
CMMC Phase 2 Paused: Which Requirements Still Apply After the Latest DoW Announcement and Prime Notices?
Anna Fitzgerald
Senior Content Marketing Manager
Marc Rubbinaccio
Head of Cybersecurity & Compliance
Note: We'll update this article as the DoW issues new guidance.
On July 13, 2026, the Department of War (DoW) announced the immediate freeze of CMMC Phase 2 requirements and launched a 60-day review of the program.
This news has dominated headlines for the past week, but Defense Industrial Base (DIB) organizations may not have felt much of an immediate impact.
That’s because during this interim period, defense contractors and subcontractors must continue to meet cybersecurity requirements to protect federal data, including CMMC Phase 1 self-assessment requirements and DFARS 7012, which has required NIST 800-171 Rev 2 since 2017.
That means the work of implementing and maintaining these requirements and enhancing cybersecurity and operational resilience is still an immediate priority for organizations that want to continue doing business with the DoW and prime contractors.
Below, we unpack what this announcement changes (and what it doesn't), how one prime contractor responded, and what defense contractors should do during the 60-day review period.

What the DoW announced is changing about CMMC
Chief Information Officer Kirsten A. Davies first announced that the DoW was pausing the transition to Phase 2 and the rest of the CMMC phased rollout, and standing up a CMMC Reform Task Force to review the program over 60 days.
The Department’s stated reasoning is lack of scalability due to “prohibitive compliance costs and bureaucratic burdens” that were forcing companies out of the DIB.
Here's what to know about this CMMC update and implementing memo 26-P-1023:
- The CMMC phased rollout is now on hold, but Phase 1 requirements remain in effect
- A 60-day review of the CMMC program is underway
- Industry feedback is being gathered through a public request for information (RFI)
- A final report recommending “scalable, resilient cybersecurity measures” is expected in mid-September
- In the meantime, new solicitations can only require CMMC Level 1 or CMMC Level 2 self-assessments
- CMMC Level 2 (C3PAO) requirements are being removed from active solicitations and existing contracts
- CMMC waiver procedures are also paused for the duration of the review period
What is not changing about DoW cybersecurity requirements
While the announcement paused the transition to Phase 2 requirements, the DoW did not cancel the CMMC program or the underlying rules to protect federal data.
In fact, a second DoW release emphasized that investing in and dynamically maintaining robust cybersecurity is still a priority for DIB organizations that want to do business with the Department.
Here is what that means at a glance:
- DFARS 252.204-7012 and CMMC Level 1 and Level 2 (Self) requirements remain in effect.
- NIST SP 800-171 Rev 2 will still be enforced by the DoW through self-assessments and select government-led assessments.
- Accurate CMMC self-assessment results and scores, along with an annual affirmation signed by a named senior executive, must still be submitted to SPRS.
- Contractors that misrepresent NIST 800-171 compliance still face False Claims Act risk.
- Primes will still flow down CMMC requirements and ask suppliers for assurance of NIST 800-171 Rev 2 compliance.
- The proposed FAR CUI rule, which requires NIST 800-171 Rev 3, is still expected to be finalized this year.
| Paused during the 60-day review | Unchanged and still enforced |
|---|---|
| The Phase 2 transition starting November 10, 2026 | NIST SP 800-171 Rev 2 compliance |
| Level 2 (C3PAO) and Level 3 (DIBCAC) designations | CMMC Level 1 and Level 2 self-assessment requirements |
| C3PAO / DIBCAC language in active solicitations and contracts | Pre-award verification of SPRS score and annual affirmation signed by executive |
| CMMC waiver procedures | DFARS 7012 safeguarding and incident reporting |
| False Claims Act exposure | |
| Prime contractor flowdown |
How primes are responding
The DoW’s announcement paused the government’s phased implementation plan for CMMC, but it is not yet clear how, or whether, it changes the deadlines primes have set for their own supply chains.
