CMMCpedia Download

CMMCpedia

CMMC program status

Official Source Material

This page tracks the status of the rollout of CMMC, the Cybersecurity Maturity Model Certification. It carries what the Department of War has announced, quoted and cited. It is updated when the Department acts. Last reviewed August 25, 2026.

Phase 2 is suspended

On July 13, 2026 the Department of War announced the immediate suspension of the CMMC Phase 2 requirements. Those requirements were scheduled to take effect on November 10, 2026. The announcement states: "Effective immediately, the Department will suspend the transition to Phase II requirements of CMMC, as well as pending and future CMMC implementation milestones across the Department of War solicitations and contracts."

Phase 2 is the phase in which the Department begins including Level 2 (C3PAO) as a condition of award in applicable solicitations. Level 2 (C3PAO) is the status earned through an assessment by a CMMC Third-Party Assessment Organization. The suspension stops certification requirements from entering solicitations and contracts while the Department reviews the program.

What still applies

The announcement is explicit that the suspension does not change your obligation to protect federal information:

  • Phase 1 remains in force. The announcement states that "all Phase I self-assessment requirements remain firmly in place." Level 1 (Self) and Level 2 (Self) statuses continue exactly as before. So do your entries in SPRS, the Supplier Performance Risk System, and your annual affirmations.
  • DFARS clause 252.204-7012, the defense contract clause that requires you to safeguard covered defense information, still binds you. The announcement states that "all defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012."
  • NIST SP 800-171 Revision 2, the publication that lists the security requirements, is still the standard. During the review the Department "will enforce cybersecurity compliance with the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments."
  • The program rule, 32 CFR part 170, remains on the books. The Department suspended implementation milestones. It did not rescind the rule, and no rulemaking to change it has been published.

The reform review

The Department CIO established a CMMC Reform Task Force to review the program. The task force also works through industry feedback from a public Request for Information. The comment window on that Request for Information closed on August 14, 2026. The task force delivers its final report to the Department CIO within 60 days of the announcement. That clock runs out in mid-September 2026. The Department has not said how it will issue any change. It has not said when certification requirements will return, in what form, or whether they will.

The Department announced the suspension by news release. The memoranda that put the suspension into effect are not on any public Department site. This page cites the release, and it will cite the memoranda if the Department publishes them. The Department CIO's CMMC resources page carries the same suspension notice and now lists the DFARS 252.204-7021 clause reference as TBD.

What this changes on this site

The guidance chapters state the program rule as written, because the rule is unchanged. The suspension changes when the Department demands a CMMC status, not what a status requires. What is CMMC and Which level applies note the suspension where the rollout schedule matters.

Sources

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.