CMMC Phase 2 timeline: suspended July 13, 2026, and what still applies
On July 13, 2026 the Department of War suspended CMMC Phase 2 outright, for every contractor and not only small ones, held all pending and future CMMC implementation milestones in abeyance until further notice, and directed a 60-day review of the program by the DoW Chief Information Officer. The Department cited prohibitive compliance costs, severe shortages in third-party assessment capacity and complex regulatory timelines, and set out to remove bureaucratic burdens on the Defense Industrial Base (DoW CIO memorandum 26-P-1023, July 13, 2026; summarized in the Crowell & Moring client alert on the July 13, 2026 memorandum). That changes the schedule, and it does not change what your existing contracts already require. Here is the rollout as it was written, what the suspension means for you, and the obligations that apply today either way.
Status as of September 9, 2026. DefenseScoop reported that day that the department was reviewing industry feedback on CMMC reform: its request for information drew more than 1,100 responses, and more than half of respondents favored the pause. The report did not announce a decision or a date for what follows Phase 2. Source: DefenseScoop, “Pentagon pores over heaps of industry feedback on CMMC reform,” September 9, 2026.
What still applies right now. DFARS 252.204-7012 requires you to implement NIST SP 800-171 and report incidents within 72 hours. DFARS 252.204-7019 and 7020 require a current self-assessment score in SPRS, refreshed at least every three years. DFARS 252.204-7021 still carries the Phase 1 self-assessment and annual affirmation of continuing compliance. Contracting officers check that score in SPRS before award. None of that waits for a phase date. The assessment mechanism can change. The need to know whether the controls are actually operating does not. Enclave AI™ re-measures on a stated schedule: connected sources about every seven days, a full Level 1 cycle every 30 days, and Level 2 on your tier’s cycle.
The phased rollout
Self-assessment enters solicitations
DoD began including CMMC Level 1 and Level 2 self-assessment requirements in solicitations. Contractors attest to their own posture and post a score.
Level 2 C3PAO certification was to enter solicitations
As written, DoD was to begin requiring a Level 2 certification from an authorized C3PAO as a condition in solicitations, with self-attestation alone no longer sufficient for the contracts that carry the requirement. On July 13, 2026 the Department of War suspended Phase 2 outright pending the DoW CIO’s 60-day review. The November 10, 2026 date is on hold, not fixed, and no replacement date has been set.
Certification for all applicable contracts, and Level 3
As written, DoD intended to require Level 2 (C3PAO) in all applicable solicitations, and as a condition to exercise option periods, and to require Level 3 (DIBCAC) in all applicable solicitations (32 CFR 170.3(e)(3)). The July 13, 2026 memorandum holds this milestone in abeyance until further notice.
CMMC applies across applicable contracts
As written, DoD would include CMMC requirements in all applicable solicitations and contracts, including option periods, where a contractor processes, stores or transmits FCI or CUI (32 CFR 170.3(c) and (e)(4)). The July 13, 2026 memorandum holds this milestone in abeyance until further notice.
These dates follow from the CMMC rule (32 CFR 170.3(e)): Phase 1 starts on the effective date of the 48 CFR CMMC acquisition rule, and each later phase one calendar year after the one before. Phase 1 is in force. Phase 2 is suspended and the later milestones are held in abeyance; what follows depends on the outcome of that review. Exact appearance in any given solicitation is at DoD and program discretion; treat the later dates as the schedule that was written, not a guarantee of when it will apply.
What to do during the suspension
A suspension is a good time to do this work, because no deadline is forcing a rush. In order:
- Measure your gap against all 110 controls. You cannot plan remediation you have not scoped.
- Remediate by impact. Close the highest-weight controls first so your score moves fastest.
- Assemble your evidence and documentation (System Security Plan and POA&M) as you go, not at the end.
- Keep your SPRS score current and accurate so what the government sees matches what you actually run.
Each of those steps starts from knowing where you actually stand.
Get your baseline while there is no rush
The free gap check gives you a directional read from 10 questions. The CMMC Level 2 Readiness Snapshot checks your intake, and the read-only configuration of any cloud you connect, against the 110-control baseline; it measures only the controls a connected source can show, and returns a PDF of your top control gaps within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2.
Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. The free gap check is a directional self-assessment and is not an official SPRS score. Phase dates reflect the DoD phased implementation schedule and are subject to DoD discretion. Patent Pending. ElasticD3M, LLC, Texas.