Is CMMC Phase 2 Still Happening? Current Status

The direct answer: no, CMMC Phase 2 is not happening on November 10, 2026. On July 13, 2026 the Department of War issued two memoranda that immediately suspended the transition to Phase 2 requirements, including the November 10 milestone that would have made third-party Level 2 certification a condition of award for contracts involving controlled unclassified information. Phases 3 and 4 and every future implementation milestone were frozen at the same time. But this is a policy pause, not a repeal. The 32 CFR Part 170 program rule and DFARS 252.204-7021 are still law, Phase 1 self-assessments and SPRS affirmations are still mandatory, and your prime's flow-down letter is still a contract term.
Status verified August 27, 2026. This page is updated when the regulatory status changes.
What actually happened on July 13
Two memoranda, effective immediately, suspended the phased escalation of assessment requirements and stood up a 60-day CMMC Reform Task Force reporting to the Department of War chief information officer. The stated driver was cost burden on small business. CIO Kirsten Davies cited Small Business Administration data suggesting the coming phases could cost the defense industrial base more than seven billion dollars per year. The reviewing body issued a public request for information on three outcomes: leveraging commercial cyber capabilities, optimizing self-attestation, and streamlining compliance. That comment window closed on August 14, 2026.
The scope of the suspension matters more than the headline. What stopped is the assessment-type escalation: the move from self-assessment to certification by an authorized third-party assessment organization, and the later phases that would have extended certification requirements across the contract base. What did not stop is everything already in force. Legal analyses published within days, including Crowell's same-day client alert, are consistent on that split.
Status at a glance
| Requirement | Status as of Aug 27, 2026 | What it means for you |
|---|---|---|
| Phase 2 third-party certification | Suspended July 13, 2026 | No Nov 10 condition of award. No replacement date set. |
| Phases 3 and 4 | Frozen | All downstream milestones are off the calendar. |
| 32 CFR Part 170 program rule | In effect | The program exists in law. Nothing was repealed. |
| Phase 1 self-assessments | Live since Nov 10, 2025 | Level 1 and Level 2 self-assessments still required. |
| SPRS score and annual affirmation | Fully in force | A current affirmation gates award and option exercise. |
| DFARS 7012, 7019, 7020, 7021 | Unchanged text | 72-hour incident reporting and SPRS posting continue. |
| NIST SP 800-171 baseline | Revision 2 | The May 2024 class deviation still pins scoring to Rev 2. |
Paused is not repealed, and the difference is legal exposure
Phase 1 went live in new solicitations on November 10, 2025 and the suspension left it completely intact. If you handle federal contract information you still self-assess at Level 1. If you handle controlled unclassified information under a Level 2 self-assessment contract, you still score yourself against the 110 controls, still post the result in SPRS, and still submit an annual affirmation of continuous compliance signed by your named Affirming Official under 32 CFR 170.22. DLA Piper's August 3 analysis makes the operational point bluntly: DFARS 252.204-7021 is still appearing in contracts, and a current affirmation is a prerequisite to award and to exercising an option.
That affirmation is the sharpest edge in the entire program, and the pause did not dull it. It is an individual attestation, and an inaccurate one is a false statement in support of payment, which is treble-damages territory under the False Claims Act. The Department of Justice Civil Cyber-Fraud Initiative continues to pursue false cybersecurity certifications, and defense counsel have been flagging the affirmation as an exposure that follows a company into acquisition diligence. The role stays with your executive. An outside advisor can build the evidence, walk the scoring, and brief the person before they sign, but the person signing is yours and the risk acceptance is yours. Our guide to the Level 2 self-assessment for small defense contractors walks the mechanics.
One more thing did not change. You still assess against NIST SP 800-171 Revision 2, not Revision 3, because the May 2024 class deviation to DFARS 252.204-7012 pins compliance and scoring to Rev 2. The Department published organizationally defined parameter values for Rev 3 in April 2025 as preparatory guidance, and pre-pause estimates put the Rev 3 rulemaking somewhere between late 2026 and mid-2027, but no verified post-pause timeline exists. Treat that window as unreliable. If you want the control-set distinction in detail, see NIST 800-171 versus CMMC.
Not sure whether the pause changed anything for your contracts?
An advisor can read your active clauses, check your SPRS status and affirmation currency, and brief your Affirming Official on what they are attesting to before the next award.
The assessor market is in the middle of a shock
Before the pause, capacity was the constraint everyone complained about: roughly 111 authorized third-party assessment organizations and about 3,200 qualified Level 2 assessors against a population north of 100,000 companies that would eventually have needed certification. That shortage was itself part of the argument for pausing.
The pause inverted the problem overnight. National Defense Magazine reported on August 17 that contractors are cancelling scheduled assessments, that more than 100 assessment organizations are seeing layoffs, and that per-assessment costs are climbing as volume thins. Two consequences follow for buyers. First, if third-party assessment resumes in any form, the arithmetic that produced the original bottleneck gets worse, not better, because capacity is leaving the market right now. Second, a company that holds or completes certification during the pause is in a materially stronger award position on the other side of whatever decision lands.
