Updated September 29, 2026. When we first published this article, the next big CMMC milestone was November 10, 2026: Phase 2, when third-party (C3PAO) certification at Level 2 was due to become a condition of award for most contracts involving Controlled Unclassified Information (CUI). On July 13, 2026, the Department of Defense (now also styled the Department of War) suspended that phase. Here is what stopped, what did not, and how we are advising contractors to use the time.
What was suspended
- Phase 2 and the other pending and future CMMC implementation milestones. The November 10, 2026 date is no longer operative, and as of this update no replacement date has been announced.
- New C3PAO requirements. While the program is under review, solicitations may require only Level 1 (Self) and Level 2 (Self) assessments, and contracting officers have been directed to amend solicitations and existing contracts to remove Level 2 (C3PAO) requirements.
- Program certainty. The Department created a CMMC Reform Task Force for a 60-day review and asked industry for input on cost drivers, self-assessments and which controls deliver the most value.
What did not change
- DFARS 252.204-7012 still requires you to safeguard covered defense information, implement NIST SP 800-171, and report cyber incidents within 72 hours.
- Phase 1 is live. Level 1 and Level 2 self-assessments, the score posted to the Supplier Performance Risk System (SPRS) and the annual executive affirmation are all still required.
- False Claims Act exposure. The Department of Justice's Civil Cyber-Fraud Initiative continues to pursue cases over misstated cybersecurity compliance. An inflated SPRS score is a legal risk whether or not an assessor ever visits.
- Your prime contractor's terms. Flow-down clauses in subcontracts are enforced by the prime, not by the calendar in Washington.
- A proposed FAR rule that would extend similar CUI safeguarding requirements across federal contracts remains pending.
What this means in practice
The pause moves a date; it does not move the work. The 110 NIST SP 800-171 requirements, the System Security Plan and the evidence behind your SPRS score are exactly what you would have needed for a third-party assessment, and they are what a self-assessment is supposed to reflect today. The mistake to avoid runs in two directions: stopping all compliance work because the deadline vanished, or treating a self-assessment as a formality because no assessor is coming.
Nobody outside the government knows how the review will end. The requirement could be relaxed, reshaped for smaller businesses, or restored on a new schedule. Plan around the requirement you can actually see: the clauses in your contracts and the terms your primes send you.
What we recommend now
- Read your actual clauses. List every contract with DFARS 252.204-7012, 7019, 7020 or 7021, note which involve CUI versus only Federal Contract Information (FCI), and check for any modification removing a C3PAO requirement. Do not assume; look.
- Make your SPRS score honest. Re-score against the DoD Assessment Methodology, correct anything overstated, and make sure the executive who signs the affirmation understands what they are attesting to.
- Keep closing gaps in priority order. Multi-factor authentication, FIPS-validated encryption, logging, incident response and the System Security Plan carry the most risk. Anything you cannot fix yet belongs in a documented POA&M.
- Revisit the enclave question. If only a few people touch CUI, a segregated environment is still usually the fastest and least expensive route to a defensible boundary, whatever the certification schedule turns out to be.
- Talk to your primes. Many will keep asking for evidence of NIST SP 800-171 compliance regardless of what the Department requires. Knowing their expectations early avoids surprises at award time.
- Stay assessment-ready. Keep evidence current and run a mock assessment, so that if third-party certification returns, or a customer asks for it, you can book an assessor instead of starting from zero.
What a Registered Provider Organization does now
An RPO like CorporateTech is not the assessor; C3PAOs are independent by design. The RPO's job is everything around the assessment: scoping and the enclave decision, the gap assessment, writing the SSP and POA&M, implementing the technical controls, collecting evidence and rehearsing. With the mandatory date paused, that work can be done at a measured pace instead of under deadline pressure, which is usually cheaper and produces a better result.
Requirements in this area are changing quickly. Confirm what applies to you with your contracting officer or counsel; this article is general information, not legal advice.
Talk to a compliance expert about your situation
A 30-minute call is usually enough to tell you where you stand and what to do first. No obligation.
Sales line: Monday to Friday, 8 AM to 6 PM Pacific. Existing clients: support is available 24x7.