Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

The CMMC 2.0 Rulemaking Process + 32 CFR & 48 CFR Status

  • cmmc
  • The CMMC 2.0 Rulemaking Process + 32 CFR & 48 CFR Status

Editor’s note: On July 13, 2026, the Department of War paused the transition to CMMC Phase 2 pending a 60-day program review. That pause is a policy decision, not a rule change. The 32 CFR CMMC Program rule and the 48 CFR CMMC Acquisition rule remain in place, and officially amending either one would require its own rulemaking. See what it would take to change CMMC below, or the CMMC News & Updates tracker for the dated record.

CMMC 2.0 represents a significant overhaul of the Department of Defense's (DoD) cybersecurity framework for defense contractors.

After receiving feedback from the defense industry, Congress, and other stakeholders, the DoD moved away from its original CMMC framework (previously referred to as CMMC 1.0) toward a more streamlined model (previously referred to as CMMC 2.0).

Introduced in November 2021, CMMC 2.0 introduced key changes to the original framework to meet three key objectives:

  • reducing costs, particularly for small businesses
  • increasing trust in the CMMC assessment ecosystem
  • clarifying and aligning cybersecurity requirements to existing federal requirements and commonly accepted standards

To ensure continued alignment with federal regulations and input from industry stakeholders, CMMC 2.0 underwent a rigorous rulemaking process that was completed on November 10, 2025, nearly four years after CMMC 2.0 (now known simply as CMMC) was first introduced.

Let's dive into what happened in those four years below.

Key stages in the CMMC 2.0 rulemaking process: how the 32 CFR CMMC Program rule was finalized

The CMMC 2.0 rulemaking process followed a structured approach to ensure clarity, transparency, and industry engagement. However, because of the length of the rulemaking process, it may not seem so clear. Below we'll break down the process into the most important milestones so you can better understand how the program has evolved over time.

4 major milestones in the rulemaking process for 32 CFR CMMC Program rule.

This section will cover the rulemaking process for the 32 Code of Federal Regulations (CFR) CMMC Program rule, which officially established the CMMC program. The next section will cover the separate rulemaking process for the 48 CFR CMMC Acquisition rule, which actually implemented CMMC requirements in DoD contracts starting November 10, 2025.

December 2023: Release of the CMMC 2.0 proposed final rule (32 CFR rule)

On December 26, 2023, the DoD published the 32 CFR CMMC Program Rule, the much-anticipated proposed rule change for the CMMC program. Dubbed CMMC 2.0, the proposed rule change revised certain aspects of the program to address public concerns in response to DoD's initial vision for the CMMC 1.0 program published back in 2020.

Most notably, CMMC 2.0 streamlined and simplified the process for small and medium-sized businesses by reducing the number of assessment levels from five to three. These levels aligned cybersecurity requirements to the sensitivity of unclassified information to be protected. It also added a self-assessment requirement to affirm implementation of applicable cybersecurity requirements and a certification requirement to verify implementation of cybersecurity requirements. These elements were added to ensure accountability while minimizing barriers to compliance with DoD requirements.

February 2024: End of public comment period for the CMMC 2.0 proposed final rule

The rule change was open for comment for 60 days. During this period, industry stakeholders submitted feedback on the proposed rule. Nearly 800 comments were received before the public comment period closed on February 26, 2024 at 11:59 p.m. These comments informed the final rule.

October 2024: Release of the CMMC 2.0 final rule

The DoD reviewed comments and made adjustments to improve the feasibility and effectiveness of the final 32 CFR rule. Because of the number of comments, this took most of 2024. They published this final rule, also known as the updated 32 CFR rule, in the Federal Register on Tuesday, October 15 for a 60-day congressional review period.

December 2024: Effective date of the CMMC 2.0 final rule

CMMC 2.0 completed its 60-day congressional review period without any changes on December 16, 2024. At this point, rulemaking was complete and the CMMC 2.0 program went into effect.

While assessments were available at this time, CMMC requirements were not included in DoD contracts yet. Let's look at why below.

The rulemaking process for the 48 CFR CMMC Acquisition rule

While the 32 CFR rule finalized the program structure, a separate rule, the 48 CFR Acquisition Rule, had to go into effect to mandate CMMC in DoD contracts by updating the Defense Federal Acquisition Regulation Supplement (DFARS).

Let's walk through the key milestones of this second rule.

