Skip to content
Contract Compliance

CMMC Phase 2 Suspended: What Small DIB Contractors Should Do Now

Josef Kamara Josef Kamara · · 12 min read · Updated July 31, 2026

Editor’s note (updated July 16, 2026): On July 13, 2026, the Department of War suspended CMMC Phase 2, including the November 10, 2026 start date for third-party (C3PAO) assessments. A 60-day review is underway and all Phase 2 milestones are on hold until further notice. CMMC Phase 1 self-assessment stays in force. We updated this article to reflect the suspension. We will update it again when the Department of War announces the review’s outcome. For current status, check dodcio.defense.gov/CMMC.

The short answer: The Department of War (DoW) suspended CMMC Phase 2 on July 13, 2026. CMMC stands for Cybersecurity Maturity Model Certification, the DoD’s cybersecurity rule for defense contractors. Phase 2 would have required many contractors to pass a paid, outside security audit. A C3PAO, an accredited third-party assessor, would have conducted it. That audit was set to start November 10, 2026. That date is now on hold. Phase 1 self-assessment still applies. Do not rush to buy a C3PAO assessment just to beat a date that is now paused. Use the pause to raise your real security score instead. Watch dodcio.defense.gov for the review outcome.

What Changed on July 13, 2026

A note on the name. In September 2025, Executive Order 14347 authorized “Department of War” as a secondary title for the Department of Defense. Both names mean the same department. The legal name has not changed, so your contract, your DFARS clauses, and 32 CFR Part 170 all still say “Department of Defense.” We use “Department of War” for what the Department has announced, and “Department of Defense” where the law and your paperwork use it.

CMMC stands for Cybersecurity Maturity Model Certification. It is the Department of Defense’s cybersecurity rule for companies that do defense work. The Defense Industrial Base (DIB) is the group of private companies that supply the U.S. military. If your company holds a defense contract, you are part of the DIB.

On July 13, 2026, DoD Chief Information Officer Kirsten Davies signed memo 26-P-1023. The memo suspended CMMC Phase 2 effective immediately. Phase 2 would have required many contractors to pass a paid, outside security audit. That audit was due to start November 10, 2026.

That outside audit is called a C3PAO assessment. C3PAO stands for CMMC Third-Party Assessor Organization. The Cyber AB accredits these firms. Cyber AB is short for the CMMC Accreditation Body. Under Phase 2, contractors handling CUI on designated contracts would need a passing C3PAO assessment. CUI stands for Controlled Unclassified Information. It covers technical drawings, export-controlled data, and other sensitive information that is not classified but still needs protection.

The memo also created a 60-day CMMC Reform Task Force review. The DoW has not said what the review will recommend. All pending and future CMMC milestones are on hold until the DoW announces a decision. That includes the November 10, 2026 start date for C3PAO assessments. It also includes the later phases that were scheduled to follow.

The DoW gave two reasons for the pause. First, the supply of accredited C3PAOs is too small to handle the number of contractors that would need an assessment. Second, the cost of certification is a heavy burden for small businesses. The pause is part of a broader Pentagon push to reform how the Department buys goods and services. This push is known as the Hegseth acquisition-reform effort.

The assessor shortage is not a vague claim. As of early 2026, the Cyber AB’s marketplace listed roughly 97 to 103 accredited C3PAOs. The government’s own Regulatory Impact Analysis for 32 CFR Part 170 made a projection. Close to 80,000 contractors would eventually need to go through the CMMC process. About 76,000 of those would need a full C3PAO assessment eventually. That number covers the entire rollout through 2028, not Phase 2 alone. It still points to the same bottleneck the DoW cited when it announced the pause. A few hundred assessor firms cannot process tens of thousands of contractors quickly. That mismatch is a big part of why the DoW hit pause.

This is a pause, not a cancellation. CMMC is written into federal law. That law is Section 1648 of the FY2020 National Defense Authorization Act. The program’s detailed rules live in 32 CFR Part 170. The DoW cannot cancel a statutory program by memo. It can only pause how fast the program rolls out. Expect CMMC to come back in some form. What we do not know yet is when, or whether the review will change any of the rules.

CMMC Stage Original Date Status as of July 16, 2026
Phase 1 (self-assessment) November 10, 2025 In force. Not affected by the suspension.
Phase 2 (C3PAO third-party assessment) November 10, 2026 Suspended July 13, 2026. No new date announced.
Phase 3 and Phase 4 November 10, 2027 and November 10, 2028 (original schedule) Suspended along with Phase 2. The DoW’s July 13 memo paused all pending and future CMMC milestones, which includes these phases.

Treat every date in that table except Phase 1 as history, not as a plan. The Phase 2 date shows what was scheduled before the suspension, not what will happen next.

What Still Applies Right Now

Phase 1 is the first stage of the CMMC rollout. It began November 10, 2025. It requires contractors to self-assess against the required security controls and post their score to SPRS. Phase 1 self-assessment is still in force. The DoW’s July 13 memo did not touch it.

