Comparison graphic: what's still worth paying for versus what can wait after the CMMC Phase 2 suspension

If you read our last post, you already know the short version: the Department of War suspended CMMC Phase 2 on July 13, 2026, and the C3PAO third-party audit that was supposed to kick in on November 10 is on hold. What we didn't get into there is the question every contractor with a CMMC budget line actually wants answered. Does that change what you should be spending money on right now?

Short answer: some of it, yes. Not all of it.

Where the line actually sits

Still worth paying forCan reasonably wait
A gap assessment against the full 110 NIST SP 800-171 controls A full C3PAO-style mock assessment timed to a November deadline that no longer exists
Remediating real, identified gaps, especially anything touching access control or CUI handling Rushing remediation purely to hit a certification date
Keeping your System Security Plan (SSP) accurate and current Formal C3PAO scheduling or deposit payments
Making sure your self-assessment score in SPRS reflects reality Anything sold to you as "must complete before Phase 2." That framing is now false.

Why "wait and see" gets expensive faster than it looks

The suspension paused the audit. It did not pause the underlying rule. The DFARS 252.204-7012 obligation to safeguard covered defense information is still in force, and so is every contractor's exposure under the False Claims Act if their actual security posture doesn't match what they've represented in a contract, an invoice, or an SPRS self-assessment score.

That kind of exposure isn't theoretical. In June 2026, an Alabama defense contractor, LOGZONE, agreed to pay $507,144 to resolve allegations that it knowingly failed to meet cybersecurity requirements on two Navy contracts. That case predates the suspension and has nothing to do with C3PAO certification. It's a straightforward misrepresentation claim, the kind that exists whether or not Phase 2 ever resumes.

So the real risk calculus isn't "do I need to be certified." It's "does what I've told the government about my security posture match what's actually true." That question didn't get suspended on July 13.

What the $50 million grant actually is, and isn't yet

You may have seen headlines about a CMMC grant program. Here's what that actually refers to: a provision inside the FY2027 National Defense Authorization Act (Senate bill S. 4784), which the Senate Armed Services Committee reported out of committee in mid-June 2026. As written, it would authorize up to $100,000 per company, capped at $50 million total program-wide, specifically to offset the direct cost of a CMMC Level 2 third-party assessment.

Two things worth being precise about, since a lot of coverage isn't:

  • It is not law. It's a committee-passed provision inside a defense policy bill that still has to clear the full Senate, get reconciled with the House version, and be signed. That process routinely takes months.
  • It only reimburses C3PAO assessment costs. That's the exact expense category the Department of War just suspended. If the grant becomes law before Phase 2 resumes, there's, for the moment, nothing for it to pay for. The provision was written before the suspension, and nobody has had to reconcile the two yet.

None of that means the grant is pointless. Phase 2 is paused, not cancelled, and the CMMC Reform Task Force's review, due back roughly 60 days from the suspension and landing around mid-September 2026, could bring some version of third-party assessment back. It just means you shouldn't budget around this money arriving, or expect it to cover anything you'd spend on today.

What's actually fundable right now

Setting the not-yet-law grant aside, two real options exist today, regardless of what happens with Phase 2:

Cyber Grants Alliance: CMMC Gap Assessment Grant

A $5,000 in-kind grant covering a full evaluation against all 110 NIST SP 800-171 controls, matched with a certified assessor. This doesn't depend on C3PAO certification resuming. A gap assessment against NIST SP 800-171 is useful with or without a third-party audit requirement sitting on top of it, since it's the same standard your self-assessment score is supposed to reflect anyway.

State Manufacturing Extension Partnership (MEP) programs

Some state MEP centers have run their own funded cybersecurity assessment programs, often using SBA-secured state funding. Purdue's MEP program in Indiana is one past example, offering free CMMC Level 1 assessments to qualifying small businesses. Programs like this open and close on their own schedules and vary a lot by state, so this isn't a standing national program. Check your own state's MEP center directly for what's currently funded rather than assuming a specific program is still open.

So what should a contractor actually do this month?

  • Don't sign anything sold to you on the basis of a November 2026 deadline. That deadline doesn't currently exist.
  • Do keep your NIST SP 800-171 gap assessment and remediation work moving. It protects you against DFARS 7012 and False Claims Act exposure regardless of CMMC's certification timeline.
  • Look at the Cyber Grants Alliance gap assessment grant and your state's MEP center before paying full price for a gap assessment out of pocket.
  • Don't budget around the $50M grant arriving, and don't assume it would cover anything you're spending on this year even if it passes.
  • Watch for the CMMC Reform Task Force's report, expected around mid-September 2026. That's roughly when some real clarity on what replaces Phase 2 should start to emerge.

The short version: the suspension changed what you're racing against. It didn't change what you're responsible for.

FAQ: CMMC costs and funding after the suspension

Is the $50 million CMMC grant available yet?

No. It's a provision inside the FY2027 National Defense Authorization Act (S. 4784), reported out of the Senate Armed Services Committee in mid-June 2026 and still moving through Congress. It is not law, and there is no application process yet.

What would the CMMC grant actually pay for?

As written, it would reimburse up to $100,000 per company toward the direct cost of a CMMC Level 2 third-party (C3PAO) assessment, capped at $50 million total. That's the exact cost category the Department of War just suspended, so even if the bill passes, there's nothing for it to reimburse until Phase 2 resumes.

Is there CMMC funding available today, before the grant passes?

Yes. The Cyber Grants Alliance offers a CMMC Gap Assessment Grant: a $5,000 in-kind evaluation against all 110 NIST SP 800-171 controls, available now regardless of Phase 2's status. Some state Manufacturing Extension Partnership (MEP) centers have also run their own funded CMMC assessment programs. Availability varies by state and by year, so check your state's MEP center directly.

Does the suspension mean I can stop spending money on CMMC right now?

No. The DFARS 252.204-7012 safeguarding obligation and False Claims Act exposure for misrepresented compliance did not pause. In June 2026, an Alabama defense contractor paid $507,144 to settle allegations that it misrepresented its cybersecurity compliance on two Navy contracts.

What's still worth paying for right now, and what can wait?

Worth paying for: a gap assessment against NIST SP 800-171, remediation of real gaps, and keeping your System Security Plan and self-assessment score accurate. What can reasonably wait: a full C3PAO-style mock assessment scheduled specifically around a November 2026 deadline that no longer exists.

When will there be more clarity on what replaces Phase 2?

The CMMC Reform Task Force is expected to deliver its findings roughly 60 days after the July 13, 2026 suspension, putting a report around mid-September 2026. Any formally revised rule would likely follow after that, not immediately.

Spending money on CMMC right now shouldn't be a guessing game.

We'll walk through what your contracts actually require today, where your DFARS 7012 and SPRS exposure sits, and whether a gap assessment grant or your state's MEP program could cover work you were about to pay for anyway.

Schedule your CMMC readiness consultation →