CMMC phase 2 Is suspended. The liability It created for MSPs isn't Why the CMMC regulation is not dead and what MSPs need to do about it On July 13, 2026, the Department of War suspended the Cybersecurity Maturity Model Certification (CMMC) Phase 2, the third-party assessment mandate that was set to take effect November 10. Within days, managed service providers (MSPs) across the defense channel started fielding the same question from clients: does this mean CMMC is dead? It doesn't. And the MSPs who answer that question wrong are about to hand their most defensible service line to competitors who read the suspension memo more carefully. Reality check Here's what actually happened. Department of War CIO Kirsten Davies suspended the requirement for defense contractors to pass a Certified Third-Party Assessor Organization (C3PAO) audit before winning Level 2 contract awards. She did not suspend Phase 1. Self-assessment, SPRS score submission, and annual affirmation obligations under DFARS 252.204-7012 remain fully enforced, and NIST SP 800-171 Revision 2 stays the standard the Department checks against through self-assessments and select government-led reviews. The reasoning behind the decision was blunt. Davies told reporters “the math just simply doesn’t math” for the roughly 100,000 companies in the defense industrial base needing third-party assessment against the roughly 100 approved C3PAOs able to deliver it, with Small Business Administration data pointing to compliance costs approaching $7 billion a year for small and mid-sized contractors. A CMMC Reform Task Force review is due back to the Department CIO by mid-September, and officials have explicitly declined to rule out ending the third-party model altogether. That's the pattern MSPs need to see clearly. The Department suspended a verification mechanism. It did not suspend the obligation that mechanism existed to verify. Access controls Here's where it gets uncomfortable for MSPs specifically.