Skip to main content

đź”” Notifications Hub: See compliance updates in one place

  • blog
  • CMMC Phase 2 Paused: What Still Applies & What the DoW, Primes & RFI Responses Signal About Potential Reform

CMMC Phase 2 Paused: What Still Applies & What the DoW, Primes & RFI Responses Signal About Potential Reform

  • September 03, 2026
Author

Anna Fitzgerald

Senior Content Marketing Manager

Reviewer

Marc Rubbinaccio

Head of Cybersecurity & Compliance

Note: This post was originally published on July 21 and has been updated with more recent information from the DoW and other stakeholders. We'll update this article as the DoW issues new guidance.

On July 13, 2026, the Department of War (DoW) announced the immediate freeze of CMMC Phase 2 requirements and launched a 60-day review of the program.

Nearly two months later, many Defense Industrial Base (DIB) organizations have not felt much practical change.

That's because during this interim period, defense contractors and subcontractors must continue to meet cybersecurity requirements to protect federal data, including CMMC Phase 1 self-assessment requirements and DFARS 7012, which has required NIST 800-171 Rev 2 since 2017.

That means the work of implementing and maintaining these requirements and enhancing cybersecurity and operational resilience is still an immediate priority for organizations that want to continue doing business with the DoW and prime contractors.

Below, we unpack what this announcement changes and what it doesn't, how primes and industry have responded, what reform could look like, and what defense contractors should do during the review period.

What the DoW announced is changing about CMMC

Chief Information Officer Kirsten A. Davies first announced that the DoW was pausing the transition to Phase 2 and the rest of the CMMC phased rollout, and standing up a CMMC Reform Task Force to review the program over 60 days.

The Department's stated reasoning is lack of scalability due to "prohibitive compliance costs and bureaucratic burdens" that were forcing companies out of the DIB.

Here's what to know about this CMMC update and implementing memo 26-P-1023:

  • The CMMC phased rollout is now on hold, but Phase 1 requirements remain in effect
  • A 60-day review of the CMMC program is underway, with the review window closing around September 11
  • Industry feedback was gathered through a public request for information (RFI) that closed on August 14
  • A final report recommending "scalable, resilient cybersecurity measures" is expected in late September or early October
  • In the meantime, new solicitations can only require CMMC Level 1 or CMMC Level 2 self-assessments
  • CMMC Level 2 (C3PAO) requirements are being removed from active solicitations and existing contracts
  • CMMC waiver procedures are also paused for the duration of the review period

What is not changing about DoW cybersecurity requirements

While the announcement paused the transition to Phase 2 requirements, the DoW did not cancel the CMMC program or the underlying rules to protect federal data.

In fact, a second DoW release emphasized that investing in and dynamically maintaining robust cybersecurity is still a priority for DIB organizations that want to do business with the Department.

Here is what that means at a glance:

Paused during the reviewUnchanged and still enforced
The Phase 2 transition starting November 10, 2026NIST SP 800-171 Rev 2 compliance
Level 2 (C3PAO) and Level 3 (DIBCAC) designationsCMMC Level 1 and Level 2 self-assessment requirements
C3PAO / DIBCAC language in active solicitations and contractsPre-award verification of SPRS score and annual affirmation signed by executive
CMMC waiver proceduresDFARS 7012 safeguarding and incident reporting
False Claims Act exposure
Prime contractor flowdown

Recommended reading

Honeywell Aerospace’s $2M Settlement Shows the Government Doesn’t Need CMMC Phase 2 to Enforce NIST 800-171

How primes have responded

The DoW's announcement paused the government's phased implementation plan for CMMC, but it is not clear how, or whether, it changes the deadlines primes have set for their own supply chains.

As the April Cyber AB Town Hall underscored, prime contractor deadlines are business decisions made independently of the DoW's rollout. Many primes were already asking suppliers to prove Level 2 (C3PAO) certification or readiness well ahead of the government's schedule, driven by supply chain risk management rather than the CMMC phased rollout calendar.

This is why suppliers that have already achieved certification still provide the highest level of assurance that they can be trusted with CUI. As Chief Executive Officer Matthew Travis noted in the Cyber AB's response to the DoW news: "A Level 2 certification by a C3PAO remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk."