SPRS stands for Supplier Performance Risk System. It is the DoD database where contractors report their cybersecurity score. That score is based on NIST SP 800-171. NIST SP 800-171 is a security standard from the National Institute of Standards and Technology. It lists 110 security controls for protecting CUI. Your SPRS score starts at 110 points. You lose points for every control you have not met.

DFARS clause 252.204-7021 can still appear in new solicitations. DFARS is short for Defense Federal Acquisition Regulation Supplement, the rulebook DoD uses to write contract clauses. Clause 7021 is the legal hook that puts a CMMC requirement into a specific contract. The DoW paused the Phase 2 third-party assessment piece. It did not remove the clause. It also kept the Level 1 and Level 2 self-assessment rules that Phase 1 put in place.

How to Know Whether This Applies to You

Check your contract for the CUI question first. Look for references to Controlled Unclassified Information, technical data, export-controlled information (ITAR or EAR), or categories listed in the CUI Registry. If your work involves engineering drawings, defense-related source code, manufacturing specs, or sensitive program details, you likely handle CUI.

Next, check for DFARS clause 252.204-7021 in your contract. If it names a CMMC level, that level applies to you. If you are a subcontractor and do not see the clause, ask your prime. The clause is required to flow down to every subcontractor who touches CUI. Your prime is responsible for passing it to you.

CMMC as a program is not canceled. It remains a statutory requirement under the FY2020 National Defense Authorization Act. A contracting officer can still write a self-assessment requirement into your contract today. Read every new solicitation and contract modification carefully. Do not assume CMMC language is gone just because Phase 2 is paused.

What Smart Contractors Do During the Pause

The pause is not a reason to stop working on your security posture. It is a good time to fix real gaps without a looming assessment date. Here is where to focus.

Run a Real SPRS Gap Analysis

Pull NIST SP 800-171 Revision 2 from csrc.nist.gov. It lists 110 security requirements across 14 control families. Go through each one. Mark it met, partly met, or not met. For each gap, note the SPRS points at risk. Add up the total. That total is your honest score, not the one many contractors self-report.

DCMA, the Defense Contract Management Agency, runs DIBCAC, the Defense Industrial Base Cybersecurity Assessment Center. DIBCAC has audited contractor self-reported SPRS scores for years. Its findings consistently show that self-reported scores overstate real posture. Many audited contractors score well below what they had claimed. Use the pause to close that gap honestly, before any assessor ever asks to see your evidence.

Build or Update Your SSP and POA&M

An SSP (System Security Plan) describes how your company meets each of the 110 controls. A POA&M (Plan of Action and Milestones) documents which controls you have not met yet and your plan to fix them. If you already have current versions of both, your gap analysis is mostly done. If you do not, building them now, while there is no assessment clock running, is the least stressful way to do it.

Close the Common Gaps

Small businesses tend to have the same handful of recoverable gaps. These are worth fixing regardless of what happens with Phase 2:

  • Access Control (AC): Multi-factor authentication (MFA) on all remote access. If you do not have MFA today, add it. It closes a high-value gap and is not hard to set up.
  • Configuration Management (CM): Written baseline configurations for your IT systems. Most small businesses run without one. Writing it down closes several controls at once.
  • Identification and Authentication (IA): Password rules, account management steps, and limits on who has administrator access.
  • Media Protection (MP): A written policy for how CUI is stored, moved, and destroyed.
  • System and Communications Protection (SC): Separating the systems that touch CUI from your general business network. This is where an enclave, covered below, can help.

For every gap you cannot close right away, add it to your POA&M with a realistic date. Nobody expects a perfect score. What matters is that you know your real gaps and have an honest plan to close them.

Do Not Rush Into a Paid Assessment

Before the suspension, some contractors were ready to book a C3PAO assessment purely to beat the November 10 date. That reason is gone now. Your current contract may not require a C3PAO assessment today. If it does not, there is no benefit to paying for one just to get ahead of a paused requirement. Spend that money on closing real control gaps instead. If the DoW announces a new Phase 2 date later, a higher SPRS score will make that assessment faster and cheaper, not slower.

Consider the Enclave Option

An enclave is a separate, secured part of your IT environment where all CUI work happens. Instead of securing your whole company network to the CMMC standard, you secure only the enclave. That shrinks the scope of any future assessment to the systems inside the enclave.

Several vendors sell managed CUI enclaves built on NIST 800-171 controls and hosted in a FedRAMP Authorized cloud. Reported monthly fees run from about $500 to $2,000, depending on user count and services included. An enclave can be a practical way to control both cost and scope. This fits a small business with five to 20 employees who handle CUI especially well. Get current quotes from at least three vendors before you decide.

Talk to Your Prime

If you are a subcontractor, ask your prime contractor how they are handling the pause. Primes manage supply chain risk across many subcontractors. They likely have a clearer read on how the contracts you support are affected. A short email asking what changes, if any, apply to your subcontract is a normal and useful question right now.

Watch for the Review Outcome

The 60-day task force review will produce some kind of announcement. Nobody outside the DoW knows yet what it will recommend or when a new Phase 2 date might be set. Check dodcio.defense.gov/CMMC periodically. Treat any date you see in a news article as unconfirmed until the DoW publishes it directly.

