The rule that created the Cybersecurity Maturity Model Certification program contains a projection that almost nobody quotes. In the regulatory impact analysis of 89 FR 83092, published 15 October 2024, the Department of Defense estimates that 8,350 medium and large entities will require a Level 2 certification assessment. It then projects how many will get one: "135 CMMC Third-Party Assessment Organization (C3PAO)-led assessments will be completed in the first year," followed by "673 C3PAO-led assessments in year 2," 2,252 in year 3, and 4,452 in year 4.
Year 2 starts on 10 November 2026. That is the date the compliance industry has spent eighteen months describing as the moment third-party certification becomes a condition of contract award. On the Department's own numbers, it was the year 673 companies out of 8,350 would be certified. Under 10 percent, and 808 across the first two years combined.
On 13 July 2026, the Department's chief information officer, Kirsten Davies, signed a memo suspending Phase 2 entirely, along with the milestones behind it, and stood up a 60-day reform task force whose report lands in the middle of this month. That has been read as a reversal. The projection suggests something duller and more useful: the schedule was bounded by assessment capacity from the day it was published, the rule said so in plain text, and the memo removed a date that the Department's own model never expected to bind.
The ramp was seven years, not one date
The rule is not coy about this. Immediately after the assessment projections, it states:
DoD is planning for a phased roll-out of each assessment level across 7 years with the entity numbers reaching a maximum by Year 4 as shown in the tables. The target of Year 4 was selected based on the projected capacity of the CMMC Ecosystem to grow to efficiently support the entities in the pipeline.
Read that second sentence again. The year-four target was not chosen from a risk assessment about how quickly controlled unclassified information needs protecting. It was chosen from a forecast of how fast the assessor market could grow. The schedule was reverse-engineered from supply.
Once you know that, the phase dates stop looking like enforcement deadlines and start looking like what they are: markers on a seven-year absorption curve, with the curve's shape set by how many people can be trained to perform an audit.
The rule reserved the right to move the date
Section 170.3(e)(2) defines Phase 2 in full:
Phase 2. Begins one calendar year following the start date of Phase 1. In addition to Phase 1 requirements, DoD intends to include the requirement for CMMC Status of Level 2 (C3PAO) for applicable DoD solicitations and contracts as a condition of contract award. DoD may, at its discretion, delay the inclusion of requirement for CMMC Status of Level 2 (C3PAO) to an option period instead of as a condition of contract award.
"Intends to." "May, at its discretion." Every phase in the schedule is drafted the same way, and that drafting is why July's suspension required no rulemaking, no comment period, and no amendment. Both 32 CFR part 170 and the DFARS acquisition rule (90 FR 43560, effective 10 November 2025, which is what started Phase 1) remain on the books today, unchanged and unamended. What was suspended was an intention the Department had explicitly reserved the right to revise.
Two official bodies, four weeks apart, on capacity
The July memo lists "severe shortages in third-party assessment capacity" among its reasons, alongside "prohibitive compliance costs" and "complex regulatory timelines," and says the program imposes "significant and often prohibitive burdens on the Defense Industrial Base (DIB), particularly the small and non-traditional businesses."
The body that accredits those assessors had said the opposite four weeks earlier. At the June 2026 Cyber AB town hall, the accreditation body reported 107 authorized C3PAOs and more than 1,000 certified assessors, 596 of them credentialed to lead. On capacity it was direct: "There is no CCA shortage relative to current demand. Some are booked through the year, but many aren't." The constraint it named was demand-side, "awareness and urgency on the part of OSCs who are waiting longer than they should."
Both statements are defensible, and the way they are both defensible is the entire problem. There is no shortage relative to current demand because current demand is a small fraction of eventual demand. The authorized assessor organizations went from 93 in December 2025 to 98 in February, 103 in March, and 107 in June: fourteen added in six months. That population was projected to deliver 673 assessments in year 2 and 4,452 in year 4. One of those numbers is reachable at the observed growth rate. The other is not.
When a schedule and a growth curve disagree, the schedule is the part that can be edited.
What the suspension is worth
There are companies for which this is real relief, and it would be dishonest to wave that off.
If you were mid-assessment with a C3PAO booked for October, you have your fee and your quarter back. If you had budgeted a Level 2 certification against a Q4 award you were not confident of winning, that money is now available for something with a clearer return. If you are a small subcontractor about to be flowed a clause you could not have satisfied in time, the suspension is the difference between bidding and not bidding. The memo's stated concern, that the program was pushing small and non-traditional firms out of the defense market, describes a real effect and deserves to be read as a finding rather than an excuse.
None of it changes what your contracts require of you today.
The 110 controls did not move
DFARS 252.204-7012 requires contractors handling covered defense information to implement the 110 controls of NIST SP 800-171. The compliance date in that clause was 31 December 2017. It is a mandatory flow-down, it survived the suspension untouched, and it was never contingent on CMMC existing.
Phase 1 is also still running. Self-assessment and annual affirmation took effect on 10 November 2025 and were explicitly left in force, and the Department said it will continue to rely on self-assessments and government-led assessments during the pause.
So the live question was never "when is the deadline." It is whether the 110 controls are implemented, whether the system security plan describes them accurately, and whether the score sitting in the Supplier Performance Risk System is one you would defend in front of someone with subpoena power. Those are the same 110 controls a Level 2 assessment measures. A third-party assessor brings no additional requirements. They bring an opinion about whether you met the ones you already had.
The work that would have produced a November certificate is the work a 2017 clause already obliges you to do. The suspension removed the witness, not the obligation.
Before the task force reports
The task force was given 60 days from 13 July, so its recommendations arrive within weeks. The plausible outcomes run from a narrower assessment scope, to a longer ramp, to broader acceptance of self-attestation for lower-risk work. Nobody outside the review knows which, and confident predictions about it are guesses wearing a suit.
One thing does not depend on the answer. If your 800-171 implementation is real, every version of CMMC that could emerge from this review costs you a fee and some scheduling. If it is not, you have been out of step with a clause from 2017 for eight years, the suspension bought you nothing, and every reform on the table still ends with someone checking those 110 controls.
The date moved. The controls did not.
