Hudson Valley Managed IT, Cybersecurity, AI & VoIP Phone Systems — Serving NY, NJ & CT
Menu Close

CMMC Phase 2 Suspended July 13, 2026: What Every Hudson Valley Defense Contractor Still Has To Do

Top 3 Key Takeaways

  1. The audit requirement is paused. The security controls are not. The Department of War suspended CMMC Phase 2 third-party audits on July 13, 2026, but DFARS 252.204-7012, NIST SP 800-171 Rev 2, Phase 1 self-assessments, SPRS score submission, and annual affirmation remain fully enforceable. Nothing about your day-to-day compliance obligations changed.
  2. DOJ False Claims Act enforcement is the real risk right now. The Civil Cyber-Fraud Initiative did not pause. Inflated or inaccurate SPRS scores still carry federal legal exposure, and prime contractors are still flowing down 800-171 obligations. Treating the suspension as a reason to slow down cybersecurity investment walks contractors into liability, not away from it.
  3. August 14, 2026 at 12:00 PM ET is the one window to influence what comes next. The 60-day CMMC Reform Task Force reports around September 13, and the public RFI closes August 14. Hudson Valley defense contractors who submit input now will help shape the replacement framework. Everyone else will inherit whatever is written without them.
Download CMMC Readiness Assessment

The bottom line up front

On July 13, 2026, the Department of War (formerly Department of Defense) suspended CMMC Phase 2 — the November 10, 2026 rollout of third-party (C3PAO) certification requirements. This is not a cancellation. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171 Rev 2, SPRS score submission, annual affirmations, and DOJ False Claims Act enforcement all remain fully in force. The pause covers the verification mechanism, not the security obligation. A 60-day CMMC Reform Task Force will report to the DoW CIO around mid-September 2026, and public comments on the reform are due August 14, 2026 at 12:00 PM ET.

If you are a Hudson Valley manufacturer, defense contractor, or supplier flowing down from a prime, this article breaks down exactly what changed on July 13, what did not change, and the seven concrete steps to take this week — with a Hudson Valley lens no one else is writing.

What exactly did the Department of War suspend on July 13, 2026?

The Department of War suspended the ramp-up of third-party CMMC assessments — specifically, the November 10, 2026 transition to Phase 2, which would have required independent C3PAO certification for Level 2 and DIBCAC assessment for Level 3. All pending and future CMMC milestones, including Phase 3 (November 2027) and Phase 4 (November 2028), are held in abeyance until further notice.

Signed by DoW Chief Information Officer Kirsten A. Davies alongside Under Secretary for Acquisition and Sustainment Michael Duffey, the action was published under case number 26-P-1023 (Federal News Network, Crowell & Moring).

Suspended, effective immediately:

  • The November 10, 2026 transition to CMMC Phase 2
  • All pending and future CMMC implementation milestones (Phase 3 and Phase 4 also on hold)
  • New solicitation requirements for CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments — contracting officers were directed to amend active solicitations and remove those clauses from existing contracts at the next option or modification
  • CMMC waiver processing during the review period

Still fully in force:

  • DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
  • NIST SP 800-171 Rev 2 — all 110 security requirements
  • CMMC Phase 1 self-assessments — Level 1 for FCI, Level 2 for CUI, in effect since November 10, 2025
  • SPRS score submission and annual executive affirmation
  • DFARS flow-down obligations from prime contractors to subcontractors
  • DOJ Civil Cyber-Fraud Initiative — False Claims Act enforcement against inflated SPRS scores continues (DefenseScoop)

The verification was cut. The obligation was not.

Is CMMC cancelled?

No. CMMC is suspended, not repealed. The program is codified in 32 CFR Part 170 and the DFARS rule finalized under DFARS Case 2019-D041. A memorandum directs procurement behavior inside the Department; it does not amend the Code of Federal Regulations. Removing CMMC entirely would require full notice-and-comment rulemaking.

DoW CIO Davies and Under Secretary Duffey both declined to rule out narrowing, restructuring, or cancelling the program once the 60-day review concludes (IntelliGRC). The most likely outcome is a reformed framework that leans on managed cybersecurity services and self-attestation rather than a full-scale C3PAO audit regime. Plan for reform, not repeal.

Who does this affect in the Hudson Valley?

