Compyl

The CMMC Compliance Guide: What’s Required After the Phase 2 Suspension

July 08, 2026
Framework · CMMC

The CMMC Compliance Guide: What’s Required After the Phase 2 Suspension

By Compyl ResearchUpdated September 2, 20266 min read

CMMC is the Department of War’s program for verifying that contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). On July 13, 2026 the Department suspended Phase 2, removing the November 10, 2026 requirement for third-party C3PAO Level 2 certification. NIST SP 800-171, SPRS scoring, annual affirmations and DFARS 252.204-7012 all remain in force — the certification gate is paused, the security obligation is not.

Key takeaways
  • Phase 2 was suspended on July 13, 2026 by Department of War CIO policy memorandum 26-P-1023. The November 10, 2026 C3PAO certification requirement is paused, not replaced.
  • NIST SP 800-171 Rev 2 (all 110 controls), SPRS scoring, annual senior-official affirmations and DFARS 252.204-7012 still apply. Nothing about your security obligation changed.
  • Contracting officers were directed to amend open solicitations to remove Level 2 and Level 3 requirements, and to modify awarded contracts at the next option period.
  • A CMMC Reform Task Force ran a 60-day review; the industry RFI closed August 14, 2026 and recommendations were expected mid-September 2026. No replacement rule has been published as of September 2, 2026.
  • Inflated SPRS scores remain False Claims Act exposure. The suspension changed who checks — not whether you have to be compliant.

What did the Department of War suspend on July 13, 2026?

On July 13, 2026 the Department of War issued two memoranda, including CIO policy memorandum 26-P-1023, “Removing Barriers to Defense Industrial Base Expansion.” Together they suspended Phase 2 of the CMMC rollout and stood up a CMMC Reform Task Force to conduct a 60-day, top-to-bottom review of the program.

The memoranda directed contracting officers to:

  • Amend active solicitations to remove CMMC Level 2 and Level 3 requirements as soon as possible.
  • For awarded contracts, issue modifications removing the suspended requirements prior to the next option period or scheduled administrative modification.
  • Continue to require Level 1 or Level 2 self-assessments where appropriate, at Department discretion.

The Task Force’s industry Request for Information closed at noon ET on August 14, 2026, covering seven compliance and cost areas. Recommendations were expected in mid-September 2026, with determinations to follow. Treat the suspension as a pause of uncertain length, not a cancellation.

What is still required today?

Most of the program survived the suspension. Only the third-party assessment gate was paused.

Requirement Status What it means now
C3PAO third-party Level 2 certification Suspended Not a condition of award while the pause holds
Government-led Level 3 (DIBCAC) assessment Suspended Removed from solicitations
Phase 1 self-assessment (Level 1 / Level 2) In force Still required at Department discretion
NIST SP 800-171 Rev 2 — 110 controls In force Unchanged; this is the actual security requirement
SPRS score submission and maintenance In force Still a legal representation to the government
Annual senior official affirmation In force Unchanged
DFARS 252.204-7012 In force Safeguarding plus 72-hour cyber incident reporting
FAR 52.204-21 In force 15 basic safeguards for Federal Contract Information

DIBCAC audits of NIST SP 800-171 compliance also continue. A contractor that quietly stood down after July 13 is still exposed to a government assessment — with a lower standard of readiness than before.

Which level do you need?

Level Who Requirements Assessment (post-suspension)
Level 1 FCI only 15 basic safeguards (FAR 52.204-21) Annual self-assessment + SPRS affirmation
Level 2 Handles CUI All 110 controls of NIST SP 800-171 Rev 2 Self-assessment + SPRS affirmation; triennial C3PAO certification suspended
Level 3 Highest-priority programs Level 2 + 24 controls from NIST SP 800-172 Government-led (DIBCAC) — suspended

Note the flow-down: primes must still ensure subcontractors meet the required safeguarding level before award. Many primes wrote CMMC-readiness language into their own supplier terms and have not removed it, so subcontractors may face contractual expectations that outlast the federal pause.

