60 Days Out: The Move That's Right No Matter What the Task Force Decides
What if CMMC gets cancelled entirely? Officials didn't rule it out. Here's why the right move is the same in every scenario anyway.
Let's start with the question every small defense contractor has been asking since July 13 — the one most compliance vendors would rather you didn't say out loud:
"What if CMMC gets cancelled entirely? Why would I buy anything right now?"
It's a fair question. It deserves a straight answer, and here it is: we don't know what the Task Force will decide. Neither does anyone else. When reporters pressed Department of War officials on whether the CMMC program could be cancelled outright at the end of the review, Katie Arrington's successor-era leadership — CISO David Davies and Under Secretary Michael Duffey — notably did not rule it out. The CMMC Reform Task Force reports to the DoW CIO within 60 days of the announcement, which puts the answer at roughly mid-September 2026. Until then, everything about the certification program is genuinely fluid.
Anyone who tells you they know how this ends is selling you their confidence, not their analysis. So we're not going to predict the outcome. We're going to do something more useful: lay out every plausible outcome side by side and ask, for each one, whether the work in front of you still pays off.
Because when you do that — when you actually run the scenarios instead of arguing about which is most likely — something remarkable happens. The right move turns out to be the same in every single one.
What We Know, and What Nobody Knows
Before the table, a quick inventory — because the honest case starts with separating fact from forecast.
What we know
- Phase II is suspended. The C3PAO third-party assessment pathway, the Phase III milestone, and pending CMMC implementation milestones are all on hold.
- Phase I self-assessment requirements "remain firmly in place." Those are the Department's own words — covering required self-assessments under both Level 1 and Level 2.
- DFARS 252.204-7012 and NIST SP 800-171 still bind you. They predate CMMC, they sit in your contracts today, and no part of the July 13 announcement touched them.
- "Select government-led assessments" were retained. The Department kept a mechanism to check the work — and if you're selected, your documentation is the only thing in the room.
- The review has a clock. Task Force findings are due within 60 days, and a public Request for Information gives the defense industrial base a formal channel for input.
What nobody knows
- Whether CMMC returns in streamlined form, gets replaced by a new model, gets cancelled outright, or simply stays suspended while the review runs long.
- What any successor framework would look like in detail — beyond officials' stated intent to build something "scalable" and "resilient" without reducing security.
- The timing of whatever comes next. Sixty days is the report deadline, not an implementation date.
That's the honest picture. Four plausible outcomes, no reliable way to handicap them. Now watch what happens when you stop trying to guess and start testing your options against all four at once.
The Four-Outcome Table
Here is every plausible ending to the 60-day review, and — for each one — the only question that actually matters to your business: does a defensible, documented NIST SP 800-171 self-assessment still serve you?
| Possible Outcome | What It Means | Does a Defensible Self-Assessment Still Serve You? |
|---|---|---|
| CMMC returns, streamlined | A reformed, lower-barrier framework built for small business realities | Yes — your documentation maps directly into the reformed program, and you enter it ahead of the field |
| CMMC is replaced | A new "scalable, resilient" model built on the same NIST foundation | Yes — NIST SP 800-171 is the substrate of whatever comes next; your work transfers |
| CMMC is cancelled outright | The certification program ends entirely | Yes — DFARS 252.204-7012 still legally binds you to protect federal data, certification program or not |
| Status quo extends | The suspension runs long while the review continues | Yes — self-assessments and select government-led assessments remain the active mechanism |
Look at the right-hand column. Every row says yes.
That is not a rhetorical trick, and it's not us stacking the deck. It's a direct consequence of something we've said in every installment of this series: the suspension paused a verification mechanism, not the underlying obligation. DFARS 7012 and NIST SP 800-171 sit beneath CMMC, beneath any replacement, and beneath a world with no certification program at all. As long as you hold — or want to hold — a defense contract, the requirement to protect federal contract information and demonstrate it survives every branch of the decision tree.
