Skip to content
WITTCO
All news posts

CMMC Phase 2 Is on Hold: What Defense Contractors Still Have to Do

· WITTCO

The Pentagon suspended Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program on July 13, 2026. Phase 2 was scheduled to start November 10, 2026. It would have made a third-party CMMC Level 2 certification a condition of award for many defense contracts involving Controlled Unclassified Information (CUI), according to an analysis by the law firm WilmerHale.

The pause does not mean CMMC is gone. Contractors still have to meet the cybersecurity requirements already in their contracts, and the self-assessment phase that began in November 2025 remains in effect.

What changed

Federal News Network reported that the Pentagon cited "severe shortages in third-party assessment capacity" compared with the roughly 80,000 companies that would eventually need an assessment, along with "prohibitive compliance costs" that were pushing small businesses away from defense work. All pending and future CMMC milestones were suspended along with Phase 2.

A new CMMC Reform Task Force was given 60 days for a top-to-bottom review, and the department asked industry for input through a public request for information.

What did not change

WilmerHale notes that "All Phase I self-assessment requirements remain firmly in place." Phase 1 began on November 10, 2025, when the Defense Department's rule adding CMMC to contract clauses took effect. That rule was published in the Federal Register on September 10, 2025.

According to Covington & Burling, contractors must still:

  • Self-assess against the requirements for their CMMC level, including the NIST SP 800-171 Rev. 2 controls for Level 2.
  • Keep a current assessment status and affirmation in the Supplier Performance Risk System (SPRS) to be eligible for award.
  • Comply with DFARS clause 252.204-7012, which covers safeguarding defense information and reporting cyber incidents.

During the pause, the department says it will enforce the standard through self-assessments and selected government-led assessments.

Where the review stands

The task force report was due to the department's chief information officer on September 11, 2026, and had not been made public as of September 21, according to Covington. The request for information drew more than 1,100 responses.

Speaking on September 9, CIO Kirsten Davies said more than half of the respondents favored the pause, DefenseScoop reported. She also said "CMMC was hitting small to medium-sized businesses really, really hard and inappropriately hard," and that the department wants to move away from point-in-time assessments toward ongoing compliance.

A quick refresher on the levels

The CMMC program rule, published October 15, 2024 and effective December 16, 2024, sets three levels:

  • Level 1: the 15 basic security requirements in FAR clause 52.204-21, for companies handling Federal Contract Information. Self-assessment.
  • Level 2: the 110 security requirements of NIST SP 800-171 Rev. 2, for companies handling CUI. Self-assessment or a third-party assessment, depending on the contract.
  • Level 3: 24 additional requirements drawn from NIST SP 800-172, assessed by the government.

What to do now

  1. Keep your SPRS assessment status and affirmation current. It is still a condition of award.
  2. Close any remaining NIST SP 800-171 gaps and keep records that back up your self-assessment.
  3. Make sure you can meet the DFARS 252.204-7012 incident reporting duty, including who reports and how.
  4. Decide whether to keep a third-party assessment on your calendar. Covington notes that some contractors may benefit from pursuing one even while it is not required.
  5. Watch for the task force report, which could change both the timeline and the assessment model.

If you need help closing NIST SP 800-171 gaps, WITTCO can handle the technical side, from endpoint protection and patching to backups and Microsoft 365 security settings.

Sources

More from the newsroom

Let’s take a look at your setup.

Book a free assessment. We’ll tell you what’s working, what’s risky and what we’d fix first, even if you never hire us.

Prefer email? info@getwittco.com