Cyber One Solutions logo.
Get Support

CMMC

CMMC Phase 2 Is Suspended, Not Gone: What Defense Contractors Still Owe Under Phase 1

Published August 23, 2026 · Cyber One Solutions

The Pentagon paused CMMC Phase 2 certification on July 13, 2026, and comment on its reform review closed August 14. Phase 1 and DFARS duties never stopped.

On August 14, 2026, the public comment period closed on the Department of Defense's Request for Information on reforming the Cybersecurity Maturity Model Certification (CMMC) program, the formal review step the Pentagon launched after it suspended CMMC Phase 2's third-party certification requirement on July 13, 2026. Reporting from DefenseScoop and a client alert from WilmerHale describe how Department of Defense Chief Information Officer Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey jointly paused the requirement that would have forced many contractors handling Controlled Unclassified Information to pass an outside assessment before winning new work. Cyber One Solutions covered the incoming Phase 2 requirement in a July 13 brief built around its planned November 10, 2026 start date. That start date no longer applies, and the responsible reaction is not to relax but to confirm exactly which obligations are still active.

Why This Matters for Defense Contractors and Subcontractors

The suspension does not reach every Department of Defense contractor. Phase 2's third-party certification was only ever going to apply to contracts and subcontracts whose solicitation specified Level 2 (C3PAO) certification, the outside-assessment tier the Department reserves for the highest-risk Controlled Unclassified Information work. CUI work assigned Level 2 (Self) was never moved to a third-party requirement in the first place and stays self-assessed either way. Within that narrower Level 2 (C3PAO) group, including aerospace and manufacturing subcontractors around the Houston-Clear Lake corridor near NASA Johnson Space Center, engineering and logistics firms across the Dallas-Fort Worth defense corridor, and smaller machine shops or IT integrators anywhere in the 48-state defense industrial base whose contract specifies that certification tier, the specific outside-assessment requirement many were expecting this fall is now paused, but the underlying cybersecurity obligation was never eliminated.

According to DefenseScoop, Davies pointed to a capacity and cost mismatch, noting that more than 100,000 defense industrial base companies would need third-party assessments while only roughly 100 approved assessors exist to perform them, and concluding that "the math just simply doesn't math for small to medium-sized businesses to even get compliant by the transition date." DefenseScoop also reported that during this interim period the Department will enforce cybersecurity compliance through the NIST SP 800-171 Revision 2 standard using self-assessments and selected government-led assessments, which is the clearest statement available that the security baseline itself did not move. A client alert from WilmerHale reaches the same conclusion on the contract side, confirming that Phase 1 self-assessment requirements for CMMC Level 1 and Level 2 remain in place, that DFARS clause 252.204-7012 continues to require safeguarding covered defense information, and that annual affirmation through the Supplier Performance Risk System (SPRS) is unchanged.

The cost of guessing wrong in either direction is real. Federal News Network interviewed the leadership of a small defense contractor that completed its Level 2 certification before the pause, who described a four month effort, more than 50 new policy documents, a migration of Controlled Unclassified Information into a compliant cloud environment, and an investment the company put at more than $200,000, undertaken largely because prime contractors were already pushing the requirement down to subcontractors. Their frustration is understandable, but the underlying work is not wasted, because the documentation and controls they built are what NIST SP 800-171 requires regardless of who verifies them. WilmerHale's alert also cautions that the review leaves significant uncertainty about CMMC's future structure, which means a third-party requirement could return on a different timeline or in a different form once the CMMC Reform Task Force completes the roughly 60 day review it began in mid-July, informed by the Request for Information the U.S. Small Business Administration's Office of Advocacy flagged ahead of its August 14, 2026 deadline.

What It Means for Your Obligations

Confirm what your specific contract or subcontract currently requires rather than assuming the pause changed it automatically. Purchasing activities are directed to amend solicitations and modify existing contracts that carried Phase 2 language, but that removal happens contract by contract, not all at once.

If your contract or subcontract specifically imposes CMMC Level 1, confirm that obligation is current: a self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21, with the result recorded as MET or NOT MET in the Supplier Performance Risk System, plus the separate annual affirmation your designated affirming official must submit. Handling Federal Contract Information alone does not automatically trigger these submissions; check the specific solicitation or contract clause that does.

If your contract or subcontract specifically imposes CMMC Level 2, keep that System Security Plan and Plan of Action and Milestones current against all 110 NIST SP 800-171 Revision 2 controls, along with the numeric score those documents produce in the Supplier Performance Risk System. DFARS 252.204-7012 keeps this documentation load-bearing regardless of whether the assessment method is self-assessment or a third-party review, and self-affirmation is a binding representation to the government, not a form you file once and forget.

Keep an accurate, current inventory of every system, cloud service, and vendor that stores, processes, or transmits Controlled Unclassified Information. The suspension changed how compliance gets verified; it did not change what falls in scope.

Preserve the access control, logging, and incident response evidence a C3PAO assessor would have asked for. If the Reform Task Force reinstates a third-party requirement with a different structure, contractors with continuously maintained evidence will be ready and contractors who let controls lapse during the pause will not.

Confirm with your prime contractor, in writing, whether any Phase 2 language was actually removed from your subcontract. DFARS 252.204-7021 obligates primes to flow down the correct requirement, but it does not obligate them to volunteer that a change occurred.

If your organization already completed or scheduled a C3PAO assessment before the pause, keep that documentation and keep the underlying controls operating. Nothing in the Department's guidance suggests the security standard itself is being lowered, only how and when outside verification of it will be required.

The Bottom Line

A suspended assessment mechanism is not the same thing as an eliminated cybersecurity obligation. Phase 1 self-assessment, DFARS 252.204-7012, and NIST SP 800-171 Revision 2 are all still fully enforceable, and the Reform Task Force's recommendations could reset the third-party certification timeline on short notice once its review concludes. Contractors who keep their System Security Plan, self-assessment score, and vendor confirmations current during the pause are the ones who will not be scrambling when it ends. This brief is general security and compliance awareness, not legal or contracting advice, and Cyber One Solutions does not currently offer CMMC compliance services, including certification, C3PAO assessments, or CMMC-specific readiness consulting. Our separate managed cybersecurity offering provides general security operations, including multi-factor authentication, endpoint detection, audit logging, and access control, but it is not a substitute for a scoped CMMC program or assessment. Contractors in the Houston area supporting the Johnson Space Center supply chain who need CMMC-specific guidance should engage a qualified CMMC provider and accredited assessor.

Sources