What changed: CMMC dates and developments
Dates below are event or document dates, not claims that this page was updated on those dates. Reporting and official actions are labeled separately.
| Date | Development | What it means | Source |
|---|---|---|---|
| September 21, 2026 | Industry reporting: the Task Force considered more than 1,100 comments in early September; its report was not public as of this report. | Context on the review, not a new compliance deadline. | Covington / Inside Government Contracts |
| September 11, 2026 | Review milestone: the reported due date for the Task Force report to the CIO. The July 13 directive established a 60-day review. | An internal reporting milestone is not a public-release deadline or an automatic restart of Phase 2. | July 13 CIO memorandum (60-day review); Covington (September 11 due date) |
| September 3, 2026 | Official document listing: DARS lists Class Deviation 2026-O0025, Revision 3, for FAR Part 40 / DFARS Part 240, dated September 3. | The index confirms the document and its date. This entry does not interpret changes between the revision attachments. | DARS class-deviation index |
| August 14, 2026 | Official deadline: the public comment deadline for the CMMC reform RFI. | This was a comment deadline, not a contractor certification deadline. | SBA Office of Advocacy notice |
| July 13, 2026 | Official action: Phase 2 and pending future implementation milestones were suspended; the CIO established the reform review. | Phase 1 self-assessments and applicable safeguarding duties continue. | CIO reform memorandum; implementation procedures |
We record verified changes in this log and identify the source and date for each entry.
Task Force report status: We did not locate an official public report or a confirmed public-release date in the official sources checked on September 25. That does not establish whether a report was delivered internally. See our CMMC reform review coverage for the developing analysis.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and defense industrial base compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis or provider-category recommendations. We are not affiliated with the Department of War/Department of Defense, DCMA DIBCAC, The Cyber AB, or any U.S. government agency. This article is educational, not legal, contracting, or compliance advice. For interpretation of your procurement, consult your contracting officer and qualified counsel.
Current CMMC implementation status
| Item | Current position | Required action |
|---|---|---|
| Phase 1 | Self-assessment requirements remain active where applicable. | Maintain the required Level 1 (Self) or Level 2 (Self) status, SPRS records, and affirmation. |
| Phase 2 and later implementation milestones | Suspended pending further direction; no replacement date found in the sources checked. | Do not treat November 10, 2026 as an active Phase 2 deadline. |
| New Level 2 (C3PAO) and Level 3 (DIBCAC) procurement designations | Not permitted during the suspension under the July 13 procedures. | Use the current written requirement and obtain clarification of conflicting language. |
| Active solicitations and existing contracts containing those requirements | Agencies are directed to amend affected solicitations and modify affected contracts. | Obtain the actual amendment or modification; do not assume the public announcement rewrote your contract. |
| Applicable safeguarding and incident-reporting obligations | Continue; the pause is not a release from these duties. | Continue meeting the obligations in your applicable clauses. |
| CMMC waiver procedures | Suspended during the review. | Do not plan on obtaining a waiver during this review. |
Source: July 13 implementation procedures, attachment pages 1–2. For existing contracts, the procedures direct removal of affected requirements before the next option exercise or during the next scheduled administrative modification. Active solicitation amendments are to be issued as soon as practicable.
Already assessed? See our JSVA status and expiration guide for qualifying legacy assessments, our voluntary assessment decision guide for assessment timing, and our conditional-status closeout guide for the separate 180-day clock.
The 30-second answer: which 2026 date is yours?
| If this is you | The 2026 answer | Your next move |
|---|---|---|
| You handle FCI only, with no CUI | Level 1 (Self) may apply when your contract requires CMMC. | Confirm the information and scope; complete the required annual self-assessment and affirmation. |
| You handle CUI and the current requirement is Level 2 (Self) | Assess against the 110 NIST SP 800-171 Rev. 2 requirements. | Verify the assessment scope, evidence, current SPRS status, and affirmation. |
| Existing paperwork says Level 2 (C3PAO) or Level 3 (DIBCAC) | The July 13 procedures direct amendments/modifications to affected requirements. | Ask for the current written amendment or modification before deciding what assessment to buy. |
| You are a subcontractor | Your written subcontract or supplier requirement can set the relevant date. | Ask the prime to distinguish government flow-down from its own commercial supplier policy. |
| You are not sure whether you handle CUI | A calendar cannot answer a scoping question. | Clarify the information and system boundary before buying an assessment. |
Need a starting checklist? Get our free 32-point CMMC Level 2 readiness checklist by email. It helps organize a readiness discussion; it does not determine your binding contractual deadline.