The no-regrets move
When the same action is correct in every possible future, you no longer need to predict the future to act. That's what makes a properly documented self-assessment a no-regrets move: it satisfies your DFARS obligation today, it satisfies your prime's flow-down today, it protects you in a government-led assessment today, and it positions you for whatever framework emerges tomorrow. There is no outcome where being able to prove you protect federal data turns out to be the wrong thing to have done.
Not sure where your posture actually stands?
Book a free 30-minute consultation. We'll walk through what your contracts require right now, where your documentation stands, and what a defensible self-assessment looks like for a business your size — no pressure, no predictions we can't back up.
Book a Free 30-Minute Consultation → Run the Free Assessment Tool"So I'll Just Wait for September" — Why Waiting Isn't Neutral
The most tempting response to uncertainty is to freeze. Wait for the report, then decide. It feels prudent. It feels free.
It isn't free. Waiting is a choice, and it has a price tag that accrues daily:
Primes are still gating awards on compliance
The Department suspending a phase does not amend your subcontract. Prime contractors still flow down DFARS 7012, still ask for your SPRS score, and still choose the supplier whose compliance story doesn't create risk on their contract. That gate did not open on July 13 — and the suppliers who can walk through it confidently are winning the work right now.
Solicitations still need suppliers
Defense demand didn't pause for the review. Under Secretary Duffey framed the suspension itself as a way of keeping companies in the industrial base "who would otherwise be forced out of the market at a time when we need them most." The market needs suppliers now — and it will award contracts now, to contractors who can attest to their posture now.
Half your competition is standing still
The "CMMC might be cancelled, so I'll do nothing" logic is widespread — which is precisely what makes it exploitable. Every competitor who freezes for 60 days hands you 60 days of relative advantage. Windows like this don't come along often, and they close the moment the report lands and everyone unfreezes at once.
Notice what's absent from that list: penalties, enforcement scare stories, countdown clocks. You don't need them. The cost of waiting isn't a threat — it's an opportunity cost, and it's already running.
One More Thing the 60 Days Are For: Being Heard
There's a second action available to you during this window, and it costs nothing but an afternoon.
Alongside the Task Force, the Department issued a public Request for Information — described by CISO Davies as truly the defense industrial base's opportunity to give direct feedback. The Task Force will synthesize those responses into its recommendations.
Here's why that matters for you specifically: small contractors have historically been the least-heard voice in this process. The compliance frameworks that nearly priced you out of defense work were shaped substantially by input from organizations with compliance departments, enterprise IT, and lobbying budgets. This review exists in part because the resulting math didn't work for the other 120,000+ small businesses in the DIB — as Davies put it, "the math just simply doesn't math."
If the next framework is going to be built for businesses your size, businesses your size need to show up in the record. Describe your real compliance burden. Describe what's achievable and what isn't. It's rare that saying so actually reaches the people redesigning the system. Right now, it does.
Your 60-Day Action Plan
Here's what a well-run small contractor does between now and mid-September — a sequence that leaves you stronger no matter which row of the table comes true:
Confirm what your contracts actually require
Read your DFARS clauses and your primes' flow-downs. Your obligations are whatever your contracts say they are — and no press release changed a word of them. This is a one-afternoon exercise that anchors everything else.
Baseline honestly
Not a spreadsheet of optimistic yes/no answers — an honest gap analysis against all 15 Level 1 practices (and NIST SP 800-171 if you handle CUI). Our free assessment tool covers all 15 L1 practices and produces a prioritized gap report in under 30 minutes.
Fix your evidence, not just your policies
A policy proves intent. Evidence proves operation. In a select government-led assessment — the mechanism the Department deliberately kept — only one of those carries the day. If your documentation says one thing and your systems say another, close that gap now, while nobody's asking to see it.
Complete your self-assessment and affirmation properly
Phase I is still in force. If your last self-assessment was a checkbox exercise, this is the quarter to make it defensible: documented scope, artifact-backed answers, a current SPRS score you'd be comfortable explaining to anyone who asked.
