Compliance · CMMC · Sunday Framework

CMMC Phase II was suspended on July 13, 2026: what should a Hawaii defense contractor do now?

Keep working the NIST SP 800-171 controls. The Department of War paused the third-party assessment schedule for 60 days, but DFARS 252.204-7012, your SPRS score, prime flow-downs, and the 110 controls behind CMMC Level 2 are all still in force for Hawaii defense contractors. Use the window to firm up your System Security Plan, close obvious control gaps, and be ready to snap back when the review closes around September 11, 2026.

What actually changed on July 13, 2026

On July 13, 2026, the Department of War issued memo 26-P-1023 suspending the Cybersecurity Maturity Model Certification Phase II rollout that had been scheduled to take effect November 10, 2026. DoW Chief Information Officer Kirsten Davies announced a 60-day study by a new CMMC Reform Task Force, with a final report due on or about September 13, 2026. During the review, requiring activities may include only CMMC Level 1 (Self) or Level 2 (Self) assessments in new solicitations. C3PAO third-party assessments and DIBCAC Level 3 assessments are off the table for new awards until further notice, and existing solicitations that carried a C3PAO requirement are being amended to remove it.

The pause is narrow on purpose. It does not touch 32 CFR Part 170, DFARS 252.204-7012, the 110 NIST SP 800-171 Rev 2 controls, or the self-assessment cadence. It also does not affect assessments already in progress, contracts already awarded with a Phase II condition, or prime contractor supply-chain requirements. Hawaii defense contractors who read the memo as “CMMC is dead” will be behind their neighbors when the snap-back arrives.

Who this affects on Oahu and the neighbor islands

DoD spending in Hawaii runs into the billions each year, and the base has a long tail of small subcontractors. If your Hawaii business touches Pearl Harbor Naval Shipyard, Marine Corps Base Hawaii, Wheeler Army Airfield, Schofield Barracks, Camp H.M. Smith, PMRF Barking Sands on Kauai, or the Space Force detachments, you are likely in scope for DFARS 252.204-7012 or the newer 252.204-7021 flow-down. The most exposed local firms are engineering and construction subs on shipyard work, IT and cabling firms on base network and SCIF projects, test-and-evaluation professional services, and any Hawaii software or data firm that handles CUI touching missile defense, undersea warfare, or Indo-Pacific command activity.

Three categories are always in scope even in a small firm: any Microsoft 365 tenant that stores CUI, any file share or SharePoint site that receives CUI attachments, and any endpoint that opens CUI. A 15 to 40-endpoint Hawaii defense sub is a common shape, and it is the shape this playbook is written for.

The framework: how a Hawaii defense contractor uses the 60-day window in 6 steps

Six-step plan for a 15 to 40-endpoint Hawaii firm holding at least one DoD subcontract with DFARS 252.204-7012 flowed down. Written so the president, controller, or contracts lead can hand it to the internal IT lead or the managed IT provider and get action, not another meeting.

1) Confirm your CUI boundary in writing

The single most common CMMC self-assessment failure in a small firm is a fuzzy boundary. On one page, name every system that stores, processes, or transmits CUI for a DoD contract: the Microsoft 365 tenant, the file share, the ticketing tool, the backup target, the endpoint pool, and any third-party service (accounting, HR, project management) that ever touches CUI. Every system not on the page is out of scope. Every system on the page inherits the full 110-control obligation. If the answer is “we're not sure,” that is the first weekend action.

2) Re-score your current SPRS self-assessment against NIST SP 800-171A

During the review window, DoW will enforce cybersecurity through self-assessment and select government-led assessments. Your SPRS score is now the primary evidence a contracting officer sees. Re-perform the score against the 320 assessment objectives in NIST SP 800-171A with current evidence — screenshots dated inside 90 days, current policies, current runbooks — and upload the result. Do not carry a 2024 score into a 2026 solicitation.

