CMMC status — last updated October 2, 2026. This page is kept current as the Department of War's review of CMMC plays out. The short version: Phase II — third-party (C3PAO) certification as a condition of contract award — remains suspended, and since September 3 a DFARS class deviation directs contracting officers to remove the requirement from solicitations and contracts. The reform task force's report was due to the CIO by September 11; it has not been published. Your self-assessment, NIST SP 800-171, and CUI-protection obligations have not changed.

Timeline so far

  • July 13, 2026 — The Department of War suspended the transition to CMMC Phase II and opened a 60-day program review. Industry comments on a Request for Information were due August 14; the CIO later said more than 1,100 responses, over 10,000 pages, came in and were read by people, not AI.
  • September 3, 2026 — Revision 3 of DFARS Class Deviation 2026-O0025, signed by John Tenaglia, Principal Director for Defense Pricing, Contracting and Acquisition Policy. It directs contracting officers to remove third-party CMMC assessment requirements from solicitations and contracts. Self-attestation to NIST SP 800-171 is still required.
  • September 9, 2026 — At the Billington CyberSecurity Summit, DoW CIO Kirsten Davies said compliance "equals a point-in-time check of where are you right now" while "cybersecurity is a dynamic process. It needs to be contiguous and continuous." Read that as the direction of travel: ongoing evaluation rather than a one-time assessment.
  • September 11, 2026 — The 60-day review ended; the CMMC Reform Task Force report was due to the CIO by this date. As of late September it had not been published and no release date had been announced; that was still the case when this page was updated.

What to watch next

  • Publication of the task-force report, and any revised rule or timeline that follows it.
  • Whether continuous evaluation becomes a program requirement, and what evidence it expects. That is the model OCIC is built on: verify the real configuration continuously and keep the evidence current, so a change in the assessment model is not a change in your work.
  • Prime flow-downs. Primes that handle CUI can keep requiring 800-171 evidence from subcontractors regardless of the federal timeline, and many will.

Sources: DefenseScoop, Sept 9, 2026; Washington Technology, Sept 9, 2026; Inside Government Contracts, Sept 2026.


The July 13 announcement, explained

On July 13, 2026, the Department of War — the Pentagon — announced an immediate suspension of the transition to Phase II of the Cybersecurity Maturity Model Certification (CMMC), along with a 60-day, top-to-bottom review of the program.

If you sell to the defense market, you have probably already seen the headlines, and maybe a few confident predictions about what it means. Here is the calm version: less changed than the headlines suggest, and the parts that changed are the parts that were still in the future. The obligations you already carry are still on the books.

Here is what was actually suspended, what still applies, and what to do about it.

What was suspended

Phase II was the stage that would have made a third-party assessment your gate to the contract. Starting November 10, 2026, applicable contracts involving Controlled Unclassified Information (CUI) would have required certification at CMMC Level 2 by a C3PAO — a Certified Third-Party Assessment Organization — as a condition of award. No certificate, no contract.

That is the piece that is now paused. The Department of War is running a 60-day review of the whole program, with industry responses to a Request for Information due August 14, 2026. The stated reason is cost and capacity: the department and the Small Business Administration heard, repeatedly, that the framework as designed put a heavy, expensive burden on exactly the small businesses the defense industrial base depends on — more than 120,000 of them potentially in scope, served by roughly 100 approved assessors. The math did not work, so the mandatory-certification gate is on hold while they rethink it.

What did not change

This is the part that gets lost in the noise, and it is the part that matters most:

  • Phase I is still in effect. The self-assessment requirements that took effect in late 2025 — where you assess your own environment against the standard and report it — remain in force. They were not suspended.
  • NIST SP 800-171 still applies. If your contracts carry DFARS clause 252.204-7012, the requirement to implement the 800-171 security controls has been law for years. That did not move.
  • Your SPRS score is still a legal representation. The score you submit to the government about your own security posture is something you are attesting to. It was true before July 13, and it needs to be true now.
  • The duty to protect CUI never went anywhere. The government paused one mechanism for verifying that you protect controlled information. It did not pause the obligation to actually protect it — or the consequences (including False Claims Act exposure) if you say you do and you don't.

In plain terms: the government suspended the audit at the door. It did not suspend the requirements inside the building.

Should you stop your readiness work?

No — and if anything the suspension is a reason to get the quiet, unglamorous work done while the pressure is off.

A few reasons this is the wrong moment to coast:

  1. Certification is being reworked, not retired. [October 2 update: see the status block above — a class deviation has since directed contracting officers to remove the third-party requirement from contracts, and the task-force report that would say what comes next has not been published, so the argument below is our expectation, not an announced outcome.] A 60-day review is a redesign, not a repeal. The most likely outcome is a version of third-party assessment that is less costly and better staffed — which means the gate comes back, and the organizations that kept working are the ones that walk through it easily.
  2. The obligations that remain are the hard part anyway. Implementing 800-171, writing a defensible System Security Plan (SSP), building real evidence, and keeping your SPRS score honest is the bulk of the work. A certificate is just someone confirming you did it. Do the work now and the eventual assessment — self or third-party — is a formality instead of a fire drill.
  3. Primes are not waiting for the DoW. Flow-down happens by contract. A prime that handles CUI can — and many will — keep requiring their subcontractors to meet 800-171 and show evidence, mandate or no mandate, because the prime is still on the hook for the data.
  4. Security drift doesn't observe policy timelines. The gap between "assessed" and "actual" opens the day after any point-in-time review. Suspension or not, an environment that drifts out of compliance is an environment that is less secure — and, if you've attested otherwise, out over its skis legally.

What to do now, by situation

If you only handle Federal Contract Information (FCI) — roughly Level 1 territory. Keep your basic safeguarding practices in place and your self-assessment current. Nothing about the July 13 announcement lowers that bar. This is a good window to make sure your Level 1 hygiene is genuinely done, not just claimed.

If you handle CUI — Level 2 territory. This is where the suspension changes your timeline but not your destination. Keep implementing 800-171. Keep your SSP and Plan of Action & Milestones (POA&M) real and current. Keep your SPRS score honest. Treat the review period as breathing room to close gaps deliberately rather than a reprieve from having them.

If you're a prime. Decide — on purpose — what you will require of your subcontractors during the review period, and tell them clearly. The data-protection obligation still rolls downhill to you; ambiguity now becomes risk later.

If you were mid-assessment or about to book one. Don't throw away the progress. A readiness posture you can prove is an asset regardless of which verification mechanism the department lands on.

What's still uncertain

We won't pretend to know the outcome. The open questions are real: what the redesigned assessment model looks like, whether the Level 2 threshold or scoping changes, how quickly a revised rule appears after the 60-day review, and what happens to contracts that already contain CMMC language. We're watching the review and the task-force report, and this page is updated as the picture firms up — see the status block at the top.

What isn't uncertain is the through-line: protect the data, document it, and keep it true. That was the point before CMMC, it's the point during the pause, and it will be the point when the next version arrives.


If you want a straight answer about where you actually stand against these requirements — and what it would take to close the gap — that's exactly the conversation our CMMC & compliance readiness work is built for. We've sat on the assessor's side of the table, so we can tell you what holds up and what doesn't.

First published July 19, 2026 · Last updated October 2, 2026.

Sources: Department of War release, July 13, 2026; Federal News Network; U.S. Small Business Administration; Breaking Defense.