48 CFR CMMC rule milestones as of September 10, 2025.

September 2020: Release of the 48 CFR CMMC Acquisition interim final rule

On September 9, 2020, DoD published the 48 CFR CMMC interim final rule, Defense Federal Acquisition Regulation Supplement (DFARS): Assessing Contractor Implementation of Cybersecurity Requirements. This implemented the DoD's vision for the initial CMMC Program and outlined the basic features of the framework, including the five-tiered model, required assessments, and implementation through contracts, to protect FCI and CUI.

This interim rule was open for public comment for 60 days. During this period, they received approximately 750 comments. These comments highlighted a variety of industry concerns related to:

  • the costs for a C3PAO certification
  • the costs and burden associated with implementing, prior to award, the required process maturity and 20 additional cybersecurity practices that were included in the CMMC 1.0 Program
  • interpretations of the CMMC framework implementation requirements and control objectives
  • the impact the rule would have on small businesses in the DIB

November 2020: Effective date of 48 CFR interim final rule

The 48 CFR CMMC interim final rule became effective on November 30, 2020. Designed to increase compliance with its cybersecurity regulations and improve security throughout the defense industrial base (DIB), this rule introduced one new provision and two new clauses:

  • DFARS provision 252.204-7019: Required contractors to conduct a NIST SP 800-171 self-assessment and submit scores via the Supplier Performance Risk System (SPRS) for contract eligibility. This provision was eliminated on February 1, 2026, when it became redundant of DFARS 252.204-7021.
  • DFARS clause 252.204-7020: Ensured subcontractors had SPRS scores on file before contract award. This clause was renumbered to DFARS 252.240-7997 on February 1, 2026 and revised to remove references to Basic assessments.
  • DFARS clause 252.204-7021, also known as 48 CFR 252.204-7021: Mandates contractors achieve and maintain the required CMMC certification level and flow down requirements to subcontractors.

This rule kicked off the five-year phase-in period. For the current numbering and what each clause requires today, see our guide to the DFARS clauses behind CMMC.

March 2021: Start of DoD's internal review of CMMC's implementation

Because they received so much feedback on the 48 CFR CMMC interim final rule, the DoD decided to pause the planned CMMC rollout and initiate an internal review of CMMC's implementation in March 2021.

This review involved cybersecurity and acquisition leaders within DoD to refine policy and program implementation based on input from the industry and the Defense Contract Management Agency (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) received relating to the initial CMMC Program.

August 2024: Release of proposed rule change to 48 CFR

On August 15, 2024, the Department of Defense published for public comment the DoD's proposed amendments to the 48 Code of Federal Regulation (CFR) rule. These amendments were focused on incorporating contractual requirements related to the CMMC 2.0 program requirements proposed in 32 CFR part 170.

The most notable changes included:

  • Requiring contractors to prove CMMC compliance at the level included in a given solicitation and contracting officers to verify the results in the SPRS.
  • Requiring contractors to obtain certifications or perform self-assessments under the CMMC program before contract award by adding a new provision, DFARS 252.204-7YYY (which would become 7021).
  • Requiring contractors to maintain compliance at the specified CMMC level throughout contract performance and notify contracting officers if lapses or changes in CMMC certification levels occur.
  • Removing the Non-Federal Organization (NFO) control requirements

October 2024: End of public comment period

The public comment period closed on October 15, 2024 at 11:59 p.m. At this point, the DoD had to review this feedback and make any final changes to the rule before submitting it to the Office of Information and Regulatory Affairs (OIRA) for regulatory review. The rule was expected to go before Congress in mid-October, but this did not happen.

July 22, 2025: 48 CFR rule submitted to OIRA

On July 22, 2025, the DoD submitted the final 48 CFR Acquisition Rule to the Office of Information and Regulatory Affairs (OIRA), a part of the Office of Management and Budget (OMB), for review. Included in the submission was clause 204.7503, which stated that CMMC requirements must be included in all applicable solicitations and contracts awarded after October 1, 2025.

This turned out to be an old reference from CMMC 1.0 and has officially been removed. While the exact date remained pending at this time, the CyberAB's August Town Hall said that this rule would likely be published in the Federal Register by end of September and that CMMC would become enforceable before the end of 2025. This was in line with an earlier estimate from the July CyberAB Townhall, which said it could appear as early as the fall.

Spoiler alert: they were right.

August 25, 2025: 48 CFR rule clears regulatory review

As of August 25, 2025, OIRA cleared the final 48 CFR rule and began preparing it for final publication in the Federal Register.

