
CMMC Phase II Is Suspended. Here's What Still Binds You.
On July 13, 2026, the U.S. Department of War announced the suspension of CMMC Phase II and ordered a 60-day reform review. For Taiwanese manufacturers in the U.S. defense supply chain, the obligations that matter most — Phase I self-assessments, NIST SP 800-171 Rev 2, and DFARS 252.204-7012 — remain fully enforceable. And with self-assessment as the interim standard, the False Claims Act risk of getting your attestation wrong just went up.
What Happened on July 13
On July 13, 2026, the U.S. Department of War announced — in a release titled "Forging the Arsenal of Freedom" — the immediate suspension of CMMC Phase II requirements, memorialized in a memorandum dated July 10, 2026. The requirements had been scheduled to take effect on November 10, 2026.
Alongside the suspension, the Department created a CMMC Reform Task Force with a mandate to deliver recommendations within 60 days. The stated reasons: the cost burden of the program, a shortfall of qualified assessors, and the need to align CMMC with the Department's Acquisition Transformation System.
If your company supplies parts, components, or subassemblies into the U.S. defense industrial base — directly or through a prime — this changes your timeline. It does not change your obligations.
What Is Actually Suspended
Phase II is the stage of the CMMC rollout that would have made third-party certification a condition of new contract awards for many programs handling Controlled Unclassified Information (CUI). That requirement is now on hold while the Reform Task Force does its work.
What that means in practice: the C3PAO assessment you may have been racing to schedule before November is no longer a near-term contractual gate.
What Still Binds You — Today
Nothing else went away. Three sets of obligations remain fully enforceable:
1. CMMC Phase I self-assessments. Level 1 self-assessments and attestations for companies handling Federal Contract Information (FCI), and Level 2 self-assessments and attestations for companies handling CUI, continue to apply.
2. NIST SP 800-171 Rev 2. The 110 security controls remain the standard for protecting CUI, enforced through self-assessments — and through select government-led assessments. The government has not stopped checking; it has changed who does the first check.
3. DFARS 252.204-7012. The contractual safeguarding obligations in this clause remain fully in force. If the clause is in your contract — or flowed down to you from a prime — you are bound by it regardless of what happens to CMMC. Taiwanese subcontractors should pay particular attention here: these obligations typically reach you through flow-down provisions in purchase orders and subcontracts, not through a direct contract with the U.S. government.
The Part That Should Worry You: Self-Attestation and the False Claims Act
Here is the angle many suppliers will miss. With third-party certification paused, self-assessment is now the interim standard — as legal analysts at Hunton Andrews Kurth have noted in their briefing on the change. Your company assesses its own compliance with NIST SP 800-171 and attests to the result.
That sounds like relief. It is also exposure. Every self-assessment score you submit and every attestation you sign is a representation to the U.S. government. A false attestation — including one that is merely careless — can create liability under the False Claims Act, the U.S. government's primary tool for pursuing contractors who misrepresent compliance.
An independent assessor checking your work before you attest was, in a sense, a safety net. That net is gone. The question for your compliance program is no longer "when is our audit?" It is "can we defend what we attest?"
What Taiwanese Manufacturers Should Do Now
1. Do not pause your compliance program. The Reform Task Force reports within 60 days, and requirements may return in modified form. More importantly, your NIST SP 800-171 and DFARS 7012 obligations continue regardless of what the task force recommends.
2. Map your FCI and CUI scope. You cannot attest accurately to controls you have not scoped. Know which systems, people, and facilities touch U.S. defense data.
3. Re-verify your SPRS score against evidence. If you have already submitted a self-assessment score, confirm that every point of it is supported by documentation you could hand to a government assessor. If it is not, correct it — an inflated score on file is exactly the kind of record that creates False Claims Act problems later.
4. Check your flow-downs. Review the purchase orders and subcontracts you hold with U.S. primes for DFARS 252.204-7012 language. Those clauses did not get suspended, and your prime's compliance team will be asking about them.
5. Run your self-assessment like an audit. Structured control reviews, packaged evidence, a current System Security Plan, and honest POA&Ms for anything not yet in place. The standard to hold yourself to is simple: would this survive a government-led assessment?
6. Watch the 60-day window. The task force's recommendations will shape what certification looks like when it returns. Companies that keep their programs warm will re-enter that process from the front of the line.
The Bottom Line
The suspension changes the timing of certification, not the substance of compliance. For Taiwanese manufacturers competing for the trust of U.S. primes, demonstrable NIST SP 800-171 compliance — with the evidence to back it — is now a differentiator rather than a checkbox. The suppliers who treat this pause as a head start, rather than a holiday, will be the ones holding defensible attestations when the rules tighten again.
Sources
- U.S. Department of War, "Forging the Arsenal of Freedom," war.gov, article 4542329, July 13, 2026
- Crowell & Moring, client alert on the CMMC 60-day reform review, July 2026
- Hunton Andrews Kurth, briefing on NIST SP 800-171 self-assessment as the interim standard, July 2026
