8 min read
CMMC Compliance Deadline: What the Phase 2 Pause Changed
Laura Arce Fonseca
on Sep 26, 2025
Quick Answer: There is no active CMMC certification deadline. On July 13, 2026, the Department of War suspended CMMC Phase 2, which would have required third-party Level 2 assessments starting November 10, 2026, and Phases 3 and 4 are on hold with it. Phase 1 did not change. If your contract carries CMMC clauses today, you still owe a self-assessment, a current SPRS score, and an annual affirmation.
If your organization holds Department of Defense contracts, or plans to bid on them, the compliance picture shifted in July 2026 and has not settled since.
The short version is that the certification deadline you were working toward is gone. The obligations underneath it are not.
That distinction carries most of the weight here. Contractors reading the pause as a cancellation are exposed right now, in ways that have nothing to do with a certification date. Below is what was suspended, what is still enforced, and what to do with the time you have been handed.
(Updated August 18th, 2026)
Key Takeaways
- CMMC Phase 2 was suspended on July 13, 2026. There is no current CMMC compliance deadline for third-party Level 2 certification, and no confirmed date for one.
- Phase 1 obligations continue unchanged. NIST SP 800-171, DFARS 252.204-7012, your SPRS score, and your annual affirmation all remain contractual requirements today.
- The suspension was a policy memorandum, not a regulatory change. No rule was repealed, so every cybersecurity duty in your contract still stands.
- With third-party assessments paused, your self-reported SPRS score becomes the primary evidence of compliance, which raises rather than lowers your exposure.
- Want a clear read on where you stand across all 110 controls?

CMMC at a Glance - What Changed and What Did Not
Two things happened at once, and conflating them is the most common mistake right now.
A verification step was suspended. The underlying security obligations were not touched.
|
Paused for Now |
Still Required Today |
|---|---|
|
Mandatory Phase 2 third-party (C3PAO) assessments for Level 2 |
NIST SP 800-171, all 110 controls across 14 domains |
|
Level 3 assessments under Phase 3 |
DFARS 252.204-7012 safeguarding and 72-hour incident reporting |
|
New Level 2 and Level 3 clauses in solicitations and contracts |
A current, accurate SPRS score and annual affirmation |
|
All remaining rollout milestones, held in abeyance |
FAR 52.204-21 basic safeguarding for FCI |
|
FedRAMP Moderate equivalent cloud for CUI, and flow-down to subcontractors |
Is There Still a CMMC Compliance Deadline?
No. There is no active CMMC certification deadline. The Department of War suspended CMMC Phase 2 on July 13, 2026, removing the November 10, 2026 requirement for third-party Level 2 assessments. Phase 1 self-assessment obligations continue exactly as before.
That is the whole answer, and it is worth stating plainly because a lot of coverage has muddied it.
What the suspension did not do matters more than what it did. The CMMC Program rule at 32 CFR Part 170 was not repealed. The DFARS was not amended. No regulation changed.
A memorandum directs how the government exercises its discretion. It does not rewrite the law underneath. Every contractual cybersecurity duty you had on July 12 you still had on July 14.
If you take one thing from this article: the pause lifted a verification step. It did not lift the obligation to protect covered defense information.
What the Department of War Actually Did
On July 13, 2026, two memoranda were issued.
The Chief Information Officer directed the immediate suspension of Phase 2. A companion memorandum from the Under Secretary of Defense for Acquisition and Sustainment told contracting officers to amend active solicitations and contracts, stripping Level 2 and Level 3 assessment requirements.
A new CMMC Reform Task Force was stood up at the same time, with 60 days to deliver a top-to-bottom review of the program. Recommendations are expected in early to mid September 2026.
Why the Pause Happened
The stated reasons were capacity and cost, and both are worth understanding because they shape what comes next.
- Assessor supply. More than 100,000 businesses in the defense industrial base needed assessments. Roughly 100 authorized C3PAOs existed to perform them. The arithmetic never worked.
- Cost burden. Small Business Administration data cited by the CIO put the annual cost of future phases at over 7 billion dollars across small and midsize firms.
- Supplier base. Compliance barriers were pushing smaller and non-traditional firms out of defense work at a time when the department wants more of them, not fewer.
The department also issued a request for information asking industry which NIST 800-171 controls deliver genuine risk reduction. Responses closed on August 14, 2026. You can follow official program status on the DoD CIO CMMC program page.
Read that question carefully. It suggests a program being reshaped around effectiveness, not one being abandoned.
Who CMMC Still Applies To
The scope did not narrow. If you handle federal data, you are still in it.
