On July 13, 2026, the Department of War - as the Department of Defense is now styled - suspended CMMC Phase 2, the stage of the Cybersecurity Maturity Model Certification rollout that would have started writing third-party assessment requirements into new contracts this November. Across the defense industrial base, you could hear the exhale. Some of that relief is earned: a certification deadline that loomed over a hundred thousand companies just moved. But in the three weeks since, a more dangerous reading has been spreading through government contracting circles: "CMMC is dead, we can stand down."

That reading will cost somebody a contract. What got suspended is the checkpoint where a third party verifies your security. The security itself - the contract clauses and the NIST requirements behind them - never paused. Here's what actually changed, what didn't, and what it means for one of the most commonly fumbled systems in a compliance scope: the wireless network.

Flat illustration of a government building and compliance checklist beside a shield with a WiFi symbol and a pause badge
The certification clock is paused - the wireless security requirements behind it are still contractually in force

What Actually Happened to CMMC?

A quick recap for anyone who hasn't lived this saga day to day. CMMC is the Pentagon's answer to a long-standing problem: contractors have been contractually promising cybersecurity for years, and the department wanted proof. Level 1 covers companies handling federal contract information. Level 2 - the one that matters for most of the defense industrial base - applies to anyone handling controlled unclassified information (CUI) and maps one-to-one to the 110 security requirements of NIST SP 800-171 Rev 2.

The rollout was deliberately phased. Phase 1 began on November 10, 2025, putting self-assessment requirements into new contracts. Phase 2, scheduled for November 10, 2026, would have phased in certification by authorized third-party assessment organizations (C3PAOs) for many Level 2 contractors. Then came the July 13 memoranda: Phase 2 and every later milestone suspended, and a 60-day top-to-bottom review launched under a new CMMC Reform Task Force, with recommendations due around mid-September, as Federal News Network reported.

The "why" is mostly arithmetic. According to the Small Business Administration, Phase 2 would have pushed more than 120,000 small defense contractors toward certification through a pipeline of only about 100 approved assessment organizations, at a cost SBA analysis put near $600,000 per certification for small firms needing a third-party assessment. Whatever the task force recommends in September, it's reviewing how compliance gets verified and what that verification costs - not whether CUI needs protecting.

What Still Applies While Phase 2 Is on Hold?

Everything except the certification appointment. Three obligations survived July 13 untouched:

  • DFARS 252.204-7012. If your contracts include this clause - and if you handle CUI, they do - you are required to implement the NIST SP 800-171 safeguards now, as a condition of the contract you already signed. This clause predates CMMC and was never part of the suspension
  • DFARS 252.204-7019 and -7020. You still need a current self-assessment score posted in the Supplier Performance Risk System (SPRS), and primes still flow the requirement down to subcontractors
  • Phase 1. The self-assessment requirements that began appearing in contracts in November 2025 remain in effect, and the department has said it will keep enforcing NIST SP 800-171 through self-assessments and select government-led assessments during the review

Suspended Is Not Repealed

The July memos moved the moment somebody checks your work. They did not change what the work is. And a self-assessment score in SPRS is a representation to the federal government - if your posted score says "implemented" and your WiFi says otherwise, the pause hasn't protected you from anything.

What Does NIST SP 800-171 Require From Your WiFi?

Two requirements in the access control family name wireless explicitly, and they're short enough to quote in full:

  • 3.1.16: "Authorize wireless access prior to allowing such connections." Every SSID in your environment exists on purpose, is documented in your system security plan, and connecting to it is a granted permission - not a default
  • 3.1.17: "Protect wireless access using authentication and encryption." The word doing the heavy lifting is authentication - of the user or device, individually

That second requirement is where the classic small-contractor setup fails. A shared WPA2 password does encrypt traffic, but it authenticates nobody in particular: it can't tell the machinist from the intern from the former employee who left in March, and it produces no per-user record of who was on the network. Assessment guidance for 3.1.17 points to 802.1X - WPA2-Enterprise or WPA3-Enterprise - where each person or device presents its own credential against a RADIUS server.

