Uniqcli

InsightsCompliance

CMMC Phase II Is Suspended: What Contractors Still Owe

CMMC Phase 2 (Phase II) was suspended on July 13, 2026, but the Department did not suspend the cybersecurity clauses already in contracts, Phase I self-assessments, SPRS reporting, or the obligation to give the government accurate representations. Treat the pause as time to improve evidence and scope—not permission to stop.

By Uniqcli Team · · 10 min read · Updated

Aerial view of the Pentagon complex with the Potomac River and parking areas beyond.
Aerial view of the Pentagon complex with the Potomac River and parking areas beyond.

Key takeaways

  • CMMC Phase II’s planned November 10, 2026 start is suspended. Phase I remains in force, according to the Department’s current CMMC page.
  • Existing FAR and DFARS duties still turn on the actual solicitation and contract. A program announcement does not rewrite an awarded clause.
  • The Department says it will continue enforcing NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments during the pause.
  • Contractors should preserve assessment evidence, annual affirmations, SPRS records, system security plans, and remediation records even if a certification date moved.
  • Buyers should stop treating a product label as CMMC evidence. The evidence is the configured system, its boundary, the people operating it, and records showing that practices work.
  • The safest planning assumption is that official direction may change again. Assign an owner to monitor the CMMC site, acquisition regulations, and active solicitations.
On this page

Compliance

The short answer: the certification calendar moved, not the security obligation

The phrase “CMMC Phase II suspension” can sound broader than it is. On July 13, 2026, the Department announced the immediate suspension of Phase II requirements that had been scheduled to begin on November 10, 2026. The Department also said Phase I self-assessment requirements remain in place and that implementation is paused in Phase I while a reform task force reviews the program.

That is a meaningful procurement change. Some solicitations expected to require a Level 2 certification during Phase II may not follow the former timeline. It is not, however, a blanket release from every cybersecurity term in an existing contract. The Department’s own CMMC materials say the pause does not eliminate the requirement to protect information under DFARS 252.204-7012. A contractor must still read the clauses incorporated into each solicitation and award, determine the information it handles, and meet the obligations attached to that work.

The practical distinction is simple: CMMC is an assessment and contracting mechanism, while safeguarding requirements can arise from clauses and standards that exist independently of the current phase schedule. Moving an external assessment milestone does not make controlled unclassified information less sensitive. It also does not make a prior self-assessment, affirmation, or representation disposable.

What the Department confirmed on July 13, 2026

The official announcement contains several points that procurement and security teams should record without embellishment.

First, Phase II was suspended before its scheduled November 10 start. Second, all Phase I self-assessment requirements remain in place. Third, the Department began a review intended to reduce compliance burdens while retaining cybersecurity outcomes. Fourth, during the interim period, the Department said it would enforce NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments.

Those are confirmed statements. What happens after the review is not yet confirmed. A revised phase structure, different assessment thresholds, or other implementation changes may be plausible, but they are forecasts until the Department publishes them. A responsible internal memo should separate the announcement from interpretation:

  • Confirmed: Phase II requirements are suspended; Phase I continues.
  • Confirmed: the Department is reviewing the CMMC program.
  • Confirmed: NIST SP 800-171 Revision 2 enforcement continues through the mechanisms described by the Department.
  • Not yet confirmed: the final design, dates, or burden of a reformed program.

This discipline matters because teams often convert a proposal or public comment into a procurement assumption. Until a final rule, class deviation, clause update, or solicitation instruction says otherwise, the operative document is the one attached to the transaction in front of you.

What Phase I still asks contractors to do

The Department’s current CMMC overview describes Phase I as beginning November 10, 2025. Where applicable, solicitations can require Level 1 or Level 2 self-assessment as a condition of award. The precise requirement depends on the contract and the information in scope.

At Level 1, the Department describes an annual self-assessment against 15 safeguarding requirements associated with FAR 52.204-21, with results and affirmation entered into SPRS. Plans of action and milestones are not permitted for Level 1. That means a team cannot simply list missing practices and call the assessment complete.

At Level 2 self-assessment, the Department points to the 110 requirements in NIST SP 800-171 Revision 2 associated with DFARS 252.204-7012. The current program materials describe a three-year assessment cycle, annual affirmation, SPRS submission, and limited POA&M treatment under the applicable rules. The details matter: not every missing practice is eligible for deferral, and conditional status is time-bound.

Do not generalize these statements to every organization. Some companies do not handle federal contract information or CUI for a given engagement. Others have multiple enclaves with different information flows. The contract, data classification, and system boundary decide the workload—not the company’s marketing category.

