CMMC is the US Department of War's cybersecurity requirement for defense contractors and their subcontractors. If your small business handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) as part of work for the US defense industrial base, CMMC applies to you. On July 13, 2026, the Department suspended Phase 2 of the program, which would have required third-party assessments starting November 10, 2026. Phase 1, which requires self-assessments, remains in effect. Here is what that means for small businesses in the defense supply chain.

What is CMMC and who needs it?

The Cybersecurity Maturity Model Certification (CMMC) is a framework the Department of War uses to verify that contractors and subcontractors protect sensitive information. The program applies to any business, regardless of size, that handles one of two categories of information:

  • Federal Contract Information (FCI): Information provided by or generated for the government under a contract that is not intended for public release. This triggers CMMC Level 1.
  • Controlled Unclassified Information (CUI): Information the government requires to be safeguarded under specific laws, regulations, or policies, such as technical data, export-controlled information, or certain types of financial and personnel data. This triggers CMMC Level 2.

The key point for small businesses: CMMC requirements flow down through prime contracts. If you are a subcontractor to a defense prime and your work involves FCI or CUI, the CMMC requirement applies to you, even if your contract is with a private company rather than the government directly.

What changed with the July 2026 suspension?

On July 13, 2026, the Department of War announced an immediate suspension of Phase 2 of CMMC implementation. Phase 2 had been scheduled to begin on November 10, 2026, and would have required Level 2 contractors to obtain third-party certification from a CMMC Third Party Assessment Organization (C3PAO).

During the suspension:

  • Contracts may only require Level 1 (Self) or Level 2 (Self) assessments.
  • Program managers and contracting officers may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments.
  • The underlying requirements of NIST SP 800-171 Rev 2 and DFARS clause 252.204-7012 remain in effect. The suspension does not eliminate the obligation to protect CUI.

On September 3, 2026, the Department issued Class Deviation 2026-O0025, Revision 3, which made the suspension binding. Contracting officers are now required to remove or revise third-party assessment requirements from both new solicitations and existing contracts. This is not a temporary pause that can be reversed casually; reversing a class deviation is a more involved process than lifting a policy suspension.

The Department has stated it will conduct a comprehensive review of CMMC aimed at "lowering barriers for small, medium, and non-traditional businesses" and "replacing bureaucratic compliance with scalable, resilient cybersecurity measures." No restart date for Phase 2 has been announced.

What still applies today?

Even with Phase 2 suspended, the following requirements are active and enforceable:

  • DFARS clause 252.204-7012 requires contractors to implement NIST SP 800-171 Rev 2 to protect CUI. This has been in defense contracts since 2017.
  • CMMC Level 1 self-assessment is required for contractors handling FCI. This is an annual self-assessment against the 15 security requirements in FAR clause 52.204-21, with results entered into the Supplier Performance Risk System (SPRS).
  • CMMC Level 2 self-assessment is required for contractors handling CUI. This is a self-assessment every three years against the 110 security requirements in NIST SP 800-171 Rev 2, with annual affirmation and SPRS score entry.
  • Prime contractors can still require more. Even though the government has suspended third-party assessment requirements, a prime contractor can still flow down stricter cybersecurity requirements to subcontractors as a condition of doing business. Some primes may continue to require C3PAO certification or equivalent evidence of compliance.

Does a Canadian supplier to US defense contractors need CMMC?

If your Canadian business is a subcontractor to a US defense prime and you handle FCI or CUI, the CMMC requirements flow down to you. The suspension of Phase 2 applies equally to foreign suppliers in the defense supply chain. During the suspension, your prime contractor should only be requiring Level 1 (Self) or Level 2 (Self) assessments from you.

However, the underlying obligation to protect CUI under NIST SP 800-171 Rev 2 applies regardless of the assessment method. If your prime is passing CUI to you, you are expected to implement the 110 controls in NIST SP 800-171, maintain your SPRS score, and affirm compliance annually.

Canadian businesses should also consider that some US primes may continue to require third-party evidence of compliance as a business condition, even if the government is not mandating it. The suspension is a government procurement rule, not a limit on what private parties can require in their supply chain agreements.

What should you do this quarter?

For small businesses in the defense supply chain, the Phase 2 suspension is not a reason to stop working on cybersecurity. The underlying requirements are still there, and the suspension could be lifted when the Department completes its review. Here is a practical sequence:

  1. Determine whether you handle FCI or CUI. Review your contracts for DFARS clauses, markings, or references to controlled information. Ask your prime contractor directly if you are unsure. If you do not handle either category, CMMC does not apply to you.
  2. Complete your self-assessment. For Level 1, assess against the 15 requirements in FAR 52.204-21. For Level 2, assess against NIST SP 800-171 Rev 2. Identify gaps and document them in a System Security Plan (SSP) and Plan of Action and Milestones (POA&M).
  3. Enter your SPRS score. The Supplier Performance Risk System is where self-assessment results are recorded. Your score, ranging from -203 to 110, reflects how many controls you have fully implemented. A perfect score of 110 means all 110 NIST SP 800-171 controls are in place.
  4. Affirm compliance annually. CMMC requires annual affirmation that your assessment is current and accurate. Missing this step can make your CMMC status lapse.
  5. Ask your prime what they require. Even with the government suspension, your prime may have additional expectations. Clarify whether they require third-party assessment, specific scores, or particular controls as a condition of your subcontract.

The bigger picture for small businesses

The CMMC program was created because self-attestation alone was not working. Years of breach data showed that many contractors were attesting to compliance without actually implementing the required controls. The third-party assessment requirement was intended to close that gap by having independent assessors verify what contractors claimed.

The suspension of Phase 2 reflects a policy debate about how to balance security requirements with the burden on small businesses. The Department has signaled it wants to lower barriers for smaller contractors while maintaining cybersecurity standards. What emerges from the current review may look different from the original CMMC structure.

For small businesses, the practical takeaway is this: the suspension gives you more time, but it does not eliminate the requirement to protect sensitive information. If you handle CUI, you are still expected to implement NIST SP 800-171 controls. The businesses that use this period to close their gaps will be better positioned when the program resumes, whatever form it takes.

One question to ask your IT lead this week

Do we know whether we handle FCI or CUI, and if so, what is our current SPRS score?

If the answer is "I don't know," that is the conversation to have before the next contract renewal. The suspension does not change the fact that inaccurate self-attestation carries real consequences, including potential False Claims Act liability for misrepresenting compliance status.

If you are unsure where your business stands on the controls that CMMC and NIST SP 800-171 cover, our free cybersecurity assessment takes about five minutes and covers many of the same areas.


This article is intended for general informational purposes only and does not constitute professional security, legal, or compliance advice. CMMC requirements and implementation status are based on Department of War guidance as of the date of publication and may change. Organizations should consult qualified legal and cybersecurity professionals before making compliance decisions based on this article. This is not legal advice.