The short version. On 13 July 2026 the Department suspended Phase 2 of the CMMC rollout, along with all pending and future CMMC milestones. Phase 2 would have required third-party C3PAO assessments on contracts involving controlled unclassified information starting 10 November 2026. That requirement is paused. Almost nothing else is.

110
NIST SP 800-171 Rev. 2 controls still required for CUI. Unchanged by the suspension.
17
CMMC Level 1 practices, aligned to FAR 52.204-21 basic safeguarding.
60
Days the CMMC Reform Task Force has to report, from 13 July 2026.

What was suspended, and what was not

The distinction matters more than the headline. The assessment mechanism paused. The security obligation did not.

ObligationStatus after 13 July 2026
Phase 2 third-party (C3PAO) assessmentSuspended until further notice
DFARS 252.204-7012 (safeguarding CUI)Fully in force
FAR 52.204-21 (basic safeguarding)Fully in force
NIST SP 800-171 Rev. 2, all 110 controlsFully in force
SPRS score submissionContinues
Annual affirmation where 252.204-7021 appliesContinues
Phase 1 self-assessment (since Nov 2025)In effect
DIBCAC auditsContinuing as scheduled
Good to know: a contractor who treats the suspension as a reprieve and lets their SPRS score go stale carries the same exposure as before, including False Claims Act risk on an inaccurate certification. The government did not stop auditing. It stopped requiring a third party to do it.

Which CMMC level applies to you

Three questions decide it, and the first one is the one most contractors get wrong.

Level 1: Federal Contract Information only

Seventeen practices, aligned to the basic safeguarding requirements in FAR 52.204-21. Annual self-assessment. If nothing you touch is marked or meets the definition of CUI, this is your tier.

Level 2: Controlled Unclassified Information

All 110 controls of NIST SP 800-171 Rev. 2. This is where most Northern Virginia and Richmond subcontractors land. Under the suspended Phase 2, many of these contracts would have required third-party assessment; self-assessment and affirmation obligations continue in the meantime.

Level 3: the most sensitive programs

Adds selected NIST SP 800-172 requirements on top of Level 2, with government-led assessment. A small minority of contractors.

The CMMC compliance framework, in plain language

CMMC did not invent new security requirements. It is a verification layer on top of NIST 800-171, which has been a contractual obligation since DFARS 252.204-7012. If you have been complying with 7012 all along, CMMC is largely a documentation and evidence exercise. If you have not, CMMC is the point at which that becomes visible to a prime or an auditor.

That framing explains why the suspension changes less than it appears to. Pausing the verification step does not pause the thing being verified. For the mechanics of each control family, see our NIST 800-171 compliance services.

Certification versus self-assessment

These get used interchangeably and they are not the same thing. Certification means an accredited third party (a C3PAO) assesses you and certifies the result. Self-assessment means you assess yourself and affirm the score in SPRS.

With Phase 2 suspended, third-party certification requirements are on hold. Self-assessment and affirmation continue unchanged. Contractors partway through a certification engagement are in the most awkward position, and the honest answer is that nobody knows yet whether that work carries forward. The task force report will decide it.

A CMMC compliance checklist you can actually use

Ten items. If you can tick all ten today, the suspension costs you nothing. If you cannot, the suspension bought you time you should spend.

  1. Classify your data. Confirm in writing, per contract, whether you handle FCI, CUI, or both.
  2. Map the boundary. Identify every system, cloud service and person that touches CUI.
  3. Score yourself honestly. All 110 controls, with evidence, not optimism.
  4. Refresh SPRS. An outdated or inflated score is the most common unforced error we see.
  5. Produce a current System Security Plan. Not a template with your name on it.
  6. Maintain a POA&M. Real dates, real owners, real closure.
  7. Check cloud equivalency. Where CUI lives, confirm FedRAMP Moderate equivalency.
  8. Complete your annual affirmation where DFARS 252.204-7021 applies.
  9. Keep contemporaneous evidence. Logs and artifacts, not just policy documents.
  10. Diarise September. Re-check everything when the task force reports.
Key takeaways
  • Phase 2 third-party assessment is suspended; DFARS 7012, FAR 52.204-21, NIST 800-171 and SPRS are not.
  • Most Virginia subcontractors handling CUI sit at Level 2 and owe all 110 controls today.
  • The reform task force reports around mid-September 2026, and that is when this picture changes.
  • Use the pause to close gaps, not to stop. DIBCAC audits are continuing.

What we are telling Virginia contractors

The organisations that will come out of this well are the ones that treated CMMC as a security programme rather than a certificate. If the controls are real, the verification method is somebody else's problem.

Our Virginia team works out of Woodbridge and supports contractors across Northern Virginia, Richmond and the DC metro. If you want a read on where you actually stand, that is what a Navigate Clarity Conversation is for.

Frequently asked questions

Is CMMC still required in 2026?

Phase 2, the third-party assessment requirement, was suspended on 13 July 2026. The underlying obligations were not. DFARS 252.204-7012, FAR 52.204-21, NIST SP 800-171 Rev. 2, SPRS score submission, annual affirmation and Phase 1 self-assessment all remain in force. You are not off the hook; the verification step is paused.

Which CMMC level does a Virginia defense contractor need?

Level 1 if you handle only Federal Contract Information. Level 2 if you handle Controlled Unclassified Information, which covers most DoD subcontractors in the Commonwealth. Level 3 applies to the most sensitive programs and adds NIST SP 800-172 requirements.

Do I still need a C3PAO assessment?

Not while Phase 2 is suspended. Whether assessments already underway carry forward depends on the CMMC Reform Task Force recommendations, expected around mid-September 2026.

Is CMMC just NIST 800-171?

At Level 2, largely yes. CMMC verifies the same 110 controls NIST SP 800-171 Rev. 2 already required under DFARS 252.204-7012. The difference is evidence and accountability, not new controls.

Keep exploring

Ready for a clear path forward?

Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.

Start with a Clarity Conversation