WINSTON & MILLER

Articles

CMMC Level 2 in late 2026: Phase 2 is paused, your obligations are not

The November 10, 2026 C3PAO deadline is no longer active. The 110 NIST SP 800-171 requirements still are.

Articles · · 6 min read · By Winston & Miller

Status as of October 6, 2026. CMMC policy is moving; check the sources below before acting on any date.

On July 13, 2026, the Department of War (DoD) suspended Phase 2 of the Cybersecurity Maturity Model Certification program pending a 60-day review by a CMMC Reform Task Force. Phase 2 was the step that would have required third-party (C3PAO) Level 2 certification in applicable contracts starting November 10, 2026. As of early October, no replacement date has been published.

Many contractors read that as a reprieve. It is not. The suspension paused one assessment method. It did not pause the security requirements.

What is paused

  • Mandatory C3PAO third-party assessments for Level 2
  • DIBCAC assessments during the review period
  • The case-by-case waiver process

What still applies

  • Phase 1 self-assessments. Phase 1 began November 10, 2025, when the DFARS rule took effect. Level 1 and Level 2 self-assessment requirements remain in force.
  • All 110 NIST SP 800-171 Rev. 2 requirements for any contractor handling Controlled Unclassified Information under DFARS 252.204-7012.
  • SPRS scores and annual affirmations. A senior official still affirms compliance. A false affirmation carries False Claims Act exposure.
  • Conditional status closeouts. A conditional Level 2 status still carries its 180-day POA&M closeout clock.

What to do this quarter

  1. Re-score honestly. Walk all 110 requirements against evidence, not intent. A score you can't defend is a liability, not an asset.
  2. Fix the System Security Plan first. No SSP means no valid assessment. The SSP must describe the CUI boundary and how each requirement is met.
  3. Burn down the POA&M. Some requirements can't sit on a POA&M for conditional status. Close those first.
  4. Keep evidence assessment-ready. When Phase 2 resumes, the timeline may be short. Programs with clean evidence will be first in line for C3PAO slots.
  5. Consider a voluntary assessment. Primes still want proof. An independent readiness review shows a prime you will not be the weak link in their supply chain.

Why this matters for small businesses

Primes flow CMMC requirements down to subcontractors. A small business with a defensible SPRS score and a clean SSP is easier to put on a team. The pause is a window to get ahead, not a reason to wait.

Sources: Latham & Watkins, July 30, 2026 · The Defense Compliance Report, updated October 3, 2026 · NIST SP 800-171 Rev. 2

  • CMMC
  • CMMC Level 2
  • CMMC Phase 2
  • NIST SP 800-171
  • SPRS
  • C3PAO
  • DFARS 252.204-7012
  • CUI
  • POA&M

Need this done on your program?

Winston & Miller supports primes and program offices across the National Capital Region with RMF, ATO, ISSO/ISSM and CMMC work.

Request a capability statement