CMMC Phase 2 Paused: What Actually Changed (And What Didn't)
If you've stopped preparing for CMMC because you heard "Phase 2 got paused," you may be making a mistake. Here's exactly what the July 2026 DoD memo did and didn't change — and what your organization should still be doing right now.
What happened
On July 13, 2026, the Department of Defense — now officially the Department of War — released two memoranda suspending the upcoming transition to CMMC Phase 2, including the previously mandatory November 10, 2026 deadline for Level 2 C3PAO certification. In its place, DoD stood up a 60-day CMMC Reform Task Force to review the program, citing "significant and often prohibitive burdens" the current version of CMMC places on defense contractors. The task force's Request for Information closes August 14, 2026, with recommendations expected to follow.
In plain terms: the rule that would have forced every contractor handling CUI to get a formal, third-party Level 2 certification by November is on hold while DoD figures out what CMMC should look like going forward.
What's paused vs. what's still required
| Requirement | Status |
|---|---|
| Level 2 C3PAO third-party certification (Nov 10, 2026 deadline) | Paused |
| Phase 2 contract clause rollout (36-month schedule) | Paused |
| DFARS 252.204-7012 (safeguarding CDI, incident reporting) | Still in force |
| CMMC Level 1 self-assessment (FCI environments) | Still in force |
| Annual SPRS score submission (DFARS 252.204-7019) | Still in force |
Why "paused" isn't "cancelled"
Three reasons contractors shouldn't stand down:
- The review is about how CMMC gets enforced, not whether it exists. DoD's stated goal is to reduce burden on contractors, not eliminate the underlying security requirements DFARS 252.204-7012 has required for years.
- Phase 2 will come back in some form. A 60-day review with an RFI due August 14 is not "CMMC is over" — it's DoD gathering input before deciding what the next version looks like. Contractors who keep working during the pause will be ahead when it returns.
- Your self-assessment and SPRS obligations are due regardless. If you handle FCI or CUI today, the controls you're supposed to have in place haven't changed — only the third-party verification of Level 2 has been delayed.
What to do during the review window
If your organization was mid-preparation for a C3PAO assessment, this is a good moment to redirect effort toward the things that are still unambiguously required: confirming your Level 1 self-assessment is current, making sure your SPRS score reflects reality, and keeping your System Security Plan and POA&M up to date. None of that work is wasted — it's the same foundation Phase 2 will eventually assess against, whatever shape it takes after the task force's recommendations land.
See where you actually stand
Score110's Quick Check is a free, 5-minute readiness score mapped to real NIST 800-171 controls — no signup required to see your result.
Take the Quick Check →