Any Hudson Valley business that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) — directly or through a prime contractor flow-down — is affected. That includes hundreds of small manufacturers, precision machine shops, aerospace suppliers, engineering firms, and IT services providers across Orange, Ulster, Dutchess, Rockland, Putnam, and Sullivan counties.

The Hudson Valley has a deeper defense footprint than most people realize. Suppliers here flow parts, engineering services, and IT support into primes like Sikorsky (Stratford, CT), IBM Federal, Lockheed Martin, Boeing, ITT/Goulds Pumps, and dozens of tier-2 aerospace and industrial buyers. Even a five-person machine shop that produces one component for a DoD supply chain is likely subject to DFARS 7012 flow-down clauses.

The suspension changes what the federal government will directly require in a new contract. It does not change what your prime contractor can flow down to you.

What do Hudson Valley defense contractors need to do this week?

Do not stand down. The verification mechanism paused; the security obligation did not. Seven concrete actions this week protect your contracts, your prime relationships, and your DOJ risk exposure.

1. Confirm your current SPRS score and affirmation

Level 1 requires annual submission. Level 2 (Self) requires assessment every three years plus annual affirmation. Log in to SPRS today and verify your score is current and your affirmation is on file. An expired affirmation is a documented gap the moment a contracting officer looks.

2. Audit your active contracts for Level 2 (C3PAO) or Level 3 requirements

Under the July 13 implementation memo, contracting officers were directed to remove C3PAO and DIBCAC assessment clauses from active solicitations as soon as practicable, and from existing contracts at the next option period or scheduled modification. Modifications are not automatic. Contact your contracting officer in writing and get the amendment schedule documented.

3. Keep your NIST 800-171 Rev 2 program running

All 110 controls still apply everywhere DFARS 7012 applies. Access controls, MFA, incident response, configuration management, media protection, physical security, personnel screening, risk assessment, security assessment, and system communications protections — every control family. This is the checklist your prime contractor will still ask you to attest to.

4. Watch the DOJ Civil Cyber-Fraud Initiative

False Claims Act cases against defense contractors who submitted inflated or false SPRS scores are still active. The July 13 pause did not change enforcement. If your SPRS score does not match your actual control implementation, your legal exposure is the same today as it was on July 12.

5. Submit input to the CMMC Reform RFI by August 14, 2026, 12:00 PM ET

The Department opened a Request for Information — "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base" — that will feed directly into the 60-day Reform Task Force. If you are a Hudson Valley small manufacturer struggling with compliance cost, this is your one window to influence what replaces the C3PAO audit (Carbide Secure summary).

6. Review every prime contractor flow-down clause in writing

Primes can require whatever they want in their subcontracts. Some will keep the C3PAO expectation independent of the federal timeline because their downstream compliance officers do not want to loosen posture. Others will relax. Ask each prime, in writing, what they still expect and when. Do not assume.

7. Do not pause your cybersecurity investment

Cyber insurance underwriters, prime contractors, and DOJ enforcement all still expect NIST 800-171-grade controls. Ransomware groups targeting Northeast defense manufacturers have not paused. This is the wrong moment to defer EDR, MDR, backup, or incident response investments.

Not sure where your SPRS score stands after July 13?

We are offering a free CMMC readiness review to Hudson Valley defense-adjacent businesses through August 2026. Thirty minutes, no sales pressure — a real look at your SPRS score, your control gaps, and your prime flow-down obligations.

Book Free CMMC Readiness Review

What should you tell your prime contractor this week?

Send a short written note to every prime you subcontract to. Ask three questions: (1) Are you removing the Level 2 (C3PAO) requirement from our subcontract? (2) If not, what timeline should we plan to? (3) What documentation do you want us to submit in the interim — SPRS score, System Security Plan, POA&M, or all three?

Written confirmation protects both sides. It documents your compliance posture, and it puts the prime on record about their expectations. That is the paper trail you will want if a contracting officer or auditor comes back to you six months from now.

What is the 60-day CMMC Reform Task Force reviewing?

The Task Force is a cross-department team — Office of the CIO, Acquisition and Sustainment, Research and Engineering, Information and Security, Legislative Affairs, Public Affairs, and Legal — charged with a top-to-bottom review of CMMC. The stated goal: preserve genuine cyber hygiene while lowering compliance barriers for small, medium, and non-traditional defense contractors.

