Skip to content
    August 16, 2026| Top Floor Team| 10 min read

    CMMC Phase 2 Is Suspended: What Still Applies in 2026?

    The Department of War CIO suspended CMMC Phase 2 on July 13, 2026 under memo 26-P-1023, pausing the third-party assessment requirement that had been scheduled to appear in solicitations from November 10, 2026, together with the Phase 3 and Phase 4 milestones behind it, while a CMMC Reform Task Force runs a review with recommendations due in roughly 60 days. Nothing already in force relaxed. DFARS 252.204-7012 safeguarding and its 72-hour cyber incident report still apply, NIST SP 800-171 Rev 2 is still the control baseline underneath, and since November 10, 2025 Phase 1 has required Level 1 or Level 2 self-assessments, a current Supplier Performance Risk System score, and a senior official affirmation in applicable solicitations. If you handle Controlled Unclassified Information, the suspension changed when an outside assessor arrives, not whether you have to be compliant.

    That sentence is the article. The rest is which instrument says what, what the task force can and cannot reach, and the one situation where slowing down is genuinely the right call.

    Dateline and revision commitment. This piece describes the position as of August 16, 2026. The CMMC Reform Task Force's recommendations are expected roughly 60 days from the July 13 announcement, which puts them around mid-September 2026. We will revise this article in the week the report lands and say what changed, because an article about a suspension is only useful while its account of the suspension is current. Until then the regulatory radar entry carries the running status.

    Key takeaways

    • The suspension pauses the mechanism that puts a certification requirement into a contract. It is not a repeal of the program rule, not a change to the control baseline, and not an amnesty on anything already attested to.
    • DFARS 252.204-7012 is untouched: adequate security on covered systems, NIST SP 800-171, a cyber incident report to the Department within 72 hours of discovery, media preservation, malicious software submission, and flow-down.
    • Phase 1 was never suspended. Applicable solicitations still carry a CMMC level to be met at award, with self-assessment results in SPRS and a senior official affirmation.
    • Two rules keep getting conflated: the 32 CFR Part 170 program rule effective December 16, 2024, and the 48 CFR acquisition rule effective November 10, 2025. Only the second puts a clause into a solicitation.
    • An affirmation is a representation to the government. A pause is the cheapest window you will get to make an inaccurate SPRS score accurate before anyone comes to check it.

    What the suspension actually covers

    The memo pauses the phased introduction of CMMC assessment requirements into new solicitations beyond Phase 1. In practical terms that means the trigger for CMMC Third-Party Assessor Organization (C3PAO) certification assessments at Level 2, which had a scheduled date, no longer has one. Phase 3, which would have brought Level 3 government-led assessments into applicable solicitations, and Phase 4, which would have applied the requirements to all applicable solicitations and option periods, are suspended with it.

    A Request for Information posted to SAM.gov alongside the announcement asked the defense industrial base for input on compliance cost drivers, which controls deliver measurable risk reduction, the role of self-attestation, and commercial cybersecurity capabilities. Responses were due by noon Eastern on August 14, 2026. The site tracks the announcement and the RFI window in the regulatory radar entry for the suspension.

    Read the scope carefully, because the common misreading is expensive. A suspension of the phase schedule is a suspension of the mechanism that puts a certification requirement into a contract. It is not a repeal of the program rule, not a change to the control baseline, and not an amnesty on anything a contractor has already attested to.

    What did not change, in the order it will bite you

    DFARS 252.204-7012. The safeguarding clause has been in defense contracts since 2016 and is untouched. It requires adequate security on covered contractor information systems, implementation of NIST SP 800-171, a cyber incident report to DoD within 72 hours of discovery, media preservation, and malicious software submission. It flows down to subcontractors. Nothing in the July memo modifies it.

    NIST SP 800-171 Rev 2. The 110 security requirements are the substance of Level 2 and the thing 7012 already obliged you to implement. Suspending an assessment does not suspend a control. Note the number: 110 requirements, in 14 families. The 171 in the title is the document number, and a surprising amount of vendor content treats it as a control count.

    Phase 1. Phase 1 began on November 10, 2025 when the CMMC acquisition rule took effect, and it was never suspended. Under DFARS 252.204-7021 applicable solicitations carry a CMMC level requirement that must be met at award, self-assessment is the path for Level 1 and for Level 2 where permitted, and the results have to be in SPRS with an affirmation from a senior company official. The radar entry for Phase 1 has the underlying Federal Register citation.

    The False Claims Act. An affirmation is a representation to the government. The Department of Justice's Civil Cyber-Fraud Initiative has pursued contractors over cybersecurity representations, and a suspended assessment schedule does nothing to a score you submitted last year that was never true. If anything, a pause is the cheapest window you will get to make an inaccurate SPRS score accurate before anyone comes to check it.

    The two start dates people keep conflating

    This is worth three paragraphs because getting it wrong produces confidently wrong advice.

    There are two separate rules. The program rule is 32 CFR Part 170, published October 15, 2024 and effective December 16, 2024. It created the CMMC program: the levels, the assessment types, the scoring, the POA&M rules, the accreditation ecosystem. It put no requirement into any contract.

    The acquisition rule is the 48 CFR rule (DFARS Case 2019-D041) published September 10, 2025 and effective November 10, 2025. That is the instrument that puts a CMMC clause into a solicitation, and its effective date is what started Phase 1.