Handling Federal Contract Information only, meaning information needed to perform a contract but not for public release, puts you at CMMC Level 1. Handling Controlled Unclassified Information puts you at CMMC Level 2 or above.
If you are unsure which applies, our guides on who needs CMMC compliance and CMMC Level 1 versus Level 2 walk through the distinction.
This applies to prime contractors and subcontractors alike. There is no exemption based on company size, and prime contractors continue to screen their supply chains on readiness regardless of what the department does with the rollout calendar.
The CMMC Self-Assessment Is Still a Live Requirement
Phase 1 has been in force since November 10, 2025.
Applicable solicitations still carry a requirement for a CMMC self assessment at Level 1 or Level 2, and a CMMC Status is still a condition of award on those contracts. For a refresher on how the tiers differ, see our breakdown of the levels of CMMC.
Nothing about the July suspension touched this. Contractors who stopped their self-assessment work in July have created a live contract eligibility problem for themselves.
DFARS 252.204-7012 Has Not Moved
DFARS 252.204-7012 has appeared in Department of Defense contracts since 2016. It predates CMMC by years, it was never dependent on CMMC, and it survived the suspension untouched.
If your contract contains this clause, four duties apply today.
- Implement all 110 NIST SP 800-171 controls on every system that stores, processes, or transmits CUI.
- Report cyber incidents to the Department of Defense through DIBNet within 72 hours of discovery.
- Use cloud services that meet FedRAMP Moderate equivalency for any CUI they hold.
- Flow the same requirements down to every subcontractor that touches CUI.
CMMC was only ever the mechanism for checking whether you had done this. Removing the check does not remove the requirement, and it does not remove the liability attached to it.
Want the full breakdown in one place? Fill the form below to download the CMMC Phase 2 Pause Brief, covering what changed, what did not, and the specific steps worth taking during the review period.
Your SPRS Score Is Now the Main Evidence
Here is the part that most contractors have not worked through.
With third-party assessments paused, the government leans harder on what you tell it about yourself. Your Supplier Performance Risk System score and your annual affirmation become the primary record of your compliance.
An inflated SPRS score is not a paperwork gap. It is a statement to the federal government, and an unsupported one is a potential false claim.
The Defense Industrial Base Cybersecurity Assessment Center can still assess your environment at any time and compare its findings to the number you posted. That has not been suspended either.
What That Gap Costs in Practice
In June 2026, a Navy contractor settled with the Department of Justice for 507,144 dollars.
The company had self-reported a perfect score of 110. A subsequent assessment of the same environment scored it at negative 170. The SPRS scale runs from negative 203 to 110, so that is close to the bottom of the range.
The settlement was not about failing an audit. There was no audit to fail. It was about the distance between what the company claimed and what was actually there.
That case is not isolated. Department of Justice cyber-fraud recoveries reached 52 million dollars across nine settlements in FY2025, part of a record 6.8 billion dollars in False Claims Act recoveries overall. Cyber-fraud resolutions have more than tripled in two consecutive years.
The enforcement engine never paused. If anything, less audit and more self-attestation moves the exposure onto you.
What to Do About Microsoft 365 and GCC High
A specific question is coming up repeatedly right now. Contractors midway through a GCC High migration, budgeted against a November 2026 assessment, are asking whether to pause the spend.
Usually the answer is no, and the reasoning is worth setting out.
- Your tenant decision follows your data, not the assessment calendar. If you hold CUI, and particularly if you hold export-controlled or ITAR data, that requirement did not change in July. The suspension altered when you get checked, not what you are holding.
- Tenant choice and control implementation are separate questions. They get conflated constantly. Correctly configured commercial Microsoft 365 satisfies a meaningful share of the 110 controls, but CUI workloads generally need a FedRAMP Moderate equivalent environment. Our guide to building versus buying a CMMC enclave walks through that decision.
- The configuration work maps to obligations that are enforced today. Entra ID conditional access, Intune compliance policies, Purview labelling and retention, and Defender logging all support controls you are self-attesting to right now under Phase 1.
Pausing that work does not defer your exposure. It creates exposure immediately, against requirements that are already live, while removing the assessment that would have caught the problem early.
What Defense Contractors Should Do During the Review
The review period is genuinely useful if you treat it as working time rather than waiting time.
- Run an honest gap assessment. Score all 110 controls against how your environment actually operates, not how it was designed to operate.
- Correct your SPRS score. Update it to reflect reality, and back it with a current System Security Plan and real evidence.
- Remediate by risk, not by convenience. Prioritize controls tied directly to CUI exposure, and track the remainder in a Plan of Action and Milestones with dates you will actually meet.
