Do I Still Need CMMC? What the 2026 Suspension Actually Changed
By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Regulatory facts verified against primary sources on August 14, 2026
The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with, endorsed by, or sponsored by the Department of War, the Department of Defense, the Cyber AB, DCMA DIBCAC, NIST, or any U.S. government agency.
Do I still need CMMC? Yes — where a current solicitation, contract, option, or subcontract requires a CMMC Status. Separately, if DFARS 252.204-7012 applies, the NIST SP 800-171 safeguarding duty still binds you even when no independent CMMC assessment is currently required. The July 13, 2026 suspension did not create a blanket exemption. It paused the transition to CMMC Phase 2, the step scheduled to expand Level 2 (C3PAO) requirements starting November 10, 2026. Level 1 (Self) and Level 2 (Self) remain available requirements during the suspension. CMMC self-assessment results and annual affirmations still go into SPRS where the applicable CMMC rule, clause, or provision requires them. And 32 CFR Part 170 — the CMMC Program rule — remains in force.
What changes the answer is the paperwork you're holding. A signed contract, a live bid, and a subcontract flow-down are three different positions, and none of them is changed merely by reading a government announcement.
There's also a wrinkle almost nobody has connected, and it's the reason this page exists: the clause numbers changed in early 2026 for instruments issued under a DoW class deviation. The July memo cites the older framework. So a contractor who reads the news, opens their contract, and searches for the clause they were told to look for may not find it — and conclude they're off the hook when they aren't. We'll show you both systems and exactly what to search for.
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining material regulatory claims with primary-source citation and mapping a contractor's level, CUI scope, assessment type, environment, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
The 60-second version
| Question | Answer |
|---|---|
| Was CMMC cancelled? | No. Phase 2 and the later implementation milestones were suspended pending review. The CMMC Program rule was not repealed. |
| Are Level 1 and Level 2 self-assessments still required? | Yes, where the current solicitation or contract requires them. |
| Do I need a C3PAO assessment right now? | Not as a new Department-designated condition of award during the suspension. Program offices may currently designate only Level 1 (Self) or Level 2 (Self). An existing contract, subcontract, or voluntary assessment decision is separate. |
| Can I stop NIST SP 800-171 work? | No, wherever DFARS 252.204-7012 applies to your contract. That safeguarding clause remains in effect. |
| Does my prime's flow-down still bind me? | It was not amended automatically. The July memoranda direct Department personnel; they do not rewrite an executed subcontract. |
| Does my SPRS record still matter? | Yes. CMMC self-assessment results, CMMC Status, and affirmations continue to be recorded in SPRS. A legacy NIST SP 800-171 DoD Basic score is a related but separate record, and the clause package in your instrument determines whether that older mechanism applies. |
| What decides my answer? | Your written instrument, your FCI/CUI scope, the assessment type it specifies, and whether a formal amendment or modification has issued. |
This page is for: DoD primes and subcontractors staring at an active solicitation, a signed contract, an option period, a prime flow-down letter, or a scheduled assessment, trying to decide what to keep paying for.
This page is not: legal advice, contract interpretation, or a substitute for scope validation by a qualified practitioner. The clause in your contract and the data in your systems set your requirement. Not a checklist. Not this page.
Do I still need CMMC? Find your situation first
Answer capsule: Whether a contractor still needs CMMC depends on the written instrument that governs the work, not on the July 2026 announcement. The Department of War suspended new Level 2 (C3PAO) and Level 3 (DIBCAC) designations, but Phase 1 self-assessment requirements, DFARS 252.204-7012 safeguarding obligations, and existing contract terms remain in force until formally changed.
Find yourself below. Each one lands somewhere different.
1. You hold a signed contract that names Level 2 (C3PAO) or Level 3. You are not automatically released. The Department directed contracting officers to remove those requirements by modification before the next option exercise or during the next scheduled administrative modification.
2. You're bidding on an active solicitation that still names Level 2 (C3PAO) or Level 3. The Department directed program offices to initiate amendments, but the change reaches your bid through the issued amendment. Watch for it. Don't assume it landed.
3. You're responding to a brand-new solicitation. During the suspension, program offices may designate only Level 1 (Self) or Level 2 (Self). Confirm which status the instrument requires.
4. Your prime flowed CMMC down to you in a signed subcontract. Nothing changed automatically on July 13. The memoranda do not amend the subcontract in your file.
5. You handle FCI only — no CUI anywhere in the assessed environment. Almost nothing changed, and this is not the Level 2 certification spend driving the headlines.
6. You have a C3PAO assessment booked or paid for. This is a real money decision with a genuine trade-off. We work through it below.
What exactly did the July 13, 2026 suspension pause?
Answer capsule: On July 13, 2026, the Department of War suspended the transition to CMMC Phase 2, originally scheduled for November 10, 2026, along with pending and future implementation milestones. During the suspension, program managers may designate only CMMC Level 1 (Self) or Level 2 (Self) in procurement documents and may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments. Phase 1 self-assessment requirements and DFARS 252.204-7012 remain in effect.
The original four-phase schedule put Phase 1 from November 10, 2025 through November 9, 2026, with Phase 2 beginning one calendar year after Phase 1 started. The July action stopped that Phase 2 transition before it arrived.
Two documents did the work, both dated July 13, 2026. CIO Memorandum 26-P-1023, signed by Department of War Chief Information Officer Kirsten A. Davies, directed the suspension and established a CMMC Reform Task Force. The attached implementation procedures told program managers, requiring activities, and contracting personnel what to do about solicitations and contracts already in motion.
We read the implementation procedures in full. Here is what they actually say, stripped of the press-release language.
What is paused
- The November 10, 2026 transition to Phase 2.
- New Level 2 (C3PAO) designations in procurement requests and requirement documents.
- New Level 3 (DIBCAC) designations.
- Pending and future implementation milestones, held in abeyance pending further guidance.
- Waivers. This one gets almost no coverage. The CMMC Program rule at 32 CFR 170.3(c)(2) lets the Department waive CMMC requirements for a procurement before the solicitation. The implementation procedures state that no waivers shall be granted during the review. If a waiver was your plan, that door closed on July 13 too.
What is still in force
- CMMC Level 1 (Self) and Level 2 (Self) assessments, where required by the procurement or contract.
- NIST SP 800-171 Revision 2 as the CMMC Level 2 assessment standard during the interim, enforced through self-assessments and select government-led assessments.
- DFARS 252.204-7012, named explicitly in the Department's July 13 announcement as continuing to bind contractors and subcontractors where included and applicable.
- CMMC self-assessment result and affirmation posting in SPRS.
- 32 CFR Part 170 — the program rule itself. Not repealed. Still in force. On our August 14 check, the eCFR displayed Title 32 as current through August 12, 2026.
What depends entirely on your paperwork
- Whether your specific solicitation has actually been amended.
- Whether your specific contract has actually been modified.
- Whether your prime has changed anything in writing.
- Whether an assessment you already booked still serves a contractual or business purpose.
