CMMC Phase 2 Pause: What Defense Contractors Need to Know

CMMC Phase 2 Pause: What Defense Contractors Need to Know

Quick Answer: On July 13, 2026, the DoW paused CMMC Phase 2—the requirement for third-party C3PAO certification as a condition of contract award, originally set for November 10, 2026. Phase 1 self-assessments remain mandatory, existing certifications retain full value, and DFARS cybersecurity obligations are unchanged. Smithers will continue conducting assessments and is allowing rescheduling without penalty or fee.

The announcement came without warning—and for many defense contractors preparing for the November 10, 2026 deadline, it raised more questions than it answered. On July 13, 2026, DoW Chief Information Officer Kirsten Davies signed a policy memorandum (publication case 26-P-1023) pausing Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program and launching a 60-day, top-to-bottom review.

This is not a rollback of CMMC. It is not a reprieve from cybersecurity obligations. Understanding exactly what changed—and what did not—is essential for every contractor in the Defense Industrial Base.

What Is the CMMC Phase 2 Pause, and Why Did It Happen?

The CMMC Phase 2 Pause specifically pauses the requirement for Organizational Seeking Certification (OSCs) to obtain a Level 2 certification from an accredited C3PAO as a condition of contract award. This requirement had been scheduled to take effect on November 10, 2026. Along with Phase 2, all pending and future CMMC implementation milestones—including Phases 3 and 4—are frozen until further notice.

The driving forces behind the pause were cost and capacity, from small businesses' perspective.

The CMMC Reform Task Force, reporting to the DoW CIO, has been charged with recommending a revised framework within 60 days. Industry stakeholders can submit responses to a public Request for Information (RFI) through August 14, 2026.

What Does the CMMC Phase 2 Pause Not Change?

The pause is a policy memo—not a regulatory amendment. Several critical requirements remain fully in effect:

  • Phase 1 self-assessment and self-attestation went into effect in November 2025 and remain unchanged. DFARS 204.7503(b) still requires contracting officers to verify CMMC status in SPRS prior to contract award.
  • DFARS 252.204-7012 remains fully operative, including the 72-hour incident reporting requirement to DIBNet and mandatory flow down to subcontractors.
  • NIST SP 800-171 compliance continues to be required for all contractors handling Controlled Unclassified Information (CUI).
  • Annual SPRS affirmations must still be submitted by a named senior Affirming Official and are subject to enforcement under the Department of Justice's Civil Cyber-Fraud Initiative.
  • Voluntary C3PAO assessments remain available and valid. The Cyber AB confirmed on July 13, 2026, C3PAOs remain authorized to conduct Level 2 assessments and issue CMMC certificates in eMASS for publication to SPRS.

One critical nuance: the CMMC Phase 2 Pause binds DoW personnel, not your prime contractor's subcontract terms. DFARS 252.204-7021(f) requires primes to flow down the substance of the clause. Several primes have already indicated they will continue requiring C3PAO certifications for their supply chains, regardless of the DoW-level suspension. Confirm any changes to your flow downs in writing before altering your assessment plans.

What Happens to Existing CMMC Certifications During the Pause?

If your organization has already obtained a Level 2 CMMC certificate, that certification loses none of its value—in fact, it gains value. As of the Cyber AB's May 2026 town hall, 1,391 Final Level 2 certificates had been issued. Nothing in the suspension invalidates them.

Under DFARS 252.204-7021(d)(1)(i), a Level 2 (C3PAO) status satisfies any lesser designation during the suspension. This means a completed certification still qualifies your organization for contract award at any applicable level. Certification also remains a differentiator with prime contractors and in merger and acquisition due diligence.

Smithers Response to the CMMC Phase 2 Pause

Smithers will continue to conduct CMMC assessments and issue certificates during this pause for clients who want to be CMMC certified. We recognize the disruption this announcement created, and we are responding accordingly.

All currently scheduled assessments may be rescheduled or delayed without penalty or fee. We remain available to answer any CMMC status or compliance questions during this period.

It is worth noting that your CMMC preparation costs have already been incurred. Your assessment costs remain future expenses—and proceeding with certification now carries real strategic advantage when your competitors pause or disengage from the process.

What Should You Do If You Choose to Delay Your CMMC Level 2 Inspection?

