CMMC Phase 2 Is Paused. Here’s What Small Defense Suppliers Still Have to Do.

Short answer: the Department of War has paused the requirement for third-party (C3PAO) CMMC certifications, but nothing you already owe the government has gone away. If you handle Controlled Unclassified Information (CUI), you still need to meet NIST SP 800-171, keep an accurate SPRS score, and affirm it every year.

Who this is for

Owners and managers of small manufacturers, machine shops, and service companies that supply DoD or a defense prime, and who have heard “CMMC is on hold” and want to know what that really means.

What happened

CMMC rolled out in phases. Phase 1 began November 10, 2025, and required self-assessments. Phase 2 was set to begin November 10, 2026, and would have required most contractors handling CUI to get certified by an outside assessor (a C3PAO).

On July 13, 2026, the Department of War suspended Phase 2 and later milestones while a CMMC Reform Task Force reviewed the program, citing cost and the burden on small businesses. On September 3, 2026, a class deviation made the pause binding on contracting officers. The Task Force’s 60-day review closed in mid-September; as of early October, its report has not been made public.

What is paused

  • New requirements for Level 2 (C3PAO) third-party certification
  • Level 3 (government-led) assessment requirements
  • The November 10, 2026 Phase 2 start date

What still applies

  • DFARS 252.204-7012: safeguard CUI, report cyber incidents within 72 hours
  • NIST SP 800-171 Rev. 2: all 110 security requirements
  • DFARS 252.204-7019 and -7020: a current NIST SP 800-171 assessment score posted in SPRS
  • CMMC Level 1 and Level 2 self-assessments where your contract requires them, plus the annual affirmation by a senior company official
  • Your prime’s flowdown requirements. Many primes are still asking suppliers for scores and SSPs.

Why “paused” doesn’t mean “safe to wait”

Your score is a legal statement. When you post an SPRS score and affirm compliance, you’re telling the government something it relies on when awarding contracts. Overstating it can create False Claims Act exposure, and that risk exists with or without Phase 2. The Department of Justice has continued to settle cybersecurity cases with defense contractors in 2026.

Primes haven’t paused. Large primes still have to manage risk in their supply chains. Expect questionnaires, requests for your SSP, and score checks to continue.

Phase 2 may come back in a new form. The Department has said the goal is to reduce cost and paperwork, not cybersecurity. Whatever comes next will almost certainly still be built on NIST SP 800-171. Work you do now isn’t wasted.

Readiness takes months. If third-party assessments return with short notice, companies that waited will be scrambling for the same limited pool of assessors.

What to do now: a five-step checklist

  1. Read your contracts. Look for DFARS 252.204-7012, -7019, -7020 and -7021. They tell you whether you handle CUI and which CMMC level applies.
  2. Find your CUI. Where does it arrive, where is it stored, and who can reach it? A smaller footprint means less to protect.
  3. Write or update your System Security Plan (SSP). Without one, you can’t have a valid assessment.
  4. Score yourself honestly against all 110 requirements, and build a Plan of Action & Milestones (POA&M) for the gaps.
  5. Fix the high-value gaps first. Multi-factor authentication, encryption, logging, and access control carry the most weight.

Common mistakes

  • Assuming the pause cancels SPRS and the annual affirmation (it doesn’t)
  • Posting a score from an old or informal review
  • Treating the SSP as a policy binder instead of a description of how your systems actually work
  • Waiting for a prime to ask before starting

Not sure where you stand?

I help small defense suppliers get an honest SPRS score, a real System Security Plan, and a clear plan to close the gaps, at a small-business price. I’m a CMMC Registered Practitioner and Service-Disabled Veteran with 20+ years in DoD cybersecurity.

Book a free 20-minute call: (770) 315-1839, or see the CMMC Readiness Package.

This article reflects public information as of October 2026 and is not legal advice.

Sources

Leave a comment