CMMC Phase 2 Suspended: What Still Applies to You Right Now

CMMC Phase 2 Suspended: What Still Applies to You Right Now

CMMC Phase 2 Suspended: What Still Applies to You Right Now

On July 13, 2026, the Department of War suspended Phase 2 of the CMMC program pending a 60-day review. If you sell into the defense supply chain, you have probably already seen the headlines. What you may not have seen is what actually changed, because the answer is narrower than most of the coverage suggests.

What was actually suspended

Phase 2 was the part of the CMMC rollout that introduced third-party certification. Under that phase, contractors handling certain categories of information would need an accredited assessor to certify their cybersecurity controls before they could be awarded or keep a contract that required it. That third-party layer is what is on hold. It is not the entire program, and it is not your existing obligations under DFARS.

The review window is 60 days from the suspension date, which puts a decision point in mid-September 2026. Nobody outside the department knows yet whether Phase 2 resumes as written, gets restructured, or gets replaced with something else. Planning around a guess is a bad use of your time. Planning around what is still in force is not.

What did not pause

This is the part contractors keep getting wrong, and it is the reason this article exists. Three obligations are still live, suspension or no suspension:

  • Phase 1 self-assessment against NIST SP 800-171 controls remains a live requirement for contracts that call for it.
  • Submitting your Basic Assessment score to the Supplier Performance Risk System, known as SPRS, is still required, and that score is visible to prime contractors evaluating you for teaming or subcontracts.
  • The annual senior official affirmation, where a company officer certifies the accuracy of the submitted score, is still due on schedule.
  • DFARS 252.204-7012, the clause requiring safeguarding of covered defense information and rapid reporting of cyber incidents, was never tied to CMMC in the first place and has not moved.

A prime contractor can still write NIST 800-171 evidence requirements directly into a teaming agreement or subcontract, regardless of what phase CMMC is officially in. That flow-down authority comes from the contract itself, not from the certification program. Subcontractors who read “CMMC is paused” as “compliance is paused” are the ones most likely to get caught short when a prime asks for documentation they assumed they no longer needed.

What foreign and new entrants should do differently

If your company is outside the United States, or new to defense contracting, the temptation is to treat a suspended certification requirement as one less thing to build toward. That reading misses the actual risk. The self-assessment and SPRS obligations were never the hard part of a compliance program. Documenting your control environment against the 800-171 framework, closing the gaps you find, and being ready to show your work to a prime who asks: that work does not get easier by waiting, and it does not disappear because the certification layer is paused.

If anything, this is a reasonable window to keep building rather than stall. A company that walks into the resumption of Phase 2, whenever it lands and whatever shape it takes, already holding a clean SPRS score and current documentation is in a materially better position than one that used the suspension as a reason to pause. The review does not change the underlying standard. It changes who checks your work against it, and when.

Frequently asked questions

Does the suspension apply to contracts already in place?

The suspension affects the third-party certification requirement going forward. It does not retroactively remove self-assessment, SPRS, or DFARS safeguarding obligations attached to contracts you already hold. Read your specific contract clauses rather than assuming a blanket exemption.

Should we stop working on our compliance program until the review finishes?

That is a decision for your compliance counsel and leadership to make based on your specific contract exposure. What is publicly known is that self-assessment and SPRS submission remain active requirements, and a prime can still require evidence of NIST 800-171 alignment through contract terms independent of CMMC’s certification timeline.

How will we know when the review concludes?

The Department of War will issue guidance when the 60-day review period ends. Until an announcement lands, treat any prediction about the outcome, including this one, as speculation rather than something to plan around.

Where Nortrane fits

Nortrane helps foreign and domestic manufacturers read regulatory shifts like this one in the context of their specific contract exposure, rather than reacting to the headline. If you are weighing how the CMMC review affects your near-term subcontracting plans, our overview of how a foreign company enters the U.S. defense market covers where compliance readiness fits into the broader sequence, and our piece on teaming agreements versus subcontracting explains how a prime’s own requirements can outpace the federal timeline. This is general information, not legal advice. For a read on your specific situation, that is a private conversation.

Tags
Share Article:

Nortrane Advisory Team

Nortrane's advisory team works daily with foreign and domestic manufacturers, subcontractors, and suppliers navigating FAR, DFARS, CMMC, and ITAR/EAR requirements to enter or expand within the U.S. defense and aerospace industrial base.

Leave a Comment