CMMC Phase 2 Suspended: What Arizona Defense Contractors Should Do Now

On July 13, 2026, the Department of Defense suspended CMMC Phase 2. The November 10 deadline for mandatory third-party C3PAO assessments is gone. Phases 3 and 4 are frozen. And DoD officials explicitly did not rule out cancelling the program entirely after a 60-day review.

If you’re an Arizona defense contractor, you probably heard about this from a prime, a trade group, or a LinkedIn post. And you’re wondering: does this mean I can stop?

No. Here’s why.

What Actually Changed

The certification deadline is gone. You no longer need to have a C3PAO assessment completed by November 2026. The requirement for third-party certification is paused indefinitely pending a 60-day review.

Phases 3 and 4 are frozen. The later rollout phases that would have expanded CMMC requirements to more contract types are on hold.

The 60-day review could go any direction. DoD may reinstate Phase 2 as-is, modify it, delay it further, or potentially restructure the program. Nobody knows yet.

What Did NOT Change

DFARS 252.204-7012 is still in every CUI contract. This clause requires you to implement all 110 NIST SP 800-171 controls and report cyber incidents within 72 hours. It was there before CMMC existed. It’s still there now. The suspension didn’t touch it.

Your SPRS score is still required. Every contractor handling CUI still needs an accurate SPRS score on file. Contracting officers still check it before awarding work.

The DOJ is still enforcing false scores. The Civil Cyber-Fraud Initiative didn’t pause. MORSE Corp ($4.6M settlement), LOGZONE ($507K settlement), and the 233% increase in enforcement between 2024-2025 are all still precedent. If your score doesn’t match reality, the DOJ can still come after you.

Your prime still cares. Raytheon, Boeing, Northrop, General Dynamics, and every other prime in Arizona’s defense corridor are still flowing down security requirements to their subcontractors. They have their own compliance obligations. They don’t stop just because the government paused a certification program.

Why Stopping Preparation Is a Mistake

The controls are still required. CMMC didn’t create the 110 controls. NIST SP 800-171 did, and DFARS 252.204-7012 made them mandatory. The suspension removed the certification deadline. It didn’t remove the requirements.

Preparation takes 12-18 months. If Phase 2 resumes in 6 months with a 12-month implementation window, contractors who stopped preparing will be scrambling. Contractors who kept going will be ready.

Your competitors are still preparing. The contractors who see this suspension as an opportunity to get ahead rather than a reason to stop are the ones who will win contracts when certification resumes.

It protects your business regardless. The 110 controls exist because defense contractors are targeted by nation-state cyber actors. China, Russia, and others actively attack the defense supply chain. The security protections aren’t bureaucratic overhead. They’re the things keeping your intellectual property, your client relationships, and your contract eligibility intact.

What Arizona Defense Contractors Should Do Right Now

1. Don’t stop. If you’re mid-implementation, keep going. The controls are still required under DFARS, and you’ll be ahead when certification resumes.

2. Talk to your prime. Ask them directly: are they still requiring NIST 800-171 compliance in their flow-downs? (The answer will be yes.)

3. Verify your SPRS score. Is it accurate? Is it documented? Does it match your current environment? If you submitted a score two years ago and haven’t updated it, now is a good time.

4. Use the breathing room wisely. The suspension gives you time you didn’t have before. Use it to close gaps, build your SSP, complete your POA&M, and get your documentation in order. Don’t use it to relax.

5. Watch for updates. The 60-day review will produce guidance. We’re tracking it and will update our clients as information becomes available.

How Asteroid IT Helps

We’re a Phoenix-area managed IT and cybersecurity provider with a CyberAB Certified CMMC Professional on staff. We work with Arizona defense contractors throughout the Tucson-Phoenix corridor, from small machine shops to engineering firms supporting Raytheon, Boeing, and the Fort Huachuca intelligence community.

We help you implement the 110 controls, build your SSP, manage your POA&M, deploy compliant technology, and prepare for whatever comes next from DoD.

Want to know where you stand? We’ll review your SPRS score and assess your current compliance posture. Free. No obligation.

Call 480-937-7021 or schedule a free CMMC assessment.

Scroll to Top