There is one more thing worth saying plainly, because it shapes everything downstream: this was done by memo, not by rulemaking. We found no amendment to the text of 32 CFR Part 170 and no withdrawal of DFARS 252.204-7021 or 252.204-7025. Our operational inference is simple: current designation policy could change again through new Department guidance without waiting for Part 170 to be rewritten.
Why CMMC can be paused and still apply to you
Answer capsule: CMMC obligations operate in three separate layers: the contract requirement that makes a CMMC Status a condition of award or performance, the underlying safeguarding duty imposed by FAR and DFARS clauses, and the assessment mechanism used to verify compliance. The July 2026 suspension changed Department policy for new independent-assessment designations and directed changes to affected solicitations and contracts. It did not remove the safeguarding layer.
This is the single most common point of confusion we see, and it's why two things that sound contradictory are both true.
Think of it as a stack.
| Layer | What it is | Typical instrument | What July 13 changed |
|---|---|---|---|
| 1. Contract requirement | A CMMC Status is a condition of award or an ongoing contract requirement | DFARS 252.204-7025 in the solicitation; DFARS 252.204-7021 in the contract | New requirements may designate only Level 1 (Self) or Level 2 (Self). Affected active solicitations and existing contracts are supposed to be amended or modified; check whether yours actually was. |
| 2. Safeguarding duty | You must protect the information whether or not an independent CMMC gate is approaching | FAR 52.204-21 or deviation clause 52.240-93 for FCI; DFARS 252.204-7012 for covered defense information | No removal. DFARS 252.204-7012 remains in effect where included and applicable. |
| 3. Assessment and record | How implementation is evaluated and recorded — self-assessment, C3PAO, DIBCAC, CMMC Status, affirmation, and related SPRS entries | 32 CFR Part 170; DFARS 252.204-7021; SPRS; the July memoranda | New C3PAO and DIBCAC designations are paused. CMMC self-assessments and select government-led assessments continue. |
We call this the CMMC Requirement Stack. It is an explanatory component of The CMMC Path Framework, our decision logic for mapping a contractor's level, data scope, assessment type, environment, and timeline to the right provider category. It is not a score, a ranking, or compliance advice.
Read the stack once and the headlines stop being confusing. "CMMC Phase 2 was suspended" is a statement about new independent-assessment requirements and the rollout schedule. "You still have to protect CUI" is a statement about safeguarding. Both are correct. Vendors who collapse the layers — in either direction — are the reason you're on this page.
For a deeper rule-versus-clause breakdown, compare the three levels in our CMMC Levels guide and then use the CMMC provider-category map to see which kind of help belongs at each layer.
The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The written requirement sets your path, not a generic checklist. Because a general answer can't resolve those facts for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
Definitions, once, then we use them freely: FCI (Federal Contract Information) is non-public information provided by or generated for the Government under a contract to develop or deliver a product or service, excluding information the Government provides to the public and simple transactional information. CUI (Controlled Unclassified Information) is unclassified information that law, regulation, or government-wide policy requires or permits an agency to safeguard or control. A C3PAO (CMMC Third-Party Assessment Organization) is an authorized or accredited organization that performs formal CMMC Level 2 certification assessments. DIBCAC is the Defense Industrial Base Cybersecurity Assessment Center, the government team that performs Level 3 and other government-led assessments. SPRS is the Supplier Performance Risk System, where CMMC assessment results, statuses, and affirmations are recorded and where certain NIST SP 800-171 DoD Assessment results are posted. RPO/RP means Registered Provider Organization or Registered Practitioner — readiness and advisory help, not the formal certification decision.
The honest part: some of what you were paying for bought a deadline
Here's the thing most vendor pages won't tell you, because it costs them money to say it.
A slice of your CMMC budget was buying a date, not security. Rush fees to be assessment-ready by November 10. Premium consulting hours priced against a hard deadline. Tooling purchased to close a gap before an assessor walked in. Scheduling deposits to hold a scarce assessor slot. That deadline is gone for now, and the urgency premium attached to it went with it. If you were paying for speed alone, you can stop paying the urgency premium without pretending the underlying work disappeared.
We're not going to pretend otherwise, and we'd be suspicious of anyone who did.
Now the pivot, and it's the whole argument of this page.
Underneath the deadline was work that had nothing to do with the deadline. Mapping where your CUI actually lives. Access control. Multifactor authentication. Logging. A System Security Plan that describes the system you actually run. An assessment result and SPRS record that match reality. None of that was created by the November date, and none of it disappeared when the date did. Where DFARS 252.204-7012 applies, the safeguarding obligation exists independently of the paused Phase 2 gate. And the same implementation evidence feeds every credible path forward.
Because here's the uncomfortable truth about the review: the controlling documents do not tell you what CMMC will look like in 2027. They announce a broad review, a 60-day recommendation period, and future guidance. Any page that tells you confidently how this resolves is guessing.
That uncertainty changes less than it sounds like it does. Run the scenarios. If independent certification returns broadly, you're ahead. If it returns narrowly, you're ready if you're in the narrowed group. If the program is restructured, the Department has still said it will enforce a security baseline during the interim. And even if the CMMC rollout were later cancelled, DFARS 252.204-7012 would remain in an existing contract unless the contract itself changed.
Our editorial judgment is that real controls, accurate scope, and defensible records are the lowest-regret investment across the live scenarios. There are several scenarios where an inaccurate or stale record is much worse. We'll show you exactly why in a moment, with a case the Justice Department already resolved.
And if this doesn't apply to you, we'd rather you left. If you're genuinely FCI-only — no CUI anywhere in your environment, no flow-down asking for more — this story is smaller than the headlines suggest. If your instrument requires Level 1, that path did not disappear on July 13, but it is not the Level 2 certification project driving six-figure fear. Start with our CMMC Level 1 self-assessment checklist instead of reading the rest of this page.
Which CMMC clause is actually in your contract?
Answer capsule: The clause-number story is not “old numbers disappeared.” As of August 14, 2026, the codified DFARS still displays 252.204-7019 and 252.204-7020. But effective February 1, 2026, DoD class deviation 2026-O0025 directs contracting officers to use revised FAR Part 40 and DFARS Part 240 in lieu of the codified coverage for affected acquisitions. In instruments issued under that deviation, FAR 52.240-93 replaces the basic FCI safeguarding clause, DFARS 252.204-7019 is not prescribed, and DFARS 252.240-7997 carries the government Medium/High NIST SP 800-171 assessment function. DFARS 252.204-7012, 252.204-7021, and 252.204-7025 keep their numbers.
This is the part we haven't seen anyone else connect, and it has practical consequences.
The Department's own July 2026 implementation procedures refer to FCI basic safeguarding by the codified citation, FAR 52.204-21. But the Revolutionary FAR Overhaul moved information-security coverage from FAR Part 4 to Part 40, and DoD's deviation moved related DFARS coverage from Part 204 to Part 240. The revised FAR Part 40 prescribes FAR 52.240-93 for basic safeguarding in covered deviation-issued instruments.
So if you read the July memo, open a newer solicitation, and search only for 52.204-21, you may come up empty and conclude the requirement does not apply. Search the deviation number and the replacement clause before you make that call.