Working on a COTS-only procurement? Check the COTS exclusion and current waiver policy. The exclusion is procurement-specific, not a blanket exemption for a company.
What is the real CMMC deadline in 2026?
There is no universal date in 2026 when every defense contractor must hold a CMMC certificate. The original Phase 2 transition was suspended on July 13. Your applicable obligations depend on the current written solicitation, contract, option, or subcontract requirement.
A deadline article—including this one—cannot tell you your exact contractual deadline without reviewing that requirement. A program milestone describes rollout policy; an award, option, status expiry, affirmation, or closeout requirement can create a different deadline for your organization. The pause is not permission to stop safeguarding covered information.
Rule-stated date vs. your contract-triggered deadline
| Question | Program-level schedule | Your organization |
|---|---|---|
| What date matters? | The original Phase 2 transition is suspended; no replacement date was found in the sources checked. | The date in your current written procurement or subcontract requirement, plus any status/affirmation/closeout deadline. |
| What does it determine? | Which assessment requirements agencies may designate during the rollout. | What you must maintain for the systems and information used on the work. |
| Where do you verify it? | Current Department guidance alongside the standing rules. | The actual solicitation or contract, amendments/modifications, and applicable SPRS records. |
| What should you do? | Track official changes rather than assume the historical calendar remains operative. | Obtain written clarification and work backward from the applicable event. |
Why you keep seeing “October 31, 2026”
You will still find pages describing October 31 or November 10, 2026 as a universal deadline. October 31 is not the original Phase 2 transition date. November 10, 2026 was the original date derived from the phase intervals in 32 CFR § 170.3(e) and the November 10, 2025 DFARS effective date. That transition was suspended. Neither date should replace a review of your current written requirement.
The date that actually matters: your award, option, or flow-down date
Two DFARS provisions explain the standing contract mechanism. Read them alongside current suspension guidance and the actual version incorporated in your procurement:
- DFARS 252.204-7025 is a solicitation provision. It identifies the required level and requires the relevant current SPRS status and affirmation for each covered contractor information system before award. Its printed list of assessment types does not override the suspension instructions for new designations.
- DFARS 252.204-7021 is the contract clause. It addresses maintaining the required status, annual affirmations, applicable subcontract flow-down, and the CMMC UID information supplied for covered systems.
An option or subcontract does not necessarily contain a new -7025 provision. For those events, read the incorporated clause, modification, or subcontract requirement. Ask which clause version and any applicable acquisition deviation govern the instrument; an older citation number alone does not tell you whether the requirement applies.
The original CMMC implementation timeline: Phase 1, 2, 3, and 4
This is the original rollout schedule, not a list of currently active future deadlines. Phase 1 self-assessment requirements remain active; the July 13 direction suspended the Phase 2 transition and later pending milestones.
| Phase | Original start date | Original role in the rollout | Current interpretation |
|---|---|---|---|
| Phase 1 | November 10, 2025 | Level 1 (Self) and Level 2 (Self) requirements in applicable procurement, with the original rule allowing some earlier C3PAO use. | Self-assessment obligations continue. The suspension instructions now control permitted new designations. |
| Phase 2 | November 10, 2026 | Expansion of Level 2 (C3PAO) award requirements. | Suspended; not an active transition deadline. |
| Phase 3 | November 10, 2027 | Further Level 2 (C3PAO) application and introduction of Level 3 (DIBCAC) requirements. | Pending milestone suspended; not a replacement Phase 2 date. |
| Phase 4 | November 10, 2028 | Full implementation under the original rollout. | Pending milestone suspended; not an announced restart date. |
Sources: 32 CFR § 170.3(e), DFARS final rule effective date, and July 13 CIO memorandum. The original end of Phase 1's first calendar year does not terminate applicable self-assessment or safeguarding obligations.
