CMMC Phase 2 Is Paused—CUI Compliance Is Not: What Defense Contractors Must Do Now

Last updated: July 23, 2026

The Department of War has temporarily suspended CMMC Phase 2, which was scheduled to begin November 10, 2026. That announcement has caused widespread confusion across the Defense Industrial Base.

Some contractors are interpreting the decision to mean that CMMC Level 2 has been canceled, NIST SP 800-171 is no longer required, or Controlled Unclassified Information no longer needs to be protected.

None of those conclusions is correct.

What the DoW did was pause the expansion of contractual CMMC Level 2 third-party certification requirements and CMMC Level 3 DIBCAC requirements. It did not eliminate CMMC Level 2 self-assessments, DFARS cybersecurity obligations, NIST SP 800-171 implementation or the responsibility to properly handle and safeguard CUI.

The clearest way to understand the announcement is:

The certification timeline has been paused for review. The obligation to protect CUI has not.

CMMC Phase 2 Pause: Key Takeaways

For contractors looking for a direct answer, here is what the July 2026 CMMC announcement means:

  • CMMC Phase 2 certification requirements will not begin on November 10, 2026 as previously scheduled.
  • Program offices may currently designate CMMC Level 1 Self or CMMC Level 2 Self requirements.
  • Program offices may not currently designate CMMC Level 2 C3PAO or Level 3 DIBCAC assessment requirements.
  • Phase 1 self-assessment requirements remain in effect.
  • NIST SP 800-171 Revision 2 remains the applicable CMMC Level 2 security baseline during the review.
  • DFARS 252.204-7012 and existing CUI safeguarding obligations remain in effect when applicable to a contract.
  • Select government-led cybersecurity assessments may still occur.
  • Contractors should use the review period to continue implementation, close gaps and prepare for whatever certification model follows.

What Did the DoW Actually Pause?

On July 13, 2026, the Department announced the immediate suspension of the rollout of CMMC Phase 2 and began a 60-day review of the certification program.

Phase 2 was scheduled to expand the use of third-party CMMC Level 2 assessments in applicable solicitations and contracts. During the suspension, requiring activities have been directed to use only:

  • CMMC Level 1 Self
  • CMMC Level 2 Self

They may not designate:

  • CMMC Level 2 C3PAO
  • CMMC Level 3 DIBCAC

Active solicitations containing the paused requirements are to be amended. Existing contracts containing them are expected to be addressed before the next option period or during a scheduled administrative modification.

This is meaningful relief for contractors that were facing the cost, scheduling challenges and administrative burden of a mandatory third-party assessment.

It is not, however, a cybersecurity exemption.

CMMC Phase 2 and CMMC Level 2 Are Not the Same Thing

One of the most common sources of confusion is the difference between a CMMC implementation phase and a CMMC security level.

CMMC Phase 2

“Phase 2” refers to a stage in the planned contractual rollout of the CMMC program.

Phase 2 would have expanded the use of CMMC Level 2 C3PAO assessments as a condition of eligibility for applicable contracts. That rollout stage is what has been suspended.

CMMC Level 2

“Level 2” refers to the CMMC cybersecurity level used to protect CUI.

CMMC Level 2 remains based on the 110 security requirements in NIST SP 800-171 Revision 2. During the suspension, Level 2 is still required through a self-assessment rather than a C3PAO certification assessment.

Therefore, saying “CMMC Level 2 has been paused” is misleadingand erroneous.

A more accurate statement is:

The Phase 2 requirement for mandatory CMMC Level 2 third-party certification assessments has been suspended. CMMC Level 2 self-assessment requirements remain available and in effect for applicable procurements.

What Is Paused?

The suspension affects the following areas:

CMMC Phase 2 implementation

The November 10, 2026 enforcement of Phase 2 has been suspended for 60 days.

Level 2 C3PAO requirements

Program offices and requiring activities may not currently designate a CMMC Level 2 C3PAO certification assessment in procurement request and requirement documents.

Level 3 DIBCAC requirements

CMMC Level 3 government certification assessment requirements are also paused during the review.

Pending implementation milestones

The Department has suspended pending and future CMMC certification implementation milestones while the program is reviewed.

Certain certification requirements in the supply chain

Where subcontract eligibility would have depended on a C3PAO certification requirement introduced through Phase 2, that certification requirement is temporarily paused. Applicable self-assessment and cybersecurity flowdown responsibilities are not automatically eliminated.

What Is Not Paused?

The following responsibilities remain active.

1. CUI handling, marking and safeguarding

The federal CUI program continues to govern how CUI is designated, handled, safeguarded, marked, transported, disseminated, reused and disposed of.

The term “handling” under 32 CFR Part 2002 includes activities such as marking, safeguarding, transporting, disseminating and disposing of CUI. The CMMC announcement did not suspend or repeal those responsibilities.

Contractors must continue following the CUI requirements incorporated into their contracts, agreements and agency instructions.

2. DFARS 252.204-7012

For applicable DoD contracts, DFARS 252.204-7012 still requires contractors to provide adequate security for covered contractor information systems and protect covered defense information.

The Department’s current CMMC guidance explicitly states that pausing the program in Phase 1 does not eliminate contractors’ responsibility to protect information under DFARS 252.204-7012.

3. NIST SP 800-171 Revision 2

The Department has stated that, during the review period, cybersecurity compliance will be enforced against NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments.

Contractors should not stop implementing access controls, incident response procedures, media protection, physical safeguards, configuration management or the other NIST SP 800-171 requirement families.