Areas of review:

  • Cost drivers — the DoW cited an SBA estimate of more than $7 billion per year in aggregate compliance costs for small and mid-sized DIB businesses
  • C3PAO capacity — approximately 104 authorized C3PAOs for roughly 100,000 DIB companies. Davies described the math bluntly: "the math just simply doesn't math"
  • Which of the 110 NIST 800-171 controls actually reduce risk in a modern environment
  • Whether commercial managed cybersecurity services or SaaS platforms can substitute for separate third-party assessments
  • How to reduce administrative overhead without lowering security effectiveness

The final report is due to DoW CIO Davies around mid-September 2026. Public guidance will follow the report by several weeks.

What happens after mid-September 2026?

The most likely outcome is a revised framework — not a return to the pre-July 13 status quo, and not a full cancellation. Expect narrower third-party audit scope, broader acceptance of managed-service attestations, and a compliance regime designed to keep small businesses in the DIB rather than push them out.

Possible outcomes on the table:

  • Narrowed C3PAO scope — only the highest-risk contracts require third-party audit
  • Managed-service attestation — recognized cyber MSPs can attest on behalf of small clients
  • Extended self-assessment window — self-affirmation with periodic government spot-checks
  • Cancellation — unlikely, but not ruled out by Davies or Duffey

The one certainty: NIST 800-171 and DFARS 7012 will remain. The security floor is not moving.

What Hudson Valley manufacturers should keep doing regardless of the reform outcome

The underlying threat picture has not paused. Ransomware operators, nation-state actors, and business email compromise groups continue to target Northeast defense manufacturers. Cyber insurance underwriters still require NIST 800-171-grade controls. Prime contractors still expect a defensible security posture. The nine-item baseline below is what a Hudson Valley manufacturer should have running today, CMMC reform or not.

Control areaWhat good looks like in 2026
Identity & accessEnforced MFA on every account, conditional access, no shared logins
Endpoint detection & responseManaged EDR (Huntress class or better), 24/7 SOC monitoring
Managed detection & response24/7 human-verified triage on high-severity alerts
Configuration managementBaseline images, change management, patch discipline
Incident responseDocumented plan, tested quarterly with tabletop exercises
Backup & disaster recoveryImmutable, off-site, tested restores (Datto DRaaS or equivalent)
Security awarenessMonthly training, phishing simulation, tracked completion
Cloud & vendor riskFedRAMP Moderate (or equivalent) where CUI touches the cloud
DocumentationCurrent System Security Plan (SSP), Plan of Action & Milestones (POA&M), SPRS score

This is also the exact baseline our Hudson Valley clients maintain every day. It is what we mean when we talk about our Hudson Valley cybersecurity and IT compliance services.

Who is the Hudson Valley's IT compliance authority?

The honest answer: there are only a handful of MSPs in the Hudson Valley that live in the compliance conversation every day, and Fisch Solutions is one of them. We have spent 20 years supporting Hudson Valley manufacturers, defense-adjacent suppliers, municipal governments, and regulated small businesses. We run NIST 800-171-aligned control environments in production for local clients right now. We deliver annual SPRS-ready self-assessment support. We maintain Huntress-class EDR, 24/7 managed detection, and Datto immutable backup as our standard security stack — not as an upsell.

What separates a compliance-fluent MSP from a general break-fix shop, at this moment in particular, is whether the team is already fluent in the DFARS 252.204-7012 / NIST 800-171 / SPRS conversation before the client asks. Fisch is. That is why our team is regularly asked to speak on cybersecurity, publish practitioner content, and support other Hudson Valley businesses through their compliance work.

Third-party validation we point clients to:

If you are evaluating Hudson Valley MSPs on the specific question of CMMC / NIST 800-171 fluency, ask this: can the provider walk me through my current SPRS score, my POA&M, and my DFARS 7012 flow-down obligations in the first call? If the answer is yes, you have a compliance-serious partner. Ours is.

Free CMMC Readiness Review for Hudson Valley Defense-Adjacent Businesses

Available through August 2026. Real look at your SPRS score, control gaps, and prime flow-down obligations. No sales pressure.

Schedule 30 Minutes

Additional resources for Hudson Valley defense contractors

Frequently asked questions

Is CMMC cancelled?

No. CMMC Phase 2 was suspended by the Department of War on July 13, 2026 pending a 60-day Reform Task Force review. CMMC Phase 1 self-assessment requirements remain in effect, and further guidance is expected after the review concludes around mid-September 2026.

Do I still need to submit an SPRS score?

