CMMC Phase 2: suspended, and what still applies

Cybersecurity Maturity Model Certification (CMMC) was written to arrive in phases. Phase 1 started on November 10, 2025. Phase 2 was scheduled for November 10, 2026 and would have introduced certification assessments performed by a CMMC Third-Party Assessment Organization (C3PAO).

Phase 2 was suspended on July 13, 2026. Phase 1 was not.

This page sets out the schedule as written, what the suspension changed, what it did not change, and what a defense contractor should be doing while it holds.

What moved and what did notA two-column comparison. The left column is headed Suspended and lists Level 2 C3PAO designation, Level 3 DIBCAC designation, and the November 2026 Phase 2 transition. The right column is headed Still in force and lists DFARS 252.204-7012, NIST SP 800-171, Level 1 and Level 2 self-assessments, the SPRS score, the annual affirmation, and 72-hour incident reporting.SuspendedStill in forceLevel 2 C3PAO designationLevel 3 DIBCAC designationNovember 2026 Phase 2 transitionDFARS 252.204-7012NIST SP 800-171Level 1 and Level 2 self-assessmentsSPRS scoreAnnual affirmation72-hour incident reporting
Two columns. The left column lists the suspended items. The right column lists the obligations that remain in force.

The schedule as written

The CMMC final rule set out a phase-in over three years.

Phase Start What it introduced
Phase 1 November 10, 2025 Level 1 (Self) and Level 2 (Self) assessment requirements, with the matching affirmations in the Supplier Performance Risk System (SPRS)
Phase 2 November 10, 2026 Level 2 certification assessments performed by a C3PAO
Phase 3 Later Level 3 certification assessments performed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)

Each phase added a verification method. None of them changed the underlying security requirements, which come from NIST SP 800-171 and from FAR 52.204-21.

What happened on July 13, 2026

The Department of War (DoW) announced the immediate suspension of the Phase 2 transition, together with pending and future CMMC implementation milestones. The DoW Chief Information Officer established a CMMC Reform Task Force to conduct a review and report within 60 days, with the stated aim of reducing compliance barriers for small, medium, and non-traditional businesses.

The implementing memorandum is specific about what a program office may ask for during the suspension.

During the suspension Status
CMMC Level 1 (Self) May be designated
CMMC Level 2 (Self) May be designated
CMMC Level 2 (C3PAO) May not be designated
CMMC Level 3 (DIBCAC) May not be designated
Waivers None granted during the review

Active solicitations and existing contracts carrying an affected requirement are to be amended or modified.

The November 2028 date

Class Deviation 2026-O0025, Revision 3, signed September 3, 2026, moved the suspension out of a policy memorandum and into the clause-insertion rules. DFARS 204.7504(a) now splits at a single boundary:

  • Until November 9, 2028. Clause DFARS 252.204-7021 goes into a solicitation or contract only if the program office or requiring activity determines that the contractor is required to have a specific CMMC level.
  • On or after November 10, 2028. The clause goes in whenever the program office or requiring activity determines that contractor information systems will process, store, or transmit Federal contract information (FCI) or controlled unclassified information (CUI).

Read that carefully, because it is narrower than "CMMC restarts in 2028." The date governs when the clause is inserted by default rather than by specific designation. A class deviation stays in effect only until it is rescinded or folded into the regulation, and this one has been revised more than once. Task force recommendations or a new rulemaking could move it again.

What still applies today

Nothing in the suspension touches the safeguarding obligations themselves.

Obligation Where it comes from Status
Safeguard covered defense information DFARS 252.204-7012 In force
Implement the 110 requirements of NIST SP 800-171 DFARS 252.204-7012, paragraph (b)(2)(ii)(A) In force
Report a cyber incident within 72 hours DFARS 252.204-7012, paragraph (c) In force
Post a NIST SP 800-171 self-assessment score SPRS, under DFARS 252.204-7019 and 252.204-7020 In force
Affirm continuous compliance annually DFARS 252.204-7021, paragraph (d)(3) In force where the clause is present
Basic safeguarding of FCI FAR 52.204-21 In force
Flow requirements down to subcontractors DFARS 252.204-7012 (m) and 252.204-7021 (f) In force

The False Claims Act and the Department of Justice Civil Cyber-Fraud Initiative are also unaffected. A score posted to SPRS is a representation the government can rely on whether or not a third party has verified it. See SPRS score.

What to do while the suspension holds

  1. Read your own solicitation. A class deviation changes what contracting officers insert going forward. It does not retroactively rewrite a contract you already signed. Check the clauses you actually have.
  2. Keep the self-assessment current. Level 1 (Self) and Level 2 (Self) are still designated, and the affirmation is still annual. See NIST SP 800-171 self-assessment.
  3. Keep the score accurate. A stale or optimistic SPRS score is the exposure that did not pause.
  4. Work the POA&M. A plan of action and milestones with real closure dates is evidence of a working program and is what converts a Conditional status to Final when assessments resume.
  5. Do not dismantle scope work. A secure enclave that narrows what is in scope keeps its value regardless of who performs the assessment.
  6. Keep collecting evidence. An assessment that resumes in 2028 will ask what you were doing in 2026 and 2027. Continuous records are easier to produce than reconstructed ones.

How the kit relates to this

Item Kit role
Run the controls that the 110 requirements describe Performs
Keep the records an assessor asks to see Records
Track POA&M items and closure dates Assists
Calculate or submit your SPRS score Organization
Decide which CMMC level your contract requires Organization
Affirm continuous compliance Organization

The kit does not change your CMMC status and does not speak to a contracting officer. See AIC CMMC Complete™.

Common questions

Is CMMC cancelled? No. Phase 1 is in force and the program is under review. The Phase 2 transition is suspended and the DFARS now carries a November 2028 boundary for clause insertion.

Can I still get a Level 2 certification assessment? A DoW program office may not designate one while the suspension holds. The Cyber AB Marketplace still lists authorized firms, and a prime may still ask to see a certificate you already hold. See C3PAO.

Do I still have to post an SPRS score? Yes. That obligation comes from DFARS 252.204-7019 and 252.204-7020 and was not suspended. See SPRS score.

Does the suspension remove DFARS 252.204-7012? No. The safeguarding clause and its 72-hour reporting duty are unchanged. See DFARS 252.204-7012.

Is the November 2028 date a restart date for certification? It is the date in DFARS 204.7504 at which clause 252.204-7021 is inserted on the basis of the information handled rather than only when a level is specifically designated. Treat it as a planning marker, not a guarantee.

What happens if the task force changes the program? Recommendations could lead to new rulemaking. Until a rule changes, the clauses in your contract are the ones that bind you.

Should we stop our CMMC work? That is your call, not ours. The obligations that carry legal exposure today, under DFARS 252.204-7012 and the False Claims Act, were not suspended.