Program update

CMMC Phase 2 is suspended

The Department of War suspended CMMC Phase 2, the third-party certification requirement scheduled for November 10, 2026, along with pending and future implementation milestones, and opened a 60-day program review.

Announced July 13, 2026. Reviewed July 31, 2026.

Where the phases stand

The CMMC program rule took effect in December 2024. The acquisition rule that made it contractually binding took effect on November 10, 2025, introducing clause DFARS 252.204-7021 into new solicitations. Phase 1 survived the suspension. Everything after it is on hold.

  1. Phase 1 In force

    November 2025

    Level 1 and Level 2 self-assessments

    Contracting officers include Level 1 (Self) or Level 2 (Self) assessment requirements in applicable solicitations and contracts. Self-assessment results and affirmations are submitted through SPRS.

  2. Phase 2 Suspended

    November 2026

    Level 2 third-party (C3PAO) assessments

    Would have required certification assessments by a Certified Third-Party Assessment Organization as a condition of award. Suspended by the Department of War on July 13, 2026.

  3. Phase 3 Suspended

    November 2027

    Level 3 DIBCAC assessments

    Would have introduced Level 3 assessments conducted by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center. Held in abeyance alongside Phase 2.

  4. Phase 4 Suspended

    November 2028

    Full implementation

    Would have applied CMMC requirements across all applicable solicitations and contracts prior to award. Held in abeyance alongside Phase 2.

What did not change

This is the part most coverage skipped. The suspension removed a verification step. It removed nothing you are contractually obliged to do.

Phase 1 self-assessments

Level 1 and Level 2 self-assessment requirements entered contracts in November 2025 and were not touched by the suspension. Contracting officers continue to include them in applicable solicitations, and results still go into SPRS.

DFARS 252.204-7012

The safeguarding and incident-reporting clause predates CMMC by nearly a decade and sits in your contract independently of it. Nothing about the pause changes the 72-hour incident reporting obligation or the requirement to implement NIST SP 800-171.

NIST SP 800-171 Revision 2

The Department has stated it will continue enforcing the 110 requirements through self-assessment and selected government-led assessments during the review. The standard did not pause; only the third-party verification of it did.

Annual affirmations

A senior official still affirms compliance annually in SPRS. That affirmation is a representation to the government, with the legal weight that implies.

Subcontractor flow-downs

Requirements passed to you by a prime are commercial terms in a contract between two private companies. A federal milestone slipping does not amend them. If your subcontract specifies a CMMC status or an SPRS score, that obligation stands until the prime changes it in writing.

False Claims Act exposure

Misrepresenting your security posture to win or keep a contract is actionable regardless of which CMMC phase is active. The Civil Cyber-Fraud Initiative has produced settlements against contractors whose self-reported scores did not match reality.

What it means in practice

With no assessor in the loop, the only signature on your compliance claim is your own.

The part worth sitting with
  1. 01

    The liability moved, it did not disappear

    Under Phase 2, an accredited assessor would have examined your environment and put their name to the result. With that removed, the only signature on your compliance claim is your own. You are still making the same representation, with less external validation behind it.

  2. 02

    Primes are not waiting for the Pentagon

    Flow-down requirements sit in commercial contracts between you and your prime. Many primes wrote CMMC expectations into their supplier terms and have no particular reason to relax them because a federal milestone slipped. Check what your agreements actually say.

  3. 03

    Assessor capacity is the real deadline

    There are a limited number of authorized C3PAOs. Before the suspension, schedules were already booking months out. If a requirement returns, everyone who paused will re-enter that queue simultaneously, and the organizations that kept working will be at the front of it.

  4. 04

    Government-led assessments continue

    DIBCAC retains the ability to assess contractors directly, and selected assessments are proceeding. A pause on third-party certification is not a pause on being looked at.

FAQ

Questions about the suspension

What exactly was suspended?

On July 13, 2026 the Department of War suspended Phase 2 of the CMMC rollout, which would have required Level 2 certification assessments by an accredited C3PAO as a condition of contract award beginning November 2026. Phases 3 and 4 were held in abeyance alongside it.

Phase 1 was not suspended. Self-assessment requirements that entered contracts in November 2025 remain in force.

Is CMMC cancelled?

No. The Department suspended specific implementation milestones and opened a program review. It did not rescind 32 CFR Part 170, and the underlying security requirements remain contractual through DFARS 252.204-7012 and the self-assessment obligations already in place.

Officials did not rule out restructuring the program. What emerges from the review may differ from what was paused, but the direction of travel over the past decade has been consistently toward more verification of contractor security, not less.

How long will the suspension last?

The Department opened a 60-day program review alongside a request for information on cost drivers and administrative burden. That establishes a timeline for the review, not for any replacement requirement.

We would treat specific predictions with suspicion, including our own. This page is updated when the picture changes rather than when someone speculates about it.

Should we stop our readiness work?

We would not advise it, and we would say the same if it meant less work for us.

The suspension removed a deadline, not an obligation. Organizations that keep going are positioned for whatever the review produces and are improving their actual security in the meantime. Organizations that stop will restart from zero, against a queue.

The one thing worth reconsidering is sequencing. If you were racing to book a C3PAO slot, that urgency has genuinely eased. Use the time for the scoping and remediation work that pays off regardless of what the assessment requirement turns out to be.

Does this change what our prime expects?

Only your prime can answer that, and the answer is in your subcontract rather than in the Federal Register. Flow-down clauses are commercial terms. If yours requires a CMMC status or a specific SPRS score, that obligation stands until the prime changes it.

It is worth asking them directly, in writing, rather than assuming either way.

Should we build to NIST SP 800-171 Revision 3 instead?

No. NIST SP 800-171 Revision 3 was published in May 2024 and reorganizes the requirements across 17 families, but it is not yet in effect for CMMC. A DoD class deviation keeps the program on Revision 2. Building to Revision 3 ahead of rulemaking risks showing unmet requirements against the standard an assessor would actually use.

Not sure what the pause means for your contracts?

The answer usually sits in your subcontract rather than in the Federal Register. We can read it with you.

Talk to an expert