The Department of Defense suspended CMMC Phases 2 through 4 on July 13, 2026 for a 60-day program review. Phase 1 self-assessments remain active. This advisory covers the impact, timeline, and recommended actions.
Who this is for: Defense Industrial Base (DIB) contractors, C3PAOs preparing for Level 2 assessments, ISSMs and ISSOs managing CUI environments, subcontractors in the supply chain, and compliance teams planning CMMC certification timelines.
SUSPENSION ACTIVE (July 13, 2026): The Department of Defense has suspended CMMC Phases 2, 3, and 4 pending a 60-day program review. During this period, Program Managers may only designate Level 1 (Self) or Level 2 (Self) in contract requirements. Third-party C3PAO assessments for Level 2 and all Level 3 requirements are on hold. The previously scheduled November 10, 2026 Phase 2 milestone is no longer an active deadline.
| Field | Detail |
|---|---|
| Event | CMMC Phases 2-4 suspended pending 60-day program review |
| Date | July 13, 2026 |
| Authority | Department of Defense (Department of War designation) |
| Phase 1 Status | ACTIVE -- Level 1 Self and Level 2 Self assessments continue |
| Phase 2 Status | SUSPENDED -- C3PAO Level 2 certifications on hold |
| Phase 3-4 Status | SUSPENDED -- Level 3 government-led assessments on hold |
| Review Duration | 60 days from July 13, 2026 (expected completion ~September 11, 2026) |
| NIST 800-171 Status | UNCHANGED -- the underlying security requirements remain contractually binding via DFARS 252.204-7012 |
On July 13, 2026, the Department of Defense announced a 60-day program review of the Cybersecurity Maturity Model Certification (CMMC) program. The review suspends the rollout of Phases 2 through 4 while the department evaluates the program's structure, costs, and implementation approach.
Key context:
| Stakeholder | Impact | Severity |
|---|---|---|
| DIB Contractors (Level 2 Self) | Self-assessment path remains open. No change to current obligations. | Low |
| DIB Contractors (Level 2 C3PAO) | Third-party assessment path on hold. Cannot achieve C3PAO certification until suspension lifts. | Medium |
| DIB Contractors (Level 3) | Government-led assessment path on hold. No path to Level 3 during suspension. | High |
| C3PAOs | Assessment pipeline paused. Revenue impact for organizations that built capacity for Phase 2. | High |
| Subcontractors | Flow-down requirements may soften if prime contractors defer CMMC clauses. | Medium |
| Program Managers | May only designate Level 1 (Self) or Level 2 (Self) in new solicitations. | Medium |
The suspension is a pause in the certification program, not a relaxation of security requirements. NIST 800-171 controls remain contractually binding. Organizations that halt implementation will face a larger gap when the program resumes -- and it will resume in some form.
If you have not yet completed a Level 2 Self-Assessment and submitted your SPRS score, do so now. Phase 1 is active, and having a current self-assessment on record demonstrates due diligence regardless of Phase 2 timing.
Continue collecting compliance evidence. When the program resumes -- whether as CMMC 2.0 in its current form or a revised structure -- organizations with continuous evidence trails will be positioned to certify faster than those who paused. SWT3 witness anchors create this evidence trail automatically.
Use the suspension period to close open POA&M items. Every control gap remediated during the pause reduces your time-to-certification when assessments resume.
The 60-day review is expected to conclude around September 11, 2026. Possible outcomes include resumption with modifications, further delay, or structural changes. Watch for DoD announcements and subscribe to CMMC-AB (now the Cyber AB) updates.
If you were preparing for a C3PAO assessment, document your readiness state. This includes SSP completion percentage, control implementation status, and any pre-assessment activities. This documentation will be valuable when assessments resume.
C3PAOs that invested in assessor training, tools, and capacity for the Phase 2 ramp face the most direct impact from the suspension:
| Scenario | Likelihood | Implication |
|---|---|---|
| Resume with minor modifications | Most likely | Revised Phase 2 timeline (Q1-Q2 2027), possibly adjusted cost structure or streamlined assessment scope |
| Significant restructuring | Possible | Simplified level structure, greater reliance on self-assessment with verification, or alignment with FedRAMP 20x automation approach |
| Extended delay | Possible | Phase 2 pushed to 2027-2028, similar to past CMMC delays. DFARS 252.204-7012 remains the primary enforcement mechanism. |
| Program cancellation | Unlikely | CUI protection requirements would persist under DFARS. A new program or mechanism would likely replace CMMC rather than leaving a gap. |
Regardless of outcome: The 110 controls in NIST SP 800-171 Rev 2 remain the security baseline for CUI protection. No program review changes that reality. Build evidence, close gaps, and be ready.