CMMC Phase 2 third-party assessments put on hold

On July 13, 2026, the Defense Department announced that it is suspending CMMC Phase 2. That phase was scheduled to begin on November 10, 2026, and would have pushed third-party (C3PAO) Level 2 assessments into more contracts that handle Controlled Unclassified Information (CUI).

Later milestones, including the planned expansion toward Level 3 government-led assessments, are also on hold while the department reviews the program. Official materials frame the pause as part of a broader push to cut compliance burden and keep capable vendors, including smaller and non-traditional ones, in the defense supply chain.

What still applies

Phase 1 is not paused. Where contracts already call for it, organizations still need to:

  • Complete Level 1 or Level 2 self-assessments as required
  • Post scores in the Supplier Performance Risk System (SPRS)
  • Affirm compliance on the expected cadence
  • Meet existing safeguarding and incident-reporting duties under DFARS 252.204-7012 and NIST SP 800-171 Rev. 2

False Claims Act exposure tied to inaccurate cyber representations is also unchanged. Treat this as a pause on third-party certification timing, not a holiday from cybersecurity requirements.

What happens next

A CMMC Reform Task Force is running a roughly 60-day review. The department also asked industry for input through a public request for information (RFI), with responses due in mid-August 2026. Recommendations from that process will shape whatever comes after Phase 2 as written.

There is no announced date for restarting third-party assessment mandates. Watch for a formal class deviation, DFARS change, or update to the CMMC program rule before treating the pause as a permanent rewrite of the regulations.

What to do now

  1. Confirm which CMMC level your current and upcoming contracts actually require. See our CMMC overview and the Level 1 versus Level 2 guide.
  2. Keep self-assessment, SPRS, and affirmation work current if Phase 1 clauses apply to you.
  3. If you were racing a November 2026 C3PAO date, use the pause to close gaps without assuming the third-party path is canceled.
  4. Follow CMMC on this site (or the official DoD CMMC page) for the review outcome and any new deadlines.

Primary sources: the July 13 suspension and implementation memos linked from dodcio.defense.gov/CMMC.

#program-changes#version-updates

← Back to news