Living Tracker

CMMC Phase 2 Status: The 2026 Suspension and What It Means

In July 2026 the schedule for mandatory CMMC assessments changed while the underlying rules stayed in place. This page tracks what happened, what still applies to your contracts today, and the dates worth watching. We update it as official sources publish new information.

Last reviewed: August 9, 2026 · 7 min read

The short version

On July 13, 2026 the Department of War suspended CMMC Phase 2, the phase that would have required mandatory third party assessments, and opened a 60 day review.

This is a pause on the assessment schedule, not a repeal. The program rule at 32 CFR Part 170 remains in force, and DFARS 252.204-7012 with NIST SP 800-171 still applies to contractors that handle controlled unclassified information.

Updates

August 9, 2026

Page created. The Department of War suspended CMMC Phase 2 mandatory third party assessments on July 13, 2026 and opened a 60 day review through a CMMC Reform Task Force. Public comments in response to the Request for Information are due August 14, 2026 at 12:00 PM ET. Task Force recommendations are expected around September 13, 2026. The underlying rule at 32 CFR Part 170 remains in force and DFARS 252.204-7012 with NIST SP 800-171 still applies.

What was suspended

CMMC rolled out in phases. Phase 1 introduced self assessment requirements. Phase 2 was the step that would have required many contractors to pass an assessment by an accredited third party organization, known as a C3PAO, before certain awards.

On July 13, 2026 the Department of War announced it was suspending the Phase 2 requirement for mandatory third party assessments, along with the later phases that followed it, while it conducts a review. In practice this means the deadline pressure to book and pass a C3PAO assessment on the previous timeline has been lifted for now.

What still applies today

The suspension changed the assessment schedule. It did not remove the security obligations already written into defense contracts. The following remain in effect:

32 CFR Part 170 remains in force

The CMMC program rule was not repealed. It stays on the books while the review runs.

DFARS 252.204-7012 still applies

Contractors that handle controlled unclassified information are still bound by the safeguarding and incident reporting clause in their contracts.

NIST SP 800-171 controls still apply

The 110 security requirements that support the DFARS clause remain the baseline for protecting controlled unclassified information.

SPRS self assessment reporting continues

Phase 1 self assessment and posting your score in the Supplier Performance Risk System were not paused by this action.

The review and the dates to watch

The Department of War directed a 60 day review carried out by a CMMC Reform Task Force. Two dates matter right now:

August 14, 2026 at 12:00 PM ET is the deadline for public comments in response to the Request for Information that supports the review.

Around September 13, 2026 is when the Task Force recommendations are expected. What happens after that, including any revised rule or timeline, is not yet decided. We update this page as official sources publish more.

What contractors should do now

Keep meeting your current contract terms

If your contract includes DFARS 252.204-7012, your obligations to protect controlled unclassified information and report incidents have not changed.

Maintain your NIST SP 800-171 work

A suspended assessment schedule is not a reason to let controls or your System Security Plan lapse. Keeping your posture current protects you whatever the review decides.

Keep your SPRS score accurate

Self assessment reporting continues. An up to date score keeps you eligible and credible for awards.

Use the pause to close gaps

If you were racing toward an assessment, the extra time is a chance to remediate weak areas and get documentation in order rather than to stop work.

Watch the review, do not guess at it

Decisions should follow official announcements. This page and our news watch track those sources so you can plan from facts, not rumors.

Need a C3PAO or advisor ready when the schedule firms up?

Tell us about your environment and we will match you with vetted providers from the directory, free. Getting matched now means you are ready to move the moment the review concludes.

Sources

  1. Department of War, Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements (July 2026)
  2. U.S. Small Business Administration, Office of Advocacy: DoW Requests Information for CMMC Reform Task Force (July 20, 2026)
  3. 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program (eCFR)
  4. DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
  5. NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems (NIST CSRC)

This guide is general information for defense contractors, not legal or compliance advice for your specific situation. CMMC rules and DoD contract clauses change over time. Confirm current obligations against your contract language and official DoD and Cyber AB sources before making decisions.

Keep reading