CMMC Phase 2 Is Paused: What Defense Contractors Still Need to Do

CMMC Phase 2 Is Paused: What Defense Contractors Still Need to Do

DoD suspended CMMC Phase 2 in July 2026 pending a program review. Here is what actually changed, what did not, and why the pause is not a reason to stop preparing.

What happened on July 13, 2026

The Department of War (the current designation for the Department of Defense) suspended CMMC Phase 2, along with the pending Phase 3 and Phase 4 implementation milestones. Phase 2 would have made third-party C3PAO certification a mandatory condition of award starting November 10, 2026, for most contracts involving Controlled Unclassified Information (CUI).

DoD CIO Kirsten Davies established a CMMC Reform Task Force to conduct a full review of the program. Under Secretary of War for Acquisition and Sustainment Michael Duffey was direct about the intent: the standards are not being relaxed. What is under review is the third-party assessment mechanism itself, not the underlying security requirements.

The task force timeline: A public Request for Information, “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base,” is open on SAM.gov. Industry responses are due August 14, 2026 at 12:00 PM ET. The task force must deliver its recommendations within 60 days of the suspension, placing the report around September 13, 2026.

What did not pause

This is a suspension of the third-party verification mechanism, not a suspension of your underlying obligations. The following remain fully in force:

  • Phase 1 self-assessment requirements for CMMC Level 1 and Level 2, already written into applicable DoD solicitations since November 10, 2025.
  • SPRS score reporting in the Supplier Performance Risk System. Self-assessment is now the primary enforcement mechanism during the review period.
  • DFARS 252.204-7012 safeguarding obligations for CUI, along with related flow-down clauses (7019, 7020, 7021).
  • Annual affirmations of compliance, which a senior company official must personally certify.
  • DOJ Civil Cyber-Fraud Initiative enforcement under the False Claims Act. This has continued since the pause, not slowed. An inaccurate or inflated SPRS score is a legal liability with or without Phase 2.
  • Existing CMMC Level 2 certifications, which remain valid through their normal three-year cycle if you already hold one.

What this means if you have a C3PAO assessment already scheduled

Hold your slot. The program is under review, not cancelled. If your assessment falls before the task force report in mid-September, completing it puts you in a stronger position regardless of which direction the reformed program takes.

What this means if a prime contractor requires CMMC certification from you

The federal Phase 2 timeline pausing does not change what your prime contractor can require of you directly. Prime contractors can and do flow down cybersecurity requirements to subcontractors independent of the DoD’s own rollout schedule. If CMMC certification shows up in your subcontractor agreement, that requirement stands regardless of the federal suspension. Confirm directly with each prime what they still expect and by when.

Why the pause is an advantage, not a reason to wait

A complete CMMC Level 2 remediation typically takes three to six months for small to mid-size contractors. Contractors who use this review period to close their gaps will be ready the moment a reformed framework is finalized. Contractors who treat the pause as a reason to stand down will be starting from zero again once it lands, likely with less runway than they have right now.

What to do next

  • Keep your SPRS score accurate and current. This is the active enforcement mechanism today.
  • Do not cancel a scheduled C3PAO assessment based on the pause alone.
  • Confirm in writing with your prime contractors what they still require and when.
  • If you have not started a gap assessment, this review period is the best window you will get to close the gap before a finalized framework re-establishes a hard deadline.
  • Consider submitting feedback to the RFI if compliance costs or assessor availability have materially affected your business. Responses are due August 14, 2026.

Find out exactly where you stand.

Ikaan Consulting prepares DIB contractors for CMMC readiness through gap assessment, remediation, and C3PAO audit coaching. We are not a C3PAO, so there is no conflict in the guidance you get.

Book a Free Consultation
Scroll to Top