The two rules behind the original timeline
CMMC became real in two steps:
- The CMMC Program Rule was published October 15, 2024 and became effective December 16, 2024. It established the program's assessment, scoring, status, POA&M, and affirmation structure.
- The DFARS CMMC Acquisition Rule, Case 2019-D041 was published September 10, 2025 and became effective November 10, 2025. It established the acquisition mechanism using the revised -7021 clause and new -7025 provision.
These historical effective dates do not cancel the subsequent suspension direction. For the current implementation position, use the status table above.
Phase 1: current active phase
Phase 1 remains active where applicable. Maintain the required self-assessment status, SPRS information, annual affirmation, and safeguarding duties. Obtain the written amendment or modification when existing paperwork contains a third-party or Level 3 requirement affected by the suspension.
CMMC assessment statistics: latest figures verified for this update
The newest quantitative primary source we could substantiate for this update is The Cyber AB's August 14, 2026 RFI response. These are figures reported on that date, not a live September 25 census.
| Metric | Reported figure | Data/source date | Source location |
|---|---|---|---|
| C3PAOs in the assessment ecosystem | Over 110 | August 14, 2026 | Cyber AB RFI response, ecosystem figures |
| CMMC Certified Assessors (CCAs) | Over 1,100 | August 14, 2026 | Cyber AB RFI response, ecosystem figures |
| Defense contractors reported to have attained Level 2 certifications since early 2025 | Approximately 2,000 | August 14, 2026 | Cyber AB RFI response, overarching perspectives |
How to use these figures. Keep the qualifiers “over” and “approximately.” The source is The Cyber AB's own account of the ecosystem; we did not independently recount active Marketplace listings or reconcile certifications across unique companies and information systems. These numbers do not measure appointment availability, readiness, or how many organizations face an operative certification deadline.
Why the old readiness percentage is no longer here. Dividing a rounded certification figure by a broad historical population estimate does not establish the share of the defense industrial base that is ready. The units, populations, and assessment types need to match. We also removed the claim that the pipeline cannot absorb a late-2026 surge: the figures shown do not establish that forecast, and the November transition is suspended.
Next published event to watch: The Cyber AB lists its September Town Hall for September 29, 2026 at 6:00 p.m. Eastern. That is a scheduled event, not a source of completed September results. Check the official event listing.
For citations, use the permanent statistics section and retain both the source date and the qualifier attached to each figure.
Cite or link to this tracker
The Defense Compliance Report, “CMMC Deadlines 2026: Status Tracker, Phase 2 Pause & What Still Applies,” last checked September 25, 2026. https://thedefensecompliancereport.com/cmmc-deadlines/ . Underlying assessment figures: The Cyber AB, August 14, 2026.
Permanent section links
- Current CMMC statushttps://thedefensecompliancereport.com/cmmc-deadlines/#current-cmmc-status
- Change loghttps://thedefensecompliancereport.com/cmmc-deadlines/#what-changed
- Assessment statisticshttps://thedefensecompliancereport.com/cmmc-deadlines/#cmmc-assessment-statistics
- Original implementation timelinehttps://thedefensecompliancereport.com/cmmc-deadlines/#original-timeline
- Verification ledgerhttps://thedefensecompliancereport.com/cmmc-deadlines/#what-we-verified
Which CMMC level and assessment type is your deadline for?
Your required CMMC level depends on the information, assessment scope, mission requirements, and current written procurement requirement. The table describes the standing program structure; it does not mean every listed assessment type may be newly designated during the suspension.
| Level | Information / program role | Requirements | Assessment and continuing status | POA&Ms |
|---|---|---|---|---|
| Level 1 | FCI | 15 basic safeguards under FAR 52.204-21 | Annual self-assessment and affirmation | Not permitted |
| Level 2 | CUI | 110 NIST SP 800-171 Rev. 2 requirements in 14 families | Self-assessment or C3PAO certification structure; three-year assessment cycle with annual affirmation and applicable closeout duties | Limited |
| Level 3 | Selected higher-risk CUI requirements | The Level 2 baseline plus 24 selected NIST SP 800-172 requirements | DIBCAC assessment; Final Level 2 (C3PAO) for the same scope is a prerequisite | Limited, under separate Level 3 eligibility rules |
Sources: 32 CFR § 170.5, § 170.15, § 170.16, § 170.17, and § 170.18.
