Following the Department of War’s July 13, 2026 suspension of CMMC Phase II, Echelon Risk + Cyber is urging defense contractors to continue NIST 800-171 implementation and security program development, noting that underlying contractual obligations remain fully in effect regardless of the certification pause.

Echelon Risk + Cyber, a cybersecurity consulting and managed security firm based in Pittsburgh, PA, has issued formal guidance to defense contractors following the Department of War’s July 13, 2026 suspension of CMMC Phase II requirements. The suspension removes the third-party C3PAO assessment requirement for Level 2 certification while a newly formed task force conducts a 60-day review of the program and solicits industry feedback on compliance burden. Echelon Risk + Cyber’s position is direct: contractors should not pause their security programs.
The suspension changes one thing. The C3PAO assessment requirement for CMMC Level 2 certification is off the table for now, with no confirmed reinstatement date until the task force reports in approximately mid-September 2026. What did not change is everything that actually governs a contractor’s security obligations. DFARS 252.204-7012 remains in every contract that included it before the suspension. The requirement to implement NIST SP 800-171 Rev 2 controls is unchanged. The 72-hour cyber incident reporting requirement is unchanged. Prime contractors can still flow DFARS 7012 requirements down to subcontractors, and a contracting officer can still request a System Security Plan and Plan of Action and Milestones at any time. Organizations that have not done the security work retain their False Claims Act exposure regardless of whether a formal assessment is scheduled.
Echelon Risk + Cyber’s guidance to contractors is to continue building and closing gaps in their NIST 800-171 programs, keep SSPs current, and redirect any budget previously allocated to C3PAO assessment scheduling toward security implementation work instead. The assessment requirement may pause. The threat environment has not.
As a Registered Provider Organization with certified Registered Practitioners, Echelon Risk + Cyber guides defense contractors through the full CMMC Level 2 readiness process, from scope definition and CUI flow mapping through gap assessment, remediation, and pre-audit validation. The firm’s rapid onboarding model allows contractors to begin the CMMC readiness process in weeks, with no backlog or waiting period.
Echelon Risk + Cyber has published a detailed breakdown of the suspension and its implications for contractors of all sizes. The firm is also tracking the CMMC Reform Task Force output and the public RFI process and will provide updated guidance as the 60-day review progresses.
Defense contractors interested in understanding what the suspension means for their specific contracts, SSPs, and NIST 800-171 programs can read Echelon Risk + Cyber’s full analysis, review the Echelon Risk + Cyber CMMC 2.0 compliance services, and explore the Aalyria case study detailing how Echelon Risk + Cyber helped a defense technology firm build audit-ready Level 2 compliance through embedded security engineering and governance support.
“The suspension removed the assessment deadline. It did not remove the obligation. Contractors that use this pause as a reason to slow down their security programs are trading real risk reduction for a compliance holiday that could end in 60 days. The work pays off regardless of what the task force recommends, because the contractual obligations and the threat environment have not changed,” said Josh Fleming, Senior Cybersecurity Manager for Risk Advisory Services, Echelon Risk + Cyber.
Defense contractors seeking guidance on CMMC readiness, NIST 800-171 implementation, or what the Phase II suspension means for their specific situation can contact Echelon Risk + Cyber directly to speak with a CMMC specialist.