If the Cost Still Will Not Work for Your Business

Even with the pause, some small businesses will decide defense work is not worth the long-term compliance cost. That is a legitimate business decision, not a failure. Three honest paths exist.

Subcontract through a certified prime. Find a prime contractor that already holds Level 2 certification. Work under their umbrella on tasks that do not require you to handle CUI directly. You provide labor, skills, or products. The prime handles the CUI-touching work. This is a common, legal arrangement.

Pursue FAR-only commercial work. Not all government contracting touches CUI. Federal Acquisition Regulation (FAR) contracts for commercial items, general professional services, and non-sensitive work do not trigger CMMC. State and local government contracts do not trigger it either.

Exit defense contracting. Your defense revenue may not justify the compliance cost. Teaming or scope reduction might not solve that either. If so, leaving the DIB on your own timeline is a reasonable choice. That decision is easier to make now, while there is no assessment deadline forcing a rushed exit.

None of these decisions need to happen this month. The suspension gives you room to think them through instead of reacting to a date on a calendar.

What Certification Still Costs (When It Applies)

These figures come from the government’s own Regulatory Impact Analysis. DoD published it alongside the CMMC final rule for 32 CFR Part 170. They describe the cost of the program as designed, not a bill you owe by a specific date.

The analysis puts the median cost of a Level 2 C3PAO assessment alone at about $50,000 for a small entity. Total three-year compliance costs are estimated around $104,670 for a small entity. That figure includes the assessment plus the security work needed to pass it. It assumes the company starts from a partial baseline of controls already in place. A company starting from zero should expect to pay more.

Practitioners in the C3PAO industry report a wider range. Assessment costs alone often run $30,000 to $100,000. The full project, including remediation work, often runs $50,000 to $200,000. These are practitioner estimates, not government figures. Treat them as a planning range and confirm current pricing with real C3PAO quotes for your environment.

None of these numbers are urgent right now. Phase 2 is suspended. You do not need to spend this money on a schedule set by a deadline that no longer exists. Use the pause to plan the spending, not to panic about it.

Frequently Asked Questions

Is CMMC Phase 2 canceled?

No. It is suspended, not canceled. The DoW paused Phase 2 on July 13, 2026, pending a 60-day review. It has not announced a new start date. CMMC remains a statutory program, so the DoW cannot cancel it by memo alone.

Does Phase 1 self-assessment still apply?

Yes. Phase 1 self-assessment has applied since November 10, 2025. The July 13 suspension did not change it. If your contract requires a Level 1 or Level 2 self-assessment, you still must complete it. Post your score to SPRS.

Should I still pursue a C3PAO assessment?

If a current contract already requires one, yes, keep moving forward on it. Nothing in your current contract may require it today. If so, do not rush into an assessment just to beat the old November 10, 2026 date. That date no longer applies.

Will Phase 2 come back, and when?

Unknown. The DoW has not set a new date. The 60-day task force review may recommend changes to how Phase 2 works, not just when it starts. Watch dodcio.defense.gov/CMMC for the official announcement. Treat any date reported elsewhere as unconfirmed until the DoW confirms it.

How long does a CMMC Level 2 certification last, once I get one?

Three years, under 32 CFR 170.17(a)(1), for contractors who complete a C3PAO assessment. You must also complete annual affirmations under 32 CFR 170.22 confirming you still meet the required controls. The July 13 suspension did not change this rule. It applies whenever a contractor completes an assessment, now or after Phase 2 resumes.

Does the suspension affect Level 3 (DIBCAC) assessments?

Yes. Level 3 assessments are conducted by DIBCAC, the Defense Industrial Base Cybersecurity Assessment Center. They were tied to the same Phase 2 and Phase 3 timeline that is now on hold. Until the DoW announces new guidance, treat Level 3 timing as suspended along with the rest of Phase 2.

My prime has not mentioned the suspension. Should I bring it up?

Yes. Primes manage CMMC compliance across their whole supply chain. Many are still working out what the suspension means for their subcontracts. Asking your prime how the pause affects your specific contract is a normal, useful question right now.

Next Steps

Start with a real gap analysis, not an assessment booking. Knowing your actual SPRS score matters whether Phase 2 comes back in three months or next year.

For a foundation-level look at how CMMC certification works, read CMMC Certification for Small Businesses. It covers the certification structure and level definitions that this suspension pauses, not replaces.

Need a cost accounting system that satisfies both DCAA and your prime’s requirements? Read DCAA-Compliant Accounting Systems for Small Businesses. It covers what your books need to look like.

We will update this article again as soon as the DoW announces the task force’s findings.

Josef Kamara

Written by

Josef Kamara

CPA, CISSP, CISA. Former Big Four auditor (KPMG, BDO). Specializing in government contracting compliance, cybersecurity, and audit readiness.

New to government contracting?

Our Start Here guide walks you through everything from SAM registration to your first proposal, step by step.

Start your journey