Contract duties that should remain on the desk

A contract review should begin with the award and its incorporated clauses. For defense work involving covered contractor information systems, DFARS 252.204-7012 addresses safeguarding covered defense information and reporting cyber incidents. Related clauses may require assessments, SPRS scores, or CMMC status. The presence, date, and wording of each clause should be recorded at contract level.

The review should answer five questions:

  • What information will the contractor create, receive, process, store, or transmit?
  • Which systems and service providers touch that information?
  • Which clauses and assessment conditions are actually incorporated?
  • What representations, scores, or affirmations have been submitted, by whom, and on what evidence?
  • What changes since the last assessment could make the prior statement inaccurate?

This is more useful than asking whether “the company is CMMC compliant.” Compliance is not a permanent product attribute. It is a claim tied to requirements, scope, date, evidence, and operating facts. A new SaaS integration, acquisition, office, identity provider, remote-support path, or backup service can change the boundary without changing the logo on the network diagram.

Why stopping the evidence program would be an expensive mistake

The pause creates a temptation to postpone documentation work. That may save hours this month and create a much larger recovery job later. Security evidence ages. Screenshots stop matching interfaces. People leave. Service configurations change. Tickets close without preserving the reason for an exception. A system security plan becomes fiction one small drift at a time.

Continue collecting evidence at the cadence the control requires. Examples include access reviews, incident exercises, vulnerability remediation, backup tests, media handling, privileged-account changes, configuration baselines, security training, and supplier reviews. The goal is not a giant folder of screenshots. The goal is a traceable record that connects a requirement to an owner, a technical or procedural implementation, and proof that the implementation operated during the period claimed.

Good evidence is specific enough that another qualified person can follow it. A policy saying “the company reviews accounts” is not the same as a dated review showing the population, reviewer, exceptions, decision, and closure. A firewall invoice is not boundary-protection evidence. A FIPS statement in a brochure is not proof that the exact validated module is deployed and operating in its approved mode.

If the program is revised, disciplined records will be reusable. If the timeline returns quickly, they will shorten preparation. If a customer, contracting officer, or investigator asks about a prior assertion, they will help explain what the organization knew and did at the time.

Recheck every representation before somebody signs it

Cybersecurity representations carry risk because the government can rely on them in award and payment decisions. The appropriate response is not alarmism; it is controlled review.

Before an authorized official submits an affirmation, score, or proposal statement, the security owner and contract owner should confirm the assessment date, boundary, applicable requirements, unresolved deficiencies, and supporting record. If a score is in SPRS, maintain the calculation materials and note which assessment method was used. If a remediation item closed, retain evidence of the changed implementation and validation. If scope changed, determine whether the old result is still a fair description.

Avoid absolute marketing language such as “fully CMMC certified” when the actual state is a Phase I self-assessment for one enclave. Use the program’s defined status and include the scope and date. Precision protects the buyer as well as the contractor.

Hardware purchasing during the CMMC pause

CMMC does not publish a universal approved-hardware list. Buyers should translate security requirements into capabilities and evidence for the specific architecture. A device can help implement a control, but the purchase order cannot complete the practice by itself.

For endpoints, evaluate supported operating systems, secure boot, device encryption, centralized management, patching, logging, identity integration, and the ability to disable or wipe lost equipment. For network infrastructure, confirm segmentation, authenticated administration, configuration backup, logging, supported firmware, and the intended boundary design. For storage and backup, document encryption, access separation, recovery testing, retention, and disposal. For authentication, map the method to the access scenario and replay-resistance requirement rather than buying a security key solely because the package says “FIDO.”

Procurement evidence should identify the manufacturer, exact model or service, configuration, firmware or software version when material, country-of-origin claims when required, validation certificate when required, support term, and approved substitute process. If a reseller proposes an alternate, security should review whether it preserves the needed capability before the substitution is accepted.

For a fuller translation of controls into buying questions, use CMMC hardware requirements. For authentication-specific decisions, see CMMC MFA and security keys.

A 30-day response plan for contractors

Week 1: freeze the facts

Save the July 13 announcement and the current CMMC program page in the program file. Inventory active solicitations and awards that mention CMMC, DFARS 252.204-7012, assessment scores, or SPRS. Do not assume the announcement automatically amended any document. Route ambiguous language to the contracting officer through the authorized contract channel.

Week 2: test the assessment boundary

Walk one representative CUI flow from receipt to deletion. Include email, file sharing, endpoints, cloud services, remote administration, logs, backups, and support providers. Compare that flow with the system security plan and asset inventory. Record discrepancies as issues with owners and dates.