Since nothing in the July 13 memo directs a prime to drop a requirement it set for its own risk reasons, existing deadlines may still be in place. For example, L3Harris Missile Solutions' July 30 deadline for proof of Level 2 certification was set in April, was not withdrawn after the pause, and has now passed. It’s therefore essential to monitor communications from primes or reach out for clarification if you have an existing contract or bid.

While most primes did not send out new supplier notices in the week after the announcement, Elbit America did on July 16 urging suppliers to continue to focus on meeting existing cybersecurity requirements and maturing their programs while the transition to CMMC Phase II is on hold:

"Organizations that remain focused on maturing their cybersecurity programs will be better positioned when the revised assessment timeline is announced."

The wording signals that the DoW's phased rollout and assessment requirements are expected to return in some form, although it may differ from what was codified by the 32 CFR and 48 CFR rules.

Elbit also alluded that existing third-party assessment requirements may still apply, saying: "Before scheduling or cancelling a C3PAO assessment, confirm the applicable requirement with your Elbit America buyer."

Their concluding call to action applies to all defense subcontractors: "This pause is an opportunity to strengthen your program, not a reason to delay it."

elbit supplier notice responding to dow's freeze of cmmc phase 2 requirements

Recommended reading

Why Prime Contractors Are Enforcing CMMC Level 2 (C3PAO) Ahead of DoD & What It Means For Subcontractors

How the industry responded to the CMMC reform RFI

The RFI comment window closed on August 14. About two weeks later at DIBX 2026, DoW CIO Kirsten Davies said the Department received roughly 1,100 responses amounting to more than 11,000 pages of feedback, and that more than half were supportive of reform.

One of the most detailed public comments came from the SBA's Office of Advocacy, which submitted its letter on August 14 after hosting a virtual CMMC roundtable on July 30 that drew more than 600 attendees. Advocacy’s comments carry unusual procedural weight: under the Small Business Jobs Act of 2010, agencies must give Advocacy's comments appropriate consideration and respond to them in writing when a final rule is published.

Advocacy put a number on the underlying problem driving the CMMC pause and reform: Between 2014 and 2024, the number of small business prime contractors working with the Department fell from 43,621 to 29,584, a decline of 32%. That contraction was underway well before CMMC became a rule, but Advocacy's concern is that the issues with the current implementation of the CMMC program, including prohibitive compliance costs for small businesses, will only accelerate this decline.

Advocacy identified five main cost drivers, administrative burdens, and operational challenges of organizations trying to comply with CMMC and the underlying NIST 800-171 Rev 2 standard. The most frequently cited concern was not the assessment fee, Advocacy said. It was uncertainty about CUI itself: what counts as CUI, where it enters an organization, where it flows, and which systems fall inside the assessment boundary.

The letter reported CUI being overmarked, inconsistently marked, and improperly flowed down, including cases where publicly available information was treated as protected and where PII was confused for CUI. The downstream effect is expensive. When a contractor cannot confidently tell what CUI is, it tends to pull everything inside the compliance boundary and pay to protect all of it. As Advocacy put it, “no small business should have to build and price cybersecurity architecture around an undefined category of information.”

Inconsistent, unclear, or improper CUI identification and marking was a theme that ran through comments filed by other industry groups as well, including the National Defense Industrial Association, the Professional Services Council (PSC), and the Alliance for Digital Innovation (ADI).

Beyond CUI uncertainty, the other top drivers were the cost of implementing the underlying NIST SP 800-171 requirements across their enterprise, the cost of a C3PAO assessment and limited assessor capacity, documentation and recurring “administrative” compliance costs, and the expense of selecting and managing commercial technology to support CMMC.

Advocacy was explicit that reform should not mean weaker cybersecurity. Its stated goal is not to make CMMC easier to certify, but to make the DIB harder to compromise while keeping it economically possible for small businesses to participate.

Other industry groups framed it similarly as an execution problem. PSC, for example, wrote in its reply to the RFI that the solution is "to improve execution, not to postpone or weaken the requirements."