The same problem runs the other direction. The codified DFARS pages still contain 252.204-7019 and 252.204-7020. If either clause appears in an executed instrument, do not treat it as nonexistent because a newer deviation package uses different coverage.
Here is the full picture. We built this table by reading the codified clauses, class deviation 2026-O0025, the July implementation procedures, and 32 CFR Part 170 side by side on August 14, 2026. The important distinction is not “old versus invalid.” It is codified or already-incorporated language versus a newer instrument issued under the deviation.
The CMMC Obligation Ledger
| Obligation | Codified or older instrument | Newer DoW instrument issued under deviation 2026-O0025 | What it requires | Effect of July 13, 2026 |
|---|---|---|---|---|
| Basic safeguarding of FCI | FAR 52.204-21 | FAR 52.240-93 | 15 basic safeguarding requirements for covered contractor information systems handling FCI | None |
| Offeror representation on covered-defense-information controls | DFARS 252.204-7008 | DFARS 252.204-7008 | Offeror representation tied to implementation of the safeguarding requirements associated with 252.204-7012 | None |
| Safeguarding covered defense information | DFARS 252.204-7012 | DFARS 252.204-7012 | NIST SP 800-171 implementation under the applicable clause/version direction; 72-hour cyber-incident reporting; cloud and flow-down requirements | None. The Department expressly said the clause remains in effect. |
| Pre-award notice for a current NIST SP 800-171 DoD Assessment | DFARS 252.204-7019 remains in the codified DFARS and may appear in existing instruments | Not prescribed in the Part 240 deviation package | Under the codified provision, an offeror subject to NIST SP 800-171 must have a current Basic, Medium, or High assessment for each relevant covered contractor information system before award | The July suspension did not amend this provision. Whether it applies to you depends on the clause package in your instrument. |
| NIST SP 800-171 DoD Assessment access and posting | DFARS 252.204-7020 remains codified | DFARS 252.240-7997 | Government access for Medium/High assessments and government posting of those results in SPRS. The deviation clause does not carry forward the contractor-submitted Basic-assessment mechanism from 252.204-7020. | None |
| CMMC requirements clause | DFARS 252.204-7021 | DFARS 252.204-7021 | Hold and maintain the required CMMC Status; maintain current affirmation; provide CMMC UID information; flow down the required substance | This is where the suspension bites. New requirement documents may designate only Level 1 (Self) or Level 2 (Self) during the suspension. Existing instruments still need to be checked for an issued change. |
| CMMC solicitation notice | DFARS 252.204-7025 | DFARS 252.204-7025 | States the required CMMC level and assessment type in the solicitation and requires the matching current status and affirmation before award | Same designation limits as above |
| CMMC Program rule | 32 CFR Part 170 | 32 CFR Part 170 | Levels, assessment types, scope, scoring, POA&M limits, affirmation, and flow-down | Not repealed or amended by the July memoranda |
| Prime flow-down | The executed subcontract or other contractual instrument | The executed subcontract or other contractual instrument | The requirement actually incorporated by the parties | Not amended automatically by the Department memoranda |
| Annual affirmation | 32 CFR 170.22 and DFARS 252.204-7021 | Same | An affirming official attests to continuing compliance after the assessment and annually thereafter, as applicable | Not suspended |
One caution on this table. A class deviation tells contracting officers which text to use; it does not silently rewrite every older award. Clause applicability depends on the instrument, its issue date, its modifications, and the deviation language incorporated into it. Check the clause list in your own document rather than relying on a generic “current clause” chart — that's the entire point of the exercise.
SPRS has two records people keep calling “the score”
This distinction matters enough to separate it.
| Record | Authority | What it is |
|---|---|---|
| NIST SP 800-171 DoD Assessment score | DFARS 252.204-7019/-7020 in codified or already-incorporated instruments; government Medium/High coverage under deviation clause 252.240-7997 | The older Basic/Medium/High DoD Assessment record. Under the codified clauses, a contractor may submit a Basic score. Under 252.240-7997, DoD posts Medium/High results and the contractor-submitted Basic mechanism is absent. |
| CMMC assessment result, CMMC Status, CMMC UID, and affirmation | 32 CFR Part 170 plus DFARS 252.204-7021/-7025 | The CMMC record used to establish Level 1, Level 2, or Level 3 status and continued eligibility where CMMC is required. This is not erased because a legacy Basic-score provision is absent from a newer deviation-issued instrument. |
What to actually search for
Open the PDF of your contract or solicitation and search these strings, one at a time:
2026-O0025 · 252.204-7008 · 252.204-7012 · 252.204-7019 · 252.204-7020 · 252.240-7997 · 252.204-7021 · 252.204-7025 · 52.204-21 · 52.240-93 · CMMC · Level 1 · Level 2 · C3PAO · DIBCAC
Write down four things: the clause, the required level, the assessment type, and the latest amendment or modification date. That five-minute exercise answers more of your question than any article will.
Not sure what the clauses you found actually require of you?
That's the gap this publication exists to close. Tell us your level, your FCI/CUI scope, and your timeline, and we'll map your situation to the provider category that fits — readiness, managed security, evidence and workflow, CUI enclave, or formal assessment — before you request a single quote.
→ Map my situation to the right provider category
Do not submit CUI, drawings, technical data, export-controlled content, or sensitive contract details. High-level categories only.
Do I still need a self-assessment, an SPRS score, and an annual affirmation?
Answer capsule: Where CMMC is required, the self-assessment and affirmation rules still apply. Level 1 is assessed annually. Final Level 2 (Self), Level 2 (C3PAO), and Level 3 statuses run on three-year assessment cycles, with an affirmation when the assessment is completed and annually thereafter. Results, statuses, CMMC UIDs, and affirmations are recorded in SPRS. A legacy NIST SP 800-171 DoD Basic score under DFARS 252.204-7019/-7020 is a separate record whose applicability depends on the clauses in your instrument.
And here's the part that should get your attention: with new third-party certification designations paused, your organization's own assessment and affirmation carry more of the live verification burden on the Level 1 and Level 2 self-assessment paths. The suspension did not turn a self-attestation into a free pass.
Two technical details from the Department's July 2026 CMMC FAQ can stop a Level 2 submission cold:
- If you mark the System Security Plan requirement, CA.L2-3.12.4, as Not Met, SPRS returns No CMMC Score. Without an up-to-date SSP, the assessment cannot be completed.
- If the assessment score divided by 110 is below 0.8, SPRS returns No CMMC Status. That means you need at least 88 points, not 88 requirements fully met. CMMC Level 2 uses weighted deductions of 1, 3, or 5 points depending on the requirement, so the number of unmet requirements alone does not tell you whether you cleared the threshold. And six specified requirements cannot be placed on a Plan of Action and Milestones for purposes of achieving Conditional Status under 32 CFR 170.21.
That points-versus-requirements distinction is not trivia. A page that tells you “meet 88 controls” is giving you the wrong decision rule.
SPRS operational note: The official SPRS CMMC page provides the Level 1, Level 2, and affirmation entry guides. Its separate NIST SP 800-171 page says SPRS stores NIST SP 800-171 assessment results; it does not perform the Basic assessment.
