lFor defense contractors, the CMMC timeline just changed significantly.
On July 13, 2026, the Department announced the immediate suspension of CMMC Phase 2, which had been scheduled to begin on November 10, 2026. At the same time, the Department launched a comprehensive review of the CMMC program intended to reduce compliance costs and administrative burdens, particularly for small and midsized businesses participating in the Defense Industrial Base.
That does not mean CMMC is going away. It also does not mean defense contractors should stop preparing.
Phase 1 remains in effect, NIST SP 800-171 requirements continue to apply, and contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) still have cybersecurity obligations that can directly affect their ability to compete for and maintain Department contracts.
For organizations that have been preparing for CMMC certification, the latest changes create additional time, but they also create a period of uncertainty that needs to be managed carefully.
What Changed With CMMC Phase 2?
CMMC implementation began on November 10, 2025, when the revised DFARS requirements became effective and CMMC assessment requirements began appearing in applicable procurements.
The next major milestone was supposed to arrive on November 10, 2026, with the transition to Phase 2.
That transition has now been suspended.
During the suspension, contracting programs may require CMMC Level 1 self-assessments or CMMC Level 2 self-assessments, but they are not currently permitted to designate Level 2 C3PAO assessments or Level 3 DIBCAC assessments as requirements. The Department has also directed contracting personnel to remove those higher-level assessment requirements from affected active solicitations and contracts as applicable.
This is an important distinction. The government is temporarily stepping back from expanding mandatory third-party certification requirements, but it is not stepping back from cybersecurity compliance itself.
CMMC Phase 1 Is Still Active
Organizations should not interpret the Phase 2 suspension as permission to put their CMMC programs on hold.
The Department has specifically stated that all Phase 1 self-assessment requirements remain in place. During this period, compliance will continue to be enforced through self-assessments and selected government-led assessments.
For companies dealing only with FCI, CMMC Level 1 requires an annual self-assessment against the basic safeguarding requirements associated with FAR 52.204-21, along with an affirmation of compliance.
For organizations handling CUI, CMMC Level 2 remains based on the 110 security requirements of NIST SP 800-171 Revision 2. Under the current Phase 1 structure, Level 2 self-assessments are conducted every three years, with an affirmation of continued compliance required annually.
Assessment information is maintained through the Supplier Performance Risk System, or SPRS. When CMMC is required by a solicitation, contracting officers use SPRS to verify that the contractor has an appropriate current CMMC status for the information systems involved in performing the contract.
In other words, CMMC is already affecting the contracting process.
NIST SP 800-171 Is Still the Standard to Focus On
Another source of confusion involves the transition from NIST SP 800-171 Revision 2 to Revision 3.
For CMMC purposes, Revision 2 remains the assessment standard today.
The Department has stated that Revision 3 will eventually be incorporated into CMMC through future rulemaking. Organizations may begin implementing Revision 3, but current CMMC assessments continue to evaluate compliance against Revision 2 until the applicable regulations are updated.
That makes the 110 requirements within NIST SP 800-171 Revision 2 particularly important for organizations currently preparing for Level 2.
Businesses should know not only whether security technologies are installed, but whether the required controls are actually implemented throughout the environment and whether the organization can demonstrate that implementation.
Why Was Phase 2 Suspended?
The Department has said the current CMMC structure created excessive compliance costs and administrative burdens, particularly for smaller and nontraditional defense contractors.
It also identified concerns about the capacity of the third-party assessment ecosystem. Department officials said there were not enough available assessors to complete the volume of assessments that would have been necessary before the November 2026 Phase 2 deadline.
A CMMC Reform Task Force has now been established to conduct a comprehensive review of the program. The Department announced a 60-day review process that includes industry feedback and a public Request for Information. The goal is to identify a cybersecurity model that maintains meaningful protections while making compliance more scalable for organizations throughout the Defense Industrial Base.
As of August 2026, that review is still underway.
That means additional changes to CMMC should be expected.
Should You Stop Preparing for CMMC Certification?
For most defense contractors, the answer is no.
The Phase 2 suspension gives organizations additional time before mandatory C3PAO assessments become more broadly required, but the underlying cybersecurity requirements have not disappeared.
DFARS 252.204-7012 remains in effect for applicable contracts, and the Department has explicitly stated that defense contractors and subcontractors remain obligated to safeguard covered defense information.
Companies that use the delay to improve their security posture may actually be in a stronger position when the revised certification structure is announced.
This is an opportunity to make sure systems containing FCI or CUI are properly identified, the CMMC assessment boundary is understood, NIST SP 800-171 controls are actually implemented, documentation reflects the real environment, security gaps are being remediated, and ongoing monitoring processes are established.
Waiting until a certification requirement appears in a solicitation can leave very little time to correct problems.
CMMC Is More Than an IT Checklist
One of the biggest challenges with CMMC is that organizations can have strong IT systems and still struggle with compliance.
CMMC evaluates whether required cybersecurity practices are implemented within the defined environment. That involves technology, but it also involves processes, documentation, user access, identity management, configuration management, logging, incident response, data handling and ongoing security operations.
A company may have firewalls, endpoint protection and multifactor authentication and still discover significant gaps when its environment is evaluated against all applicable NIST SP 800-171 requirements.
That is why preparation should begin with understanding where FCI and CUI exist and how that information moves through the organization.
Reducing the number of systems that process or store CUI can also significantly reduce the complexity of the CMMC environment.
How Affant Can Help Organizations Prepare
The changing CMMC schedule makes it even more important to build a cybersecurity program around the underlying requirements rather than around a single certification deadline.
Affant helps businesses evaluate and strengthen the IT environments that support CMMC readiness. That can include reviewing infrastructure, identifying security gaps, strengthening identity and access controls, implementing multifactor authentication, improving endpoint and network security, establishing monitoring and logging, protecting backups and helping organizations maintain a more controlled technology environment.
For organizations working toward CMMC Level 2, the objective should be an environment that can continuously support the requirements of NIST SP 800-171, not one that is hurriedly adjusted immediately before an assessment.
CMMC requirements may continue to evolve, but strong cybersecurity fundamentals will remain important regardless of what the final certification process looks like.
The Bottom Line
The November 2026 CMMC Phase 2 deadline has been suspended, but CMMC compliance has not been suspended.
Phase 1 remains active. Level 1 and Level 2 self-assessments can still be required. NIST SP 800-171 Revision 2 remains the current Level 2 standard, and applicable contractors remain responsible for protecting government information.
The Department’s ongoing review may change how certification is handled in the future, particularly when it comes to third-party assessments. Until that process is complete, businesses should view the delay as additional preparation time rather than a reason to stop preparing.
If your organization works with the Department or participates in the Defense Industrial Base, Affant can help you understand your current IT security posture, identify gaps and build an environment designed to support CMMC readiness.
Don’t wait for the next CMMC deadline to find out whether your environment is ready.









