CMMC Phase 2 Is Suspended: What Still Applies to Your Contracts
DoD paused Phases 2 through 4 on July 13 pending a reform review. What it did not pause: the Phase 1 self-assessment in force since November 2025, the DFARS safeguarding duty you have carried since 2017, and False Claims Act exposure for an attestation that is not true.
By Uniqcli Team · · 7 min read
Key takeaways
- DoD suspended CMMC Phases 2, 3 and 4 on July 13, 2026 — including the Nov 10, 2026 C3PAO milestone — pending a Reform Task Force review, with no replacement dates announced.
- Phase 1 was not suspended: self-assessment requirements in new solicitations, SPRS scores and senior-official affirmations have been in force since November 10, 2025.
- DFARS 252.204-7012 has required NIST SP 800-171 implementation and 72-hour incident reporting since 2017, independent of CMMC and unaffected by the pause.
- False Claims Act exposure did not move: DOJ recovered more than $52M across nine cybersecurity FCA settlements in FY2025, including Raytheon at $8.4M; LOGZONE settled separately for $507,144 in June 2026.
- The suspension pauses the audit calendar, not the controls — FIPS crypto, replay-resistant MFA, segmentation and media protection remain lead-time hardware line items today.
On this page
Compliance
The audit calendar moved. The contract clauses did not.
On July 13, 2026, the Department of Defense suspended Phases 2, 3 and 4 of the CMMC rollout — including the November 10, 2026 milestone that would have made third-party Level 2 certification the default in applicable solicitations — pending a review by a newly convened CMMC Reform Task Force. If you read that as a reprieve from cybersecurity requirements, read the contract you already signed. Phase 1 has been in force since November 10, 2025 and was not touched. The DFARS safeguarding clause that predates CMMC by eight years was not touched. And the exposure that has actually cost contractors money so far — the False Claims Act, not a failed assessment — was not touched either. This piece separates what is genuinely paused from what still binds you today.
What DoD actually suspended on July 13
The suspension covers the phased implementation schedule that the CMMC program rule at 32 CFR Part 170 laid out and the DFARS acquisition rule operationalized. Phase 2 — scheduled to begin November 10, 2026, and the point at which CMMC Level 2 certification by a Certified Third-Party Assessment Organization (C3PAO) would have become a condition of award in applicable solicitations — is on hold. So are Phase 3 (2027) and Phase 4 (2028), along with the pending milestones attached to them.
The stated reason is a review. DoD stood up a CMMC Reform Task Force with roughly 60 days to report, and issued a request for information to collect industry input; the comment window runs to August 14, 2026, and a report is expected around mid-September 2026. No replacement dates have been announced, and the department has not described what the program looks like on the other side.
There is one operational consequence contractors will see immediately: contracts and solicitations already carrying Level 2 C3PAO or Level 3 requirements are to be modified to remove them. If you are mid-capture on a bid that named a C3PAO certificate, expect an amendment. If you are already under contract with one of those clauses, expect a modification — but confirm it in writing with your contracting officer rather than assuming it happened.
We are not going to speculate about what the task force recommends, and neither should anyone quoting you hardware. In July 2026 a prediction about Phase 2's return is a prediction, not a planning input.
Paused versus still in force
Four items, two columns of reality. The left-hand pair is what changed on July 13. The right-hand pair is what did not, and it is the pair that governs what you owe a contracting officer this quarter.
Paused — Phase 2 (was Nov 10, 2026)
C3PAO Level 2 certification as the default condition of award in applicable solicitations. Suspended July 13, 2026, with no replacement date announced.
Paused — Phases 3 and 4 (2027, 2028)
Level 3 requirements appearing in applicable solicitations, then full implementation across all applicable contracts including options and renewals. Both suspended alongside Phase 2.
In force — Phase 1 (since Nov 10, 2025)
Self-assessment requirements in new solicitations, recorded in SPRS with a senior-official affirmation of continuous compliance. Untouched by the suspension.