The case that explains why accuracy matters more now
We looked for a real, attributable enforcement example rather than a hypothetical. This one is the clearest on the public record, and the admitted facts are not merely the Government's allegations.
On March 26, 2025, the Justice Department announced that MORSECORP Inc., of Cambridge, Massachusetts, agreed to pay $4.6 million to resolve False Claims Act allegations involving cybersecurity requirements in Army and Air Force contracts. As part of the settlement, MORSECORP admitted, acknowledged, and accepted responsibility for specified facts. Among them:
In January 2021, the company reported a NIST SP 800-171 score of 104. The methodology's possible range runs from −203 to 110, so 104 sits near the top. In July 2022, a third-party consultant told the company its score was −142. The company did not correct the score in the Department's reporting system until June 2023, after being served with a subpoena in March 2023.
That is a 246-point gap between what was posted and what the consultant calculated, and the 104 entry remained uncorrected for roughly two and a half years. The relator received $851,000 from the settlement.
We are not suggesting this outcome is typical, and this was not a CMMC enforcement case. The conduct predates the revised CMMC acquisition clauses becoming effective on November 10, 2025, under the final DFARS rule published at 90 FR 43560. It was a civil False Claims Act settlement about NIST SP 800-171 implementation, representations, and a reported score. Which is precisely why it matters right now: the July suspension did not suspend the False Claims Act, DFARS 252.204-7012, or the risk created by an inaccurate government record.
If your posted assessment was aspirational when you entered it, it was a problem before. It remains a problem now, and you cannot rely on a future C3PAO gate to find the mismatch first.
Is your posted record defensible today?
If there's daylight between what SPRS says and what's actually implemented, closing that gap is the single highest-value thing you can do during this window — and it's work you'd need under any outcome that keeps DFARS 252.204-7012 in your instrument.
→ See what a defensible self-assessment requires — our free readiness checklist, organized across the 14 NIST SP 800-171 Revision 2 families.
Not sure whether you need implementation help or just a second set of eyes? Compare provider categories first.
Primary enforcement source: U.S. Department of Justice, MORSECORP settlement announcement, March 26, 2025.
My contract already says Level 2 (C3PAO). Am I off the hook?
Answer capsule: Not automatically. The July 13 implementation procedures direct program offices to amend active solicitations that require Level 2 (C3PAO) or Level 3 as soon as practicable. For existing contracts, contracting officers were directed to remove those requirements by modification before the next option exercise or during the next scheduled administrative modification. Until the controlling instrument changes, get the contracting officer's position in writing before changing performance or bid strategy.
This is the distinction that costs people money: a memorandum to government personnel is not an amendment to your contract.
The implementation memo tells program managers and contracting officers what to do. It does not reach into your award document and edit it. The stated timing — before the next option exercise or during the next scheduled administrative modification — can leave a real interval between Department policy and the words still sitting in your contract.
So: don't stop, and don't assume. Ask.
Send your contracting officer a short written note asking whether the Level 2 (C3PAO) or Level 3 requirement remains operative for your instrument, when the amendment or modification will issue, and what the Government expects in the meantime. Keep the answer in the contract file. That is the difference between a documented position and a guess.
The wrinkle worth understanding
Here's something we found by reading the rule and the memo against each other, and it explains why you may still see a C3PAO requirement in the wild.
The CMMC Program rule at 32 CFR 170.3(e)(1) describes Phase 1 and says DoD may, at its discretion, include a Level 2 (C3PAO) requirement in place of Level 2 (Self) for applicable solicitations and contracts. That discretion remains in the rule because Part 170 was not amended.
The July 13 implementation procedures then direct program managers and requiring activities not to designate Level 2 (C3PAO) or Level 3 (DIBCAC) during the suspension.
Read together: the rule still contains the authority, while current Department policy instructs program offices not to use it. Our operational inference: a later policy memorandum could reopen new Level 2 (C3PAO) or Level 3 designations without first rewriting § 170.3. Your own solicitation, contract, or subcontract would still have to change through the instrument-specific process that applies to it.
If a requirement document issued or amended after July 13 still designates Level 2 (C3PAO) or Level 3, escalate for written clarification. Do not decide on your own that it is automatically void — or automatically untouched.
Primary sources: 32 CFR 170.3(e)(1) and the July 13, 2026 CMMC implementation procedures.
Does my prime contractor's flow-down still apply?
Answer capsule: Yes, where the executed subcontract requires a CMMC status or safeguarding obligation and the relevant FCI or CUI scope exists. Section 170.23 establishes CMMC flow-down rules, but the obligation you must perform is also written into your subcontract. The July 2026 memoranda direct Department personnel; they do not automatically amend an executed subcontract. Relief does not travel downhill by headline.
If you're a subcontractor, this section matters more to you than anything else on this page.
Three rules we'd hold to:
Silence is not relief. A prime who has not changed the subcontract or requirement in writing has not documented a release.
"Under review" is the same as silence for planning purposes. Keep the current written requirement in view until the prime gives you a definite answer through the process your subcontract requires.
If multiple primes touch the same shared environment, the strictest live requirement can set that environment's posture. Separately scoped systems can support different requirements. One shared network usually cannot be treated as Level 1 for one customer and Level 2 for another while the same CUI crosses it.
One detail in 32 CFR 170.23(a)(3) catches people out: when the prime contract requires CMMC Level 3, the minimum subcontractor requirement for a subcontractor that will process, store, or transmit CUI is CMMC Level 2 (C3PAO), unless the Department gives other contractual guidance. Level 3 at the top of the chain does not automatically mean Level 3 for everyone beneath it — but the rule's default is not Level 2 (Self).
Read our full CMMC flow-down requirements guide if the prime/subcontract boundary is the part you need to resolve.
Send this to your prime
Copy this. Change the brackets. Send it today.
Subject: Confirmation of current CMMC requirement — [contract / subcontract / opportunity number]
Following the July 13, 2026 suspension of CMMC Phase 2, we are confirming our obligations under this agreement. Could you please confirm in writing:
- The exact CMMC status required of us — Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), Level 3, or another stated requirement.
- The subcontract provision, flow-down clause, or prime-contract requirement that establishes it.
- Whether our systems are expected to process, store, or transmit FCI, CUI, or both.
- Whether any amendment or modification since July 13, 2026 changed this requirement.
- The evidence you require from us, and by when.
We will not transmit CUI, drawings, technical data, or sensitive contract material by ordinary email. Please identify a protected channel if any response requires that content.
A good answer names the status, assessment type, clause or subcontract provision, data basis, and date. An answer like "everyone needs Level 2" or "just send us the certificate" is not an answer — it's a prompt to ask again, politely, in writing.
Your prime answered. Now what?
A written flow-down requirement tells you what you need. It doesn't tell you who to hire — and the wrong category is an expensive mistake. Readiness, managed security, evidence workflow, enclave deployment, and formal assessment are different jobs.
→ See who to hire first for CMMC or map your situation before requesting quotes.
Do not submit CUI, drawings, technical data, export-controlled content, or sensitive contract details.
