On July 13, 2026, the Department of War (DoW, formerly DoD) suspended the move to CMMC Phase 2, which was due to start on November 10, 2026. Phase 2 would have made third-party (C3PAO) Level 2 certification a condition of award on many contracts. For now, new requirements may only call for Level 1 (Self) or Level 2 (Self). The cybersecurity rules themselves have not gone away. DFARS 252.204-7012 and NIST SP 800-171 Rev 2 still apply. A CMMC Reform Task Force has been reviewing the program, and its report is expected about now. As of October 2, 2026, the DoW CIO’s CMMC page still describes Phase 2 as suspended.
What happened
- December 16, 2024: The CMMC program rule (32 CFR Part 170) took effect. It sets out four implementation phases.
- November 10, 2025: Phase 1 began when the DFARS CMMC rule (252.204-7021) took effect. Solicitations could then require Level 1 or Level 2 self-assessments.
- July 13, 2026: The DoW CIO suspended the Phase 2 transition and put “all pending and future CMMC implementation milestones” on hold. The same day, the Under Secretary for Acquisition and Sustainment issued instructions to program offices, and the CIO set up a CMMC Reform Task Force for a 60-day review.
- July 16, 2026: The task force held its first meeting. The CIO said it would get about 15 more days after the 60-day review to finish its recommendations, and that the report would be made public.
- August 14, 2026: Responses were due to the DoW’s “Reforming CMMC and Reducing Compliance Burden” request for information. The CIO later said the department received over 1,100 responses, more than 10,000 pages in all.
- September 2026: Trade press reported a class deviation telling contracting officers how to reflect the suspension in solicitations and contracts.
Who is affected
- Level 1 (Self): No change. Contractors that hold Federal Contract Information still self-assess every year and post the results in SPRS.
- Level 2 (Self): Still in use, and now the highest level a new requirement may call for. The standard is NIST SP 800-171 Rev 2, with a self-assessment every three years and an affirmation every year. The DoW may also carry out “select government-led assessments”.
- Level 2 (C3PAO): Program offices may not require it during the suspension. Active solicitations that required it are to be amended. Existing contracts are to drop it at the next option or administrative modification. Voluntary C3PAO certification remains available. About 2,000 contractors were already certified at Level 2 by July 2026, assessed by 110 authorized C3PAOs.
- Level 3 (DIBCAC): Also may not be required during the suspension.
What to do now
- Keep your SPRS entry current. Self-assessments and affirmations are still how the DoW checks compliance during the suspension. Confirm that your score, dates and affirming official are up to date.
- Keep working on NIST SP 800-171 Rev 2. DFARS 252.204-7012 is still in effect, and government-led assessments can still happen. Keep your System Security Plan and POA&M accurate.
- Watch your solicitations and contracts. If a bid or contract asked for Level 2 (C3PAO) or Level 3, look for an amendment or modification that removes that requirement.
- Don’t throw away certification prep. The work behind a C3PAO assessment (scoping, SSP, evidence) is the same work that backs a Level 2 self-assessment. Whether to certify now or wait is a business decision. Make it with your primes’ expectations in mind.
- Talk to your primes. Ask what they will flow down to subcontractors while the review continues, and get the answer in writing.
Key dates to watch
- Now (late September to October 2026): The task force’s report. The 60-day review ran from July 13. The CIO said the report would follow about 15 days later and be made public. As of October 2, it is not posted on the DoW CIO CMMC page.
- Any new DoW CIO memo or guidance. The CIO memo says “further guidance will be promulgated in the coming months.”
- November 10, 2026: The original Phase 2 start date. Under the current suspension, Phase 2 will not begin that day.
- Federal Register notices. The phase schedule is written into 32 CFR 170.3, so lasting changes may come through rulemaking.
- Your own SPRS anniversary. Your annual affirmation comes due on its usual date.
How Galaxy can help
Galaxy Consulting is a service-disabled veteran-owned small business and a Cyber-AB Registered Provider Organization. We help small defense contractors keep their NIST SP 800-171 work on track while the rules settle: gap assessments, SSP and POA&M documentation, and SPRS self-assessment support. When certification is required again, you’ll be ready. Read more about CMMC Level 2 and Level 1, or see our CMMC services to set up a short discovery call.
This article is general information, not legal advice. Check your own contract terms with your contracting officer or counsel.
Sources (all accessed October 2, 2026)
- Department of War, “Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements,” press release, July 13, 2026. https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/
- DoW CIO Kirsten A. Davies, memo “Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of CMMC Requirements” (cleared July 13, 2026). https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf
- Under Secretary of War (A&S) Michael P. Duffey, memo “Implementing Department of War Chief Information Officer’s Suspension of the Advancement to CMMC Phase 2 Requirements,” July 13, 2026, with Attachment 1. https://dodcio.defense.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf
- DoW CIO, Cybersecurity Maturity Model Certification page. https://dodcio.defense.gov/CMMC/
- DoD, “Cybersecurity Maturity Model Certification (CMMC) Program,” final rule, 89 FR, October 15, 2024 (32 CFR Part 170). https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program
- DoD, “DFARS: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041),” final rule, September 10, 2025, effective November 10, 2025. https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
- eCFR, 32 CFR 170.3, 170.15 and 170.16 (current text). https://www.ecfr.gov/current/title-32/part-170/section-170.3 · https://www.ecfr.gov/current/title-32/part-170/section-170.15 · https://www.ecfr.gov/current/title-32/part-170/section-170.16
- The Cyber AB, “Statement on the Department of War’s Suspension of CMMC Phase II Requirements,” July 15, 2026. https://cyberab.org/News-Events/Press-Releases/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements
- The Cyber AB, response to the DoW “Reforming CMMC and Reducing Compliance Burden” RFI, August 14, 2026. https://cyberab.org/News-Events/Press-Releases/the-cyber-abs-response-to-the-dows-reforming-cmmc-and-reducing-compliance-burden-rfi
- DefenseScoop, “Pentagon task force to review CMMC hits the ground running,” July 17, 2026. https://defensescoop.com/2026/07/17/pentagon-task-force-to-review-cmmc-hits-the-ground-running/
- DefenseScoop, “Pentagon pores over heaps of industry feedback on CMMC reform,” September 9, 2026. https://defensescoop.com/2026/09/09/pentagon-pores-over-heaps-of-industry-feedback-on-cmmc-reform/
- Federal News Network, “As the Pentagon rethinks CMMC, cybersecurity isn’t pausing,” September 15, 2026. https://federalnewsnetwork.com/cybersecurity/2026/09/as-the-pentagon-rethinks-cmmc-cybersecurity-isnt-pausing/