
Updated September 9, 2026.
CMMC Phase 2 is suspended, and the 60-day review that paused it closes this month. The Department of War issued the suspension on July 13, 2026. It hasn't announced a date for the review's public report.
What didn't pause: the cybersecurity obligations already written into your contracts. The suspension memo says so directly.
- Phase 2 is off the calendar. The November 10, 2026 start of third-party assessments is suspended.
- Self-assessments only. Contracting officers may designate CMMC Level 1 (Self) or Level 2 (Self) — nothing higher.
- DFARS 252.204-7012 is untouched. NIST SP 800-171, 72-hour incident reporting, and subcontractor flowdown all still apply.
- Separately, DFARS 252.204-7019 was eliminated in February 2026, and the basic self-assessment SPRS upload went with it. DIBCAC Medium and High assessments are still posted to SPRS. Most contractors haven't caught this change.
Is CMMC Phase 2 suspended?
Yes. The Department's implementing memo states that "the upcoming November 2026 transition to Phase 2 of CMMC implementation is suspended," pending a 60-day review (Department of War CIO memorandum, July 2026).
Phase 2 was the point at which third-party C3PAO assessments would have become a condition of award on new contracts involving Controlled Unclassified Information. That start date was November 10, 2026.
The 60-day clock started July 13, so the review period closes in mid-September. The Department hasn't published a report date, and treating any specific date as firm would be guessing.
What can a contracting officer still require during the suspension?
Self-assessments only. The memo is specific: "The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self)."
That's the rule for anything being solicited or awarded right now. A program office can't make a C3PAO certification a condition of award while the suspension holds, and DIBCAC assessments are barred from new designations during the review (Latham & Watkins).
Check your existing contracts for the modification
This is the item most contractors are missing. The memo directs contracting officers to remove higher-level CMMC requirements from existing contracts "prior to the exercise of the next option period or during the next scheduled administrative modification."
So a contract carrying a Level 2 (C3PAO) designation is supposed to shed it — but only through a contract action someone has to take. Don't assume it happened.
Pull your active awards, check the CMMC designation on each, and raise it with your contracting officer if the next modification passes without the change. Chasing a requirement that should have been stripped is expensive. So is assuming it was stripped when it wasn't.
What still applies under DFARS?
The suspension memo confirms that "the cybersecurity requirements outlined in the clause at DFARS 252.204-7012 ... remain in effect." That clause requires covered contractors to implement NIST SP 800-171, report cyber incidents within 72 hours, and flow the clause down to subcontractors.
Two clause changes from February 1, 2026 matter more than most contractors realize, and they're separate from the CMMC suspension:
- DFARS 252.204-7019 was eliminated. The standalone basic self-assessment provision no longer exists, and the requirement to upload a basic self-assessment score to SPRS went with it (DoD Class Deviation 2026-O0025; Summit 7 analysis).
- DFARS 252.204-7020 was renumbered to 252.240-7997, keeping its title, NIST SP 800-171 DoD Assessment Requirements. Medium and High assessments run by DCMA DIBCAC still get posted to SPRS by those teams.
- DFARS 252.204-7021 survives. You still maintain your CMMC status for the life of the contract, with an annual affirmation from a company official.
Read those changes carefully before concluding your SPRS obligations vanished. They were restructured, not abolished, and 7012 — the clause that carries the actual security requirements — never moved.
The suspension paused the verification layer. It didn't pause the security requirements. A contractor who reads the pause as permission to stop patching, drop MFA, or let documentation go stale is reading it the way that ends in a False Claims Act case.
What is CMMC 2.0, in plain terms?
CMMC is the Department of War's method for verifying that contractors follow the cybersecurity rules already in their contracts.
Three levels. Level 1 covers basic safeguarding of Federal Contract Information. Level 2 maps to the 110 controls in NIST SP 800-171. Level 3 applies to the most sensitive programs.
For years contractors self-attested and nobody checked. Supply-chain breaches made it clear that a signature on a form isn't a working security program. CMMC was built to require proof.
Which level does your business need, and what does it cost?
It comes down to the data you handle. Federal Contract Information is the routine, non-public data involved in delivering a product or service. CUI is the sensitive technical and program data.
| Level | Data type | Standard | Assessment | DoD cost estimate |
|---|---|---|---|---|
| Level 1 | Federal Contract Information | Basic safeguarding requirements from FAR 52.204-21 | Annual self-assessment | $4,000-$6,000 |
| Level 2 (Self) | CUI | 110 controls, NIST SP 800-171 | Self-assessment, annual affirmation | $37,000-$49,000 |
| Level 2 (C3PAO) | CUI | 110 controls, NIST SP 800-171 | Third-party, valid 3 years | $105,000-$118,000 |
Clause and regulation numbers are shifting under the FAR overhaul. Confirm the exact citation in your own contract rather than the one in any article, including this one.
Cost estimates are the Department's own, compiled by Secureframe. They cover assessment only. The real number runs higher once you add the work of closing gaps: MFA, encryption, logging, access controls, written policies, and the staff time to keep them running.
It lands hardest on the smallest shops. Secureframe's compilation of DoD figures puts small businesses at roughly three quarters of the Defense Industrial Base, so a rule aimed at protecting national security data turns into a small-business budgeting exercise.