OIRA cleared DFARS case screenshot

Source: Open DFARS Cases as of 8/29/2025

September 10, 2025: 48 CFR rule published as final in Federal Register

On September 9, 2025, the Department of Defense's 48 CFR rule was submitted to the Office of the Federal Register (OFR) and released for public inspection. The next day, on September 10, 2025, it was officially published in the Federal Register.

This rulemaking milestone was the most important to date. Until now, every CMMC update came with caveats: "when the rule is finalized," "after publication in the Federal Register," "once enforcement begins." By clearing regulatory review and being published in the Federal Register, the enforcement deadline finally became real.

Sixty days after the publication date, on November 10, the 48 CFR rule took effect and the CMMC phased rollout began.

November 10, 2025: Effective date of the CMMC Acquisition rule, which implements the program

On November 10, 2025, both the Title 32 CFR CMMC Program rule and the Title 48 CFR CMMC Acquisition Rule were effective and the contractual requirements in DFARS clause 252.204-7021 revised. Meaning, the DoD began implementing CMMC requirements contractually on November 10, but not all at once. It followed a phased rollout plan designed to implement requirements in four phases over a three-year period, starting with self-assessments and ending with full implementation of all CMMC program requirements.

Starting in Phase 1, DoD contracting officers began inserting CMMC Level 1 and Level 2 self-assessment requirements (which DoD originally estimated would apply to 65% of the DIB) into new solicitations and contracts. At this time, they also had the discretion to insert CMMC Level 2 Certification Assessment (C3PAO) requirements for select contracts involving sensitive information.

In Phase 2, C3PAO certification was meant to become the default for Level 2 contracts. The Department paused that transition on July 13, 2026, along with the Phase 3 and Phase 4 milestones that would have followed. Phase 1 self-assessment requirements were not paused and remain in force.

CMMC Phased Rollout as of July 13, 2026 pause

Recommended reading

CMMC Phase 1 Self-Assessment Guide: Level 1 and Level 2 Requirements

Read More

What would it take to change CMMC? More rulemaking

Changing the CMMC program would likely require another federal rulemaking process, and rulemaking takes years. That single fact is the most useful thing to hold onto while the program is under review.

The Department can pause how it uses the rules it has. It did exactly that on July 13, 2026, when it put the transition to Phase 2 on hold and directed contracting officers to designate only Level 1 (Self) or Level 2 (Self) in the interim period. What it cannot do by memo is rewrite 32 CFR Part 170 or the DFARS 7021 clause that implements it.

Those texts stand as published until an amending rule completes the same process described above: a proposed or interim rule published in the Federal Register, a public comment period, review of comments, a final rule, and an effective date. Even if the DoW were to issue a class deviation, it would only be a temporary bridge between old text and the official start of a new final rule.

That distinction determines how to read three developments in front of the DIB right now.

1. The CMMC Reform Task Force

The Task Force has 60 days to review the CMMC program and comments collected through the public RFI and another 15 to deliver a report with reform recommendations to the DoW CIO, expected around mid-September to early October 2026. Likely what will happen is if the DoW agrees with any recommendations that change the CMMC program requirements, the DoW will introduce those in an amended rule that has to complete a separate rulemaking process to go into effect.

2. NIST SP 800-171 Revision 3

The Fall 2025 Unified Agenda listed RIN 0790-AM01, an interim final rule that would amend 32 CFR Part 170 to move CMMC from Revision 2 to Revision 3 and incorporate DoD values for organization-defined parameters.

As of August 2026, this rule has not been published in the Federal Register, 32 CFR 170 has not been amended, and Class Deviation 2024-O0013 aligning DFARS 7012 with Rev 2 remains in place. The Department's own CMMC FAQs state that it will incorporate Revision 3 through future rulemaking and that the existing class deviation holds Revision 2 in place until then.

The requirement for Revision 3 may be arriving in contracts through a different rule in the meantime. The FAR CUI rule, re-proposed in June 2026 under the Revolutionary FAR Overhaul, would make Revision 3 the baseline for CUI across nearly all federal contracts, including civilian ones. That rule is on its own track and does not amend CMMC. If it finalizes before RIN 0790-AM01 publishes, contractors serving both defense and civilian customers would need to satisfy Revision 2 for their DoD work and Revision 3 for the rest, at the same time.

3. Congressional activity

The FY2027 NDAA contains CMMC provisions in both chambers, including a small business assessment grant program in the Senate bill. Statute can direct the Department to act, but implementing that direction in contracts still runs through the DFARS. Additionally, these provisions are designed to offset the costs of existing requirements in the CMMC program rule (like the third-party assessment), not to overwrite them.