Primary source: 32 CFR 170.23, Application and flow-down of CMMC requirements.
Do I still need NIST SP 800-171? And is it Revision 2 or Revision 3?
Answer capsule: Yes, wherever DFARS 252.204-7012 applies — and the CMMC-controlling version remains NIST SP 800-171 Revision 2. CMMC Level 2 uses its 110 security requirements across 14 families. NIST itself has superseded Revision 2 with Revision 3, but NIST publication status does not silently amend 32 CFR Part 170 or your contract.
We're flagging this one hard because "NIST's current edition" and "the edition CMMC currently assesses" are now different answers. Mixing them up can send a contractor through the wrong implementation project.
The Department's July announcement named Revision 2 as the interim enforcement standard. Its CMMC FAQ says a class deviation to DFARS 252.204-7012 maintains Revision 2 for DIB assessments until Revision 3 is incorporated through rulemaking.
The CMMC version-control ledger
| Question | NIST's current publication on August 14, 2026 | CMMC-controlling source today | What to implement for the current CMMC assessment path |
|---|---|---|---|
| Level 1 | Not a NIST SP 800-171 level | 15 basic safeguarding requirements from the applicable FAR clause | The 15 Level 1 requirements |
| Level 2 | NIST SP 800-171 Rev. 3, published May 2024 | 32 CFR Part 170 still identifies the 110 requirements in NIST SP 800-171 Rev. 2 | Rev. 2, unless and until the controlling rule, clause, or deviation changes |
| Level 3 | NIST SP 800-172 Rev. 3, published May 2026 | Part 170 still identifies 24 selected requirements from the February 2021 edition of NIST SP 800-172, in addition to Level 2 | The Part 170 selection from the 2021 edition for the current CMMC Level 3 model; new Level 3 designations are presently paused |
That table resolves the apparent contradiction. NIST has moved. CMMC has not yet moved with it.
Can you implement Revision 3 anyway? Yes. The Department's FAQ says a contractor may use Revision 3 with the DoD Organization-Defined Parameters published in the Department's April 2025 memorandum. But the FAQ also warns that a Revision 3 implementation still has to account for Revision 2 requirements until the controlling CMMC and DFARS changes occur.
In plain terms: implementing Revision 3 does not excuse you from Revision 2. It may be a deliberate forward-looking architecture choice. It is not a substitute for the assessment basis currently written into CMMC.
Primary sources: the DoW CMMC FAQ, 32 CFR 170.14, and the NIST CSRC publication records linked in the table.
Should I cancel my C3PAO assessment?
Answer capsule: Not from the headline alone. The suspension stopped program offices from newly designating Level 2 (C3PAO) and Level 3 requirements during the review; it did not shut down the C3PAO assessment system. The Cyber AB said on July 15, 2026 that Level 2 assessment operations remained available. A live contractual requirement, voluntary business objective, cancellation terms, readiness state, and assessor independence all belong in the decision.
Straight answer: it depends on whether you were buying a certificate, a November deadline, or the readiness underneath it.
If you booked purely to clear the November 10 Phase 2 gate, that gate is suspended, and the near-term award value you attached to that date dropped. That's real.
But before you call your assessor, work through these:
Does a live instrument still require it? A signed contract or executed prime flow-down can remain written more strictly than current policy for new designations until it is changed through the applicable process.
What are your cancellation and rescheduling terms? Deposits, notice windows, rescheduling rights, and cancellation fees come from the engagement agreement. Read it before you move the date.
Are you actually ready? An assessment is not remediation. Paying for a formal assessment while known gaps remain can turn a deadline problem into an expensive failure record.
Is there a business objective beyond a new DoW award condition? A prime, teaming partner, board, insurer, or internal risk program may still value an independent status. Make sure that value is real and written down rather than assumed.
Is the C3PAO still authorized or accredited and in good standing? Check the organization in the Cyber AB Marketplace before signing, rescheduling, or paying another installment. A provider's marketing page is not the status record.
The Cyber AB's July 15 statement reported a dated ecosystem snapshot of 110 authorized C3PAOs, more than 1,000 Certified CMMC Assessors, and nearly 2,000 contractors with final Level 2 status. Those figures establish that the assessment system existed and remained operational immediately after the suspension. They are a July 15 snapshot, not a live Marketplace count.
One structural point we won't soften: readiness work and the formal certification assessment have an independence boundary. The Cyber AB Code of Professional Conduct says a C3PAO and its assessment team may not have served as a consultant to help prepare that organization for any CMMC assessment during the previous three years. The CAP also requires conflict checks and prohibits guarantees or promises of a certification result.
So the decision is not "consultant or assessor." It is which job do you need next, and are the roles cleanly separated? If known implementation gaps remain, start with the appropriate readiness or managed-security category. If the environment is ready and a documented objective still justifies certification, use a Marketplace-listed C3PAO that passes the conflict check.
Read the CMMC Level 2 cost guide before changing a paid engagement, and use Who to Hire First if the category itself is still unclear.
Operational sources: the Cyber AB Marketplace, the Cyber AB's July 15, 2026 suspension statement, the CMMC Assessment Process v2.0, and the Cyber AB Code of Professional Conduct v2.0. Marketplace status should be rechecked on the date of engagement.
Who might not need CMMC right now?
Answer capsule: Some contractors have no present CMMC assessment trigger from the facts in front of them. Part 170 excludes federal information systems operated on the Government's behalf and acquisitions exclusively for commercially available off-the-shelf items. Its general applicability provision covers relevant acquisitions valued above the micro-purchase threshold, subject to the phase-in. A contractor that will not process, store, or transmit FCI or CUI on a contractor information system also lacks the data-handling predicate the CMMC rule uses. Paper-only CUI receives a narrower assessment exception, not a safeguarding exemption.
We'd rather disqualify you than sell you something. Five situations where the honest answer is "less than you think."
You operate a federal information system on behalf of the Government. Section 170.3(b) says Part 170 does not apply to federal information systems operated by contractors or subcontractors on the Government's behalf. Other federal-system, contract, incident-reporting, or authorization duties can still apply. The point is narrower: the contractor-system CMMC assessment framework is not the first framework to buy against.
The acquisition is exclusively for COTS items. Section 170.3(c) excludes acquisitions exclusively for commercially available off-the-shelf items. Read that carefully. "We sell a commercial product" is not the same statement. The acquisition must be exclusively COTS, and a separate instrument or actual FCI/CUI handling can still create obligations outside that exclusion.
The acquisition is at or below the micro-purchase threshold. Section 170.3(c) frames the CMMC Program's general applicability for covered acquisitions valued greater than the micro-purchase threshold, subject to the phase-in. That threshold is in the rule. It is not an employee-count exemption, and it does not erase a separate safeguarding term already written into an instrument.
No FCI or CUI will touch a contractor information system. Part 170 ties the required status to contractor systems that will process, store, or transmit FCI or CUI in contract performance. If none of that occurs on your systems, those facts alone do not create the assessment trigger. Document the data flow rather than assuming it.