Respond to the RFI
Put your compliance reality on the record while the people redesigning the framework are actively reading. Small business input has never mattered more than it does during this exact window.
Bid
Your competitors are waiting for September. You don't have to. A finished, defensible self-assessment isn't just protection — it's a sales asset, and this is the market to use it in.
Closing the Series: What the Self-Assessment Era Actually Means
This is the sixth and final installment of The Self-Assessment Era, and the argument has been consistent from the first piece to this one:
- Part 1: What actually changed on July 13 — the suspension removed the third-party audit apparatus, not the compliance landscape.
- Part 2: The audit went away. The obligation didn't. — DFARS 7012, NIST 800-171, Phase I self-assessments, and False Claims Act exposure all remain.
- Part 3: Self-assessment is now the only path — and it was never the lesser option. It's the standard, at Level 1 and Level 2 alike.
- Part 4: "Select government-led assessments" — the three words everyone skipped, and why they raise the documentation bar rather than lower it.
- Part 5: Why "free" self-assessment isn't free — the real cost driver was never assessor fees. It's unstructured labor and rework.
- Part 6: This piece — the no-regrets case for acting during the uncertainty rather than after it.
Stitch those together and the through-line is simple: the suspension changed who checks your work, not whether the work matters. The answer to "who checks your work" is now, primarily, you — which makes structured, documented, defensible self-assessment more important than it was on July 12, not less.
That's what we build. The Turnkey CMMC Level 1 Package breaks all 15 practices into 142 defined artifacts with platform-specific templates for Microsoft 365 or Google Workspace, all 8 device and network configuration guides, an Evidence Locker, SPRS documentation, and 8 bi-weekly expert consulting sessions — $2,495/year (limited time: save $500 off the regular $2,995). Most clients complete their Level 1 assessment in 2–4 weeks. For CUI handlers eligible for self-assessment, the L2 CUI Enclave Package ($3,495/year) maps 110 practices to 182 artifacts on a dedicated enclave built for Google Workspace for Government or Microsoft 365 GCC High — pre-filled SSP, POAM framework, Risk Register, and evidence checklist, with no Active Directory, no SIEM, and no enterprise IT required.
⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.
The Bottom Line
We could have written a piece pretending to know what the Task Force will decide. Plenty will. Instead, here's the position we'd want if we were in your chair:
Nobody knows the outcome. You don't need to. When a defensible NIST SP 800-171 self-assessment pays off in every plausible future — streamlined CMMC, replaced CMMC, cancelled CMMC, or extended limbo — the uncertainty stops being a reason to wait and becomes a reason to move. The contractors who spend these 60 days finishing their documentation will be ready for any September. The ones who spend them guessing will be ready for none.
That's the whole argument. No fear, no countdown clock, no crystal ball. Just four rows, and a column that says yes.
Turn 60 days of uncertainty into a finished self-assessment.
Book a free 30-minute consultation. We'll map your contracts, your gaps, and your fastest path to a self-assessment you could hand to anyone — a prime, a government assessor, or whatever framework arrives in September.
Schedule Your Free 30 Minutes → Start with the Free AssessmentSources & Further Reading
- U.S. Department of War — "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements" (July 13, 2026)
- DefenseScoop — "DOD halts cybersecurity requirements for CMMC Phase 2: 'The math just simply doesn't math'" (July 13, 2026)
- National Defense Magazine — "BREAKING: Pentagon Suspends Phase 2 of CMMC Program" (July 13, 2026)
- U.S. Small Business Administration — "SBA Commends U.S. Department of War's Suspension of CMMC Phase II for Small Defense Contractors" (July 13, 2026)
- NIST SP 800-171 Rev. 2
This article is provided for informational purposes and does not constitute legal advice. Contractors should review their specific contract terms and DFARS clauses with qualified counsel.