Read your solicitation: the contract-wording decoder
| Wording in the document | What it describes | What to check now |
|---|---|---|
| Level 1 (Self) | Annual self-assessment and affirmation for the applicable FCI scope. | The current requirement and SPRS status for the covered system. |
| Level 2 (Self) | Self-assessment against the Level 2 requirements. | Scope, status, affirmation, and any conditional closeout deadline. |
| Level 2 (C3PAO) | Third-party Level 2 certification assessment. | Whether the document has been amended or modified under the suspension direction; distinguish any separate private supplier requirement. |
| Level 3 (DIBCAC) | Government Level 3 assessment after Final Level 2 (C3PAO). | Written clarification of any requirement affected by the suspension. |
Level 1 is not “CMMC-lite” for CUI
Level 1 exists for FCI-only situations. It’s an annual self-assessment against the 15 safeguarding requirements in FAR 52.204-21, and — this trips people up — it allows no plans of action and milestones. Every Level 1 requirement has to be met. If you touch CUI, Level 1 is not your shortcut; you’re in Level 2 territory. For a full breakdown, see our guide on CMMC Level 1 vs Level 2.
Level 2 is the common CUI path — and it’s Revision 2, not Revision 3
CMMC Level 2 continues to use NIST SP 800-171 Revision 2: 110 requirements across 14 families. That basis is in the current program rule, including 32 CFR § 170.24, and is reaffirmed in the July 13 implementation procedures. Publication of a newer NIST revision does not by itself change CMMC's incorporated assessment baseline. Build and assess the relevant SSP and evidence against the version required for your actual obligation; do not confuse a roadmap to newer standards with a change already made to CMMC.
Level 2 Self vs Level 2 C3PAO is a contract requirement — not your choice
Self-assessment and C3PAO assessment are different status paths, not interchangeable purchases. During the suspension, the Department's procedures permit new Level 1 (Self) and Level 2 (Self) designations. When existing paperwork still specifies a C3PAO, obtain the relevant amendment or modification rather than silently substituting a self-assessment. Self-assessment results go into SPRS; C3PAO results are submitted to eMASS and transmitted to SPRS under § 170.17. See RPO vs C3PAO: which do you need?.
Level 3 is not the normal 2026 path for a small contractor
The standing Level 3 pathway requires a Final Level 2 (C3PAO) status for the same assessment scope and a DIBCAC assessment under 32 CFR § 170.18. The July 13 instructions suspend new Level 3 procurement designations. A company's size alone does not determine its level; obtain written clarification if an active document still specifies Level 3.
The wrong scope makes every quote, timeline, and assessment plan wrong. For scope and applicability background, see who needs CMMC certification and our CMMC levels breakdown.
What has to be in SPRS before you can win the award?
Where the applicable solicitation requires CMMC, eligibility depends on the required current status and a current affirmation in SPRS for each relevant contractor information system—not merely a certificate PDF. Read the actual provision and any current amendment. Source: DFARS 252.204-7025(b) and (d).
| Item | Who it matters for | What to check |
|---|---|---|
| Required level and assessment type | Applicable offerors and covered systems | The current written requirement, including amendments or modifications. |
| Current CMMC status | Applicable offerors and covered systems | Status at the required level, or an eligible higher status for the same scope. |
| Current affirmation | All applicable CMMC levels | The required affirmation is current in SPRS. |
| CMMC UID | Each relevant contractor information system, including Level 1 systems | The UIDs required by the applicable provision/clause are supplied and kept current. |
| CAGE code and scope alignment | Organizations with multiple entities, sites, or systems | The assessed scope and identifiers cover the systems used on the work. |
| Conditional status | Conditional Level 2 or Level 3 systems | The separate 180-day closeout deadline and all eligibility conditions. |
| Subcontractor compliance | Applicable supply-chain work | The actual required flow-down, status, and affirmation before covered subcontract award. |
A CMMC status is not just a certificate
Under the standing acquisition mechanism, required current status and affirmation are checked for applicable awards and options. During the suspension, read those requirements together with the current written amendment or modification. See DFARS Subpart 204.75 and our SPRS guide.