Your CUI is genuinely paper-only. The Department's CMMC FAQ says an organization handling only hard-copy CUI is not required to complete a third-party CMMC assessment because of the lower-risk paper-only scenario. But two conditions attach, and they matter:
- You are still required to protect the hard-copy CUI under the applicable NIST SP 800-171 requirements and DoD Instruction 5200.48 when DFARS 252.204-7012 applies and is flowed down.
- Before you put that CUI on a system — by scanning, entering, photographing, uploading, printing, or emailing it — the receiving system is expected to satisfy the applicable CMMC assessment requirements.
That second condition is a trap. One scan-to-email of a marked drawing can change the scoping answer.
The no-trigger test
| Question | If the answer is yes | What not to assume |
|---|---|---|
| Is this a federal information system operated on the Government's behalf? | Start with the instrument and federal-system requirements, not a generic contractor CMMC package | That no cybersecurity duties apply |
| Is the acquisition exclusively COTS? | Confirm the exclusion in the actual acquisition | That every “commercial” sale is COTS-only |
| Is the acquisition at or below the micro-purchase threshold? | Confirm the value and clause package in the actual instrument | That a small company is exempt, or that separate safeguarding terms disappear |
| Will any contractor system process, store, or transmit FCI or CUI? | If no, document the data path before buying assessment work | That “we never receive marked files” proves the answer |
| Is all CUI truly hard-copy only? | Preserve the paper controls and prohibit unapproved digitization | That paper-only means unprotected |
If one of these rows fits, don't buy a CMMC package based on the headline. Confirm the instrument and data path first. That is the right answer even though it may not route you anywhere.
Primary sources: 32 CFR 170.3 and the DoW CMMC FAQ, including the hard-copy CUI answer.
The CMMC After-the-Pause Contract-Action Matrix
Answer capsule: The next action falls into four buckets: continue a live requirement, verify a document change in writing, reconsider deadline-only spending, or document that no present trigger is established. The deciding inputs are the controlling instrument, FCI/CUI scope, assessment type, and whether an amendment or modification actually issued.
This is where everything above resolves into a decision. We assembled this matrix on August 14, 2026 from the July 13 announcement, the implementation procedures attached to Memo 26-P-1023, the CMMC FAQ, 32 CFR Part 170, and the instruments contractors actually have to open. “Source status” separates a rule or memorandum statement from our action verdict.
| Your situation | Source status | What the primary sources establish | Our action verdict | Where to look for help |
|---|---|---|---|---|
| New solicitation requires Level 1 (Self) | Current suspension policy + Part 170 | Level 1 (Self) remains an allowed designation; assessment and affirmation are annual | CONTINUE — complete and maintain the stated status | Level 1 checklist if the scope is clear |
| New solicitation requires Level 2 (Self) | Current suspension policy + Part 170 | Level 2 (Self) remains allowed; 110 Rev. 2 requirements, triennial assessment, annual affirmation | CONTINUE — use evidence, not an aspirational score | Readiness, MSP/MSSP, or evidence workflow if a verified gap exists |
| Active solicitation still names Level 2 (C3PAO) or Level 3 | July 13 implementation procedures | Program offices were directed to initiate amendments removing those designations as soon as practicable | VERIFY IN WRITING — get the amendment before changing bid strategy | Contracting officer; federal-contracts counsel or RP/RPO if ambiguity remains |
| Signed contract still names Level 2 (C3PAO) or Level 3 | July 13 implementation procedures; instrument-specific effect unresolved until action | Contracting officers were directed to remove the requirement by modification before the next option or scheduled administrative modification | VERIFY IN WRITING — do not treat the memo itself as your modification | Contracting officer; counsel or RP/RPO |
| Prime says only “Level 2” | Part 170 defines two Level 2 assessment types | Level 2 (Self) and Level 2 (C3PAO) are different statuses | VERIFY IN WRITING — ask for status, provision, data basis, and date | Flow-down guide or qualified counsel |
| Executed subcontract flow-down remains unchanged | Part 170 + private instrument | The federal memoranda do not automatically amend the subcontract | CONTINUE OR ESCALATE — follow the written term while seeking a written change through the subcontract process | Prime, counsel, then the appropriate readiness category |
| C3PAO booked only for the November 10 Phase 2 gate | Date suspended; engagement terms private | The government date moved; your cancellation and rescheduling rights did not come from the memo | REPRICE THE DECISION — check live requirements, fees, readiness, and voluntary value before cancelling | C3PAO for contract terms; a separate readiness advisor for readiness strategy |
| Already hold a CMMC status | Part 170 | Normal status periods and annual affirmations remain; the suspension did not revoke achieved statuses | PRESERVE AND MAINTAIN — keep scope, evidence, and affirmations current | None unless the environment or requirement materially changes |
| FCI only, no CUI and Level 1 is specified | FAR safeguarding + Part 170 | Fifteen Level 1 requirements; annual self-assessment and affirmation | CONTINUE, SMALLER SCOPE — do not buy a Level 2 project by reflex | Level 1 checklist |
| Paper-only CUI | DoW FAQ | No third-party assessment solely for the paper-only scenario; safeguarding remains; digitization changes the answer | SAFEGUARD AND CONTROL DIGITIZATION | Scoping help before a scan, upload, print, photo, or email workflow |
| Government-led assessment notice received | July 13 announcement | Select government-led assessments continue during the suspension | RESPOND — the suspension is not a basis to ignore the notice | Qualified counsel and readiness support |
| Acquisition at or below the micro-purchase threshold | § 170.3(c) general applicability threshold | Part 170's general coverage is for covered acquisitions valued above the threshold; separately incorporated terms still need checking | VERIFY THE INSTRUMENT — DON'T BUY FROM COMPANY SIZE ALONE | Contracting officer or qualified counsel if the clause package conflicts |
| No controlling DoW instrument and no FCI/CUI handling | No trigger established from those facts | The cited CMMC predicates are absent | DOCUMENT, MONITOR, DON'T BUY YET | Monitor pipeline and data flows |
Found your row? Here's the next step that actually saves money.
Most contractors who reach this point don't have a motivation problem. They have a sequencing problem — they are about to buy the right thing at the wrong time, or the wrong thing at any time. Your level, data, environment, and timeline point to a provider category before they point to a company.
→ Map my situation to the right provider category — high-level inputs only. We resolve the category first, then the provider options.
The Find My CMMC Path tool is an educational routing tool. It does not determine compliance, interpret a contract, rank every provider, or guarantee certification.
Do not submit CUI, drawings, technical data, export-controlled content, contract files, or sensitive contract details.
What should I do about CMMC this week?
Answer capsule: Pull the controlling documents, map the FCI/CUI path, identify the exact CMMC status and assessment type, check for a formal amendment or modification, and validate the assessment records and affirmations that still apply. The first pass is document work. Do not buy technology before you know which row in the matrix is yours.
Five steps. Start with the paper, not a sales call.
1. Pull the controlling set. Collect the solicitation and every amendment, award and every modification, option documents, subcontract and flow-down provisions, and recent written direction from the prime or contracting officer.
2. Map the data at decision level. FCI, CUI, both, or neither. Paper-only or digital. Which systems process, store, or transmit it. At this stage you need a defensible high-level path, not a finished assessment scope.
