CMMC in 2026: Phase 2 Is Paused. What Do You Still Owe?

ISO Cloud Consulting editorial team
Title card: CMMC in 2026: Phase 2 Is Paused. What Do You Still Owe?

You still owe almost everything except the outside assessor. Phase 2 of CMMC, which would have required third-party (C3PAO) assessments from November 10, 2026, was suspended on July 13, 2026. Level 1 and Level 2 self-assessments, SPRS scores, annual affirmations and DFARS 252.204-7012 safeguarding and incident reporting all continue.

Key facts

  • Phase 2 (C3PAO certification for Level 2) was suspended on July 13, 2026, pending a 60-day reform review.
  • Class Deviation 2026-O0025 Revision 3, dated September 3, 2026, directs contracting officers to remove third-party assessment requirements and accept Level 1 and Level 2 self-assessments.
  • The review window closed on September 11, 2026. At the time of writing, its recommendations had not been published.
  • Level 1: 15 FAR 52.204-21 requirements, self-assessed and affirmed every year, no POA&M.
  • Level 2: 110 NIST SP 800-171 Rev 2 requirements, SPRS score from 110 down to −203, affirmed every year.
  • DFARS 252.204-7012 still requires cyber-incident reports to DoD within 72 hours of discovery.

What happened to CMMC in 2026?

CMMC started phasing into defense contracts in November 2025 with self-assessments, and the next step, third-party certification, was paused in July 2026. The pause was then written into acquisition rules in September.

Date What happened
December 16, 2024 The CMMC program rule, 32 CFR Part 170, takes effect.
November 10, 2025 The DFARS rule starts Phase 1: CMMC self-assessment requirements begin to appear in solicitations and contracts.
July 13, 2026 DoD suspends Phase 2 and launches a 60-day reform review.
September 3, 2026 Class Deviation 2026-O0025 Revision 3 tells contracting officers to remove third-party assessment requirements.
September 11, 2026 The 60-day review window closes.
November 10, 2026 The original Phase 2 start date for C3PAO assessments, now suspended.

What exactly did the Phase 2 pause suspend?

It suspended the requirement for a Certified Third-Party Assessment Organization (C3PAO) to assess and certify Level 2. It did not suspend Level 2 itself, and it did not touch Level 1.

Under the original plan, Phase 2 would have started putting "Level 2 (C3PAO)" requirements into solicitations where CUI is involved. That would have meant paying an accredited outside firm to verify all 110 requirements before award. Today, contracting officers are working with program offices to remove or revise those requirements and to accept a self-assessed Level 2 status instead.

Two points are easy to miss. First, nothing in the pause erases or invalidates a score you have already posted in SPRS. Second, the class deviation governs DoD contracting officers. Your prime contractor sets the terms of your subcontract, so read what your prime actually flows down to you.

What do you still owe if you only handle FCI?

If you only handle Federal Contract Information (FCI), you owe an annual Level 1 self-assessment against the 15 FAR 52.204-21 requirements, results entered in SPRS, and an annual affirmation by a senior official. All 15 must be met. No POA&M is allowed.

FCI is non-public information you receive or create under a government contract: order quantities, delivery schedules, a customer's internal specifications. The Level 1 requirements are basic hygiene, such as unique logins, a firewall, antivirus, patching, locked doors and escorted visitors. Our Level 1 guide explains all 15 in plain English, and our free Level 1 checklist gives you a quick first pass.

What do you still owe if you handle CUI?

If you handle Controlled Unclassified Information (CUI), you must implement all 110 NIST SP 800-171 Rev 2 requirements, keep a System Security Plan, keep a current score in SPRS, and, where your contract calls for CMMC Level 2 (Self), complete that self-assessment and affirm it every year.

These obligations come from several places, and the pause touched only one of them:

  • DFARS 252.204-7012: implement NIST SP 800-171; report cyber incidents to DoD within 72 hours of discovery; preserve images of affected systems for at least 90 days after the report; use cloud providers that meet security requirements equivalent to FedRAMP Moderate; and flow the clause down to subcontractors that handle covered defense information.
  • DFARS 252.204-7019 and 7020: a summary score in SPRS no more than three years old for each relevant system, with the date you expect to reach 110, and access for DoD if it chooses to run a Medium or High assessment.
  • CMMC Level 2 (Self), where required: a self-assessment every three years using NIST SP 800-171A, POA&M rules, and an affirmation after each assessment and every year after.

To report an incident within 72 hours you need a DoD-approved medium assurance certificate. Get it before you need it.

Do you owe anything if your contract does not mention CMMC?

Very likely, yes. CMMC is one layer on top of older contract clauses, and those clauses apply whether or not a CMMC level appears in your contract.