Yes. SPRS score submission and annual executive affirmation are Phase 1 obligations and are unaffected by the July 13 suspension. Contractors and subcontractors must continue submitting current scores and signed affirmations to remain eligible for award.

Does the July 13 suspension change DFARS 252.204-7012?

No. DFARS 252.204-7012 — the Safeguarding Covered Defense Information and Cyber Incident Reporting clause — is fully intact. Every defense contractor handling covered defense information remains contractually obligated to implement NIST SP 800-171 Rev 2 and report cyber incidents to DoD within 72 hours.

When will CMMC Phase 2 restart?

No replacement date has been announced. The CMMC Reform Task Force will deliver recommendations to the DoW CIO around mid-September 2026 (60 days after the July 13 memo). Public implementation guidance will follow the report by several weeks. The November 10, 2026 date is no longer active.

What is the CMMC Reform Task Force?

A cross-department team led by DoW CIO Kirsten Davies with representatives from Acquisition and Sustainment, Research and Engineering, Information and Security, Legislative Affairs, Public Affairs, and Legal. The Task Force is conducting a top-to-bottom review of CMMC informed by a public Request for Information and will deliver a final report and recommendations to the CIO within 60 days of July 13, 2026.

What is the CMMC RFI deadline?

Public responses to the Request for Information "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base" are due August 14, 2026 at 12:00 PM Eastern Time. This is the industry's formal window to submit input on cost, control effectiveness, and framework alternatives.

Can my prime contractor still require C3PAO assessment?

Yes. Prime contractors can flow down whatever cybersecurity requirements they choose to their subcontractors, independent of the federal CMMC timeline. Confirm in writing with every prime what they still expect and when.

Is my existing Level 2 (C3PAO) certification still valid?

Yes. Existing Level 2 assessments completed under CMMC 2.0 remain valid through their normal three-year certification cycle. The suspension pauses the rollout of new Phase 2 requirements to future contracts — it does not invalidate certifications already issued. Continue maintaining your NIST 800-171 controls, SPRS score, and annual affirmation. If your certification is approaching renewal, plan for reassessment on your normal timeline.

Does this affect False Claims Act cybersecurity enforcement?

No. The Department of Justice Civil Cyber-Fraud Initiative continues to bring False Claims Act cases against defense contractors who submitted false or inflated SPRS scores or misrepresented their cybersecurity posture. The pause did not change enforcement risk.

Where can I read the official CMMC memo?

The official memo is DoD CIO Memorandum 26-P-1023, "CMMC Reform," dated July 13, 2026, published on the Department of War CIO CMMC page. A direct PDF is hosted by Federal News Network.

Sources

  1. Department of War Chief Information Officer, "CMMC Reform" memorandum 26-P-1023, July 13, 2026 — Department of War CIO CMMC page
  2. DefenseScoop, "DoD halts cybersecurity requirements for CMMC Phase 2," July 13, 2026
  3. Crowell & Moring, "Department of War Immediately Suspends CMMC Phase II Requirements," July 13, 2026
  4. National Law Review, "DoD Suspends CMMC Deadlines and Seeks to Reassess Requirements," July 15, 2026
  5. IntelliGRC, "CMMC Phase 2 Suspension: What Changed, What's Still Required, and What's Next," July 14, 2026
  6. Summit 7, "CMMC Phase 2 Suspended with 60 Day Review," July 14, 2026
  7. Carbide Secure, "What Actually Changed for Your CMMC Level 2 Compliance," July 15, 2026
  8. The Defense Compliance Report, "Is CMMC Still Required After the Suspension?" July 15, 2026

About the author

Jason Fisch is President of Fisch Solutions, a Hudson Valley managed IT and cybersecurity firm serving manufacturers, defense-adjacent contractors, healthcare, government, and legal clients since 2006. Fisch Solutions has been recognized on the CRN MSP 500 and Channel Futures MSP 501 (#245 in 2026). Jason is a Goldman Sachs 10,000 Small Businesses alumnus and speaks regularly on MSP operations, cybersecurity, and small-business scaling across New York State.

Please follow and like us:
Please follow and like us:
Posted in Resource

Let's Talk!

Want a simple way to stay on top of New York’s new cybersecurity rules? Download our exclusive 2026 Cybersecurity Compliance Checklist for small businesses. Enter your email below to get instant access to the PDF and receive updates on compliance deadlines.