Want to learn more about services? Book a free introductory call - "Here"
CMMC Phase 2 Is Paused
DoD suspended CMMC Phase 2's third-party assessment requirement in July 2026. Here's exactly what's still required under Phase 1 and DFARS 7012, and what isn't.
CMMC BLOG
Daniel McLain
8/28/20265 min read
CMMC Phase 2 Is Paused. Here's What Still Applies to Your Company Right Now
If you've seen headlines about the Pentagon suspending CMMC Phase 2 and you're wondering whether you can stop working on your compliance program, the short answer is no. What got paused is one enforcement mechanism inside the CMMC program, not the underlying legal obligation to protect government information. If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under a Department of Defense (DoD) contract, you still have work to do, and some of it is due on a schedule that hasn't moved at all.
Here's what's actually changed, what hasn't, and what to check before you make any decisions based on this news.
First, a naming note
You'll see two names for the same department in CMMC materials right now. The Department of Defense (DoD) is still the legal name of the department under federal law. Following a September 2025 executive order, the department began using "Department of War" as a secondary title in its own communications, including some of the official releases cited below, but Congress has not passed legislation to make that the department's legal name as of this writing. We use "DoD" throughout this article since it's the legally accurate and more widely recognized term, but if you see "Department of War" in an official release, a contract, or other coverage, it's the same organization.
What actually got paused
On July 13, 2026, DoD Chief Information Officer Kirsten Davies issued a memo suspending Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements "until further notice." Phase 2 would have required mandatory third-party assessments, conducted by a Certified Third-Party Assessment Organization (C3PAO), for certain CMMC Level 2 contracts starting November 10, 2026. That specific requirement, and other pending Phase 2 milestones, are now suspended (Federal News Network; official DoD release).
Alongside the suspension, DoD stood up a CMMC Reform Task Force to conduct a full review of the program. Davies said the goal is a framework that "prioritizes speed to capability, lowers barriers for small, medium, and non-traditional businesses, and replaces prohibitive, third-party compliance models with scalable, realistic security measures," and described the current program as imposing "significant and often prohibitive burdens" on the Defense Industrial Base (DIB), particularly smaller and non-traditional businesses.
That's a real acknowledgment from the department that the compliance burden on small businesses has been a legitimate concern, not just industry griping. It's also, in our opinion, a signal that the program is being redesigned rather than abandoned. A pause and a review are not the same thing as a rule change, and nothing in the memo eliminates the underlying requirement to protect CUI and FCI.
What hasn't changed at all
This is the part that gets lost in the headlines. Several obligations remain fully in effect regardless of the Phase 2 suspension:
CMMC Phase 1 self-assessment requirements, effective since November 10, 2025, are still active. That includes annual Level 1 self-assessment against the FAR 52.204-21 requirements for FCI, with no Plans of Action and Milestones (POA&Ms) permitted, and Level 2 self-assessment against all 110 NIST SP 800-171 Revision 2 requirements every three years, with annual affirmation required in between. POA&Ms are allowed for Level 2 under defined conditions, but they must be closed within 180 days (entechus; official CMMC program page).
DFARS clause 252.204-7012 obligations are untouched by the CMMC pause. If your contract includes this clause, you're still required to safeguard covered defense information, use cloud services that meet the FedRAMP Moderate baseline (or an equivalent standard) for that information, and report cyber incidents to DoD within 72 hours through DIBNet (acquisition.gov).
Supplier Performance Risk System (SPRS) score submissions and annual affirmations continue as required.
None of this depends on whether Phase 2 assessments happen. These are separate legal and contractual requirements that exist independently of the certification program's enforcement mechanism.
If you're a subcontractor, don't assume the pause covers you
This is the nuance we see people get wrong most often. The Phase 2 suspension is a DoD program action. It does not automatically flow down relief to subcontractors, because a lot of subcontract-level CMMC requirements come from language your prime contractor put in your subcontract, not directly from the federal rule.
A prime is under no obligation to remove or relax CMMC requirements from its flow-down clauses just because DoD paused Phase 2. Some primes may choose to hold off on requiring third-party certification from subs while the review is underway. Others may keep their existing flow-down language in place, especially if they're managing risk across their own supply chain. Either way, this is a business decision your prime makes, not something the suspension decides for them.
If you're a subcontractor and you've heard "CMMC is paused" secondhand, don't treat that as confirmation that your specific subcontract obligations changed. Get it in writing from your prime.
A small example of how this plays out
Say you're a 30-person machine shop that supplies parts to a mid-tier prime, and your subcontract references DFARS 252.204-7021 with a CMMC Level 2 requirement. Before the pause, you were planning toward a C3PAO assessment ahead of a contract renewal next year. After the pause, that specific third-party assessment requirement is on hold at the DoD level, but your subcontract still says what it says until your prime updates it. You still need to be doing your Level 2 self-assessment, keeping your System Security Plan (SSP) current, and reporting incidents on the DFARS 7012 timeline. The practical move is to keep executing your compliance work and ask your prime, directly, whether the assessment timeline in your subcontract has changed.
Where the review stands as of this writing
The CMMC Reform Task Force opened a request for information (RFI) to gather industry input on cost drivers, effective security controls, and possible policy reforms; that comment period closed August 14, 2026. The task force's report to the DoD CIO was targeted for delivery within 60 days of the July 13 suspension memo, which puts the expected timeframe in mid-September 2026.
As of today, no formal outcome, new framework, or revised rule has been publicly announced. This is genuinely in progress: DoD has not yet said what will replace Phase 2's assessment model, whether the November 2026 date will simply move, or whether the structure changes more substantially. Anything you read claiming to know the outcome ahead of an official announcement should be treated as speculation, including forecasts about timing beyond the task force's own report date.
This is a fast-moving situation. Confirm the current status directly with your contracting officer or prime, or check the official DoD CMMC program page, before making a contract or budget decision based on any article, including this one.
What to do with this right now
Keep your Phase 1 self-assessment, SSP, and SPRS affirmation work on schedule. None of it is optional and none of it is paused.
If DFARS 252.204-7012 is in your contract, keep your incident reporting process and FedRAMP-equivalent cloud safeguards in place.
If you're a subcontractor, ask your prime in writing whether the Phase 2 pause changes anything in your specific flow-down requirements.
Don't cancel or indefinitely delay planned compliance work on the assumption that CMMC is going away. The direction of travel is toward a revised program, not no program.
Watch for the task force's report and any follow-on rulemaking, since that's what will determine the actual shape of Phase 2 going forward.
Official resources
Official Department of War release: Forging the Arsenal of Freedom (war.gov)
DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (Acquisition.gov)
A quick note on this article
This is general informational guidance based on publicly available sources as of August 28, 2026, not legal advice, and it isn't a substitute for reviewing your specific contract language. CMMC's regulatory status is actively changing. For a determination specific to your contracts or your assessment path, talk to a Registered Practitioner Organization (RPO) or a C3PAO.
Before investing in tools, documentation, or an assessment, make sure you understand what your contract actually requires and which parts of your environment are in scope, especially while the Phase 2 framework is under review. ICTS USA can help you sort out what's still required under Phase 1 and DFARS 252.204-7012, review your flow-down obligations, and figure out a realistic next step while the rest of the program takes shape.