Recommended reading

OT Security Is Key to DIB Resilience: What the DoW CIO Signaled about CMMC Reform at DIBX 2026

What CMMC reform could look like

At DIBX 2026, Davies gave the clearest public statement so far of the outcome the task force is working toward, and it is not a lighter standard.

Speaking directly to contractors, she described the goal as making cybersecurity a dynamic process where you "continue to assess your risk, improve your cyber posture, and, oh by the way, do business with us too." Her repeated framing for what reform should produce is results rather than red tape, and performance rather than paperwork.

She also drew a line that matters for anyone running a production floor. Protecting federal data is "table stakes," she said, and a regulatory requirement that never went away. The part she described as underserved is the resilience of manufacturing operations themselves: whether a supplier can keep producing at all. That is a security argument and a capacity argument at the same time, and it is the reason the Department is treating CMMC reform as a national security problem.

While these and other industry comments are not decisions, they point to where the task force is most likely to focus. Here is what reform could plausibly change, and what each would mean for you.

1. Clearer CUI identification, which would limit scope and prime flowdown

This is the highest-leverage item in the comments and the one that would most change day-to-day work for small contractors, partly because it asks the government to act rather than the contractor.

Advocacy recommended the Department identify anticipated CUI categories, markings, data flows, systems, and deliverables before imposing CMMC requirements.

Similarly in its reply to the RFI, ADI recommended the Department enforce scoping diligence to stop primes from “impos[ing] blanket Level 2 flowdowns on every subcontractor, including machine shops producing commercially available products that never touch CUI, because primes lack confidence in scoping determinations and default to over-inclusion to avoid audit liability."

The practical effect for a small subcontractor would be a smaller assessment boundary or a Level 1 requirement that avoids unnecessary compliance costs and burdens for data that it never touches.

2. A graduated path between Level 1 and Level 2

Advocacy recommended a risk-based progression rather than a jump from Level 1's 15 requirements to Level 2's 110 requirements and 320 assessment objectives.

Associated Builders and Contractors proposed a specific tiering model that distinguishes bid-only access to non-CUI, view-only access to CUI inside a prime-controlled or hosted enclave, and storing, processing, or transmitting CUI in a subcontractor’s own systems. A tiered model would be the most structurally significant change to the program, and it would make where your CUI actually lives the decisive scoping question.

3. Greater emphasis on a prioritized set of high-impact controls

The Department and its small business advocate have converged on nearly the same short list from opposite directions.

The DoW CIO's Brilliant at the Basics campaign published ranked IT and OT top 10 lists. Many of these were identified in Advocacy's letter as controls producing real measurable benefit according to roundtable participants, such as MFA, least privilege, encryption of CUI, network segmentation and isolation, incident response exercises, and phishing-resistance training. It also flagged some requirements for a “risk-based review,” such as continuous monitoring and log review expectations that produced a high burden with limited, measurable security benefits.

The overlap between the Brilliant at the Basics and Advocacy’s control list suggest a reformed program may weight requirements by security impact rather than applying all 110 uniformly across Level 2 contractors.

4. Recognition for organizations that already invested in CMMC or other frameworks

Advocacy formally asked for a safe harbor or grandfathering for contractors that have completed or substantially completed CMMC assessments under the existing framework. Contractors holding a Level 2 (C3PAO) certification, or who spent heavily against the original timeline, have the most to lose from a substantially redesigned program.

ADI makes a broader recommendation to extend this recognition to organizations that have completed work for other frameworks, asking the Department to establish formal CMMC reciprocity and a common control matrix with FedRAMP and other recognized security frameworks.

5. More weight on the verification mechanisms already in place

If a revised timeline pushes Phase 2 back, or narrows how much of the DIB needs a third-party assessment at all, the Department may lean more heavily on existing mechanisms to verify compliance, including DIBCAC assessments, SPRS scores, and False Claims Act scrutiny.

Most recently, on September 1, 2026, seven weeks into the pause, the DoJ announced a $2 million settlement with Honeywell Aerospace to resolve allegations that it failed to comply with NIST 800-171 requirements in a Department of Defense contract. The alleged conduct ran from 2020 to 2023, before any CMMC assessment requirement appeared in contracts, and the government enforced compliance anyway through DFARS 7012 and the False Claims Act.

To stay up-to-date on CMMC reform and other updates, we are logging each major development as it happens in the 2026 CMMC news tracker.

Recommended reading

CMMC News 2026: Every Program Update, Rule Change & Enforcement Action

What happens next

The 60-day review window closes around September 11, and the CMMC Reform Task Force is expected to deliver a final report with recommended changes in late September or early October, according to Cyber AB CEO Matthew Travis's estimate at the July Cyber AB Town Hall.

None of those dates change what defense contractors should be doing right now. Enhancing DIB cybersecurity and operational resilience remains a "critical, non-negotiable priority" for the Department as well as prime contractors, so your immediate next steps are still the same.

Step 1: Scope your CUI

  • Identify all locations where CUI enters, is stored, processed, or transmitted to determine scope
  • Evaluate whether an "all in" enterprise or enclave approach would best meet your cybersecurity needs
  • Define your CMMC assessment scope and document it in your SSP

Step 2: Stand up compliant infrastructure

  • Confirm all cloud service providers processing CUI are FedRAMP Moderate Authorized or equivalent
  • Stop using Microsoft 365 Commercial or any other non-compliant cloud offering for CUI, and migrate to and configure GCC High or Google Workspace
  • Implement FIPS 140-2 validated cryptography for CUI in transit
  • Apply MFA to all endpoints, cloud services, firewalls, and servers that process or provide security protection for CUI

Step 3: Implement and document your controls

  • Conduct a CMMC gap analysis to understand how your current cybersecurity implementation compares to NIST 800-171 Rev 2
  • Implement cyber-incident reporting requirements in DFARS 7012
  • Create and maintain all the required policies and procedures
  • Document NIST 800-171 implementation in your SSP and keep it current

Step 4: Assess and affirm

  • Conduct a self-assessment using NIST SP 800-171A (not just 800-171)
  • Identify and document any gaps in POA&Ms with remediation timelines
  • Submit supported and accurate self-assessment results and score in SPRS
  • Designate the senior official who will affirm continuous compliance and submit in SPRS

In other words, the work that determines whether you can demonstrate your ability to securely handle sensitive government information and do business with the DoW is still implementing and maintaining NIST 800-171. That remains as costly and complex as it was before the DoW announcement for most contractors.

Free SSP, POA&M, and policy templates and a requirement-by-requirement explorer are available on CMMC.com if you are starting from scratch.

updated 9/4/26 for secureframe

CMMC & NIST 800-171 Readiness Checklist

Use this checklist to assess your NIST 800-171 implementation and score all 110 requirements the way the DoD Assessment Methodology does, so the score you submit to SPRS reflects your actual posture.

How to solve the persisting readiness problem

In their July 13 announcement, the DoW referenced "recent data" from the Small Business Administration (SBA) confirming that CMMC was pushing small businesses out of the DIB. The SBA's follow-up response included analysis estimating compliance costs can range up to $600,000 for small firms requiring third-party assessments and $380,000 for firms to self-assess.

At DIBX in August, Davies put the figure that came back through RFI responses closer to $250,000 up to nearly $500,000 across a three-year window to achieve and hold the status needed to compete for contracts.

Those totals point to the piece missing from the headlines: while the C3PAO assessment adds to the total, the larger share of the CMMC cost and complexity is actually implementing and maintaining the underlying security requirements. Estimates for this vary widely, with SBA at the high end. While former CMMC Director Stacy Bostjanick put the cost of one-time NIST 800-171 implementation closer to $50,000 and annual maintenance at $34,000, this is still a hefty price tag for small contractors.

Secureframe Defense was purpose-built to reduce the cost and complexity of doing this exact work, not just assessing and documenting it.

  • The platform automatically provisions a CMMC-compliant cloud environment in Microsoft GCC High or Google Workspace as well as devices configured with the access control, logging, monitoring, security event notifications, and segmentation required by NIST 800-171 R2 to securely store and access CUI.
  • Defense Navigator turns the 110 requirements into a guided implementation workflow to get you to 100% ready, automatically generating and maintaining your SSP, implementation statements, and policies from your actual configured environment rather than templates.
  • Secureframe Comply continuously collects evidence, monitors your controls, and enforces other operational guardrails like risk assessments and vendor tracking to prevent quiet compliance drift. That means your SPRS score always reflects your real-time cybersecurity posture, and the senior official signing your annual affirmation has evidence and documentation behind it.

The Secureframe team is available to help your organization navigate these CMMC program changes and scope out your CMMC and NIST 800-171 cybersecurity program to continue to do DoW business. Schedule time to talk to our team.

One platform. Complete CMMC & NIST 800-171 readiness.

Request a demo

FAQs

Is CMMC suspended?

Yes, but the rollout is the only part that is suspended. The rest of the CMMC program and underlying security requirements remain in place. The Department of War suspended the transition to CMMC Phase 2 and pending and future implementation milestones on July 13, 2026 while a Reform Task Force reviews the program over 60 days. The review window closes around September 11, 2026, with a final report expected in late September or early October.

Is the CMMC program cancelled?

No, CMMC is not cancelled. The DoW paused the Phase 2 transition to third-party assessments and opened a 60-day review of the program on July 13, 2026. But the CMMC Program Rule at 32 CFR Part 170 is still in effect, and Phase 1 CMMC self-assessment requirements remain in force.

Do I still need a C3PAO assessment?

Not as a condition of a new DoW award during this review period. DoW Program Managers can only require self-assessments right now. However, subcontractors should reach out to their prime buyer to confirm the applicable requirement for their contracts.

What if you've already scheduled a C3PAO assessment?

Reach out to your prime buyer to confirm the applicable requirement for your contract, or your C3PAO for exact guidance on your engagement, and watch for DoW guidance following the review before making long-term decisions for your compliance program.

What if you've already completed a C3PAO assessment?

If you already hold a CMMC Level 2 (C3PAO) certification, your implementation work fully covers the Level 2 self-assessment requirements that remain in force. This may provide a competitive edge and peace of mind as well. As the Cyber AB's Chief Executive Officer Matthew Travis noted: "A Level 2 certification by a C3PAO remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk." SBA's Office of Advocacy has also asked the task force to provide a safe harbor or grandfathering for organizations that already completed assessments under the existing framework.

Is my SPRS score still required?

Yes. Under DFARS 252.204-7021 (the CMMC clause), you still need a current self-assessment score in SPRS and an annual affirmation of continuous compliance. The DoW's announcement does not change that.

Does the suspension change DFARS 252.204-7012?

No. The safeguarding and cyber incident reporting obligations under DFARS 7012 are untouched. This clause has required NIST 800-171 Rev 2 since 2017, and it's still in every covered contract.

Does the pause reduce False Claims Act risk?

No. The pause changes who is required to verify cybersecurity compliance for certain contracts, not what is required. Your SPRS score and annual affirmation are still legal representations, and those representations are what False Claims Act cases are built on. The Honeywell settlement announced on September 1, 2026 resolved conduct from a period when no CMMC assessment requirement existed at all.

What did industry ask the task force to change?

The most common theme across comments from the SBA Office of Advocacy, NDIA, PSC, and ADI was CUI identification and marking. Industry groups asked the Department to define anticipated CUI categories and data flows before imposing CMMC requirements, limit flowdown to contracts that actually involve covered information, and provide consistent assessment guidance. Several also asked for a graduated path between Level 1 and Level 2.

When will we know more?

The Reform Task Force review window closes around September 11, 2026, with recommendations expected to reach the DoW CIO and Under Secretary of War for Acquisition and Sustainment shortly after. A final report is expected in late September or early October.

Anna Fitzgerald

Senior Content Marketing Manager

Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.

Marc Rubbinaccio

Head of Cybersecurity & Compliance

Marc Rubbinaccio is an information security leader with over a decade of experience in cybersecurity. As a former auditor and security consultant, Marc performed and managed security and regulatory audits as a lead QSA. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including PCI DSS, SOC 2, ISO 27001, CMMC, and FedRAMP. He also played an integral role in Secureframe’s own CMMC Level 2 assessment and FedRAMP 20x Low authorization.