required to implement the 110 security controls in NIST SP 800-171 and to report covered cyber incidents to DoD within 72 hours. This clause predates CMMC and does not depend on it. The suspension of Phase 2 assessments has no bearing on this obligation. Shipyard prime contractors flow this clause down through their subcontractor base as a matter of course, so a machine shop in Suffolk or an engineering firm in Portsmouth working under a Newport News Shipbuilding subcontract is bound by 7012 whether or not the prime ever mentions CMMC by name.
Self-assessment and SPRS submission. CMMC Phase 1, which took effect in November 2025, requires an annual self-assessment against the applicable control set and a score submitted to the Supplier Performance Risk System, affirmed by a senior company official. That requirement is untouched. If your SPRS score is stale, inflated, or missing supporting evidence, that is a live exposure today, not a future one.
FAR 52.204-21 basic safeguarding. For contractors handling Federal Contract Information rather than CUI, the 17 basic safeguarding practices remain a contract condition regardless of anything happening with CMMC Phase 2.
Legal guidance following the suspension has been consistent on one point worth repeating: failing to actually implement the substantive security requirements underneath Level 1 or Level 2, even while the third-party audit mandate is paused, can expose a contractor to breach of contract or False Claims Act liability. The audit went away. The underlying legal duty to protect CUI did not.
What Does the 60-Day Review Mean, and When Will We Know More?
The Reform Task Force has until roughly mid-September 2026 to deliver findings and recommendations, drawing on a public comment period that closes August 14. That gives DoD a rough window for announcing what replaces the current C3PAO-heavy model, though a formal rulemaking process, if one is required, will take longer than the review itself.
Read that timeline for what it is: an internal deadline for a report, not a guaranteed date for a new rule. DoD has suspended Phase 2 before finalizing what comes next, which is exactly why contractors who assume the destination will look like Phase 1 forever are making an unverified bet. The stated goals, lowering the barrier for small businesses and replacing “prohibitive, third-party compliance models” with something more scalable, suggest the eventual framework will still require you to prove your security posture. It just may not require a $50,000 to $100,000 outside audit to do it.
Watch for task force output in September, then for any DFARS or 32 CFR Part 170 rulemaking that follows. Neither has happened yet.
Do I Still Need to Maintain My SPRS Score?
Yes. Nothing in the July 13 memo touches the SPRS submission requirement tied to Phase 1. If your score is not accurate and defensible today, that is worth fixing this month, not after the task force reports back. A contracting officer or a prime running due diligence on a subcontractor can pull your SPRS score at any time, suspension or not.
If you have not validated your score against your actual environment recently, that is the single most useful hour you can spend this week. An inflated score submitted in good faith two years ago and never revisited is a bigger liability than a low score you can explain.
How Does the Suspension Affect Contracts Already in Progress?
If a solicitation or an already-awarded contract specifically named a C3PAO assessment as a requirement, DoD has directed program managers to amend the requirements documents and directed contracting officers to modify awarded contracts, removing the C3PAO language before the next option period or the next scheduled administrative modification.
That is a directive to the contracting workforce, not an automatic change to your paperwork. Two things follow from that. First, if your contract still shows a C3PAO requirement, do not assume it quietly evaporated. Second, get the removal in writing. Email your contracting officer, ask for confirmation of how the suspension affects your specific contract, and keep that confirmation in your file. An ambiguous verbal assurance is not something you want to be relying on eighteen months from now if a new framework reintroduces third-party assessment in a different form.
Contracts that only required Phase 1 self-assessment were never touched by this suspension in the first place.
Should You Slow Down Your CMMC Compliance Work Right Now?
If you are early in a Level 2 program and have not started remediation, this is a reasonable moment to confirm which requirements your actual contracts carry before committing further budget to a C3PAO-specific timeline. That is different from stopping compliance work altogether.
If you are mid-assessment or mid-remediation, the more consistent guidance from legal and compliance advisors since July 13 has been to keep going. You are not building toward a third-party audit that might disappear. You are building toward NIST SP 800-171 implementation that DFARS 252.204-7012 already requires of you, suspension or not. A contractor with a documented System Security Plan, a defensible SPRS score, and 110 controls genuinely implemented is in a stronger competitive position no matter what the Reform Task Force recommends in September. A contractor who paused everything in July will be starting from further behind if the new framework still expects proof of implementation, just delivered differently.
The practical read: treat the C3PAO deadline as removed from your calendar, but keep the security work on it.
What Should Hampton Roads Defense Contractors Do This Month?
A few concrete actions, in order of urgency:
Confirm your contract language in writing. If any active solicitation or awarded contract names a C3PAO or Level 2 third-party assessment requirement, ask your contracting officer directly how the suspension applies and get the answer documented.
Validate your SPRS score. If you have not reviewed it in the last twelve months, or if your environment has changed since you submitted it, treat this as due now, not deferred.
Keep DFARS 252.204-7012 work moving. If you are implementing NIST SP 800-171 controls, the suspension changes nothing about that obligation. Continued progress here is what protects you regardless of what framework replaces Phase 2.
Watch the Reform Task Force output in September. Do not build a permanent compliance strategy around the assumption that things stay exactly as they are today.
Do not let “suspended” turn into “we can stop.” The DoD suspended an audit mechanism because it was unworkable at scale, not because CUI stopped needing protection.
Why Helix Stax for CMMC Readiness Right Now
A suspended assessment mandate is exactly the kind of news that gets misread as permission to relax, and that is where contractors lose ground to competitors who read the memo correctly. Helix Stax is a full-stack IT consulting firm working with Hampton Roads defense contractors on cybersecurity compliance: NIST 800-171 gap assessments, SPRS score validation, SSP development, and the practical security work, MFA, logging, segmentation, that DFARS 252.204-7012 still requires whether or not a C3PAO ever shows up.
If you are not sure where your program actually stands after this news, the free Helix Score gives you a directional read in about three minutes. If you want a full picture before deciding what to keep building and what to hold, book the free 60-minute assessment. You walk out knowing exactly which of your obligations moved on July 13, and which ones, the ones that actually carry legal risk, did not move at all.
Frequently asked questions about Helix Stax managed IT services
No. DoD suspended CMMC Phase 2, meaning the mandatory rollout of third-party (C3PAO) assessments and the Level 3 government-led assessments tied to it. CMMC Phase 1 remains in force: annual self-assessments against the applicable control set, SPRS score submission, and the underlying DFARS 252.204-7012 and NIST SP 800-171 obligations for any contract handling CUI. Nothing about your duty to protect Controlled Unclassified Information changed on July 13, 2026. What changed is how DoD verifies it, and even that is only paused for the length of a 60-day review.
Yes, and for most contractors already mid-process, that is the recommended path. Legal guidance following the suspension has consistently framed this as a speed bump, not a stop sign: contractors with assessments underway are advised to preserve that momentum rather than restart later under whatever framework the Reform Task Force recommends. Voluntary certification also keeps you ahead of competitors who pause everything and then scramble when a revised CMMC framework arrives.
For contracts and solicitations that specified a C3PAO assessment, DoD has directed program managers and contracting officers to amend the requirements documents to remove that specific clause, and to modify already-awarded contracts before the next option period or scheduled administrative modification. That process takes time and depends on your specific contracting office acting on the directive. Until you receive a written modification, do not assume the clause is gone. Confirm the status with your contracting officer in writing and keep the confirmation on file.