3. Find the exact status and assessment type. Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), Level 3 (DIBCAC), or unspecified. “CMMC compliant” is not an assessment type. “Level 2” alone is incomplete.
4. Check for formal change. Record the amendment or modification number, effective date, and the requirement it changed. If nothing has issued, record the date you checked and the person you asked.
5. Validate the records that remain live. Confirm the applicable CMMC self-assessment, CMMC status, SPRS entry, assessment scope and UID, and annual affirmation. Separately confirm whether an older NIST SP 800-171 DoD Assessment Methodology Basic score remains current for the instrument you are pursuing. Do not update any record from memory; reconcile it to evidence.
Need a working document for that first pass?
Use the free CMMC readiness checklist to organize the 14 Revision 2 families, or map the provider category first when the next job is still unclear.
Do not upload CUI, drawings, technical data, export-controlled content, or contract files to an open web form.
The Department also identifies no-cost starting resources: the Cyber AB Marketplace, Warfighting Acquisition University CMMC micro-learning, and the Defense Cyber Crime Center's DIB cybersecurity resources. You do not have to spend money to pull the documents, identify the data path, or verify a Marketplace status.
Does the CMMC review mean Phase 2 automatically restarts?
Answer capsule: No automatic restart appears in the controlling documents. Memo 26-P-1023 directs the CMMC Reform Task Force to deliver recommendations to the Department CIO within 60 days of July 13, 2026. The implementation procedures promise further guidance at the conclusion of the review. Neither document supplies a replacement Phase 2 start date.
What has a date:
- Part 170's original Phase 1 window was November 10, 2025 through November 9, 2026.
- Phase 2 was originally scheduled to begin November 10, 2026.
- The Department suspended that transition on July 13, 2026 and placed later milestones in abeyance.
- The public Request for Information closed at 12:00 p.m. Eastern on August 14, 2026.
- The task force recommendations are due within 60 days of July 13. Sixty calendar days lands on September 11, 2026.
What does not have a date: a replacement Phase 2 start, automatic resumption, a final reform model, future treatment of C3PAO and DIBCAC designations, or a completed rulemaking timetable.
The Department framed the review around reducing burden for small, medium, and non-traditional businesses. The RFI asked which requirements deliver risk reduction, which create burden without proportional benefit, where commercial capabilities can help, and how self-assessment can stay meaningful.
Our read of those questions, not a regulatory fact: the Department is testing options for a lighter or differently targeted verification model. The documents do not establish that outcome, and they do not establish cancellation.
Treat September 11 as the first hard monitoring date, not a promised decision date. A report can arrive without immediately changing a solicitation, contract, subcontract, or Part 170. And because the current designation restriction came through memoranda, a later memorandum could change that policy while instrument-specific changes still follow their own process.
Primary sources: Memo 26-P-1023, the implementation procedures, the Department's CMMC program page, and 32 CFR 170.3(e).
What we actually verified
We think you should know exactly what we read, when, and where the limits are. Here it is.
Regulatory and operational facts checked on August 14, 2026:
- The Department announcement and CIO Memo 26-P-1023.
- The implementation procedures, including designation limits, solicitation amendments, contract modifications, the waiver suspension, and the promise of further guidance.
- The Department CIO's CMMC program page and July 2026 CMMC FAQ.
- 32 CFR Part 170, including applicability, assessment frequencies, the four-phase schedule, model requirements, POA&M limits, scoring, affirmations, and flow-down, plus the final rule as published at 89 FR 83092.
- The complementary CMMC acquisition final rule at 90 FR 43560, effective November 10, 2025, which added the current DFARS CMMC solicitation provision and contract clause framework.
- The current codified text of DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025.
- The Defense Acquisition Regulations System's Revolutionary FAR Overhaul class-deviation index and class deviation 2026-O0025, effective February 1, 2026, which directs use of the deviation's FAR Part 40 and DFARS Part 240 coverage.
- NIST CSRC publication records for SP 800-171 Rev. 2, SP 800-171 Rev. 3, the February 2021 SP 800-172, and SP 800-172 Rev. 3.
- The Cyber AB's post-suspension statement, Marketplace, CMMC Assessment Process, and Code of Professional Conduct for the operational-status and assessor-independence statements used above.
- The official SPRS CMMC resources and SPRS NIST SP 800-171 resources, including the distinction between entering or affirming a CMMC record and storing a NIST SP 800-171 Basic-assessment result.
- The Department of Justice MORSECORP settlement announcement, including the settlement amount, admitted score history, correction timing, and relator share.
Regulation-stated vs. operationally verified:
| Statement type | How this page treats it |
|---|---|
| Text in Part 170, FAR/DFARS, or an official memorandum | Presented as the source states it, with the instrument named |
| A live contract, solicitation, subcontract, Marketplace listing, cancellation term, or contracting-office action | Treated as company- or instrument-specific and something the reader must verify |
| The Defense Compliance Report's recommended action | Labeled as our verdict, framework, inference, or editorial judgment |
| Ecosystem counts | Dated to the Cyber AB's July 15, 2026 statement; not presented as a live Marketplace inventory |
What we could not establish for every reader, and therefore do not pretend to know:
- Whether a particular solicitation, contract, option, or subcontract has already been amended.
- Whether a particular award used the codified clause set or class deviation 2026-O0025.
- The live number of authorized or accredited C3PAOs at the moment you read this page.
- Whether your data is FCI, CUI, both, or outside the stated assessment scope.
- Whether cancelling or rescheduling a private assessment engagement is financially better under its actual terms.
- The publication date already stored for this URL. Deployment must retain that real date rather than invent a new one.
How this was produced: editorial research by The Defense Compliance Report Editorial Team, working from primary government and official program sources. It was not formally reviewed by an outside CMMC Subject Matter Advisor, and no outside reviewer is claimed.
Frequently asked questions
Is CMMC cancelled? No. The Department suspended the transition to Phase 2 and placed later implementation milestones in abeyance. Phase 1 self-assessment paths remain, 32 CFR Part 170 remains in force, and DFARS 252.204-7012 safeguarding obligations remain where included.
Is CMMC still required in 2026? Yes, where the controlling solicitation, contract, or subcontract requires an allowed CMMC status. During the suspension, new procurement requirements may designate Level 1 (Self) or Level 2 (Self), not Level 2 (C3PAO) or Level 3.
What was the original CMMC Phase 1 period? November 10, 2025 through November 9, 2026. Phase 2 was originally scheduled for November 10, 2026, but that transition was suspended on July 13, 2026.
Are Level 1 self-assessments still required? Yes, where Level 1 (Self) is required. The assessment is annual against 15 basic safeguarding requirements, with affirmation at assessment and annually.
Are Level 2 self-assessments still required? Yes, where Level 2 (Self) is required. The assessment is every three years against the 110 NIST SP 800-171 Revision 2 requirements, with affirmation at assessment and annually thereafter.
Do I need a C3PAO assessment for a new award right now? Current suspension policy says program managers and requiring activities may not newly designate Level 2 (C3PAO) or Level 3 during this period. An existing instrument or voluntary business objective is a separate question.
