Skip to content
complianceofficer

Blog · 24 Jul 2026 · 9 min read

CMMC Phase 2 suspended: is CMMC still required in 2026?

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

The short answer: Yes, CMMC still applies, but the mandatory third-party certification you were bracing for is on hold. On 13 July 2026 the Department of War announced the immediate suspension of CMMC Phase 2, the rollout that would have required most contractors handling Controlled Unclassified Information to pass a third-party assessment starting 10 November 2026. The Pentagon opened a 60-day review and asked industry for input on cost and burden. What did not change: the Phase 1 self-assessment requirement that took effect in November 2025, and your existing duty under DFARS 252.204-7012 to implement the 110 NIST SP 800-171 controls. The controls stayed; only the mandatory verification method paused.

That distinction is the whole story, and a lot of vendor pages are getting it wrong right now, so the rest of this piece stays concrete: exactly what was suspended, what still binds you, the dates that matter, and what a defense contractor should actually do between now and the end of the review.

What was actually suspended on 13 July 2026

The Department of War suspended Phase 2 of CMMC implementation. Phase 2 was the milestone, set for 10 November 2026, that would have let contracting officers require a CMMC Third-Party Assessment Organization (C3PAO) certification at Level 2 for most contracts involving CUI. The Pentagon paused pending and future CMMC assessment milestones across its solicitations while it runs a 60-day, top-to-bottom review of the program, and it issued a Request for Information on cost drivers and administrative burden with responses due 14 August 2026. Multiple firms tracking the change, including WilmerHale, Morgan Lewis and Federal News Network, describe the same scope.

In practical terms, that means the C3PAO certification path is suspended as of 13 July 2026, and the self-assessment path is fully active. A contracting officer today can designate a Level 2 self-assessment but not compel a third-party certification for most CUI contracts while the review runs.

What did not change

This is where careful reading matters, because the suspension is narrower than the headlines suggest.

  • Phase 1 stays in force. The requirement that applicable solicitations include a Level 1 or Level 2 self-assessment, effective since 10 November 2025, was not touched.
  • DFARS 252.204-7012 still binds you. The long-standing clause requiring you to safeguard CUI to the NIST 800-171 standard and report cyber incidents within 72 hours is unaffected by the suspension.
  • The 110 controls did not move. NIST SP 800-171 Rev. 2, its 14 control families and 320 assessment objectives are exactly the same the day after the announcement as the day before. The suspension changed how you prove compliance, not what compliance is.

So if you were counting on the delay to stop implementing, that is the wrong read. You still owe the government a system that meets 800-171, an accurate self-assessment score in SPRS, and an annual affirmation. The delay removed an assessment appointment, not the obligation behind it.

The dates that matter

Date What happens
10 Nov 2025 Phase 1 took effect: Level 1 and Level 2 self-assessments in applicable solicitations
13 Jul 2026 Department of War suspends Phase 2, the mandatory third-party certification rollout
14 Aug 2026 Deadline for industry responses to the Pentagon's Request for Information
10 Nov 2026 The original Phase 2 date, now suspended pending the review

What contractors should do now

The suspension is a reprieve on the audit clock, not on the work. The teams that use it well will treat the next few months as time to close real gaps rather than as permission to stop.

  • Finish the self-assessment honestly. Score all 110 controls against your actual environment, not your intended one, and post the score to SPRS. A self-assessment you affirm is a statement the government can hold you to, so accuracy protects you under the False Claims Act.
  • Work your POA&M down. Every control you have not implemented belongs in a Plan of Action and Milestones with a real date. When the review ends and third-party assessments resume, a short POA&M is the difference between a smooth assessment and a failed one.
  • Get your CUI boundary right. Much of a CMMC gap comes down to CUI landing in places nobody scoped: email, shared drives, and the piles of scanned contract documents and PDFs where sensitive markings hide. Teams that need to find and classify that content at scale often reach for a dedicated document data extraction tool to pull structured data out of those files before deciding what is in scope.
  • Watch the review, because the rule is moving. The 60-day review could reshape timelines, scope, or the self-versus-third-party split again. This is a fast-moving rule, and the contractors caught flat-footed on 13 July were the ones relying on last quarter's guidance.

The part almost nobody is saying: your legal exposure went up, not down

Read the suspension as good news and you will miss the real shift. With third-party certification paused, your self-attestation in SPRS is now the entire compliance record. There is no assessor standing between an optimistic score and a government inquiry. Several government-contracts practices, Hunton among them, have made the same point since 13 July: moving back to self-assessment as the primary mechanism raises False Claims Act exposure rather than lowering it.

That risk is not theoretical. DOJ's Civil Cyber-Fraud Initiative has already settled cybersecurity misrepresentation cases against contractors, and an affirmed SPRS score is a statement made to obtain payment. The practical takeaway is unglamorous: a score of 72 you can evidence is worth far more than a 110 you cannot, and an honest POA&M is a defense, not an admission.

Questions defense contractors are asking right now

Is CMMC required yet?

Partly. CMMC Phase 1 has been required since 10 November 2025, so applicable solicitations already carry a Level 1 or Level 2 self-assessment requirement. Phase 2, which would have made third-party certification mandatory, is suspended as of 13 July 2026 and is not currently required on any new contract. The underlying DFARS 252.204-7012 obligation has been in force since 2017.

Who needs to be CMMC compliant?

Any organization in the defense supply chain that handles Federal Contract Information or Controlled Unclassified Information under a DoW contract, including subcontractors. Handling only FCI puts you at Level 1, roughly 60,000 companies. Handling CUI puts you at Level 2, roughly 80,000 companies. Prime contractors are responsible for flowing the requirement down, so a small shop with no direct DoW contract can still inherit it.

What is the CMMC deadline now?

There is no third-party certification deadline at present. The 10 November 2026 Phase 2 date was suspended. The live dates are 14 August 2026, when industry responses to the Request for Information are due, and roughly mid-September 2026, when the 60-day CMMC Reform Task Force is expected to report. New deadlines will most likely follow that report, so treat mid-September as the next decision point.

What happens to a C3PAO assessment I already scheduled?

You can keep it. The suspension removes the requirement to obtain certification, not the ability to. If your slot falls before the task force reports, finishing the assessment leaves you in the strongest position whichever way the program moves, and certified contractors are likely to keep an advantage on competitive CUI work. Weigh that against the cost, since nobody can currently compel you to hold one.

Why this keeps happening, and the fix

CMMC has now shifted timelines and structure several times: the move from five levels to three, the long wait for the final rule, the Phase 1 start, and now a mid-rollout suspension of Phase 2. If your compliance process depends on someone happening to read the right federal notice, you will always be a few weeks behind the rule you answer to. That is the exact failure mode CMMC compliance software that tracks the rule, not just your controls, is meant to prevent. Our engine watches what the Department of War and NIST actually publish, checks each change against the policies and controls you already have, and flags what just went stale, which is the approach described on regulatory change management. Run the compliance scan above with defense contracting and CMMC selected to see the obligation register it builds, with the last twelve months of movement and the sources linked.

Last updated July 2026. General regulatory information, not legal advice. Confirm your specific obligations with your contracting officer and counsel.

General regulatory information, not legal advice. Written by the team at ComplianceOfficer building Complianceofficer; verify anything consequential with qualified counsel.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.