Program Update

    CMMC Phase 2 is on hold. The work is not.

    In July the Pentagon suspended CMMC Phase 2. The third-party certification that was supposed to start November 10, 2026 is paused, with a reform task force report due to the DoD CIO around September 11, 2026. What stopped is the stamp — not the requirements behind it.

    What actually changed

    One thing: the third-party certification stamp. C3PAO assessments that were scheduled to become a condition of award on November 10, 2026 are suspended while the program is reformed. A task force report is due to the DoD CIO around September 11, 2026, and a revised phase-in will follow rulemaking.

    That is a change to the verification mechanism, not to the security baseline. NIST 800-171 is not the thing being reformed. Every requirement that reached your contract through DFARS is still in your contract.

    The dangerous read is "CMMC is dead." Contractors who stand down now will restart from a worse position, with a stale SPRS score they have already affirmed and an assessment window that will be shorter than this one.

    What did not pause

    CMMC Phase 1

    Phase 1 did not pause. Self-assessment and annual affirmation obligations continue on contracts that already carry them.

    DFARS 252.204-7012

    The safeguarding and cyber-incident-reporting clause is unchanged. If it is in your contract, all 110 NIST 800-171 requirements still apply today.

    SPRS score currency

    Your Supplier Performance Risk System score still has to be filed and current. A stale or optimistic score is the fastest way to lose an award.

    DIBCAC spot checks

    DIBCAC still reviews the score you filed. Nothing about the suspension removes the government's ability to verify it.

    False Claims Act exposure

    If the score you certified is theater, the FCA still applies — and civil cyber-fraud settlements have already been paid by contractors who overstated posture.

    Prime flow-downs

    Primes are not waiting for the rule to settle. Flow-down security requirements and supplier questionnaires continue regardless of the C3PAO timeline.

    Where the program stands

    July 2026

    Pentagon suspends Phase 2

    Third-party certification that was scheduled to begin November 10, 2026 is placed on hold pending reform.

    September 11, 2026

    Reform task force report due

    A task force report is due to the DoD CIO. It is expected to shape what the revised program looks like.

    After the report

    Revised program, new dates

    Expect rulemaking, a revised phase-in, and new assessment dates. The underlying control set — NIST 800-171 — is not the thing being reformed.

    What to do with the extra runway

    The pause is time, not relief. The suppliers who use it will certify quickly and cheaply when the window reopens.

    Re-score against all 110 NIST 800-171 requirements and make sure SPRS matches reality.

    Bring the System Security Plan in line with the environment you actually run.

    Work the POA&M to closure instead of letting it age — closure dates are evidence.

    Tighten the CUI boundary now; scope decisions made today lower the cost of whatever assessment lands later.

    Keep evidence continuously, not in a pre-audit sprint. Evidence maturity is the item schedules always underestimate.

    Document who affirmed the score and on what basis. That record is your FCA defense.

    Find out whether your SPRS score would survive a review

    A 30-minute scoping call covers what your contracts actually require today, how defensible your filed score is, and what to close first while the assessment window is open.

    Prefer to read first? Read the CMMC Level 2 guide

    Frequently Asked Questions

    Related reading

    CMMC Compliance Services

    Gap assessment through audit readiness.

    CMMC Level 2 Guide

    The 110 controls and how the assessment runs.

    CMMC Certification Cost

    Line-by-line cost ranges for Level 1 and 2.

    NIST 800-171

    All 14 families and 110 requirements.

    ITAR Compliance

    Export-controlled data requirements.

    Defense & DoD Suppliers

    How we work with the defense supply chain.

    Call Now