Annual affirmations don't end at the assessment
All applicable CMMC levels require affirmation—not just Levels 2 and 3. Level 1 also requires a new self-assessment annually. Level 2 and Level 3 generally have three-year assessment cycles, but annual affirmation and continuous compliance remain necessary. A Conditional status has its own shorter closeout clock. The Affirming Official is the senior-level representative responsible for the affirmation; a certificate's date alone is not proof the status remains current. Sources: § 170.15, § 170.16, § 170.17, § 170.18, and § 170.22.
The affirmation has teeth: False Claims Act risk
A knowingly false cybersecurity representation can create False Claims Act exposure when the legal elements are met. DOJ's Civil Cyber-Fraud Initiative addresses knowing misrepresentations about cybersecurity practices and related obligations. The practical instruction is simple: do not affirm compliance your evidence does not support. A missed control or later incident does not, by itself, establish fraud.
Can you win a 2026 award on a conditional status or a POA&M?
A valid Conditional status can satisfy the CMMC-status portion of eligibility where the applicable requirement permits it; it does not guarantee an award. Level 1 has no conditional/POA&M pathway. Level 2 requires at least 88 of 110 weighted points, only eligible gaps, a current affirmation, and timely closeout. A raw count of 88 implemented requirements is not the test.
| Level | POA&M eligibility | Closeout deadline | Closeout actor |
|---|---|---|---|
| Level 1 | None | Not applicable | Not applicable |
| Level 2 (Self) | Restricted gaps and required score | Within 180 days of the Conditional CMMC Status Date | Organization's closeout self-assessment |
| Level 2 (C3PAO) | Restricted gaps and required score | Within 180 days of the Conditional CMMC Status Date | Authorized or accredited C3PAO |
| Level 3 | Separate Level 3 restrictions and threshold; Final Level 2 prerequisite | Within 180 days of the Conditional CMMC Status Date | DCMA DIBCAC |
This table explains the standing program, not permission to add a currently suspended C3PAO or Level 3 procurement requirement. Source: 32 CFR § 170.21.
Level 2 begins with a maximum of 110 points and deducts the assigned value for each NOT MET requirement; scores can be negative. The methodology includes limited scoring adjustments for multifactor authentication (IA.L2-3.5.3) and CUI encryption (SC.L2-3.13.11). A score from 88 through 109 is not sufficient on its own for Conditional status: every remaining gap must also be eligible. Final status requires all applicable requirements to be satisfied under the rule's assessment findings and scoring provisions. Source: 32 CFR § 170.24.
What you cannot put on a POA&M
Level 2 POA&Ms generally may contain only eligible 1-point requirements. The narrow exception is SC.L2-3.13.11, when encryption is in use but is not FIPS-validated, producing the permitted 3-point deduction. Missing encryption entirely is not that exception.
| Cannot be deferred to a Level 2 POA&M |
| --- |
| Every 5-point requirement |
| Every 3-point requirement except the specific deployed-but-not-FIPS-validated encryption case above |
| AC.L2-3.1.20 — external connections |
| AC.L2-3.1.22 — control public information |
| CA.L2-3.12.4 — System Security Plan |
| PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5 — the specified physical-access requirements |
Source: 32 CFR § 170.21(a)(2). A qualifying score does not override these exclusions.
Level 3 is scored on its own scale
Do not apply the Level 2 88/110 threshold to Level 3. Level 3 uses its own selected 24 requirements. Conditional Level 3 requires the score ratio in § 170.21(a)(3), compliance with that paragraph's non-deferrable requirements, the applicable affirmation, and Final Level 2 (C3PAO) for the same scope under § 170.18. DCMA DIBCAC performs Level 3 POA&M closeout. These are standing status rules, not a new procurement designation during the pause.