The practical implication for contractors is that the government rollout of assessment requirements may be in flux, but the underlying cybersecurity requirements are not. NIST SP 800-171 Revision 2 has been contractually required under DFARS 252.204-7012 since 2017. Nothing in the current review touches that.

For the dated record of each of these developments as they move, see CMMC News & Updates.

Recommended reading

CMMC News 2026: Every Program Update, Rule Change & Enforcement Action

Read More

Impact of the rulemaking process on defense contractors

The rulemaking process influences how and when defense contractors must comply with CMMC.

Key considerations include:

  • CMMC Phase 1 requirements are in place. Since November 10, 2025, CMMC has been enforced in most new DoD contracts, starting with Level 1 and Level 2 (Self) requirements. Those requirements remain firmly in place despite the July 2026 pause because they sit in rules that were not amended.
  • Third-party verification is the open question. What the pause changed is who checks your work and when. In addition to select government-led assessments, self-assessment with a senior official affirmation is the primary current verification path for new awards, which puts more weight on SPRS accuracy, not less. An inaccurate score or affirmation carries False Claims Act exposure regardless of whether a C3PAO is scheduled to review it.
  • The underlying work has not changed. Contractors and subcontractors seeking to continue doing DoW business still need to define scope, set up a secure environment for CUI, implement all NIST 800-171 Rev 2 requirements and assessment objectives, document and maintain their CMMC policies, SSP, and POA&M, and complete a self-assessment every three years and affirmation every year in SPRS.
  • Primes set their own schedule. The Department paused its own Phase 2 designations. It did not direct primes to drop supplier requirements they imposed for their own risk reasons. According to Redspin's second annual report on the state of DIB CMMC readiness, conducted in late summer 2025, 47% of surveyed organizations had already received flow-down requests from primes. Confirm in writing whether your prime's requirement still stands during the interim period.

Recommended reading

Why Prime Contractors Are Enforcing CMMC Level 2 Ahead of DoD & What It Means For Subcontractors

Read More

This post was originally published in March 2025 and has been updated on August 17, 2026 for accuracy and comprehensiveness.

FAQs

Is CMMC 2.0 rulemaking complete?

Yes. The 32 CFR CMMC Program Rule was finalized in October 2024 and went into effect in December 2024. The 48 CFR Acquisition Rule, which implements CMMC in contracts, was published as final in the Federal Register on September 10, 2025 and went into effect 60 days after publication. On November 10, 2025, the 48 CFR rulemaking process was complete and the DoD began rolling out CMMC self-assessment requirements in most new contracts and Level 2 certification requirements in some high-priority contracts.

Both rules remain in force today. The July 13, 2026 pause of the Phase 2 transition was a policy decision about how the Department applies those rules in solicitations, not an amendment to either one.

What's the difference between an interim and proposed rule for CMMC?

A proposed rule goes into effect after public comments have been reviewed and incorporated, while an interim rule goes into effect before that comment process is complete. CMMC 1.0 was implemented as an interim rule. CMMC 2.0 followed the full proposed rulemaking process.

Would moving CMMC to NIST SP 800-171 Revision 3 require new rulemaking?

Yes. 32 CFR Part 170 incorporates NIST SP 800-171 Revision 2 by reference, so switching to Revision 3 requires amending the rule. The Fall 2025 Unified Agenda listed RIN 0790-AM01 as an interim final rule that would do exactly that, but as of August 2026 it has not been published in the Federal Register. The Department's own FAQs confirm that Revision 3 would be incorporated through future rulemaking. Until it is, Revision 2 is the enforced standard.

Can an organization get CMMC Level 2 (C3PAO) certified while Phase 2 is on hold?

Yes. C3PAO assessments became available in December 2024 when the 32 CFR rule went into effect, and they remain available now. The Cyber AB has confirmed that C3PAO assessments, training, and exams continue to operate during the review. Phase 1 self-assessment requirements remain in force, and Level 2 (C3PAO) certification is currently voluntary rather than a condition of award for new contracts.

Many primes, including Boeing and Lockheed Martin, began requiring evidence of CMMC readiness from subcontractors well before the deadline, and those requirements were set independently of the Department's schedule. If a prime flowdown applies to you, confirm with your buyer before cancelling a scheduled assessment.

Get secure. Stay compliant.

Request a demo
Loading...