If your contract includes FAR 52.204-21, you must apply its 15 safeguards to FCI today. If it includes DFARS 252.204-7012, you must implement NIST SP 800-171 and report incidents within 72 hours. If it includes 7019 or 7020, you need a current score in SPRS. The CMMC clause (DFARS 252.204-7021) adds the requirement to hold a CMMC status and affirm it. So a contract without a CMMC clause is not a contract without cybersecurity obligations. Read the clause list, not just the statement of work.

Why is a self-assessment not a low-risk exercise?

Because every score and affirmation you post is a representation to the federal government. If it overstates what you have in place, it can create False Claims Act liability, and DoD has ways to check.

The Department of Justice has settled False Claims Act cases in 2026 with contractors whose NIST 800-171 self-assessments did not match reality. DoD can also send DCMA's assessment team (DIBCAC) to review a supplier. Under the CMMC rule, their findings override your self-assessed status, and a failed review can make you ineligible for new awards until you earn a new status.

None of this is a reason to panic. It is a reason to score honestly. A lower, accurate score with a credible POA&M is defensible. A higher score you cannot evidence is not. Our SPRS scoring guide shows how to calculate yours line by line.

What could the reform review change?

Nobody outside DoD knows yet. Public comments from DoD leadership have focused on the burden on small businesses and on moving toward more continuous security monitoring, but no decision has been published.

What matters for planning is what sits outside the pause. The security requirements live in DFARS 252.204-7012 and in NIST SP 800-171 itself. SPRS scores come from 7019 and 7020. False Claims Act liability comes from federal law. None of these depends on whether a C3PAO or you do the checking. Whatever the review recommends, the preparation is the same: an accurate scope, a real SSP, an honest score and a POA&M you are actually working through.

What should you do this quarter?

Use the pause to get your records in order, so you are ready whichever way the rules move.

  1. List your clauses. For every active contract and subcontract, note whether FAR 52.204-21, DFARS 252.204-7012, 7019, 7020 or 7021 appears, and any CMMC level stated.
  2. Check SPRS. Is your NIST 800-171 score less than three years old? Is your Level 1 affirmation less than a year old?
  3. Confirm your data. Ask your prime or contracting officer in writing whether you receive CUI, and which documents are CUI.
  4. Re-score honestly. Test each requirement against its NIST SP 800-171A objectives and update the score if it has drifted.
  5. Update the SSP and POA&M. Make sure they describe today's systems, owners and dates.
  6. Prepare for an incident. Get the medium assurance certificate and write down who reports what within 72 hours.
  7. Brief your Affirming Official. The person who signs should understand the score and the open items before they sign.

If you need the documents, the CMMC Level 2 Starter Bundle ($175, was $207) combines an assessment workbook with SPRS score calculator, an SSP template and a POA&M tracker. For the full picture of levels, scoring and templates, see our CMMC hub. Templates help you prepare; they cannot promise a score or an assessment outcome.

Last reviewed: 29 September 2026. CMMC rules are still moving. Check your contract, your prime's flowdown and the current rule before you rely on any date.

Back to blog

Frequently asked questions

Is CMMC cancelled?

No. Only the third-party assessment step was paused. The CMMC program rule remains in effect, Level 1 and Level 2 self-assessments continue, and contracting officers can still require a self-assessed CMMC status before award. DoD's reform review may reshape how assessments work, but nothing published so far removes the security requirements themselves.

Do I need to redo my SPRS score because of the pause?

Not because of the pause itself. The class deviation does not remove or invalidate existing SPRS results. You should still re-check your score if your systems have changed, if it is close to three years old, or if you now think any requirement was marked met without full evidence. An accurate update is better than a stale, generous number.

Does the pause change anything for subcontractors?

Expect primes to follow DoD's lead, but check your own subcontract. The class deviation instructs DoD contracting officers; your prime decides what to flow down to you, and some primes may keep asking for readiness evidence. DFARS 252.204-7012 still flows down to any subcontractor that handles covered defense information.

When will third-party CMMC assessments restart?

There is no published date. The 60-day review closed on September 11, 2026, and DoD had not released its recommendations at the time of writing. Plan on the assumption that some form of independent verification returns, and keep your SSP, evidence and POA&M in a state an outside assessor could review without a scramble.

Does the pause affect the 72-hour cyber incident reporting rule?

No. The 72-hour reporting duty comes from DFARS 252.204-7012, which the pause did not change. If you handle covered defense information, you must report cyber incidents to DoD within 72 hours of discovery and preserve images of affected systems for at least 90 days. A DoD-approved medium assurance certificate is needed to file.

Templates that do this job

Editable Word and Excel files. Instant download. Licensed for one organization.