Who this is for: Defense Industrial Base (DIB) contractors, C3PAOs preparing for Level 2 assessments, ISSMs and ISSOs managing CUI environments, subcontractors in the supply chain, and compliance teams planning CMMC certification timelines.

SUSPENSION ACTIVE (July 13, 2026): The Department of Defense has suspended CMMC Phases 2, 3, and 4 pending a 60-day program review. During this period, Program Managers may only designate Level 1 (Self) or Level 2 (Self) in contract requirements. Third-party C3PAO assessments for Level 2 and all Level 3 requirements are on hold. The previously scheduled November 10, 2026 Phase 2 milestone is no longer an active deadline.

Contents

1. Quick Reference 2. What Happened 3. Impact Assessment 4. What Remains Active 5. What To Do Now 6. C3PAO Impact 7. Possible Outcomes 8. Related Guides and References

1. Quick Reference

FieldDetail
EventCMMC Phases 2-4 suspended pending 60-day program review
DateJuly 13, 2026
AuthorityDepartment of Defense (Department of War designation)
Phase 1 StatusACTIVE -- Level 1 Self and Level 2 Self assessments continue
Phase 2 StatusSUSPENDED -- C3PAO Level 2 certifications on hold
Phase 3-4 StatusSUSPENDED -- Level 3 government-led assessments on hold
Review Duration60 days from July 13, 2026 (expected completion ~September 11, 2026)
NIST 800-171 StatusUNCHANGED -- the underlying security requirements remain contractually binding via DFARS 252.204-7012

2. What Happened

On July 13, 2026, the Department of Defense announced a 60-day program review of the Cybersecurity Maturity Model Certification (CMMC) program. The review suspends the rollout of Phases 2 through 4 while the department evaluates the program's structure, costs, and implementation approach.

Key context:

3. Impact Assessment

StakeholderImpactSeverity
DIB Contractors (Level 2 Self)Self-assessment path remains open. No change to current obligations.Low
DIB Contractors (Level 2 C3PAO)Third-party assessment path on hold. Cannot achieve C3PAO certification until suspension lifts.Medium
DIB Contractors (Level 3)Government-led assessment path on hold. No path to Level 3 during suspension.High
C3PAOsAssessment pipeline paused. Revenue impact for organizations that built capacity for Phase 2.High
SubcontractorsFlow-down requirements may soften if prime contractors defer CMMC clauses.Medium
Program ManagersMay only designate Level 1 (Self) or Level 2 (Self) in new solicitations.Medium

4. What Remains Active

5. What To Do Now

1. Do NOT Stop Implementation

The suspension is a pause in the certification program, not a relaxation of security requirements. NIST 800-171 controls remain contractually binding. Organizations that halt implementation will face a larger gap when the program resumes -- and it will resume in some form.

2. Complete Your Self-Assessment

If you have not yet completed a Level 2 Self-Assessment and submitted your SPRS score, do so now. Phase 1 is active, and having a current self-assessment on record demonstrates due diligence regardless of Phase 2 timing.

3. Maintain Evidence Continuously

Continue collecting compliance evidence. When the program resumes -- whether as CMMC 2.0 in its current form or a revised structure -- organizations with continuous evidence trails will be positioned to certify faster than those who paused. SWT3 witness anchors create this evidence trail automatically.

4. Address POA&M Items

Use the suspension period to close open POA&M items. Every control gap remediated during the pause reduces your time-to-certification when assessments resume.

5. Monitor for Program Review Outcomes

The 60-day review is expected to conclude around September 11, 2026. Possible outcomes include resumption with modifications, further delay, or structural changes. Watch for DoD announcements and subscribe to CMMC-AB (now the Cyber AB) updates.

6. Document Your Readiness

If you were preparing for a C3PAO assessment, document your readiness state. This includes SSP completion percentage, control implementation status, and any pre-assessment activities. This documentation will be valuable when assessments resume.

6. C3PAO Impact

C3PAOs that invested in assessor training, tools, and capacity for the Phase 2 ramp face the most direct impact from the suspension:

7. Possible Outcomes

ScenarioLikelihoodImplication
Resume with minor modificationsMost likelyRevised Phase 2 timeline (Q1-Q2 2027), possibly adjusted cost structure or streamlined assessment scope
Significant restructuringPossibleSimplified level structure, greater reliance on self-assessment with verification, or alignment with FedRAMP 20x automation approach
Extended delayPossiblePhase 2 pushed to 2027-2028, similar to past CMMC delays. DFARS 252.204-7012 remains the primary enforcement mechanism.
Program cancellationUnlikelyCUI protection requirements would persist under DFARS. A new program or mechanism would likely replace CMMC rather than leaving a gap.

Regardless of outcome: The 110 controls in NIST SP 800-171 Rev 2 remain the security baseline for CUI protection. No program review changes that reality. Build evidence, close gaps, and be ready.

8. Related Guides and References