Your prime's requirement is not the government's requirement
This is the confusion generating the most questions from small manufacturers, and it is worth stating flatly. Large primes are continuing to demand Level 2 certification, or at minimum a current SPRS score and affirmation, from their subcontractors regardless of the Department of War pause. Those demands live in subcontracts and flow-down letters. A suspended government milestone does not amend a signed contract term. If your prime requires it, you owe it, and the pause is not a defense.
Two related errors are common. Some subs assume any defense subcontract means Level 2, when work that touches only federal contract information sits at Level 1. Others assume that having no direct relationship with the Department means the requirements do not reach them, when in fact obligations flow to any tier that handles federal contract information or controlled unclassified information. Machine shops, printed circuit board houses, and logistics providers holding controlled drawings are squarely in scope. Our CMMC compliance guide for defense contractors covers scoping, and the defense and government practice page covers how we run these programs.
What to do with the next six weeks
The rational move during a pause is not to stop. It is to spend the window on the work that holds value under every outcome scenario. Keep your NIST SP 800-171 Rev 2 posture current and your system security plan accurate. Keep your SPRS score current and your plan of action items documented with real dates. Verify your affirmation has not lapsed, since a stale one blocks award independent of anything the task force decides. Inventory which of your contracts carry 7012, 7019, 7020, and 7021, and confirm what your primes are demanding in writing. Nothing on that list becomes wasted effort if the program is restructured toward enhanced self-assessment, and all of it shortens the runway if third-party assessment resumes into a thinner assessor market. A dedicated security team led by a named Executive Security Advisor is how mid-market contractors keep that cadence running without hiring a full compliance function.
Where the money genuinely should pause: signing a new multi-year assessment prep contract priced against a November 10 deadline that no longer exists.
What to watch next
On or about September 13, 2026: the CMMC Reform Task Force report is due to the Department of War chief information officer. Expect the substance to leak into trade press quickly. A report is a recommendation, not a rule.
Mid-October 2026 at the earliest: formal determinations. Analysts consistently place this no sooner than mid-October, with real probability of slipping into late 2026 or early 2027, because a structural change to the program would require new rulemaking with its own comment period.
The two outcome scenarios most discussed: enhanced self-assessment paired with executive attestation for the majority of contractors, with third-party certification reserved for a smaller high-risk subset, or a deeper restructuring of the maturity model itself. Both leave self-assessment discipline and SPRS accuracy central, which is why the checklist above is safe under either.
Two unrelated items on the same calendar: the proposed DFARS rule extending foreign ownership, control, or influence disclosure to uncleared contractors and subcontractors at any tier above five million dollars, which closed comments around July 6, 2026 and awaits a final rule, and the still-unadopted NIST SP 800-171 Revision 3. The Small Business Administration's Office of Advocacy has been tracking the reform effort and published its own summary of the task force request for information on July 20.
We update this page when the status changes. If you want a read on your specific contract portfolio rather than the general picture, talk to a Z Cyber advisor.
Frequently Asked Questions
Is CMMC Phase 2 still happening in November 2026?
No. On July 13, 2026 the Department of War issued two memoranda immediately suspending the transition to Phase 2, including the November 10, 2026 milestone that would have made third-party CMMC Level 2 certification a condition of award for contracts involving controlled unclassified information. Phases 3 and 4 and all future implementation milestones were frozen at the same time. No new date has been set, and analysts expect formal determinations no earlier than mid-October 2026.
Is CMMC cancelled, or just paused?
Paused, not cancelled. The suspension is an administrative and policy action. It did not repeal anything. The 32 CFR Part 170 program rule remains on the books, and DFARS 252.204-7021 remains in solicitations and contracts. Only the escalation to third-party assessment under Phase 2 and later phases is suspended. Treating the pause as a repeal is the single most expensive misreading a defense contractor can make right now.
Does the CMMC pause change my DFARS 252.204-7012 obligations?
No. The suspension changed no DFARS text. Clause 252.204-7012 and its 72-hour incident reporting duty to DIBNet remain fully in effect, as do 7019 and 7020 covering self-assessment posting and government verification. Clause 252.204-7021 still appears in solicitations and contracts with Phase 1 requirements enforced. Only the escalation from self-assessment to third-party assessment under Phase 2 and later phases stopped.
Should I cancel my C3PAO assessment during the CMMC pause?
Not automatically. Two facts cut against cancelling. Large primes are still contractually requiring certification from subcontractors regardless of the pause, and the assessor pool was already small relative to demand, so a resumption would meet a queue. Contractors are cancelling and assessment organizations are reporting layoffs, which means capacity is shrinking now and would take time to rebuild. Decide from your own contract terms rather than from the headline.
When will the CMMC Reform Task Force decide what happens next?
The 60-day task force reporting to the Department of War chief information officer is due to deliver its report on or about September 13, 2026. Its public request for information closed on August 14, 2026. A report is not a decision. Formal determinations are expected mid-October 2026 at the earliest, and could slip to late 2026 or early 2027, since any structural change would require new rulemaking.
Subscribe for Updates
Get cybersecurity insights delivered to your inbox.