- Sort your cloud environment. Get CUI into a compliant tenant and out of consumer file sharing and unmanaged endpoints.
- Check your subcontractors. Every supplier touching CUI carries the same obligations, and their gap becomes your liability.
- Keep momentum. When assessments resume, the contractors who kept building will walk in prepared.
The competitive logic is simple enough. Firms treating the pause as a stop will be starting over in the autumn. Firms treating it as a build window will be ready.
Why This Is Hard to Handle Internally
The difficulty has changed shape. It used to be technical. Now it is interpretive, which is harder to staff for.
- Reading a policy memorandum correctly against an unrepealed regulation is a compliance discipline, not an IT one. Most internal teams have nobody whose job that is.
- Scoring 110 controls against 320 assessment objectives, then defending that score with evidence, is specialist work. Getting it wrong now carries False Claims Act exposure rather than a failed audit.
- Documentation fails assessments far more often than technology does. When BEMO went through its own Level 2 certification, the environment passed at 100 percent and the mock audit still surfaced five documentation errors.
- Program conditions will change again when the task force reports. Somebody has to be watching for a class deviation or a DFARS amendment, and that is rarely anyone's assigned role.
This is the work BEMO takes on:
- Gap assessment
- Control implementation
- Microsoft 365 and GCC High configuration
- System Security Plan and POA&M development
- Evidence collection
- Assessor coordination
All this is run by a dedicated compliance team rather than added to an already stretched IT function.
Our compliance-readiness security tier is built around exactly this problem.
Cost of CMMC
Cost depends on your required level, your current security maturity, and the size of your CUI environment.
Level 1 costs are mostly staff time and documentation. Level 2 varies considerably, driven by how much of the 110 controls you already meet and whether a tenant migration is involved. Organizations with mature controls already in place face a much smaller gap than those starting from a standard commercial environment.
For a fuller breakdown of what drives the number, see our guide to how much CMMC certification costs. For a scenario-based estimate against your actual headcount, licensing, and support model, the CMMC Level 2 with GCC High cost calculator gives a far more useful figure than any published range.
Use the Pause to Get Ahead of the CMMC Compliance Deadline
The certification deadline is gone. The security obligations are not.
That is the whole situation in two sentences. The contractors who act on it will be in a stronger position in September than the ones who waited to be told what to do.
Focus on building a security program so robust that successful assessments become the natural outcome of your daily operations.
Compliance is the byproduct of good security. A certificate confirms you met a standard in one day. It does not confirm you are protected tomorrow.
Your one next step: get an honest read on where you stand across all 110 controls, and a plan that holds up whatever the task force recommends. Book a meeting with BEMO to discuss your specific compliance needs. 
Frequently Asked Questions
What Is the Timeline for CMMC Compliance?
Phase 1 has been in effect since November 10, 2025 and still applies. Phase 2, originally set for November 10, 2026, was suspended on July 13, 2026, along with the later phases. No replacement dates have been published.
Is CMMC Compliance Mandatory?
Yes, where your contract requires it. Phase 1 self-assessment requirements still appear in applicable solicitations, and a CMMC Status remains a condition of award. Only the third-party assessment requirement was suspended.
Will CMMC Be Delayed?
It already has been. The CMMC Reform Task Force is reviewing the program, and recommendations are expected in early to mid September 2026. Whether Phase 2 returns on the original terms is not yet known.
Was CMMC Cancelled?
No. The program rule at 32 CFR Part 170 remains in force and the DFARS was not amended. This was a policy suspension of specific requirements, not a repeal. C3PAO assessments are also continuing for organizations that want them.
How Often Must an Affirmation of CMMC Compliance Be Submitted?
Annually. An affirming official must confirm continued compliance each year and post it to SPRS, alongside a current self-assessment score. The suspension did not change this.
Top 10 Posts
-
Google Workspace to Office 365 Migration: A Step-by-Step Guide
-
Office 365 MFA Setup: Step-by-Step Instructions
-
CMMC Compliance Deadline: What the Phase 2 Pause Changed
-
What is The CIA Triad?
-
What is Microsoft Purview ? Your A to Z Guide to Getting Secure Fast
-
SharePoint vs. OneDrive (What's the Difference Again?)
-
How Much Does ISO/IEC 27001 Lead Auditor Certification Cost in 2025?
-
When Will CMMC 2.0 Be Required for DoD Contracts?
-
How to Migrate from GoDaddy to Office 365
-
How to Set Up Office Message Encryption (OME)

Leave us a comment!