Wireless also inherits the requirements that don't mention it by name. Requirement 3.5.3 requires multi-factor authentication for network access. The identification family expects every user to be uniquely identified before getting on a system in scope. The audit family expects records you can actually produce when someone asks who was on the network on a given Tuesday. Your WiFi is not a special case - it's just the entry point where these requirements are most often waved through on convenience grounds.

One scoping note that saves real money: guest WiFi for visitors doesn't need any of this, provided it's genuinely separate - its own SSID and VLAN, routed straight to the internet, provably unable to reach anything that stores or transmits CUI. Segmentation is what keeps the front-lobby network out of your assessment scope entirely.

What Does a Compliant Wireless Network Look Like?

Stripped of the acronyms, the target state is one you can build in weeks, not quarters:

  • An 802.1X-secured SSID for staff and corporate devices, authenticated against a RADIUS server tied to the identity provider you already run - so access follows your directory, and disabling a departed employee's account cuts their WiFi the same minute
  • Certificates instead of passwords where possible. Certificate-based authentication (EAP-TLS) is the strongest available method, satisfies the something-you-have factor, and ends credential sharing by construction; a cloud PKI with SCEP enrollment issues and renews the certificates without manual touch
  • A segmented guest network for visitors, isolated from anything in CUI scope
  • Authentication logs, kept and reviewed. RADIUS authentication and accounting records - who connected, when, from which device, through which access point - are exactly the audit evidence your system security plan needs to point to, and network analytics can watch them for anomalies so a human doesn't have to
  • A written wireless section in your SSP listing every SSID, its purpose, its authentication method, and who authorizes access - which is most of what 3.1.16 asks for

If you're starting from a shared-password network, our PSK-to-802.1X migration guide walks through the sequencing - including how to run both side by side while devices move over.

Why Keep Building During the Pause?

Because the pause is a queue, not a cancellation. When certification requirements return - in current form or reformed - the arithmetic that triggered the suspension still holds: a hundred-odd assessment organizations and a six-figure backlog of contractors who waited. Companies that used the quiet months to close gaps walk into that queue ready; companies that stood down get to rediscover their flat network under deadline pressure, at deadline prices.

The Assessor's Question

Whenever the third-party checkpoint returns, the wireless portion of it stays the same: "Show me every SSID, who authorized it, how users authenticate to it, and the log of who connected last month." If you can answer that today, the September report is news you read, not news that reorganizes your quarter.

There's also the plainer reason: the requirements are already in your contracts. DFARS 252.204-7012 doesn't wait for CMMC, and treating every network connection as untrusted until authenticated was a good idea before the Pentagon required it. The certification pause changes when you'll be graded - not whether the material is on the syllabus.

Building Toward CMMC on a Timeline That Moved?

IronWiFi gives defense contractors 802.1X WiFi authentication with per-user identity, certificate-based access through cloud PKI, segmented guest networks, and complete authentication audit logs - evidence your SSP can point to.

Start Free Trial Explore WPA-Enterprise

Trusted by 1,000+ organizations in 108 countries

Conclusion

The CMMC story since 2019 has been a pendulum of deadlines announced, softened, and rescheduled, and the July suspension is one more swing. Through all of it, one thing has never moved: contractors who handle CUI are contractually required to protect it, and NIST SP 800-171 defines what protecting it means - wireless included.

So treat the suspension as what it is: borrowed time. Authorize your wireless access deliberately, authenticate people and devices individually, segment what doesn't belong in scope, and keep the logs. Watch for the task force's report in September, but don't wait for it - every one of those steps is required today and stays required under any version of the program that emerges.

The contractors who come out of this pause ahead won't be the ones who guessed the reform outcome correctly. They'll be the ones for whom the outcome didn't matter.

Daniel Konecny

Daniel Konecny

Blog Writer, IronWiFi

Daniel writes about enterprise WiFi authentication and identity security at IronWiFi. With deep expertise in RADIUS, 802.1X, and cloud infrastructure, he covers practical network security for IT teams managing thousands of devices.

About the author