3) Update the System Security Plan to reflect the real environment

Your SSP has to describe the environment as it actually runs today: users, devices, cloud services, backups, third parties, and the network diagram. If it still references a data center you decommissioned during the pandemic, an on-prem file server replaced by SharePoint, or a former employee's laptop pool, an assessor will find it. Rewrite the SSP in plain English against today's environment and version-control it.

4) Rebuild the Plan of Actions and Milestones with owners and dates

Every unmet control needs a POA&M entry: the gap, the owner, the remediation date, and the interim risk. A POA&M full of “in progress” with no dates is what an assessor flags first. During the suspension window, the POA&M is the fastest place to move your score without buying new tools — many gaps are documentation gaps.

5) Close the six controls that almost always fail in small Hawaii firms

The recurring gaps we see across 15 to 40-endpoint Hawaii defense subs are: 3.5.3 multi-factor authentication on privileged and remote access (missing on legacy admin accounts), 3.13.11 FIPS-validated cryptography (breaks on a home-office Wi-Fi router), 3.14.6 monitoring communications (no real EDR or SIEM), 3.8.9 backup protection (backup credentials shared, no offline copy), 3.11.2 vulnerability scanning (no cadence), and 3.3.5 audit log correlation (logs collected but never reviewed). Closing these six alone typically lifts an SPRS score by 20 to 30 points.

6) Respond to the DoW Request for Information by August 14, 2026

The Task Force is soliciting industry input through a public RFI, with responses due on or about August 14, 2026 (Day 30). A short, honest Hawaii submission — real cost data, real timelines, real assessor-availability problems for firms outside CONUS — is worth more than a polished corporate letter. Small-business voice is what the Task Force asked for.

What this looked like for a 25-endpoint Honolulu engineering subcontractor last week

A 25-endpoint Honolulu civil-and-marine engineering firm — one Kakaako office, one field trailer at a shipyard site, prime relationships with two mainland defense integrators — ran this playbook the week the DoW memo dropped. Baseline: SPRS score of 62 posted in 2024, SSP last updated 2023, POA&M with 41 open items and no dates, one Microsoft 365 Business Premium tenant (not GCC), no EDR.

Actions between Tuesday July 14 and Friday July 18, 2026:

Outcome by Friday afternoon: SPRS score up from 62 to a defensible 89 with a plan to reach 105 by October 31; SSP and POA&M current; EDR live; MFA universal; RFI response drafted. Total outside labor: about $9,200 over four days plus two full days of the president's time. Cost of waiting until September: a lost quarter of runway and a stale SPRS score visible to every contracting officer.

Why this framework, and who runs it

HI Tech Hui has been the managed IT and cybersecurity provider for Hawaii businesses since 2014, operating from 401 Kamakee Street in Kakaako with a Cyberuptive-run SOC and a compliance practice that has walked Hawaii clients through HIPAA, PCI DSS, SOC 2, and CMMC readiness. The 6-step playbook above is a working version of the checklist we hand to Hawaii defense subs during a compliance engagement.

If you take one thing from this post: the suspension paused the audit — it did not pause the security requirement, the self-assessment, or the executive affirmation. A Hawaii defense contractor who spends the next 60 days working the framework will end the year with a stronger SPRS score, a cleaner SSP, and a real relationship with the C3PAO ecosystem when the snap-back arrives. A Hawaii defense contractor who spends the next 60 days waiting will be visibly behind. For related reading, see our CMMC vs SOC 2 vs HIPAA decision guide, the broader what compliance does my Hawaii business need walkthrough, the 2026 Hawaii cyber insurance renewal checklist, and the HIPAA IT controls for Hawaii medical practices post for a companion sector comparison.

Frequently asked questions from Hawaii defense contractors

Was CMMC canceled by the July 13 2026 suspension?

No. The Department of War suspended only the Phase II third-party (C3PAO) assessment schedule for a 60-day review. NIST SP 800-171 Rev 2, DFARS 252.204-7012, Level 1 and Level 2 self-assessments, SPRS scoring, and 72-hour incident reporting all remain in force. The stated review window closes around September 11, 2026, with a final Task Force report to the DoW CIO on or about September 13.