A POA&M is not a rescue plan
If closeout is not successfully completed within 180 days of the Conditional CMMC Status Date, that status expires. The July suspension is not a stated extension of this separate status clock. Do not treat closeout as starting a fresh three-year assessment cycle. Track the actual status, affirmation, and closeout dates in SPRS and your assessment record. Sources: § 170.21(b), § 170.16, and § 170.17. See our conditional-status closeout guide.
Compare readiness vs. assessment-ready paths → A C3PAO assessment is not the same thing as implementation help. If your scope, SSP, evidence, and control ownership aren’t stable, you need readiness support first — not an assessor. See which provider category fits your situation.
Do subcontractors face the same 2026 CMMC deadline?
A subcontractor can have a different relevant date and scope from the prime. For applicable subcontracts involving FCI or CUI, read the current flow-down and required status—not merely the prime's company-wide certification level. Sources: DFARS 252.204-7021 and 32 CFR § 170.23.
| Situation | What to establish |
|---|---|
| FCI-only subcontract work | Whether Level 1 applies to the actual subcontract and system scope. |
| Subcontract work involving CUI | The written level, assessment type, scope, and date, including any suspension-related updates. |
| Prime asks for certification despite the pause | Whether this is a still-incorporated government flow-down or the prime's separate commercial supplier condition. |
| Prime offers to waive a requirement | A prime cannot waive an applicable government requirement. Changes to its own commercial condition are a separate question. |
What to ask your prime before you accept a deadline
Don't accept a vague “you'll need CMMC.” Ask for written answers:
- Will this work require us to process, store, or transmit CUI, FCI, or neither, and on which systems?
- Which clauses, level, assessment type, and versions apply to our subcontract?
- Is the requested certification a government flow-down or your company's separate supplier policy?
- What current amendment or modification addresses the July 13 suspension?
- What event and date require our status, and what must be completed before information is shared?
The answers turn “someday” into a documented planning requirement.
For a full look at how requirements move through the supply chain, see our CMMC flow-down requirements guide.
What to do now, based on how much runway you have
Work backward from a documented requirement, not an assumed program restart. A close award date matters only after the applicable requirement and current status are clear.
| Your situation | What to do now |
|---|---|
| Award, option, or subcontract decision is approaching | Obtain the current requirement and any amendment/modification; verify scope, SPRS status, and affirmation. |
| You hold Conditional status | Calculate the 180-day deadline from the actual Conditional CMMC Status Date and arrange the required closeout. |
| Level 1 applies | Complete the annual self-assessment, keep the required SPRS information current, and affirm as required. |
| Level 2 (Self) applies | Confirm the CUI boundary, SSP, evidence, weighted score, eligible gaps, status, and affirmation. |
| You are considering a voluntary C3PAO assessment | Establish the business reason, current readiness, proposed assessment scope, actual provider availability, and change/cancellation terms. |
| You do not know whether you have CUI or an applicable clause | Resolve that question before buying a certification assessment. |
A consultation about scope or scheduling can happen before readiness is complete. That is different from paying to begin a formal assessment before the necessary controls and evidence are ready. See our voluntary assessment decision guide for the separate timing decision.
Which provider category fits your 2026 CMMC deadline?
If you are still scoping, remediating, or building evidence, you need readiness or implementation help. If you have a reason to pursue certification and your scope, controls, SSP, and evidence are ready, you need an authorized or accredited C3PAO for the assessment. A GRC tool can organize work; it cannot, by itself, make the organization compliant.
Readiness help is not the same as assessment help
Do not assume a firm can implement your controls and then certify that same work. Verify the applicable independence and conflict-of-interest requirements, including 32 CFR § 170.9, before engaging a C3PAO. Separate contracts or engagements do not automatically resolve a prohibited conflict.
What to verify before you pay anyone
Confirm the provider's actual role, current authorization/accreditation where relevant, proposed scope, deliverables, information-handling arrangements, pricing, scheduling, and any referral compensation. For cloud or enclave decisions, evaluate the particular offering and your obligations rather than assume one product is universally required.
See CMMC provider categories, how to find an authorized C3PAO, and who to hire first. These guides are for choosing support; they do not replace the current written contract requirement.