As the April Cyber AB Town Hall underscored, prime contractor deadlines are business decisions made independently of the DoW's rollout. Many primes were already asking suppliers to prove Level 2 (C3PAO) certification or readiness well ahead of the government’s schedule, driven by supply chain risk management rather than the CMMC phased rollout calendar.
This is why suppliers that have already achieved it still provide the highest level of assurance that they can be trusted with CUI. As Chief Executive Officer Matthew Travis noted in the Cyber AB’s response to the DoW news: “A Level 2 certification by a C3PAO remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk.”
Since nothing in the July 13 memo directs a prime to drop a requirement it set for its own risk reasons, existing deadlines may still be in place, like L3Harris Missile Solutions’s request for proof of Level 2 certification by July 30, 2026. It’s therefore essential to monitor communications from primes or reach out for clarification if you have an existing contract or bid.
Many primes have not sent out new supplier notices in the week after the announcement, but Elbit did on July 16 urging suppliers to continue to focus on meeting existing cybersecurity requirements and maturing their programs while the transition to CMMC Phase II is on hold, saying:
“Organizations that remain focused on maturing their cybersecurity programs will be better positioned when the revised assessment timeline is announced.”
The wording signals that the DoW's phased rollout and assessment requirements are expected to return in some form, although it may be different than what was codified by the 32 CFR and 48 CFR rules.
In the interim period, Elbit alluded that existing third-party assessment requirements may still apply, saying: “Before scheduling or cancelling a C3PAO assessment, confirm the applicable requirement with your Elbit America buyer.”
Their concluding takeaway is a call to action that applies to all defense subcontractors: “This pause is an opportunity to strengthen your program – not a reason to delay it.”

Recommended reading
Why Prime Contractors Began Enforcing CMMC Level 2 (C3PAO) Ahead of DoD & What It Means For Subcontractors
What happens next
The DoW has said further guidance will come after the task force’s 60-day review and report is delivered, which is expected around mid-September 2026 about a month after the comment window for the DoW's RFI on program reform closes on August 14. Before then, you can expect the Cyber AB to address the DoW announcement at its next Town Hall on July 28 and more primes to follow Elbit with supplier notices of their own.
However, none of those dates change what defense contractors should be doing right now. Enhancing DIB cybersecurity and operational resilience remains a “critical, non-negotiable priority” for the Department as well as prime contractors so your immediate next steps are still the same:
Step 1: Scope your CUI
- Identify all locations where CUI enters, is stored, processed, or transmitted to determine scope
- Evaluate whether an “all in” enterprise or enclave approach would best meet your cybersecurity needs
- Define your CMMC assessment scope and document it in your SSP
Step 2: Stand up compliant infrastructure
- Confirm all cloud service providers processing CUI are FedRAMP Moderate Authorized or equivalent
- Stop using Microsoft 365 Commercial or any other non-compliant cloud offering for CUI, and migrate to and configure GCC High or Google Workspace
- Implement FIPS 140-2 validated cryptography for CUI in transit
- Apply MFA to all endpoints, cloud services, firewalls, and servers that process or provide security protection for CUI
Step 3: Implement and document your controls
- Conduct a CMMC gap analysis to understand how your current cybersecurity implementation compares to NIST 800-171 Rev 2
- Implement cyber-incident reporting requirements in DFARS 7012
- Create and maintain all the required policies and procedures
- Document NIST 800-171 implementation in your SSP and keep it current
Step 4: Assess and affirm
- Conduct a self-assessment using NIST SP 800-171A (not just 800-171)
- Identify and document any gaps in POA&Ms with remediation timelines
- Submit supported and accurate self-assessment results and score in SPRS
- Designate the senior official who will affirm continuous compliance and submit in SPRS
In other words, the work that determines whether you can demonstrate your ability to securely handle sensitive government information and do business with the DoW is still implementing and maintaining NIST 800-171. That remains as costly and complex as it was before the DoW announcement for most contractors.
