Living Tracker
CMMC Phase 2 Status: The 2026 Suspension and What It Means
In July 2026 the schedule for mandatory CMMC assessments changed while the underlying rules stayed in place. This page tracks what happened, what still applies to your contracts today, and the dates worth watching. We update it as official sources publish new information.
Last reviewed: August 9, 2026 · 7 min read
The short version
On July 13, 2026 the Department of War suspended CMMC Phase 2, the phase that would have required mandatory third party assessments, and opened a 60 day review.
This is a pause on the assessment schedule, not a repeal. The program rule at 32 CFR Part 170 remains in force, and DFARS 252.204-7012 with NIST SP 800-171 still applies to contractors that handle controlled unclassified information.
Updates
August 9, 2026
Page created. The Department of War suspended CMMC Phase 2 mandatory third party assessments on July 13, 2026 and opened a 60 day review through a CMMC Reform Task Force. Public comments in response to the Request for Information are due August 14, 2026 at 12:00 PM ET. Task Force recommendations are expected around September 13, 2026. The underlying rule at 32 CFR Part 170 remains in force and DFARS 252.204-7012 with NIST SP 800-171 still applies.
What was suspended
CMMC rolled out in phases. Phase 1 introduced self assessment requirements. Phase 2 was the step that would have required many contractors to pass an assessment by an accredited third party organization, known as a C3PAO, before certain awards.
On July 13, 2026 the Department of War announced it was suspending the Phase 2 requirement for mandatory third party assessments, along with the later phases that followed it, while it conducts a review. In practice this means the deadline pressure to book and pass a C3PAO assessment on the previous timeline has been lifted for now.
What still applies today
The suspension changed the assessment schedule. It did not remove the security obligations already written into defense contracts. The following remain in effect:
32 CFR Part 170 remains in force
The CMMC program rule was not repealed. It stays on the books while the review runs.
DFARS 252.204-7012 still applies
Contractors that handle controlled unclassified information are still bound by the safeguarding and incident reporting clause in their contracts.
NIST SP 800-171 controls still apply
The 110 security requirements that support the DFARS clause remain the baseline for protecting controlled unclassified information.
SPRS self assessment reporting continues
Phase 1 self assessment and posting your score in the Supplier Performance Risk System were not paused by this action.
The review and the dates to watch
The Department of War directed a 60 day review carried out by a CMMC Reform Task Force. Two dates matter right now:
August 14, 2026 at 12:00 PM ET is the deadline for public comments in response to the Request for Information that supports the review.
Around September 13, 2026 is when the Task Force recommendations are expected. What happens after that, including any revised rule or timeline, is not yet decided. We update this page as official sources publish more.
What contractors should do now
Keep meeting your current contract terms
If your contract includes DFARS 252.204-7012, your obligations to protect controlled unclassified information and report incidents have not changed.
Maintain your NIST SP 800-171 work
A suspended assessment schedule is not a reason to let controls or your System Security Plan lapse. Keeping your posture current protects you whatever the review decides.
Keep your SPRS score accurate
Self assessment reporting continues. An up to date score keeps you eligible and credible for awards.
Use the pause to close gaps
If you were racing toward an assessment, the extra time is a chance to remediate weak areas and get documentation in order rather than to stop work.
Watch the review, do not guess at it
Decisions should follow official announcements. This page and our news watch track those sources so you can plan from facts, not rumors.
Sources
- Department of War, Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements (July 2026)
- U.S. Small Business Administration, Office of Advocacy: DoW Requests Information for CMMC Reform Task Force (July 20, 2026)
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program (eCFR)
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems (NIST CSRC)
This guide is general information for defense contractors, not legal or compliance advice for your specific situation. CMMC rules and DoD contract clauses change over time. Confirm current obligations against your contract language and official DoD and Cyber AB sources before making decisions.
Keep reading