In force — DFARS 252.204-7012 (since 2017)
The safeguarding clause requiring NIST SP 800-171 implementation and 72-hour cyber incident reporting. It never depended on CMMC and does not pause with it.
Phase 1 is the part that still names a number
Phase 1 has been in effect since November 10, 2025 — the effective date of the DFARS acquisition rule published September 10, 2025 under DFARS Case 2019-D041, which added clause 252.204-7021 and provision 252.204-7025. Under Phase 1, DoD may require a Level 1 or Level 2 self-assessment in new solicitations, with the result posted in the Supplier Performance Risk System and affirmed by a senior official. That requirement is unaffected by the July 13 suspension.
Level 1 applies to contractors handling Federal Contract Information only. It is 15 requirements drawn from FAR 52.204-21, self-assessed annually, affirmed in SPRS, and scored strictly MET or NOT MET — no Plan of Action and Milestones is permitted. If you have seen '17 practices' written somewhere, that is the 2021-era framing that stuck around on the open web; 32 CFR 170.15 says 15.
Level 2 applies to contractors handling Controlled Unclassified Information and is 110 requirements mapped one-to-one to NIST SP 800-171 Rev 2, assessed against 320 objectives. Whether a given contract calls for self-assessment or C3PAO certification depends on what the solicitation specifies. The scoring model is unchanged: you start at 110, the floor is -203, a score of 88 or better supports Conditional Level 2 status with a POA&M, 110 with no POA&M is a Final status, and Conditional status carries a 180-day closeout clock.
The revision you are assessed against did not move either. DoD Class Deviation 2024-O0013 pins the requirement to NIST SP 800-171 Rev 2. Rev 3 timing remains uncertain, and putting a date on it in a procurement plan would be inventing one.
The duty that predates CMMC by eight years
CMMC is an assessment and verification layer. It is not the source of the underlying obligation. DFARS 252.204-7012 has required contractors handling covered defense information to implement NIST SP 800-171 and to report cyber incidents within 72 hours since 2017. Suspending phases of a verification program does not suspend a safeguarding clause sitting in contracts you have already signed.
That distinction matters more than usual right now, because the enforcement that has actually cost contractors money has not arrived through failed assessments. It has arrived through the False Claims Act — specifically, the theory that representing compliance you do not have is a false claim for payment. DOJ recovered more than $52 million across nine cybersecurity False Claims Act settlements in fiscal year 2025.
The settlements are not confined to primes. Raytheon agreed to pay $8.4 million to resolve allegations that it failed to meet cybersecurity requirements on DoD contracts. In June 2026, LOGZONE settled for $507,144. The dollar figures differ by two orders of magnitude; the exposure model does not. A senior official's affirmation in SPRS is a representation to the government, and it does not become less of one because the audit that would have checked it has been postponed.
recovered by DOJ across nine cybersecurity False Claims Act settlements in fiscal year 2025
Level 2 requirements mapped one-to-one to NIST SP 800-171 Rev 2, assessed against 320 objectives — unchanged by the suspension
LOGZONE False Claims Act settlement, June 2026
Phase 1 effective date. Self-assessments and SPRS affirmations have been in force since — and were not suspended
Six moves that are correct regardless of what the task force reports
None of these depend on knowing when — or whether — Phase 2 returns. All of them are things a contracting officer, an inspector general, or a relator's attorney could ask about tomorrow.
- Confirm in writing with your contracting officer whether a solicitation or contract carrying a Level 2 C3PAO or Level 3 requirement is being amended. Do not infer a modification from a press release.
- Keep your SPRS score current and your senior-official affirmation on the calendar. Phase 1 runs on its own clock, and a stale affirmation is the easiest finding in the file.
- Re-run your NIST 800-171 Rev 2 self-assessment against evidence rather than memory. A score that reflects aspiration instead of deployment is the exact shape the False Claims Act cases have taken.