Do COTS-only contracts and DoD waivers change your deadline?
COTS-only exclusions and waivers are different mechanisms. The COTS-only exclusion concerns the procurement's scope. The July 13 implementation procedures separately suspend waiver procedures during the review.
COTS-only procurement. The standing acquisition rule excludes contracts solely for commercially available off-the-shelf items. Do not extend that exclusion to a mixed procurement or to every contract held by a company that also sells COTS products. Check the actual solicitation and applicable definition. Source: DFARS Subpart 204.75.
Waivers during the review. 32 CFR § 170.5(d) contains limited waiver authority in the standing program rule. However, the July 13 implementation procedures, attachment page 2 state that no waivers are to be granted during the program review. Do not present a waiver as an available route around a current requirement during that period. The pause does not erase otherwise applicable safeguarding and incident-reporting duties, including those in DFARS 252.204-7012.
What we verified for this CMMC deadlines 2026 guide
Check date: September 25, 2026. We distinguish the standing program rule, current implementation directions, source-reported ecosystem statistics, and secondary reporting. The eCFR pages consulted displayed Title 32 as current through September 23, 2026. That is the source's currency date—not a claim that Part 170 changed on that date.
| Subject | Source and relevant location | Scope of this check |
|---|---|---|
| Current suspension status | CIO CMMC page; July 13 CIO reform memorandum | Official public status and the 60-day review direction; no replacement date found in the sources checked. |
| Permitted designations, amendments/modifications, safeguarding, and waiver suspension | July 13 implementation memorandum and attachment | Full three-page document, including the waiver instruction on attachment page 2. |
| August 14 comment deadline | SBA Office of Advocacy notice | Deadline in the official notice, not evidence of any reopening. |
| September 3 deviation listing | DARS index: 2026-O0025 Revision 3 | Document identity/date verified from the listing; revision attachments not substantively compared in this update. |
| Task Force meeting, comment count, and reported September 11 due date | Covington, September 21 report | Secondary reporting, explicitly labeled; not an official final report. |
| Original program and acquisition effective dates | 2024 program final rule; 2025 acquisition final rule | Historical publication/effective dates, not a claim that suspended future milestones remain active. |
| Status, UID, affirmation, and contract mechanism | DFARS -7025; DFARS -7021; Subpart 204.75 | Standing text; actual instruments and applicable deviations must be read for procurement-specific advice. |
| Assessment, affirmation, scoring, and closeout | 32 CFR Part 170, particularly §§ 170.15–170.18 and 170.21–170.24 | Program requirements and separate recurring/conditional clocks. |
| COTS exclusion and standing waiver authority | Subpart 204.75; § 170.5(d) | Read together with the current suspension of waiver procedures. |
| Assessment ecosystem figures | Cyber AB August 14 RFI response | Issuer-reported figures as of August 14; not a September Marketplace census. |
| False Claims Act context | DOJ Civil Cyber-Fraud Initiative | Enforcement context, not a prediction of liability in an individual case. |
What we did not establish
We did not review your contract, determine your CUI scope, certify any organization, verify a named provider's current Marketplace status, or establish that the Task Force report was delivered internally. We did not substantiate newer numerical results from the August Town Hall slides or a September Town Hall that had not yet occurred. We did not calculate an industry readiness percentage or infer a national assessment backlog from the reported counts.
Report a source-backed correction through our corrections policy.
CMMC deadlines 2026: FAQ
Phase 2 is suspended, but applicable self-assessment, safeguarding, affirmation, and closeout obligations continue. These answers separate the paused rollout from obligations that may still apply to your organization.
What is the CMMC deadline in 2026?
There is no universal 2026 certification deadline for every defense contractor. The original November 10 Phase 2 transition is suspended, and no replacement date was found in the official sources checked for this update. Check the current written requirement and any separate status, affirmation, or closeout deadline.
Is the CMMC deadline October 31 or November 10, 2026?
October 31 was not the original Phase 2 transition date. November 10, 2026 was the original transition date derived from the rule's phase intervals and the DFARS effective date, but it was suspended on July 13. Neither date is a universal current contractor deadline.