Does the CMMC pause help a Hawaii subcontractor that a prime is asking for CMMC proof?

Only partially. The suspension removes the C3PAO requirement from new DoD solicitations during the review window, but primes can still require CMMC readiness or a current NIST SP 800-171 score from Hawaii subcontractors under their own supply-chain risk clauses. Read the prime's flow-down language literally and get any relaxation in writing before you slow your program.

What is DFARS 252.204-7012 and does it still apply to Hawaii businesses?

Yes. DFARS 252.204-7012 is the safeguarding clause that has required contractors handling CUI to implement NIST SP 800-171 since December 31, 2017. It is unaffected by the CMMC Phase II suspension. If your Hawaii business holds a DoD contract of any real size, that clause is almost certainly baked in and still binding, including the 72-hour incident reporting piece.

What is SPRS and what score does a Hawaii defense contractor need?

SPRS is the Supplier Performance Risk System, the DoD portal where contractors post their NIST SP 800-171 self-assessment score. The maximum score is 110 (one point per fully implemented control, with weighted deductions for gaps). Award-eligibility increasingly turns on the score being current and accurate, and a false or stale SPRS submission carries real False Claims Act exposure. A 110 is aspirational; a defensible 95 with a live POA&M is realistic for a small Hawaii firm.

Can a Hawaii defense contractor pause CMMC work until September 2026?

Not sensibly. The suspension does not touch NIST 800-171 Rev 2, DFARS 7012, or prime flow-downs. The 60-day review could easily stretch past September, and any snap-back will penalize firms that stopped. The right move is to treat the window as extra runway for self-assessment, System Security Plan, and POA&M work — not as a compliance holiday.

How much does CMMC Level 2 self-attestation cost for a small Hawaii firm?

For a 15 to 40-endpoint Hawaii defense contractor with a single tenant and one Microsoft 365 GCC or GCC High environment, the honest range for a first credible SPRS submission is $18,000 to $60,000 all-in — policy work, gap analysis, remediation, and evidence gathering — spread over 3 to 6 months. Cost climbs quickly with multi-tenant environments, on-prem file shares, and legacy line-of-business apps that were never designed with CUI segregation in mind.

Do subcontractors on Hawaii shipyard, missile, or space-range work need CMMC?

Almost always yes when CUI is in scope. Work tied to Pearl Harbor Naval Shipyard, PMRF Barking Sands, Wheeler Army Airfield, Camp H.M. Smith, and the Space Force detachments on Oahu and Kauai routinely involves CUI. If the prime contract or task order names DFARS 252.204-7012 or 252.204-7021, plan on Level 2 self-assessment as a floor and read the current DoW memo before assuming a C3PAO is optional.

What should show up in a defensible Hawaii SPRS score by September 2026?

A current System Security Plan reflecting the real CUI boundary; a Plan of Actions and Milestones with owners and dates for every open control; multi-factor authentication on all remote access and privileged accounts; endpoint detection and response on every in-scope device; encrypted backups tested inside the last 90 days; annual security awareness training with completion evidence; and a signed executive affirmation in SPRS with a submission date inside the last 12 months.

Bottom line for Hawaii defense contractors

The July 13, 2026 CMMC Phase II suspension is a procedural pause, not a compliance holiday. DFARS 252.204-7012, NIST SP 800-171 Rev 2, SPRS scoring, and prime flow-downs are still on the table for every Hawaii defense contractor holding CUI. The review window closes on or about September 11, 2026, with the Task Force report on September 13. Spend it boundary-mapping, re-scoring SPRS, rewriting the SSP, rebuilding the POA&M, closing the six controls that almost always fail in a small Hawaii shop, and putting a real Hawaii voice into the DoW RFI by August 14. When the snap-back arrives, the firms that used the window well will be first in line for the C3PAO calendar.