On July 13, 2026, the Department of War (DoD) suspended Phase 2 of the Cybersecurity Maturity Model Certification program pending a 60-day review by a CMMC Reform Task Force. Phase 2 was the step that would have required third-party (C3PAO) Level 2 certification in applicable contracts starting November 10, 2026. As of early October, no replacement date has been published.
Many contractors read that as a reprieve. It is not. The suspension paused one assessment method. It did not pause the security requirements.
What is paused
- Mandatory C3PAO third-party assessments for Level 2
- DIBCAC assessments during the review period
- The case-by-case waiver process
What still applies
- Phase 1 self-assessments. Phase 1 began November 10, 2025, when the DFARS rule took effect. Level 1 and Level 2 self-assessment requirements remain in force.
- All 110 NIST SP 800-171 Rev. 2 requirements for any contractor handling Controlled Unclassified Information under DFARS 252.204-7012.
- SPRS scores and annual affirmations. A senior official still affirms compliance. A false affirmation carries False Claims Act exposure.
- Conditional status closeouts. A conditional Level 2 status still carries its 180-day POA&M closeout clock.
What to do this quarter
- Re-score honestly. Walk all 110 requirements against evidence, not intent. A score you can't defend is a liability, not an asset.
- Fix the System Security Plan first. No SSP means no valid assessment. The SSP must describe the CUI boundary and how each requirement is met.
- Burn down the POA&M. Some requirements can't sit on a POA&M for conditional status. Close those first.
- Keep evidence assessment-ready. When Phase 2 resumes, the timeline may be short. Programs with clean evidence will be first in line for C3PAO slots.
- Consider a voluntary assessment. Primes still want proof. An independent readiness review shows a prime you will not be the weak link in their supply chain.
Why this matters for small businesses
Primes flow CMMC requirements down to subcontractors. A small business with a defensible SPRS score and a clean SSP is easier to put on a team. The pause is a window to get ahead, not a reason to wait.
Sources: Latham & Watkins, July 30, 2026 · The Defense Compliance Report, updated October 3, 2026 · NIST SP 800-171 Rev. 2
- CMMC
- CMMC Level 2
- CMMC Phase 2
- NIST SP 800-171
- SPRS
- C3PAO
- DFARS 252.204-7012
- CUI
- POA&M
Need this done on your program?
Winston & Miller supports primes and program offices across the National Capital Region with RMF, ATO, ISSO/ISSM and CMMC work.
Request a capability statement