Managed IT and Managed Security · Leesburg, VA

CMMC

Is CMMC Phase 2 Paused, and What Still Applies?

Yes. A Department of War implementing memo dated 2026-07-13 suspended the November 2026 transition to CMMC Phase 2, pending the DoW CIO's 60 day review. During the suspension, contracts may only call for CMMC Level 1 (Self) or Level 2 (Self). The memo says the Department will keep enforcing NIST SP 800-171 Rev 2 through those self-assessments and select government-led assessments, and that DFARS 252.204-7012 remains in effect.

Capital Cyber. Sources are listed at the end of the article.

What the Memo Suspended

Under 32 CFR 170.3(e), Phase 2 was to begin one year after Phase 1 and add CMMC Level 2 (C3PAO) certification as a condition of award for applicable contracts. The 2026-07-13 memo says: "The upcoming November 2026 transition to Phase 2 of CMMC implementation is suspended."

During the suspension, program managers and requiring activities "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments". The allowed designations are CMMC Level 1 (Self) and CMMC Level 2 (Self). Active solicitations that already carried a C3PAO or DIBCAC requirement are to be amended to remove it, and existing contracts modified before the next option period or at the next scheduled administrative modification. No waivers are granted during the review.

What Did Not Change

In the memo's words, the Department "will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments", and the requirements of DFARS 252.204-7012 "remain in effect".

So a contractor that handles Controlled Unclassified Information still implements the 110 requirements of NIST SP 800-171 Rev 2, still reports cyber incidents within 72 hours under DFARS 252.204-7012, and still posts a self-assessment in SPRS with a senior official's affirmation.

Why Waiting Is the Wrong Read

With no third-party assessor between a self-assessment and the government, the Affirming Official's signature carries the weight. Under 32 CFR 170.22 that senior official attests that the company has implemented, and will maintain, every applicable requirement. A pause in third-party certification does not lower the bar the signature attests to.

What Happens Next

The memo says "Further guidance will be promulgated at the conclusion of the CIO's 60-day review." As of 2026-10-08 we have not found a published outcome of that review. We re-check before relying on this status, and this article carries the date it was last reviewed.

Frequently Asked Questions

4 QUESTIONS
Is CMMC Phase 2 paused?

Yes. A Department of War implementing memo dated 2026-07-13 suspended the November 2026 transition to CMMC Phase 2, pending the DoW CIO's 60 day review. As of 2026-10-08 no outcome of that review has been found published.

Do I still need to comply with NIST SP 800-171?

Yes. The memo says the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and Level 2 self-assessments and select government-led assessments, and that DFARS 252.204-7012 remains in effect.

Can a contract still require a C3PAO assessment during the suspension?

Not a new designation. The memo says requiring activities may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during the suspension, and directs that existing requirements be removed by amendment or modification.

Do I still post a score in SPRS?

Yes. Level 1 and Level 2 self-assessments are entered in SPRS with an affirmation by a senior official (32 CFR 170.15, 170.16 and 170.22).

Talk it through in 30 minutes.

A call is a conversation, not a pitch. Tell us how your business runs and we will tell you what we would manage.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call