How to solve the persisting readiness problem
In their July 13 announcement, the DoW referenced “recent data” from the Small Business Administration (SBA) confirming that CMMC was pushing small businesses out of the DIB. The SBA’s follow-up response included analysis estimating compliance costs can range up to $600,000 for small firms requiring third-party assessments and $380,000 for firms to self-assess.
Those totals point to the piece missing from the headlines: while the C3PAO assessment adds to the total, the larger share of the CMMC cost and complexity is actually implementing and maintaining the underlying security requirements. Estimates for this vary widely, with SBA at the high end. At our Summit in May, former CMMC Director Stacy Bostjanick put the cost of one-time NIST 800-171 implementation closer to $50,000 and annual maintenance at $34,000.
Secureframe Defense was purpose-built to reduce the cost and complexity of doing this exact work, not just assessing and documenting it.
- The platform automatically provisions a CMMC-compliant cloud environment in Microsoft GCC High or Google Workspace as well as devices configured with the access control, logging, monitoring, security event notifications, and segmentation required by NIST 800-171 R2 to securely store and access CUI.
- Defense Navigator turns the 110 requirements into a guided implementation workflow to get you to 100% ready, automatically generating and maintaining your SSP, implementation statements, and policies from your actual configured environment rather than templates.
- Secureframe Comply continuously collects evidence, monitors your controls, and enforces other operational guardrails like risk assessments and vendor tracking to prevent quiet compliance drift. That means your SPRS score always reflects your real-time cybersecurity posture, and the senior official signing your annual affirmation has evidence and documentation behind it.
The Secureframe team is available to help your organization navigate these CMMC program changes and scope out your CMMC & NIST 800-171 cybersecurity program to continue to do DoW business. Schedule time to talk to our team.
One platform. Complete CMMC readiness.
FAQs
Is the CMMC program cancelled?
No. The DoW paused the Phase 2 transition to third-party assessments and opened a 60-day review of the program. But the CMMC Program Rule at 32 CFR Part 170 is still in effect, and Phase 1 CMMC self-assessment requirements remain in force.
Do I still need a C3PAO assessment?
Not as a condition of a new DoW award during this 60-day review period. DoW Program Managers can only require self-assessments right now. However, subcontractors should reach out to your prime buyer to confirm the applicable requirement for their contracts.
What if you've already scheduled a C3PAO assessment?
Reach out to your prime buyer to confirm the applicable requirement for your contract or your C3PAO for exact guidance on your engagement, and watch for DoW guidance following the 60-day review before making long-term decisions for your compliance program.
What if you've already completed a C3PAO assessment?
If you already hold a CMMC Level 2 (C3PAO) certification, your implementation work fully covers the Level 2 self-assessment requirements that remain in force. This may provide a competitive edge and peace of mind as well. As the Cyber AB’s Chief Executive Officer Matthew Travis noted: “A Level 2 certification by a C3PAO remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk.”
Is my SPRS score still required?
Yes. Under DFARS 252.204-7021 (the CMMC clause), you still need a current self-assessment score in SPRS and an annual affirmation of continuous compliance. The DoW’s announcement does not change that.
Does the suspension change DFARS 252.204-7012?
No. The safeguarding and cyber incident reporting obligations under DFARS 7012 are untouched. This clause has required NIST 800-171 Rev 2 since 2017, and it's still in every covered contract.
When will we know more?
The Reform Task Force is due to report within 60 days of July 13, 2026, so expect further guidance around mid-September 2026.

Anna Fitzgerald
Senior Content Marketing Manager
Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.

Marc Rubbinaccio
Head of Cybersecurity & Compliance
Marc Rubbinaccio is an information security leader with over a decade of experience in cybersecurity. As a former auditor and security consultant, Marc performed and managed security and regulatory audits as a lead QSA. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including PCI DSS, SOC 2, ISO 27001, CMMC, and FedRAMP. He also played an integral role in Secureframe’s own CMMC Level 2 assessment and FedRAMP 20x Low authorization.