    So "CMMC took effect in December 2024" and "CMMC started in November 2025" are both true statements about different instruments, and an article that treats them as one date will get the phase arithmetic wrong from there on. When you read a source that gives a single CMMC start date, check which rule it is describing before you plan around it.

    What the task force can reach, and what it cannot

    The review can plausibly reach the assessment model: which contracts require a certification assessment rather than a self-assessment, how the phases are sequenced, how POA&M and conditional status work, and how much of the burden falls on small businesses. Those are program-design questions, and the RFI asked about several of them directly.

    It reaches DFARS 252.204-7012 far less easily. That clause predates CMMC, sits in a different rulemaking, and encodes an obligation the department has enforced independently for years. It is possible to imagine a reformed CMMC that leans harder on self-attestation. It is much harder to imagine one that stops requiring NIST SP 800-171 on systems that hold CUI, because that requirement is the reason the program exists.

    There is also a separate rulemaking moving in the opposite direction. The FAR Council's proposed government-wide CUI rule would apply NIST SP 800-171 Rev 3 to CUI-handling contractors across all federal agencies, not only defense. It is not final, and CMMC remains anchored to Rev 2, but the direction of travel matters when you are deciding whether the underlying control work is a durable investment. The radar entry for the proposed FAR CUI rule carries the citation and the comment history.

    Where we would tell you to slow down

    Here is the part that costs us work.

    If you were about to sign a C3PAO assessment contract for a certification your contracts do not currently require, stop and re-price it. The requirement that would have compelled that assessment is the one that got suspended. Paying now for a certificate whose governing model is under active review is a real risk, not a hedge, and any consultancy telling you the pause changes nothing at all about your spending plan is selling rather than advising.

    If you are a Level 1 shop that touches Federal Contract Information and no CUI, the pause changes nothing for you either way, because Level 1 was always a self-assessment. Spending on third-party readiness at Level 1 was questionable before July and it still is.

    And if you have no defense contracts, no defense subcontracts, and no realistic pipeline, this whole program is a marketing email you can delete. We see companies build CUI enclaves on the strength of a prime's mailing list.

    What we would not do is treat the pause as a reason to stop implementing 800-171. The controls are contractually owed today under 7012, they are the same controls under any plausible reform, and the alternative is carrying a knowingly inaccurate affirmation into a period when the government has asked the industry to explain why compliance is expensive.

    Where Top Floor fits

    Our CMMC practice does the unglamorous half: scoping the CUI boundary so the assessment surface is as small as it honestly can be, working the 110 requirements to the assessment-objective level rather than to a checklist, and getting the System Security Plan into a state where an assessor can follow it. During a pause, that work is worth more, not less, because it is the part that survives whatever the task force recommends.

    Where the CMMC work sits alongside a SOC 2 attestation or an ISO 27001 certification for commercial customers, it is usually better run as one program than three, which is what compliance as a service is for.

    We do not perform CMMC certification assessments. A C3PAO cannot assess a client it consulted for, which is a conflict rule worth knowing before you buy readiness and assessment from the same logo.

    How to decide this week

    Three steps, in order.

    First, check whether your current contracts and open solicitations name a CMMC level. Not your prime's letters, the contract documents. Phase 1 clauses are live, and a level named at award is an obligation regardless of the suspension.

    Second, pull your SPRS score and the date it was submitted, and ask one question: is it still true? If the answer is no, or nobody knows, that is this quarter's work, and it is the item with legal exposure attached.

    Third, take your remediation plan and re-sort it by what 7012 requires today rather than by what an assessor would have looked at in November. Multifactor authentication, encryption of CUI at rest and in transit, boundary protection, and logging move to the top. Assessment-preparation theater moves down.

    Frequently asked questions

    Is CMMC cancelled?

    No. The Department of War CIO suspended Phases 2 through 4 on July 13, 2026 under memo 26-P-1023 and stood up a reform task force with recommendations due in roughly 60 days. The 32 CFR Part 170 program rule is still in force, the 48 CFR acquisition rule that started Phase 1 on November 10, 2025 is still in force, and applicable solicitations still carry CMMC level requirements that must be met at award. A pause on the later phases is not a repeal of the program.

    Do I still need an SPRS score during the suspension?

    Yes. The Phase 1 requirement is unchanged: applicable solicitations require a CMMC level at award, self-assessment results have to be recorded in the Supplier Performance Risk System, and a senior company official has to affirm continuing compliance. The affirmation is a representation to the government, so an inaccurate score carries False Claims Act exposure whether or not an assessor is scheduled to visit.

    Does the suspension change DFARS 252.204-7012?

    No. The safeguarding clause is a separate instrument that predates CMMC and was not touched by the July 2026 memo. If your contract carries 7012, you still owe implementation of NIST SP 800-171 on covered systems, a cyber incident report to the Department within 72 hours of discovery, media preservation, malicious software submission, and flow-down to subcontractors that handle covered defense information.

    Should we cancel a scheduled C3PAO assessment?

    It depends on whether a contract requires it. If a current award or a live solicitation names a Level 2 certification assessment, you still owe it and cancelling creates a contract problem. If you booked the assessment in anticipation of the November 2026 Phase 2 trigger and nothing in your contracts requires it yet, re-price the decision, and weigh it against the risk that assessment capacity tightens sharply if third-party requirements return in revised form.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.