On July 13, 2026, the Department of War (DoW) suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, four months before it was due to start on November 10. Phase 2 would have made a Level 2 certification assessment by a C3PAO a condition of award on applicable contracts. That requirement is on hold while a CMMC reform task force reviews the program.
Phase 1 began on November 10, 2025, and still applies. In DoW’s words, “All Phase I self-assessment requirements remain firmly in place.”
What you still owe
While the program is paused in Phase 1, CMMC asks for self-assessments at two levels:
- Level 1: a self-assessment every year, with an annual affirmation.
- Level 2: a self-assessment every three years, with an annual affirmation.
The CMMC clause in each contract, DFARS 252.204-7021, sets which of these applies to you.
During the pause, DoW says it “will enforce cybersecurity compliance with NIST 800-171 Rev 2 through self-assessments and select government-led assessments,” so your self-assessment may be checked against the systems it describes.
What the suspension does not change
The suspension is a DoW announcement. The CMMC rule itself, 32 CFR Part 170, still sets out the original phase schedule: when we checked on October 7, 2026, the eCFR showed no amendment to that section since December 2024. DoW has not said what will follow the task force’s review.
The rule’s Level 2 scoring has not changed either:
- An assessment scores all 110 requirements of NIST SP 800-171 Rev. 2, for a maximum of 110.
- Each requirement you have not met subtracts 1, 3 or 5 points, and the score can go below zero.
- Partial credit exists only in a few cases, such as multifactor authentication (3.5.3).
A Conditional Level 2 status lets you finish some work after the assessment, within limits. You need a score of at least 88. Only one-point requirements can stay open on the POA&M, with one exception for CUI encryption that is not FIPS-validated (3.13.11). Six requirements, among them the System Security Plan (3.12.4), cannot be on the POA&M at all, and everything open must close within 180 days.
The scope covers your security tools too. Systems that protect CUI are in scope even when they do not store it.
What to do now
- Check the DFARS 252.204-7021 clause in your current contracts and in any you are bidding on, and note the level each one requires.
- Re-run your Level 2 self-assessment the way the rule scores it: all 110 requirements, the full value subtracted for each one you have not met, and a check on whether your open items would qualify for a Conditional status. Each annual affirmation says you have implemented the requirements and will keep them in place, so the assessment behind it has to hold up.
- Close the five-point and three-point gaps first. Apart from the CUI encryption exception, they cannot sit on a POA&M for a Conditional status.
- Keep the System Security Plan current, since it must be met outright.
- Draw the scope with your security tools in it. Identity, logging and endpoint protection that protect CUI are assessed along with the systems they protect.
- Prepare for a C3PAO assessment anyway. The rule still contains Phase 2, and contractors who are ready when DoW announces its next step won’t be starting over.
How we can help
Automata runs Level 2 readiness assessments against all 110 requirements, scored the way 32 CFR 170 scores them, and then closes the gaps alongside your team. The details are on our CMMC page.
Sources
All checked October 7, 2026.
- DoW CIO, About CMMC: the July 13, 2026 suspension, the task force, and the Phase 1 self-assessment and affirmation schedule.
- 32 CFR Part 170: phases (§ 170.3), Level 2 requirements (§§ 170.14, 170.16–17), assessment scope (§ 170.19), POA&M conditions (§ 170.21), affirmations (§ 170.22) and scoring (§ 170.24).
- DFARS final rule, 90 FR 43560: Phase 1’s start on November 10, 2025.
- DFARS 252.204-7021: the CMMC contract clause.