If you are a defense contractor trying to figure out where your compliance obligations stand right now, you are not alone. On July 13, 2026, the Department of Defense suspended CMMC Phase 2 requirements and opened a 60-day review through a newly formed Reform Task Force. That pause has left a lot of contractors unsure what still applies to them and what can wait. Here is a straight answer.

What was actually suspended

Phase 2 of the CMMC rollout, originally scheduled to take effect November 10, 2026, has been paused. Phase 2 would have made third-party assessments (C3PAO for Level 2, DIBCAC for Level 3) a mandatory requirement for contracts involving Controlled Unclassified Information. That mandate is now on hold while the Reform Task Force studies whether to restructure, scale back, or otherwise change the program. The task force's public comment period closed August 14, and recommendations are expected in mid-September.

In short: the requirement for independent third-party certification has been paused. The underlying framework has not been eliminated.

What CMMC requires right now

This is the part that gets lost in the headlines. Several requirements were never touched by the Phase 2 suspension and remain fully active today.

If your contract requires any of the above, that requirement did not go away on July 13. Primes are also continuing to flow these requirements down to subcontractors, regardless of what happens with Phase 2. Our CMMC compliance services page covers what meeting each of them involves in practice.

Good to know: a pause in one enforcement mechanism is not a pause in the underlying risk. DIBCAC audits are continuing, and self-reported SPRS scores remain subject to scrutiny.

What could change in mid-September

The Reform Task Force is expected to deliver recommendations to the DoD Chief Information Officer in mid-September 2026. Nobody can say with certainty what those recommendations will contain, but the range of realistic outcomes includes adjustments to the third-party assessment requirement, changes to the assessment cost burden on small and midsize contractors, or a revised timeline for when Phase 2, or some version of it, takes effect.

What almost certainly will not change: the government's underlying interest in protecting Controlled Unclassified Information, or the expectation that contractors handling CUI have real, documented security practices in place.

What this means for you right now

If you are a contractor currently handling or planning to handle CUI, this is a reasonable moment to do three things.

  1. Confirm your Phase 1 self-assessment and SPRS score are current. These obligations did not pause, and a stale score is now more visible than it might have been a year ago, given the scrutiny contractors are under to make sure their self-reported numbers are accurate.
  2. Do not stand down your compliance program. Gap assessments, control implementation, and documentation you have already built do not become less relevant because a future assessment requirement is paused. If Phase 2 comes back in some form, the contractors who kept moving will be ahead of the ones who stopped.
  3. Watch for the mid-September announcement, and plan to revisit your compliance posture once the Reform Task Force's recommendations are public. We will update this page when that happens.
Key takeaways
  • Only the Phase 2 third-party assessment mandate was suspended, on July 13, 2026.
  • DFARS 7012, FAR 52.204-21, NIST SP 800-171 Rev 2, Phase 1 self-assessments and SPRS reporting all remain in force.
  • Primes are continuing to flow these requirements down regardless of the pause.
  • Reform Task Force recommendations are expected in mid-September 2026.

The bottom line

CMMC is not gone. Phase 2's third-party assessment mandate is paused while the government figures out how to reduce the compliance burden without reducing the underlying protections. Everything that predates Phase 2, including the rules requiring you to protect sensitive information, follow baseline security practices, and meet the underlying security standards, plus your self-assessment and SPRS reporting, is still fully in effect today.

If you are unsure where your organization stands against any of these requirements, that is exactly the kind of gap worth closing while the industry waits for more clarity, not after.

Frequently asked questions

Do I still need a C3PAO assessment right now?

No. The third-party assessment requirement was part of Phase 2, which is currently paused. That said, if your contract already calls for one under Phase 1 rules or a prime's own flow-down requirements, check that specific contract language rather than assuming the pause applies to you.

Is my Phase 1 self-assessment still due?

Yes. Phase 1 self-assessments were not affected by the July 13 pause and remain on their existing schedule, along with your SPRS score submission and annual affirmation.

When will we know what happens next?

The Reform Task Force is expected to deliver its recommendations to the DoD Chief Information Officer in mid-September 2026. Until then, treat your current obligations as unchanged.

What CMMC requirements still apply after the Phase 2 pause?

DFARS 252.204-7012, FAR 52.204-21, NIST SP 800-171 Rev 2, Phase 1 self-assessments, SPRS scoring and annual affirmations all remain fully in force. Only the Phase 2 third-party assessment mandate was suspended.

Keep exploring

Ready for a clear path forward?

Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.

Start with a Clarity Conversation