Living Tracker
CMMC Phase 2 Status: The 2026 Suspension and What It Means
In July 2026 the schedule for mandatory CMMC assessments changed while the underlying rules stayed in place. This page tracks what happened, what still applies to your contracts today, and the dates worth watching. We update it as official sources publish new information.
Last reviewed: September 23, 2026 · 7 min read
The short version
On July 13, 2026 the Department of War suspended CMMC Phase 2, the phase that would have required mandatory third party assessments, and opened a 60 day review.
This is a pause on the assessment schedule, not a repeal. The program rule at 32 CFR Part 170 remains in force, and DFARS 252.204-7012 with NIST SP 800-171 still applies to contractors that handle controlled unclassified information.
Get CMMC status updates
Updates when the program status changes. No more than twice a month.
Updates
September 23, 2026
The CMMC Reform Task Force submitted its recommendations to Department of War Chief Information Officer Kirsten Davies on September 11, 2026. As of this update, the report has not been made public. A public release is expected between late September and early October 2026. This page will be updated when the findings are released. On September 3, 2026, the Department of War issued DFARS Class Deviation 2026-O0025, Revision 3, directing contracting officers to remove third-party CMMC assessment requirements from active solicitations and contracts. This does not alter self-assessment obligations or the DFARS 252.204-7012 safeguarding clause, which remain in effect. The RFI comment period closed August 14, 2026. More than 1,100 responses were received.
August 9, 2026
Page created. The Department of War suspended CMMC Phase 2 mandatory third party assessments on July 13, 2026 and opened a 60 day review through a CMMC Reform Task Force, including a Request for Information seeking public comment. The underlying rule at 32 CFR Part 170 remains in force and DFARS 252.204-7012 with NIST SP 800-171 still applies.
What was suspended
CMMC rolled out in phases. Phase 1 introduced self assessment requirements. Phase 2 was the step that would have required many contractors to pass an assessment by an accredited third party organization, known as a C3PAO, before certain awards.
On July 13, 2026 the Department of War announced it was suspending the Phase 2 requirement for mandatory third party assessments, along with the later phases that followed it, while it conducts a review. In practice this means the deadline pressure to book and pass a C3PAO assessment on the previous timeline has been lifted for now.
What still applies today
The suspension changed the assessment schedule. It did not remove the security obligations already written into defense contracts. The following remain in effect:
32 CFR Part 170 remains in force
The CMMC program rule was not repealed. It stays on the books while the review runs.
DFARS 252.204-7012 still applies
Contractors that handle controlled unclassified information are still bound by the safeguarding and incident reporting clause in their contracts.
NIST SP 800-171 controls still apply
The 110 security requirements that support the DFARS clause remain the baseline for protecting controlled unclassified information.
SPRS self assessment reporting continues
Phase 1 self assessment and posting your score in the Supplier Performance Risk System were not paused by this action.
The review and the dates to watch
The Department of War directed a 60 day review carried out by a CMMC Reform Task Force.
September 11, 2026 -- The Task Force submitted its recommendations to DoW CIO Kirsten Davies. As of late September 2026, the report has not been made public. A public release is expected between late September and early October 2026.
What contractors should do now
Keep meeting your current contract terms
If your contract includes DFARS 252.204-7012, your obligations to protect controlled unclassified information and report incidents have not changed.
Maintain your NIST SP 800-171 work
A suspended assessment schedule is not a reason to let controls or your System Security Plan lapse. Keeping your posture current protects you whatever the review decides.
Keep your SPRS score accurate
Self assessment reporting continues. An up to date score keeps you eligible and credible for awards.
Use the pause to close gaps
If you were racing toward an assessment, the extra time is a chance to remediate weak areas and get documentation in order rather than to stop work.
Watch the review, do not guess at it
Decisions should follow official announcements. This page and our news watch track those sources so you can plan from facts, not rumors.
Sources
- Department of War, Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements (July 2026)
- U.S. Small Business Administration, Office of Advocacy: DoW Requests Information for CMMC Reform Task Force (July 20, 2026)
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program (eCFR)
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems (NIST CSRC)
- Department of War, DFARS Class Deviation 2026-O0025, Revision 3 (September 3, 2026)
- DoD CIO, CMMC Program Page: https://dodcio.defense.gov/CMMC/
This guide is general information for defense contractors, not legal or compliance advice for your specific situation. CMMC rules and DoD contract clauses change over time. Confirm current obligations against your contract language and official DoD and Cyber AB sources before making decisions.
Keep reading