- Work your POA&M as if a 180-day closeout clock applies — because for anyone who reaches Conditional status it does, and because an open item is a real gap regardless of who is checking it.
- Close the hardware-dependent gaps now, while the calendar is soft. FIPS-validated cryptography, replay-resistant MFA, boundary and segmentation gear and media protection are lead-time items, not paperwork items.
- Treat any pitch that reads 'CMMC is cancelled, stand down' as disqualifying. Phases 2 through 4 are suspended pending a review; the department has not withdrawn the program or the underlying requirements.
The suspension pauses the audit calendar, not the controls
Here is the practical translation. What DoD moved is the date on which someone else checks your work. What it did not move is the work. A boundary that is not segmented, a CUI share that is not encrypted with a validated module, an administrator account reachable with a password and a texted code — those are contract gaps today, under a clause in force since 2017, whether or not a C3PAO is ever scheduled.
A meaningful share of them are hardware gaps, and hardware gaps have lead times that paperwork does not. FIPS-validated cryptography where cryptography protects CUI (3.13.11), encryption of CUI at rest (3.13.16), boundary protection at every external interface (3.13.1), replay-resistant multifactor authentication for network and privileged access (3.5.3), media protection across removable devices (3.8.x) — each ends in a line item on a purchase order, and each takes longer to procure, stage and deploy than it takes to write the policy describing it.
To be explicit about what buying does and does not do: no purchase — hardware, license or service — confers certification on its own, and what a supplier can do is make the controls implementable. There is no CMMC-certified switch, drive or firewall, and a datasheet claiming otherwise is describing something that does not exist. What we quote is the capability behind the control — the equipment, the software licensing that runs on it and the integration work around both — never a Uniqcli certification, and we quote against the SSP you already have, not a generic bundle.
Questions contractors are asking this month
Does the July 13, 2026 suspension mean I can stop working on CMMC?
No. DoD suspended Phases 2, 3 and 4 — the milestones that would have brought C3PAO Level 2 certification and Level 3 into solicitations — pending a CMMC Reform Task Force review. Phase 1, in force since November 10, 2025, was not suspended: DoD may still require Level 1 or Level 2 self-assessments in new solicitations, recorded in SPRS with a senior-official affirmation. Separately, DFARS 252.204-7012 has required NIST SP 800-171 implementation and 72-hour incident reporting since 2017, independent of CMMC entirely.
I'm bidding on a solicitation that requires a Level 2 C3PAO certificate. What happens now?
DoD has indicated that contracts and solicitations already carrying Level 2 C3PAO or Level 3 requirements are to be modified to remove them. In practice that is an amendment you should expect but not assume — get the change confirmed in writing by the contracting officer before you rework your capture plan, and keep the self-assessment path current in the meantime, because Phase 1 still applies to new solicitations.
When will Phase 2 restart?
No new dates have been announced. DoD gave the CMMC Reform Task Force roughly 60 days from the July 13 suspension, with an RFI comment window running to August 14, 2026 and a report expected around mid-September 2026. Anything more specific than that is speculation, and planning around a guessed date is how contractors end up short on lead-time items when a schedule firms up.
If nobody is auditing right now, what is the real risk of a self-assessment that overstates my posture?
The False Claims Act. An SPRS score and a senior official's affirmation are representations to the government, and DOJ has been settling cases on exactly that theory — more than $52 million across nine cybersecurity False Claims Act settlements in fiscal year 2025, including an $8.4 million Raytheon settlement. The pattern has continued since: LOGZONE settled for $507,144 in June 2026. The suspension changed who checks and when. It did not change what you asserted.
Keep reading
Related on CMMC and 800-171
Close the lead-time gaps while the calendar is soft
Send the control gaps from your SSP or gap assessment and we'll turn them into a priced, availability-checked bill of materials — equipment, the licensing that runs on it and any staging work it needs. The capability behind the control, never a certification claim.