Cybersecurity Maturity Model Certification (CMMC) Level 2 was built as a technical framework, but the accountability behind it has never lived in IT alone. That is truer in 2026 than it was a year ago.
On July 13, 2026, the Department of War (DoW) paused mandatory third-party (C3PAO) certification requirements while a Reform Task Force reviews the program. Some executives are reading that pause as a reason to step back. It’s actually a reason to lean in, since self-assessment puts more of the accountability directly on leadership.
Dig deeper below to learn more.
The certification mechanism under review is the third-party (C3PAO) assessment, not the standard itself. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2 and Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 remain fully in force during this review period.
Under CMMC 2.0, a senior official inside your organization, known as the Affirming Official, personally certifies your self-assessment results in the Supplier Performance Risk System (SPRS). For most contractors, that is the CEO, another senior executive, or, where the role exists, the Facility Security Officer (FSO).
A signature carries more weight when there is a documented Shared Responsibility Matrix (SRM) behind it, showing exactly which controls your organization owns and which a provider owns. That clarity is what protects the person signing, and it’s a reasonable thing for leadership to ask for before anyone puts their name on an attestation.
CMMC readiness isn’t a single line item on an annual IT budget. CMMC readiness isn't a single line item on an annual IT budget. For government contracting businesses, it deserves its own dedicated line item: a multi-year commitment that must be planned against your contract pipeline, not against a certification deadline that can move.
Our Compliance Without Compromise guide breaks down where compliance costs concentrate, how outsourced and in-house models compare, and why early budgeting consistently outperforms reactive spending. It’s worth a look before your next budget cycle locks in.
"If CMMC only shows up on the leadership agenda when news drops, you're already behind. The contractors who pass consistently treat it as a standing business risk, reviewed with the same rigor as revenue forecasts and signed by an executive who understands and verifies the evidence and process," says Ketan Patel, MBA, CISA, ISI Senior Vice President, Compliance.
None of this requires waiting for the CMMC Reform Task Force to finish its review. The standard, the attestation, and the accountability for both are already in place, and they will most likely still be in place whatever the Task Force recommends. The organizations that treat 2026 as a leadership problem, not just a technical one, are the ones that will be ready regardless of what changes next.
A senior official inside your organization, known as the Affirming Official, personally certifies your self-assessment results in SPRS. That’s typically the CEO, another senior executive, or, where the role exists, the FSO, and the requirement is unaffected by the Phase II suspension.
It doesn’t change the underlying standard. False Claims Act exposure applies when a certification was known, or reasonably believed, to be false, not from an honest mistake. Removing the third-party check means that verification now must happen internally before anyone signs.
It needs to be planned against your contract pipeline over multiple years, not a single fiscal year or a single regulatory deadline. Waiting until a solicitation requires certification is consistently the most expensive path.
No. DFARS 252.204-7012 and NIST SP 800-171 Revision 2 obligations are unchanged, and readiness work completed now remains applicable under any outcome of the review.