If your organization decides to defer its Level 2 C3PAO certification, do not treat the suspension as permission to stand down from cybersecurity work. Take the following steps:

  1. Confirm customer requirements in writing. Ask your customers whether a CMMC self-assessment meets their subcontract terms. Do not assume relief flows automatically.
  2. Continue maintaining and improving your CUI environment. DFARS 252.204-7012 remains fully in effect. Remediate identified gaps on a defensible timeline rather than shelving the findings. Any vulnerabilities in your CUI enclave remain your liability.
  3. Keep your System Security Plan (SSP) current. Continue documenting your system's CUI compliance. An outdated SSP creates evidentiary gaps that a DIBCAC confirmation assessment or a DOJ investigation will exploit.
  4. Review supporting documentation at least annually. Plans of Action and Milestones (POA&Ms), network diagrams, and policy documents should reflect your current environment.
  5. Conduct your annual self-assessment and submit your SPRS affirmation. This is a legal certification. Ensure every score you submit is defensible with documentation and evidence. False certifications are the explicit target of the Civil Cyber-Fraud Initiative, which carries civil and criminal damages.

If your organization has already initiated a C3PAO assessment, those records document your compliance posture and survive the suspension.

What Is Happening With DIBCAC and CMMC Level 3?

The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) has suspended Level 3 inspections per the CIO's memorandum. Smithers expects DIBCAC to redirect those resources toward conducting SPRS Level 2 confirmation assessments of OSCs—a development that raises, rather than lowers, the stakes of maintaining an accurate and well-documented SPRS score.

What Comes Next for CMMC?

Three developments warrant close attention:

  • August 14, 2026: The RFI comment period closes. If CMMC compliance costs affect your organization, submitting a response is one of the few direct channels available to influence the Task Force's recommendations. Small and midsize contractor voices are currently underrepresented.
  • Mid-September 2026: The CMMC Reform Task Force is expected to deliver its recommendations. Watch for any class deviation, DFARS rule change, or amendment to 32 C.F.R. Part 170—these are the mechanisms that would constitute a genuine regulatory change. The current suspension is a memo, and a memo can be reversed as quickly as it was issued.
  • Ongoing: The government wide CUI rule, folded into the June 23, 2026, FAR Overhaul rule making, is unaffected by the CMMC Phase 2 Pause. Contractors operating across both defense and civilian contracts receive no reprieve from that parallel regulatory track.

The Bottom Line: A Pause, not a Repeal

The CMMC Phase 2 Pause is a speed bump, not a stop sign. The underlying legal framework—32 C.F.R. Part 170, DFARS cybersecurity clauses, and SPRS obligations—remains in force. Organizations that maintain compliance momentum, accurate documentation, and a defensible SPRS score will be better positioned regardless of how the CMMC program is ultimately reformed.

Smithers remains committed to supporting your CMMC readiness throughout this period. Contact our team with any questions about your current compliance status, assessment options, or what this pause means for your specific contracts.

If you have any questions or concerns, please reach out to us anytime, to learn more.


Frequently Asked Questions About the CMMC Phase 2 Pause

Does the CMMC Phase 2 Pause eliminate the need to comply with NIST SP 800-171?

No. NIST SP 800-171 compliance remains required under DFARS 252.204-7012 for all contractors handling CUI. The pause suspends Phase 2 third-party certification requirements only—it does not change underlying cybersecurity obligations.

Can a C3PAO still assess and certify my organization during the pause?

Yes. The Cyber AB confirmed on July 13, 2026: C3PAOs remain authorized to conduct Level 2 assessments and issue CMMC certificates in eMASS for publication to SPRS. Voluntary certification is fully available and retains significant contractual value.

Is my existing CMMC Level 2 certificate still valid?

Yes. As of May 2026, 1,391 Final Level 2 certificates had been issued, and none are invalidated by the suspension. A Level 2 (C3PAO) status satisfies any lesser designation under DFARS 252.204-7021(d)(1)(i).

Do I still need to submit annual SPRS affirmations during the pause?

Yes. Annual SPRS affirmations are still required under Phase 1, which went into effect in November 2025 and is unaffected by the Phase 2 suspension. Submitting a false or unsupported affirmation carries civil and criminal damages under the DOJ's Civil Cyber-Fraud Initiative.

Will my prime contractor still require CMMC Level 2 certification even though DoD paused Phase 2?

Potentionally. Several prime contractors have indicated they will continue requiring C3PAO certifications for their supply chains. The DoW suspension binds DoW personnel, not prime contractor subcontract terms. Confirm requirements in writing with each customer before changing your assessment plans.

How long will the CMMC Phase 2 Pause last?

The DoW has not stated a fixed end date. The CMMC Reform Task Force is expected to deliver its recommendations to the DoW CIO in mid-September 2026.

What is the deadline to submit comments to the CMMC Reform Task Force RFI?

The RFI comment period closes on August 14, 2026. Contractors who wish to provide cost data or compliance burden feedback should submit responses through the official SAM.gov posting before that date.

How can we help?

Cancel
Show Policy

Download Checklist

Related Information: CMMC

Latest Resources

See all resources