The consolation is real. The controls that satisfy CMMC are the same ones that stop the ransomware and email fraud already hitting companies your size.
Scoping is where small contractors get it wrong
In both directions. Over-scope and you buy controls no contract asked for. Under-scope and you're non-compliant on data you didn't know you held.
The cloud question catches the most people. If CUI lands in a commercial Microsoft 365 tenant, that tenant is in scope, and commercial cloud isn't automatically sufficient for CUI. That's why GCC High comes up in nearly every Level 2 conversation. Settle that before you budget anything else, because it changes the licensing, the migration, and the timeline.
When do you have to comply?
Nobody can give you a date, and anyone who does is guessing. The rollout is paused and the review period closes this month.
Don't let that feel comfortable. In our experience Level 2 readiness runs six to nine months. Assessor capacity will tighten the moment a new date is announced, and the firms that kept working through the pause clear the queue first.
Whatever the review recommends, NIST SP 800-171 is still the standard your contracts name today.
How a small contractor gets ready without panic
Start with scope: where CUI and Federal Contract Information live. Which systems, which mailboxes, which shared drives, which cloud tenants.
Then run a gap assessment against the 110 controls in NIST SP 800-171. From there you build a System Security Plan documenting how you meet each control, and a Plan of Action and Milestones for the gaps you haven't closed. Not every control is POA&M-eligible, so confirm which of your gaps have to be closed outright before you plan around a deferral.
Most of the remediation is ordinary security hygiene done thoroughly: enforced MFA, encryption at rest and in transit, centralized logging, tightened access, and an incident response process someone has rehearsed. Our rundown of the controls that stop attacks covers much of the same ground, our explainer on NIST, ISO 27001, and CIS shows how the frameworks connect, and our vendor risk management guide helps with the flowdown questions your primes are asking.
Plenty of small contractors handle this with a fractional security leader or a CMMC compliance partner rather than a full-time hire, which keeps the cost proportional to the contract.
Frequently asked questions
Does CMMC apply to subcontractors?
Yes. If you handle Federal Contract Information or CUI, the requirement flows down to you from the prime. A prime can't legally pass CUI to a subcontractor that lacks the appropriate level, which is why primes are still asking suppliers about status during the suspension.
Can a contract still require a C3PAO assessment right now?
No. The suspension memo limits allowed designations to CMMC Level 1 (Self) or Level 2 (Self), and directs contracting officers to remove higher-level requirements from existing contracts at the next option exercise or administrative modification. Check your active awards rather than assuming the change was made.
Do I still have to post a self-assessment score to SPRS?
The basic self-assessment provision at DFARS 252.204-7019 was eliminated effective February 1, 2026, and the basic SPRS upload requirement went with it. Medium and High assessments run by DCMA DIBCAC are still posted to SPRS by those teams under the renumbered clause 252.240-7997. Check what your specific contracts require rather than assuming the obligation disappeared.
How long is a CMMC certification valid?
A Level 2 C3PAO certification runs three years, paired with an annual affirmation from a company official. Level 1 self-assessments are annual. It's a program you maintain, not a project you finish.
Should we stop readiness work during the pause?
No. DFARS 252.204-7012 is untouched by the suspension, so the NIST SP 800-171 controls are still contractually required. Every gap you close now counts under the current rules, on insurance questionnaires, and under whatever verification regime follows.
We're not a defense contractor. Does any of this matter?
The certification doesn't. The controls do. NIST SP 800-171 is a solid baseline for any small business, and cyber insurers and larger customers increasingly ask for the same safeguards.
Sources and further reading
- Department of War CIO — Implementing the Suspension of CMMC Phase II — the suspension itself, the allowed Level 1 (Self) and Level 2 (Self) designations, the DFARS 252.204-7012 carve-out, and the direction to modify existing contracts. Accessed September 2026.
- Federal News Network — Pentagon suspends CMMC Phase 2 requirements — the July 13, 2026 announcement and the 60-day reform review. Accessed September 2026.
- Latham & Watkins — What Defense Contractors Should Know About DoD's Suspension of CMMC Phase 2 — the review timeline and the DIBCAC designation pause. Accessed September 2026.
- DoD Class Deviation 2026-O0025 — the February 1, 2026 DFARS changes themselves. Accessed September 2026.
- Summit 7 — Why the FAR Overhaul Ended DFARS 7019 and 7020 — the February 1, 2026 elimination of 252.204-7019, the renumbering of 7020 to 252.240-7997, and what changed for SPRS. Accessed September 2026.
- Secureframe — CMMC for small business — DoD assessment cost estimates by level and the DIB small-business share. Accessed September 2026.
Not sure whether your contracts pull you into Level 1 or Level 2, or whether a stale Level 2 designation is still sitting on an active award? Book a complimentary engineer call and we'll scope it with you before a new deadline forces the question.
By Joel Baum, who leads cybersecurity, threat research, and compliance strategy at The NetSys Group. NetSys has delivered managed IT, cybersecurity, and cloud services since 1998 to businesses across NY, NJ, CT, PA, and Southwest Florida.
Discuss cmmc 2.0 compliance services for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.