Do existing contracts have to meet CMMC in 2026, or only new awards?
It depends on the current contract and applicable clauses. The July 13 instructions direct amendments to affected active solicitations and modifications to existing contracts containing C3PAO or Level 3 requirements. Obtain the actual written change; do not assume the announcement removed every obligation from an existing contract.
Do option periods after November 10, 2026 trigger CMMC?
An option can require verification of the status required by the applicable contract. November 10 is not currently an automatic Phase 2 trigger. Check the actual clause and any modification issued under the suspension instructions before the option is exercised.
Are COTS-only contracts excluded from CMMC?
Yes. Contracts solely for commercially available off-the-shelf (COTS) items are excluded under DFARS Subpart 204.75. Confirm your solicitation is truly COTS-only before relying on the exclusion.
Can DoD waive a CMMC requirement?
Not as a route available during the current review: the July 13 implementation procedures suspend waiver procedures and say no waivers are to be granted during the review. The standing limited authority in 32 CFR § 170.5(d) should not be presented without that current restriction.
Is CMMC mandatory in 2026?
Applicable Phase 1 self-assessment requirements remain active. The pause does not remove safeguarding duties or required SPRS status and affirmations from covered work. Phase 2's original November 10 transition is suspended; applicability still depends on the actual work and written requirement.
Do all Level 2 contractors need a C3PAO in 2026?
No. During the suspension, the Department's procedures permit new Level 1 (Self) and Level 2 (Self) procurement designations, not Level 2 (C3PAO) or Level 3 (DIBCAC). Existing documents should be addressed through the directed amendments/modifications. A voluntary assessment or separate commercial supplier condition is a different question.
Can DoD require a C3PAO assessment before November 10, 2026?
The Phase II transition has been suspended. New Level 2 (C3PAO) and Level 3 designations are suspended during the suspension period. Verify the current written solicitation amendment or contract modification before relying on any Level 2 (C3PAO) or Level 3 requirement.
Do subcontractors need CMMC?
Applicable FCI/CUI subcontract work can carry CMMC requirements. Verify the actual flow-down, system scope, assessment type, date, and any suspension-related update. Ask whether a prime's additional certification demand is a government flow-down or its own commercial supplier requirement.
Can a POA&M get us through award?
A qualifying Conditional Level 2 or Level 3 status can satisfy the CMMC-status condition where applicable, but a POA&M alone does not guarantee eligibility or award. Level 2 needs at least 88/110 weighted points, only eligible gaps—including the narrow deployed-but-not-FIPS-validated encryption exception—and closeout within 180 days of the Conditional CMMC Status Date. Level 3 has separate criteria. Level 1 does not permit POA&Ms.
Does CMMC use NIST SP 800-171 Rev. 2 or Rev. 3 in 2026?
The current rule maps Level 2 to Revision 2 (110 requirements, 14 control families). Don't treat Revision 3 as controlling unless and until DoD updates the rule.
What should we do first if we're behind?
Confirm whether you handle FCI, CUI, or both. Then check the solicitation or flow-down language, identify the required level and assessment type, verify your current SPRS status, and build a plan backward from your award or option date.
Can a C3PAO implement our controls and then assess us?
Do not assume that implementation and certification by the same firm are permissible. Check the applicable independence and conflict-of-interest rules; separate engagements alone are not a safe harbor. Formal Level 2 certification assessments must be performed by an authorized or accredited C3PAO.
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider options. Please do not submit CUI, export-controlled files, drawings, source code, sensitive contract attachments, or controlled technical information through this form.
Related reading
- CMMC implementation phases explained
- The CMMC certification process, step by step
- CMMC Level 2 requirements (all 110)
- CMMC levels breakdown: Level 1, 2, and 3
- CMMC readiness checklist
- How SPRS scoring works
- CMMC certification cost and timeline
- CMMC flow-down requirements for subcontractors
- GCC High and CMMC
- Who needs CMMC certification
Last checked: September 25, 2026. Source dates and the limits of this review are listed in what we verified. This is an independent editorial resource, not a government notice or a determination of your contractual obligations. For corrections, see our corrections policy.