Back to InsightsCertifications

CMMC Phase 2 Is Suspended. What Still Applies.

Rachel PhillipsMarch 31, 2026· Updated August 17, 2026

If you have been working toward a November 2026 CMMC deadline, that deadline is gone.

On July 13, 2026, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification rollout, along with the implementation milestones that were scheduled to follow it. Phase 2 was the step that would have made third-party certification a condition of award for many Level 2 contracts, and it was set for November 10, 2026.

Here is the part that is getting lost in the coverage, and it is the part that can cost you a contract: the requirements already written into your contracts did not go away. What was suspended was the escalation, not the obligation.

What actually happened

The Department of War paused the transition to Phase 2 and the CMMC milestones queued behind it, and stood up a reform task force to review the program from top to bottom.

SBA Administrator Kelly Loeffler announced the suspension the same day, noting the requirements had been "originally scheduled to go into effect on November 10, 2026." The stated reason was cost. Small contractors had reported compliance running toward $600,000, and SBA described CMMC as becoming "an untenable barrier pushing them out of the Defense Industrial Base." More than 120,000 small contractors sit in that industrial base.

A public request for information collected industry feedback through August 14, 2026. The task force's recommendations are due to the Department's CIO within 60 days of the July announcement, which puts the report in mid-September.

So this is a pause with a review attached and a date on it. It is not a repeal.

What still applies today

This is the section to act on. Two clauses do the work, and both are live right now.

DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. This clause predates the CMMC phase rollout by years and was untouched by the suspension. Where it appears, your covered systems are "subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171," and you have to "rapidly report cyber incidents to DoD," which the clause defines as within 72 hours of discovery.

DFARS 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. Where a solicitation carries this clause, you must "have and maintain for the duration of the contract a current CMMC status" at the level the contracting officer specifies, for every system used in performance that processes, stores, or transmits federal contract information or controlled unclassified information. That means entering self-assessment results into the Supplier Performance Risk System, keeping annual affirmations current, and reporting your CMMC unique identifiers to the contracting officer.

Read those two together and the practical picture is clear. If a contract you hold or a solicitation you are chasing carries the CMMC clause, you still have to meet the level named in it. The suspension changed who verifies you, not whether the requirement exists.

Which level applies to you

The levels did not change.

Level 1 covers contractors handling Federal Contract Information: invoices, schedules, routine correspondence. Fifteen basic practices, self-assessed annually, no outside audit.

Level 2 covers contractors handling Controlled Unclassified Information: technical data, drawings, test results, anything the government has marked as CUI. It maps to all 110 requirements in NIST SP 800-171. This is where most small defense contractors land, and it is the level Phase 2 would have changed.

Level 3 covers the most sensitive CUI, adds requirements from NIST SP 800-172, and involves a government-led assessment. A small number of companies need it.

If you are doing technical work for the Department of War, assume Level 2 until you have confirmed otherwise by reading your actual contract.

What to do with the pause

The instinct is to stop spending. That is the wrong read, for three reasons.

The clause is still in your contract. Stopping work on NIST SP 800-171 does not make 252.204-7012 or 252.204-7021 stop applying. A pause in third-party verification is not a pause in the requirement.

The bottleneck just eased, and that is an opportunity. The assessor shortage was the loudest complaint about the original timeline: tens of thousands of companies needing Level 2 against a much smaller pool of accredited assessment organizations. With the rush suspended, the queue is shorter than it was going to be. A company that keeps working through its gaps now is positioned to move when the program restarts, rather than joining a scramble.

The work is slow no matter when you start it. The expensive part of CMMC was never the assessment fee. It is the documentation: a System Security Plan that genuinely reflects your environment, policies your team can actually describe, and months of evidence showing you have been following them. That takes the time it takes, and no deadline change compresses it.

The practical move is unglamorous. Read your contracts and find out which clauses you actually carry. Run an honest gap assessment against the 110 requirements rather than a checkbox exercise. Fix documentation first, because that is where most small businesses fall down. Make sure your SPRS entries are current, since that obligation is live today.

On cost, the figures we published earlier still give the right shape: the Department's own regulatory analysis put Level 2 in the neighborhood of $101,000 for a small business including preparation and assessment, with Level 1 self-assessment far cheaper. Treat those as planning ranges rather than quotes, and note they were built for the pre-suspension program.

What to watch

The task force report lands around mid-September, and it is the thing that determines what CMMC looks like next. The plausible outcomes range from a delayed restart of the same program to meaningfully reworked requirements for small businesses. Nobody outside the review knows which.

Two other threads are worth tracking. CMMC-style cybersecurity requirements have been under development for civilian agencies, which means this may eventually reach contractors who never touch defense work. And the program has been built on NIST SP 800-171 Revision 2, while Revision 3 has been out since 2024, so the technical baseline itself may move.

The bottom line

Paused is not cancelled, and it is not permission to stop.

The companies that will be hurt by this suspension are the ones who read "CMMC is on hold" and shelved the project, then find themselves holding a contract with a clause they cannot satisfy, or facing a restarted program with the same gaps they had in July.

The requirements in your contracts are live today. The review changes the schedule, not the direction of travel. If you are unsure which clauses you actually carry or what level your work requires, talk to an advisor and find out before a contracting officer asks.

Ready to take the next step?

Book your free Market Assessment. A senior FEDCON advisor will review your business and show you exactly where the opportunities are.