In July the Pentagon suspended CMMC Phase 2. The third-party certification that was supposed to start November 10, 2026 is paused, with a reform task force report due to the DoD CIO around September 11, 2026. What stopped is the stamp — not the requirements behind it.
One thing: the third-party certification stamp. C3PAO assessments that were scheduled to become a condition of award on November 10, 2026 are suspended while the program is reformed. A task force report is due to the DoD CIO around September 11, 2026, and a revised phase-in will follow rulemaking.
That is a change to the verification mechanism, not to the security baseline. NIST 800-171 is not the thing being reformed. Every requirement that reached your contract through DFARS is still in your contract.
The dangerous read is "CMMC is dead." Contractors who stand down now will restart from a worse position, with a stale SPRS score they have already affirmed and an assessment window that will be shorter than this one.
Phase 1 did not pause. Self-assessment and annual affirmation obligations continue on contracts that already carry them.
The safeguarding and cyber-incident-reporting clause is unchanged. If it is in your contract, all 110 NIST 800-171 requirements still apply today.
Your Supplier Performance Risk System score still has to be filed and current. A stale or optimistic score is the fastest way to lose an award.
DIBCAC still reviews the score you filed. Nothing about the suspension removes the government's ability to verify it.
If the score you certified is theater, the FCA still applies — and civil cyber-fraud settlements have already been paid by contractors who overstated posture.
Primes are not waiting for the rule to settle. Flow-down security requirements and supplier questionnaires continue regardless of the C3PAO timeline.
Third-party certification that was scheduled to begin November 10, 2026 is placed on hold pending reform.
A task force report is due to the DoD CIO. It is expected to shape what the revised program looks like.
Expect rulemaking, a revised phase-in, and new assessment dates. The underlying control set — NIST 800-171 — is not the thing being reformed.
The pause is time, not relief. The suppliers who use it will certify quickly and cheaply when the window reopens.
Re-score against all 110 NIST 800-171 requirements and make sure SPRS matches reality.
Bring the System Security Plan in line with the environment you actually run.
Work the POA&M to closure instead of letting it age — closure dates are evidence.
Tighten the CUI boundary now; scope decisions made today lower the cost of whatever assessment lands later.
Keep evidence continuously, not in a pre-audit sprint. Evidence maturity is the item schedules always underestimate.
Document who affirmed the score and on what basis. That record is your FCA defense.
A 30-minute scoping call covers what your contracts actually require today, how defensible your filed score is, and what to close first while the assessment window is open.
Prefer to read first? Read the CMMC Level 2 guide
Gap assessment through audit readiness.
The 110 controls and how the assessment runs.
Line-by-line cost ranges for Level 1 and 2.
All 14 families and 110 requirements.
Export-controlled data requirements.
How we work with the defense supply chain.