The Suspension of July 13, 2026
On July 13, 2026, the Department of Defense suspended the transition to Phase 2 of the Cybersecurity Maturity Model Certification, the program built over five years to certify the cybersecurity posture of the defense industrial base. The decision arrived through two administrative memoranda: one signed by the department's Chief Information Officer, the other by the Under Secretary of Defense for Acquisition and Sustainment. Together, they order contract activities to accept only self-assessment, mandate the removal of higher-level assessment requirements from active solicitations and existing contracts, and block all waivers during a 60-day review period, as reported by Lawfare[1].
The department frames the move as reducing bureaucratic burden on small supplier firms. The justification has real merit: third-level certification carries substantial costs for companies with thin margins. The manner in which the suspension arrives nonetheless fundamentally shifts the legal framework compared to routine regulatory adjustment.
What Existed Before, What Changes Now
CMMC rests on two legislative rules, adopted through a public notice-and-comment process. The CMMC Program Rule, effective December 2024, establishes assessment levels, the third-party assessor ecosystem, the annual affirmation regime, and case-by-case waiver authority vested in senior acquisition officials. The companion rule, the acquisition rule, effective November 10, 2025, inserted the operative contract clause into the Defense Federal Acquisition Regulation Supplement.
Both rules remain formally in effect, free of amendments and revocations through formal procedure. The suspension touches only their practical application, imposed administratively.
The Legal Problem: Memo Against Binding Rule
The line separating a legislative rule from an interpretive guidance is the backbone of this matter. Under the Administrative Procedure Act, an agency may rapidly modify its own interpretation of an existing rule, bypassing the public comment process. The 2015 Supreme Court decision in Perez v. Mortgage Bankers Association confirmed this principle, as noted in the Lawfare analysis.
Interpretive guidance remains distinct from a binding rule. The CMMC Program Rule and the acquisition rule carry the force of law, adopted through public comment period. Suspending their practical effect through an administrative memo opens a question courts will face: can a document lacking legislative force freeze the application of a rule that possesses such force?
Two recent developments in U.S. administrative law make this question particularly relevant. The Supreme Court has reduced the interpretive deference granted to federal agencies. The same Court has stiffened the conditions under which an agency can reverse course from a prior regulatory position, adding a second layer of legal fragility to the suspension.
The Factual Premise Under Scrutiny
The department justifies the suspension by citing the weight of third-level certification on small supplier firms. The analysis published by Lawfare[1] observes that the central factual premise fails scrutiny against available data.
The reduction in bureaucratic burden, when weighed against the current cybersecurity threat environment, appears less substantial than stated in the two memoranda. The security benefit sacrificed by the suspension, according to the same analysis, exceeds the administrative savings gained by smaller firms.
This gap between stated rationale and verifiable fact adds a third layer of fragility to the suspension, beyond the two administrative profiles already identified: the nature of the memo relative to the binding rule, and the judicial tightening of constraints on federal agency reversals.
The Governance Signal
A cybersecurity framework that depends on written rules, published, subjected to public comment, and then frozen through two internal memos reveals an incomplete accountability structure. The central question remains open: which named official answers for the decision to accept only self-assessment during the next 60 days?
The memo signed by the CIO and the one signed by the Under Secretary for Acquisition and Sustainment share operational responsibility. The decision-making framework leading to the suspension lacks public exposure equivalent to that required by notice-and-comment. This gap between immediate suspension power and procedural transparency defines the risk every General Counsel in the defense industrial base must now evaluate, as also reported by Nextgov/FCW[2], which cites statements from official John Tenaglia on the matter.
The suspension produces a second effect, less visible than the first: companies that had invested in third-level assessments find themselves with a compliance expense lacking, for now, immediate contractual offset.
Three Decisions for the Board
For the General Counsel, Chief Risk Officer, and Board Audit & Risk Committee of firms active in the defense industrial base, the CMMC suspension imposes three distinct decisions.
- The General Counsel must establish what residual contract exposure exists should enforcement of higher levels resume before the 60-day review ends, given that the underlying rules remain formally in effect.
- The Chief Risk Officer must update the cybersecurity risk framework by separating technical security risk, which remains unchanged, from regulatory risk, temporarily suspended and lacking duration certainty.
- The Board Audit & Risk Committee must evaluate what disclosure to investors the suspension requires, especially for publicly traded firms with federal contracts tied to third-level certification.
The three decisions described above share a common trait: each requires a written, dated response traceable to an identifiable person within the organization, never to an anonymous committee or generic policy.
The Chief Executive Officer faces a strategic decision distinct from the three listed above: maintain already-planned investments in third-level certification, or redirect the compliance budget toward the self-assessment required immediately, betting on the duration of the suspension.
Regulatory Horizon
The suspension remains in effect from July 13, 2026, with review set at 60 days. The CMMC Program Rule, December 2024, and the acquisition rule, November 10, 2025, both remain formally applicable, free of textual modifications. The jurisdictional framework concerns only U.S. Department of Defense contracts, with no automatic extension to other regulated sectors.
Defense industrial base firms that had already completed third-level assessments maintain, for now, a documentary advantage over those who activated only self-assessment: should enforcement resume at review's end, the time gap to reach full compliance remains shorter for those who invested in the complete audit trail.
The question of which official formally answers in writing for the suspension decision remains without official answer. A second question opens accordingly: should the 60-day review confirm the suspension in permanent form, which formal procedure will render it legitimate in the eyes of a Court that has already reduced deference granted to agencies?
This article was written by an AI editorial author with human oversight, in accordance with transparency obligations under Regulation (EU) 2024/1689 (AI Act, Article 50). Sources are linked in the text.
Article by ATLAS
Sources
- Lawfare 9 Sep 2026 (lawfaremedia.org)
- Nextgov/FCW (nextgov.com)