Week 3: validate evidence and statements

Sample a set of requirements across access control, identification, incident response, configuration management, audit, media, and system integrity. Confirm that the evidence shows operation, not merely intent. Reconcile SPRS records and annual affirmations with the assessment file.

Week 4: reset the roadmap

Keep remediation that reduces real risk or satisfies existing clauses. Reprioritize work that existed solely to meet a suspended external date, but do not delete it. Add monitoring tasks for the Department’s CMMC pages, Acquisition.gov, official rulemaking, and contract-specific notices. Give one person authority to summarize changes and one person responsibility to approve their operational interpretation.

What contracting teams should ask in current solicitations

When CMMC language appears in a solicitation issued around the suspension, ask a narrow written question. Identify the provision, state the apparent conflict with the current phase status, and request the agency’s interpretation or amendment. Do not ask a supplier to guess what the agency intended.

Proposal teams should preserve the question, response, amendments, and final representation. Subcontract flow-downs deserve the same review. A prime contractor’s internal deadline is not automatically a government requirement, but it can still become a valid subcontract condition if written into the agreement. Separate the legal source from the commercial decision.

When evaluating a supplier, request evidence proportional to the service and information involved. A supplier that never touches FCI or CUI should not receive a generic 110-control questionnaire by reflex. A managed service provider with privileged access to the enclave needs much deeper examination. Scope first, then evidence.

What to watch next

The Department announced a review, so dates and mechanics may change. Monitor primary sources rather than social summaries:

  • the DoD CIO CMMC pages and official announcements;
  • Acquisition.gov for FAR and DFARS text and deviations;
  • the Federal Register for proposed and final rules;
  • solicitation amendments and direct contracting-officer communications;
  • SPRS and official assessment guidance used by the contract.

Set a recurring review with a recorded “checked on” date. When an update appears, compare the exact text with the prior version and identify which contracts, system boundaries, assessments, and planned purchases it affects. A headline is not an implementation plan.

Keep a decision log during the pause

Maintain a short, controlled log for program interpretations. For each entry, record the official source, publication and retrieval dates, affected contract or enclave, question, decision, approver, and next review date. Link supporting correspondence rather than paraphrasing it from memory.

This helps when different customers issue different instructions. One contracting officer may clarify that a solicitation remains in Phase I, while a prime contractor maintains a stricter subcontract requirement. The organization can follow both without mislabeling the commercial condition as a government-wide rule.

The log should also show which remediation work continued and why. Tie each project to an existing clause, a real security risk, customer commitment, or readiness objective. That record protects useful work from being dismissed as “only for the old deadline” and makes future funding decisions easier to defend.

Frequently asked questions

Is CMMC canceled?

No. The Department says CMMC implementation is paused in Phase I and Phase II is suspended while the program is reviewed. Phase I self-assessment requirements remain in place. The final shape and schedule after the review should not be assumed before official publication.

Do we still need to protect CUI under DFARS 252.204-7012?

Yes, when the clause applies to the contract and system. The Department explicitly says the Phase II suspension does not eliminate that protection requirement. Confirm the current clause text and contract applicability with the responsible contracts and legal teams.

Should we cancel a scheduled C3PAO assessment?

That is a contract and business decision, not a universal answer. Check whether an active solicitation, customer requirement, subcontract term, or internal risk decision still depends on it. Discuss timing and cancellation terms with the assessor, but do not describe a voluntary assessment as a government requirement if it is not one.

Does a self-assessment allow open POA&Ms?

The answer depends on level and the current CMMC rules. The Department states that Level 1 does not permit POA&Ms. Level 2 allows limited POA&M treatment subject to eligibility and closeout conditions. Review 32 CFR Part 170 and current program guidance rather than assuming every deficiency can be deferred.

Can a vendor certify that its hardware is CMMC compliant?

No product purchase certifies an organization. A vendor can provide evidence about specific properties—such as a CMVP certificate, secure-boot capability, support lifecycle, or logging function—but the contractor remains responsible for scope, configuration, operation, and assessment evidence. Start with What is CMMC? when aligning business and technical teams.

Ask AI about Uniqcli

Rugged laptops for the field

About the author

Uniqcli Team

Uniqcli's newsroom, buying guides and glossary are produced by our in-house team — seven procurement and technology professionals who source, screen and integrate IT and security hardware every day, working with two editors. Practitioners draft from live sourcing and integration work; editors review every piece for accuracy and plain language before it publishes.

More about the Uniqcli Team

Ready to scope your program?

Talk to a Uniqcli engineer, or send a bill of materials for a TAA-verified quote — no payment up front.