What should contractors do during the suspension?

  1. Do not stand down. The pause removed the assessment gate, not the 110 controls. Every requirement you were remediating for is still a term of your contract.
  2. Score honestly in SPRS. The Department of Justice has pursued False Claims Act cases over inflated scores. A suspended certification requirement does not make a false representation safe.
  3. Keep the enclave. Scope discipline — isolating CUI in a defined enclave — routinely halves assessment cost and timeline. It is also the cheapest thing to preserve while the rules settle.
  4. Keep collecting evidence continuously. Whatever the Task Force recommends, it will be evidenced against NIST SP 800-171. Continuous collection beats reconstructing a binder under a reinstated deadline.
  5. Keep your C3PAO relationship warm. If certification returns, assessor capacity will tighten faster than it did before. Cancelling outright is the expensive choice.
  6. Read your contracts, not the headlines. Requirements already flowed down from a prime remain contractual obligations between you and that prime regardless of the federal suspension.

Common failure points

  • FIPS-validated cryptography — “we encrypt” is not enough; modules must be FIPS 140-validated for CUI.
  • Undocumented inheritance — cloud or MSP coverage claimed without a shared responsibility matrix; external service providers handling CUI need FedRAMP-equivalent standing.
  • Scope creep — CUI landing on unmanaged endpoints because nobody built an enclave.
  • SSP drift — a system security plan describing an environment that no longer exists is a fast fail in any assessment, government-led or otherwise.

Compyl maps all 110 NIST SP 800-171 controls into one control library shared with your other frameworks, automates evidence collection, tracks POA&M items to closure, and keeps your SSP live. See the NIST CSF 2.0 Implementation Guide and Continuous Controls Monitoring Guide.

Frequently asked questions

Is CMMC still required in 2026?

Partly. The requirement to obtain third-party CMMC Level 2 certification from a C3PAO was suspended on July 13, 2026. Phase 1 self-assessments, NIST SP 800-171 Rev 2 compliance, SPRS scoring, annual affirmations and DFARS 252.204-7012 all remain in force.

What happened to the November 10, 2026 CMMC deadline?

It was suspended. Department of War CIO policy memorandum 26-P-1023, issued July 13, 2026, paused Phase 2 and directed contracting officers to strip Level 2 and Level 3 requirements from solicitations and, at the next option period, from awarded contracts.

Do I still need a C3PAO assessment?

Not as a condition of award while the suspension holds. Program offices may require Level 1 or Level 2 self-assessments instead. Contractors already mid-assessment should confirm the position with their contracting officer rather than assume either outcome.

Does NIST SP 800-171 still apply?

Yes. All 110 controls of NIST SP 800-171 Rev 2 remain mandatory under DFARS 252.204-7012, and DIBCAC continues to audit against them. The suspension changed the verification mechanism, not the security requirement.

What happens to a contract that already carries the CMMC clause?

Contracting officers were directed to issue modifications removing the suspended requirements before the next option period or scheduled administrative modification. Until that modification is issued, talk to your contracting officer rather than acting unilaterally.

Does the suspension apply to subcontractors?

The federal suspension applies across the supply chain, but flow-down terms already written into a prime’s subcontract are a contractual matter between the prime and the subcontractor. Many primes have not removed CMMC-readiness language from their supplier agreements.

Will CMMC come back?

The CMMC Reform Task Force conducted a 60-day review; the industry RFI closed August 14, 2026 and recommendations were expected mid-September 2026. As of September 2, 2026 no replacement rule has been published. Plan for the controls to stay and the verification method to change.

Stay NIST SP 800-171 ready, whatever comes next

Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.

Request a demo →

About this guide. By Compyl Research. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.

The CMMC Compliance Guide: What’s Required After the Phase 2 Suspension

Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies