Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

CMMC 2.0 Timeline: Key Dates, Deadlines & the Current Phase

  • cmmc
  • CMMC 2.0 Timeline: Key Dates, Deadlines & the Current Phase

CMMC didn't appear overnight. It's the product of nearly a decade of federal rulemaking, starting with the first basic safeguarding clause in 2016 to the phased enforcement of CMMC assessment requirements that began in late 2025.

While the phased rollout was put on hold on July 13, 2026, Phase 1 enforcement of this program officially started as planned on November 10, 2025 —approximately four years after the first iteration (CMMC 1.0) was introduced.

This post answers where CMMC enforcement stands right now, then walks through the complete timeline to trace how the program got here, why it took so long, and what's going to happen next.

What CMMC phase are we in?

CMMC is in Phase 1 of enforcement currently. Phase 1 self-assessment requirements took effect on November 10, 2025 and remain fully in force.

While Phase 2 was meant to begin on November 10, 2026, one year after Phase 1 began, the DoW paused the transition to Phase 2 and the rest of the phased rollout described below while the CMMC Reform Task Force reviews the program over 60 days.

What are the CMMC phases?

As described in 32 CFR § 170.3(e), CMMC was designed to roll out gradually through contracts in four phases that would each begin one year after the other. These phases dictated which requirements DoW program managers could insert into solicitations and contracts and when.

The phased rollout began 60 days after the publication of the 48 CFR rule in the Federal Register, on November 10, 2025. While Phase 1 remains live, Phases 2 through 4 are on hold as of July 13, 2026 pending the review:

CMMC Phased Rollout as of July 13, 2026 pause
  • Phase 1 (started November 10, 2025): Requires CMMC Level 1 or Level 2 self-assessments for certain contracts. The DoD had the discretion to include Level 2 certification assessment requirements into contracts at this time, but now during the 60-day review, Program Managers may only designate Level 1 (Self) or Level 2 (Self).
  • Phase 2 (on hold): Would have expanded rollout of Level 2 (C3PAO) assessment requirements as a condition of contract award for applicable contracts, or delayed to an option period. Was planned to begin one year after Phase 1 starts, on November 10, 2026.
  • Phase 3 (on hold): Would have made Level 2 C3PAO assessments required as a condition of contract award for all applicable solicitations and contracts and expanded rollout of Level 3 (DIBCAC) assessment requirements. Was planned to begin one year after Phase 2 starts, on November 10, 2027.
  • Phase 4 (on hold): Would have fully implemented CMMC requirements for all relevant contracts. Planned to begin one year after Phase 3 starts. Was planned to begin one year after Phase 3 starts, on November 10, 2028.

To understand why the program was designed with this phased implementation plan and why it's currently on hold, let's take a closer look at how this program was developed.

CMMC 2.0 Timeline: A Complete Overview

The development of CMMC has been a step-by-step process. We’ll break down the major steps below to help you understand how this program has evolved over time and where it stands today. 

CMMC 2.0 Timeline as of July 13, 2026 pause

May 2016: FAR 52.204-21 released

In response to increases in cyber threats aimed at the Defense Industrial Base (DIB), the DoD, General Services Administration (GSA), and National Aeronautics and Space Administration (NASA) released the FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems

This contract clause requires contractors and subcontractors to implement 15 basic safeguarding requirements pulled from NIST SP 800-171 Revision 2 to protect federal contract information (FCI) being processed, stored, or transmitted on contractor information systems. 

The FAR clause did not provide for DoD verification of a contractor's implementation of the 15 basic safeguarding requirements.

October 2016: DFARS 252.204-7012 released

DFARS clause 252.204-7012 was released in October 2016, requiring defense contractors and subcontractors to provide “adequate security” for all covered defense information. Less than a year later, a memorandum stated that, to provide adequate security, the contractor must implement all 110 NIST 800-171 Revision 2 requirements prior to contract award.  The deadline to implement NIST 800-171 was December 31, 2017.

By signing a defense contract, vendors were essentially self-attesting that they meet all of the security requirements outlined in DFARS, even if those requirements were not explicitly spelled out within the contract itself. Like FAR clause 52.204-21, DFARS clause 252.204-7012 did not require DoD to verify a contractor's implementation of those security requirements, prior to contract award. But if the government found out they weren’t meeting those requirements or a whistleblower reported non-compliance, they could get sued for making false claims. So this "self-attestation" model of security wasn't just having a negative effect on federal security, it was also introducing legal risk to companies within the DIB.

Years after the release of the FAR and DFARS clauses, many contractors and subcontractors were still not consistently implementing mandated system security requirements for safeguarding FCI or CUI. So the DoD decided they needed to move away from this self-attestation model of security and take steps to assess a contractor's ability to protect this information.

September 2020: The CMMC interim rule released

Starting in 2019, the DoD started working on a framework to make sure contractors and subcontractors were implementing the DoD’s cybersecurity requirements and capable of protecting unclassified information. This framework, CMMC 1.0, built on existing requirements from DFARS 252.204-7012 and added a way to verify compliance through third–party certification. CMMC 1.0 was introduced under an interim rule in September 2020. 

This interim rule was a temporary set of guidelines issued by the DoD to begin implementing CMMC requirements while the final rule-making process was still ongoing. It provided initial guidance and requirements for defense contractors to start preparing for CMMC compliance.

Based on DFARS Clause 252.204-7012, the CMMC interim rule established a five year phased approach for CMMC implementation, during which CMMC compliance is only required in select pilot contracts approved by the office of the Under Secretary of Defense of Acquisition and Sustainment (OUSD(A&S)). 

November 2021: CMMC 2.0 announced

More than a year after the interim rule was released, the DoD officially suspended the CMMC 1.0 pilot efforts and released CMMC 2.0. CMMC 2.0 introduced significant changes to the CMMC program to simplify the certification process, align more closely with existing cybersecurity standards, and reduce the compliance burden on small businesses.

Here’s an overview of the key changes in CMMC 2.0:

  • Reduced levels – CMMC 2.0 simplifies the framework from five levels to three: Foundational (Level 1), Advanced (Level 2), and Expert (Level 3).
  • Stronger alignment with NIST – Compliance requirements now closely follow NIST SP 800-171, Revision 2 (for CMMC Level 2) and NIST SP 800-172 (for CMMC Level 3), making adherence easier for organizations already using these frameworks.
  • Self-assessments for certain levels – Level 1 and some Level 2 contracts allow for annual self-assessments instead of third-party assessments, reducing compliance costs.
  • More focused requirements – Removed some unique CMMC requirements that did not align with existing standards and focused more precisely on protecting Controlled Unclassified Information (CUI).
  • Greater accountability and transparency – Self-assessments require affirmation by a senior company official, reinforcing accountability and compliance integrity.

December 16, 2024: The 32 CFR CMMC Program Rule in effect

CMMC 2.0 is the foundation for the final rule, also known as the 32 Code of Federal Regulations (CFR) CMMC Program rule. First published as a proposed rule on December 26, 2023, the DoD published it as a final rule in the Federal Register on October 15, 2024 and it went into effect on December 16, 2024. 

This rule is basically the set of guidelines and requirements the DoD put in place to get everyone on the same page.

It introduced a framework with three levels of cybersecurity practices. Each level builds on the previous one, getting more advanced:

  • Level 1: Foundational - Basic practices that everyone should be doing, like updating antivirus software and managing passwords.
  • Level 2: Advanced - More comprehensive practices, aligned with NIST SP 800-171 Rev. 2, like encryption and incident response plans.
  • Level 3: Expert - For the most sensitive information, with advanced measures like continuous monitoring and proactive threat hunting.

Why three levels? Because not every contractor handles the same type of information. Some might just handle basic contract details, while others might handle detailed plans or sensitive communications. The three levels let companies match their security efforts to the type of information they’re dealing with and allow DoD officials and contract owners the assurance that the organizations they’re working with are protecting their data according to a specific standard.

If you’re a contractor or subcontractor working with the DoD, you’ll need to get certified at one of these levels. The specific level and assessment you need depends on the type of contracts you’re bidding on and the sensitivity of the information involved.

For Levels 2 and 3, you’ll need to undergo an assessment by a third-party organization (C3PAO) or the DoD, respectively, to make sure you’re actually following the required practices. Level 1 can often be self-assessed, but it still requires you to demonstrate compliance with the basic practices.

While rulemaking under Title 32 CFR, which was required to formally establish the DoD's CMMC Program in regulation, concluded in December 2024, a separate rulemaking process was still underway. This rulemaking process was for Title 48 CFR, which was required to update contractual requirements in the DFARS to actually implement the CMMC program. The next important milestone in this process took place over six months after the 32 CFR rule went into effect.

July 22, 2025: 48 CFR CMMC Acquisition rule sent to OIRA for review, indicating enforcement is imminent

On July 22, 2025, the DoD submitted the 48 CFR CMMC Acquisition rule to the Office of Information and Regulatory Affairs (OIRA), a part of the Office of Management and Budget (OMB), for review.

Originally, the submission included clause 204.7503, which stated CMMC certification would be a requirement for most DoD contracts starting October 1, 2025. However, that was an old reference from CMMC 1.0 and has officially been removed.

While the exact date was still pending at this time, the CyberAB’s August Town Hall did say CMMC was expected to become enforceable before the end of 2025—and they were right.

The 48 CFR rule cleared regulatory review approximately six weeks later, on August 25, 2025. It was then published as final in the Federal Register on September 10, 2025

November 10, 2025: 48 CFR Rule in effect, kicking off CMMC Phase 1

The CMMC Program implementation date was 60 days after publication of the 48 CFR rule, meaning Phase 1 of the CMMC rollout began on November 10, 2025. On this day, the DoD began rolling out CMMC self-assessment requirements in most new contracts. These requirements were expected to apply to 65% of the DIB, according to DoD estimates in the 32 CFR rule. During Phase 1, the DoD also had the discretion to require third-party Level 2 assessments for select high-priority acquisitions.

Bottom line: Since November 10, 2025, most new contracts have required at least CMMC Level 1 or Level 2 (Self) compliance at the time of award. Those Phase 1 self-assessment requirements are still in force today, even with the transition to Phase 2 now on hold (more on that below).

July 13, 2026: DoW suspends the transition to CMMC Phase 2

On July 13, 2026, the DoD, now commonly referred to by its official secondary title the Department of War (DoW), paused the transition to CMMC Phase 2 and opened a 60-day review of the program through implementing memo 26-P-1023.

Critically, this did not affect the underlying cybersecurity obligations in contracts today. Here's what changed and did not change during the 60-day review period:

  • New solicitations can designate only CMMC Level 1 (Self) or Level 2 (Self); Level 2 (C3PAO) requirements are being removed from active solicitations and existing contracts.
  • CMMC waiver procedures are paused.
  • Industry can weigh in through a public request for information (RFI), with the comment window closing August 14, 2026.
  • A CMMC Reform Task Force is expected to deliver a final report, with recommendations for "scalable, resilient" cybersecurity measures, around mid-September 2026.
  • DFARS 252.204-7012 and NIST SP 800-171 Rev 2 remain in effect, and Phase 1 self-assessment requirements stay in force.

What happens next in the CMMC phased rollout?

What happens next in the CMMC phased rollout is now pending review. Industry can comment through a public request for information (RFI) until August 14, 2026, and the CMMC Reform Task Force is expected to report around mid-September 2026 with recommendations for a more "scalable, resilient" approach. Phase 2 may return on a revised timeline, in a revised form, or both.

If the program's history is any indicator, the dates may change but the direction of the program and the increased assurance it is designed to provide the DoW and primes will likely hold. The 2020 interim rule gave way to CMMC 2.0 in 2021, the 32 CFR Program Rule in 2024, and the 48 CFR Acquisition Rule in 2025, each one slipping its predecessor's expected timing without reversing course.

In the mean time, DIB organizations should continue to strengthen their cybersecurity programs. Just like the DoW's Phase 2 pause pending a program review, the phased rollout was never meant to be license for organizations to wait on implementation. The phases set when assessment requirements could be written in by Department officials in new contracts and solicitations, not when the underlying security requirements had to be met. FAR 52.204-21 and DFARS 252.204-7012 have required the implementation of a subset or the full NIST SP 800-171 Rev 2 since 2016 and 2017, so the controls behind CMMC are already contractual for anyone handling CUI.

That means defense contractors' and subcontractors' obligations to protect federal data haven't changed:

If you handle FCI, you’ll need:

  • Implementation of all 15 requirements from FAR 52.204-21 (renumbered to FAR 52.240-93)
  • An annual self-assessment with senior official affirmation submitted in SPRS
  • Documented practices and evidence of implementation to support affirmations every year

If you handle CUI or SPD, you’ll need at least CMMC Level 2, which includes:

  • Full implementation of all 110 NIST SP 800-171 Rev 2 requirements and 320 assessment objectives
  • A System Security Plan (SSP), POA&M, and SPRS score of at least 88 to 110
  • A self-assessment every three years and senior official affirmation of compliance every year
  • Documented practices and evidence of implementation to support affirmations every year

Bottom line: If you plan to work with the DoW, directly or indirectly, CMMC compliance is not optional and the pause does not change your near-term work. Identify your scope, implement the required NIST 800-171 controls, generate your SSP and POA&M, submit your SPRS score and annual affirmation, and be ready for third-party verification to return.

This post was originally published in September 2024 and has been updated on July 22, 2026 for accuracy and comprehensiveness.

CMMC Level 2 Compliance Checklist

Not sure where you stand against the 110 requirements? Our CMMC Level 2 compliance checklist walks through what you need in place now, pause or no pause.

FAQs

What is the final rule of the CMMC? 

The final rule of the CMMC, also known as the 32 CFR CMMC Program Rule, is a set of guidelines and requirements established by the Department of Defense (DoD) to ensure that defense contractors implement appropriate cybersecurity practices to protect sensitive information. It introduces a tiered framework with three levels of security, each with increasing complexity and rigor.

Has CMMC 2.0 been released?

Yes, the DoD released the long-awaited final CMMC 2.0 rule in October 2024 and it went into effect in December 2024. However, these requirements were not implemented contractually at this time. CMMC 2.0 requirements began appearing in new DoD contracts on November 10, 2025, sixty days after the publication of the 48 CFR rule in the Federal Register.

Is CMMC required yet?

Yes. CMMC has been required in applicable new defense contracts since November 10, 2025, starting with Level 1 (Self) and Level 2 (Self) requirements. During the 60-day review that started on July 13, 2026, DoW program managers can only insert these Phase 1 self-assessment requirements in new solicitations. Level 2 (C3PAO) certification requirements are paused and being removed from solicitations and contracts.

What is the deadline for CMMC compliance?

There is no single deadline, and the phased schedule is currently paused. Phase 1 self-assessment requirements took effect November 10, 2025 and remain in force. Phase 2 (Level 2 C3PAO certification) was scheduled for November 10, 2026 but is suspended pending the DoW's 60-day review, with further guidance expected around mid-September 2026. Because primes set their own flowdown deadlines independent of the government schedule, contractors should confirm requirements with their prime buyers and be ready before verification returns.

Why there is no real "deadline" for CMMC compliance?

As the Cyber AB has emphasized, the November 10 dates of the previously planned CMMC rollout marked the start of each implementation phase, not a cutoff by which every contractor must be certified. Requirements were meant to be inserted by DoW program managers in new solicitations and contract awards as each phase began, or proactively by primes before each phase. CMMC is not retroactive, so existing contracts were not modified mid-performance. In practice, under CMMC, "deadline" is shorthand for "when a requirement starts appearing in new contracts."

What CMMC phase are we in right now?

Phase 1. Self-assessment requirements that began November 10, 2025 remain in effect. Phase 2, which was scheduled to expand Level 2 (C3PAO) requirements starting November 10, 2026, is suspended as of July 13, 2026, along with the rest of the phased rollout.

When will CMMC Phase 2 resume?

The DoW has not set a date. The CMMC Reform Task Force is due to report within 60 days of July 13, 2026, so expect further guidance around mid-September 2026. Prime and DoW communications signal that the assessment transition is expected to return in some form, though it may differ from what the 32 CFR and 48 CFR rules originally codified.

One platform. Complete CMMC readiness.

Request a demo
Loading...