What if my solicitation still says Level 2 (C3PAO)? Program offices were directed to initiate amendments removing that designation. Ask the contracting officer for the actual amendment before changing bid strategy.
What if my signed contract still says Level 2 (C3PAO)? Do not treat the July memorandum as though it edited the contract. Contracting officers were directed to remove suspended requirements by modification before the next option exercise or during the next scheduled administrative modification. Get the instrument-specific direction in writing.
Can my prime still require CMMC from me? An executed subcontract is not automatically amended by a memorandum to Department personnel. Confirm the provision, data basis, assessment type, and any change with the prime in writing.
Do subcontractors still need CMMC? Yes, where the applicable requirement flows down and the subcontractor will process, store, or transmit FCI or CUI. Under § 170.23, when a prime contract requires Level 3, the default minimum for a CUI-handling subcontractor is Level 2 (C3PAO) absent other Government guidance.
Can I stop NIST SP 800-171 work? No, wherever DFARS 252.204-7012 applies. Its safeguarding requirement survived the suspension.
Is CMMC using NIST SP 800-171 Revision 2 or Revision 3? Revision 2. NIST's current publication is Revision 3, but the Department says CMMC assessments remain against Revision 2 until the controlling rulemaking and related clause changes occur.
Which version of NIST SP 800-172 controls CMMC Level 3? Part 170 still selects 24 requirements from the February 2021 edition, even though NIST superseded that publication with SP 800-172 Revision 3 in May 2026. New Level 3 designations are currently paused.
Did DFARS 252.204-7019 and -7020 disappear? Not from the codified DFARS. Both still appear on Acquisition.gov. Under class deviation 2026-O0025, newer Department instruments may omit -7019 and use 252.240-7997 for the relevant government-assessment coverage formerly addressed by -7020. Check the clause list in your instrument.
What CMMC clause numbers should I search? Search both systems: 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, 252.204-7025, 252.240-7997, 52.204-21, and 52.240-93.
Do I still need an SPRS record and annual affirmation? Where the CMMC requirement applies, assessment results/status and affirmations remain part of the program. Do not confuse that CMMC record with the older NIST SP 800-171 DoD Assessment Methodology Basic score; determine which records your instrument requires.
Is my existing CMMC status still valid? The suspension did not revoke achieved statuses. Maintain the applicable scope, security requirements, status period, and annual affirmations.
Can a C3PAO still assess me if I want one? The Cyber AB said assessment operations remained available after the suspension. Verify the C3PAO's current Marketplace standing, conflict status, engagement terms, and the business reason for proceeding.
Can the C3PAO that prepared us perform our certification assessment? Not when the Cyber AB's three-year consulting conflict applies. Its Code of Professional Conduct bars a C3PAO and assessment team from assessing an organization they helped prepare for any CMMC assessment during the preceding three years.
Does CMMC apply if I only sell COTS items? Part 170 excludes acquisitions exclusively for commercially available off-the-shelf items. “Commercial” and “exclusively COTS” are not interchangeable.
Does CMMC apply at or below the micro-purchase threshold? Section 170.3(c) states the CMMC Program's general applicability for covered acquisitions valued greater than the micro-purchase threshold, subject to the phase-in. Check the actual instrument for separately incorporated safeguarding terms before treating the dollar threshold as the entire answer.
Does company size or employee count exempt us from CMMC? No employee-count exemption appears in Part 170. The rule's stated predicates are the instrument, acquisition conditions, system type, and FCI/CUI handling — not head count.
Does CMMC apply if I never handle FCI or CUI? If no contractor system will process, store, or transmit FCI or CUI in contract performance, those facts alone do not establish a CMMC assessment trigger. Document the path and confirm the instrument.
Do I need a third-party assessment for paper-only CUI? The Department FAQ says no for a genuinely paper-only CUI scenario. You must still safeguard the paper, and the receiving system is expected to meet applicable assessment requirements before the CUI is digitized.
Can DIBCAC still assess us during the suspension? The Department says select government-led assessments continue. A notice should be handled on its own terms, not ignored because Phase 2 was suspended.
Can I get a CMMC waiver during the review? The July 13 implementation procedures say no CMMC waivers will be granted during the review period.
When should I check for the next CMMC update? The task force recommendations are due within 60 days of July 13, which lands on September 11, 2026. That is a monitoring date, not a promised restart or completed policy change.
Where this leaves you
The Phase 2 certification schedule moved. The underlying safeguarding requirement didn't. That is the whole story, and everything on this page is the detail that tells you which half applies to your company.
If you take one thing from here, take this: open the controlling instrument and search both sets of clause strings. That turns a national announcement into a specific answer about your business — and right now, that is the only answer worth spending against.
Need help deciding what type of CMMC provider you need?
Tell us your level, high-level FCI/CUI scope, environment, and timeline. We will route the situation to the provider category that fits before you request quotes.
Already know the category you need? Request CMMC provider quotes.
Do not submit CUI, drawings, controlled technical information, export-controlled data, contract files, credentials, network diagrams, vulnerability details, or sensitive contract terms.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when that relationship is disclosed. Compensation does not control our regulatory analysis, provider-category routing, or Cyber AB status checks. This page contains no named provider recommendation.
Not advice: This article is educational research. It is not legal, contractual, cybersecurity, procurement, or compliance advice. Requirements turn on the controlling instrument, the information handled, system scope, and the facts of performance. Confirm disputed applicability or contract meaning with the contracting officer, prime, a qualified federal-contracts attorney, or an appropriately qualified CMMC professional before making an expensive or irreversible decision.
Not affiliated: The Defense Compliance Report is not affiliated with, endorsed by, or sponsored by the Department of War, the Department of Defense, DCMA DIBCAC, NIST, the Cyber AB, or any U.S. government agency. We do not issue CMMC statuses, authorize C3PAOs, or guarantee assessment outcomes.
Primary sources cited on this page
- Department of War, “Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements,” July 13, 2026
- Department CIO Memorandum 26-P-1023, “Removing Barriers to DIB Expansion,” July 13, 2026
- CMMC implementation procedures attached to Memo 26-P-1023
- Department CIO CMMC program page and CMMC Frequently Asked Questions, July 2026
- 32 CFR Part 170, Cybersecurity Maturity Model Certification Program, and the final rule as published at 89 FR 83092
- CMMC acquisition final rule, 90 FR 43560, effective November 10, 2025
- Acquisition.gov: DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025
- Defense Acquisition Regulations System, Revolutionary FAR Overhaul class deviations, including 2026-O0025
- NIST CSRC: SP 800-171 Rev. 2, SP 800-171 Rev. 3, SP 800-172, February 2021, and SP 800-172 Rev. 3
- Cyber AB: post-suspension statement, July 15, 2026, Marketplace, CMMC Assessment Process v2.0, and Code of Professional Conduct v2.0
- SPRS: CMMC assessment and affirmation resources and NIST SP 800-171 assessment-record resources
- U.S. Department of Justice, “Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations,” March 26, 2025
Corrections: Found something wrong? Tell us here. · Methodology · Editorial standards