4. Current NIST SP 800-171 assessments in SPRS

Contractors required to implement NIST SP 800-171 under DFARS 252.204-7012 are generally required at the time of award to have a current Basic NIST SP 800-171 DoD Assessment.

Contracting officers verify that an assessment score is posted in the Supplier Performance Risk System before applicable awards, option exercises or extensions.

The Phase 2 pause does not mean contractors should remove, ignore or allow their SPRS information to become inaccurate.

5. CMMC Level 2 self-assessments

The Department continues to require CMMC Level 2 self-assessment status.

A Level 2 self-assessment must be conducted against the applicable NIST SP 800-171 requirements. Results are submitted into SPRS, and affirmation is required at the time of assessment and annually thereafter.

6. Limited POA&M rules

CMMC does not permit contractors to defer every unmet requirement through a Plan of Action and Milestones.

Only certain requirements may be included on a CMMC POA&M. Critical requirements—including the System Security Plan and several physical protection requirements—cannot be placed on the POA&M.

A contractor seeking Conditional Level 2 status must meet the applicable minimum score and POA&M restrictions. The official CMMC guidance identifies 88 out of 110 as the minimum passing score for conditional status.

That does not mean 88 represents complete implementation.

A Level 2 score of 110 is the requirement and remains the goal.

7. The 180-day POA&M deadline

When an organization receives Conditional Level 2 Self status, it must remediate the approved deficiencies, conduct a closeout self-assessment and submit the updated results within 180 days of the Conditional CMMC Status Date.

If the POA&M is not closed successfully within that period, the conditional status expires.

8. Supply-chain responsibilities

Prime contractors and subcontractors must still determine which suppliers will receive, process, store or transmit FCI or CUI.

Applicable safeguarding, assessment and contractual flowdown requirements do not disappear merely because Phase 2 certification requirements are paused. DFARS also continues to impose subcontractor requirements when subcontract performance involves covered defense information or operationally critical support.

The accurate message is:

Mandatory C3PAO certification requirements in the supply chain are paused. Applicable cybersecurity, self-assessment and flowdown responsibilities remain.

Is a Score of 88 Now Required for Every Defense Contract?

No.

This is another area where contractors need to distinguish between different assessment mechanisms.

A score of 88 out of 110 is the minimum passing score associated with obtaining a Conditional CMMC Level 2 status under the CMMC framework. It is not a universal score threshold automatically applied to every DoD contract.

Separately, DFARS requires contractors subject to NIST SP 800-171 to have a current Basic assessment score posted in SPRS before certain awards and contract actions. The applicable solicitation and contract determine whether a specific CMMC status is required.

Contractors should review the actual solicitation, DFARS clauses, CMMC requirement and information type rather than relying on a single number presented without context.

Should Contractors Cancel Their C3PAO Assessments?

Contractors should not make an automatic cancellation decision based only on the announcement.

Before canceling or postponing an assessment, determine:

  • Whether the C3PAO assessment is still required by an active customer, prime contractor or separate business commitment. It is within a prime's authority to do so and you can still be contractually bound to meet the requirement.
  • Whether the relevant solicitation has been formally amended.
  • Whether the contract has been modified.
  • What cancellation, rescheduling or deposit provisions exist in the C3PAO agreement.
  • Whether completing the assessment voluntarily would provide a competitive advantage.
  • Whether the organization is genuinely ready for an assessment.

The safest approach is to confirm the current contractual requirement before making a costly or irreversible decision.

A contractor may decide to postpone the assessment itself while continuing all implementation, documentation, evidence collection and readiness work. 

Why Contractors Should Keep Moving Forward

The review may change how cybersecurity compliance is verified. It may alter which contracts require certification, how third-party assessments are used or how the government balances cost against risk.

The final result has not yet been announced.

What is already clear is that the Department still expects contractors to protect federal information. It has not abandoned NIST SP 800-171 or CUI safeguarding. Instead, it has shifted the interim emphasis toward self-assessments and select government-led verification.

Organizations that stop their programs now could lose valuable time and create larger compliance gaps.

Organizations that continue moving forward would be wise to use the review period to:

  • Complete their CUI inventory.
  • Confirm their CMMC assessment scope.
  • Update their System Security Plan.
  • Validate their NIST SP 800-171 implementation.
  • Correct inaccurate or unsupported assessment scores.
  • Close eligible POA&M items.
  • Collect and retain assessment evidence.
  • Improve physical and media protection.
  • Review subcontractor flowdowns.
  • Train employees on CUI handling.
  • Prepare for either self-assessment or future certification.

The assessment format may change.

The underlying work required to properly protect CUI remains.

What About the New Government-Wide FAR CUI Rule?

Federal policy continues moving toward more standardized CUI requirements across civilian agencies and the federal supply chain.

However, contractors should be careful when describing the status of the new government-wide FAR CUI rule.

As of July 14, 2026, the expanded FAR CUI framework remains part of a proposed rulemaking effort. The proposal would create a more uniform way for agencies to identify CUI requirements, communicate them to contractors and establish contract clauses and incident-reporting procedures.

Existing laws, regulations, agency policies and contract requirements already require CUI protection in applicable circumstances. The new proposed FAR framework is intended to standardize how those requirements are communicated and implemented across federal contracting.

Therefore:

  • Do not assume federal CUI responsibilities are limited to DoD contracts.
  • Do not claim the proposed government-wide FAR CUI rule is already final.
  • Do expect federal CUI requirements to become more standardized and visible across the government.

What Defense Contractors Should Do Now

The appropriate response to the CMMC Phase 2 suspension is not to stop.

It is to separate implementation readiness from certification timing.

Continue implementing NIST SP 800-171

Review each requirement and its assessment objectives. Do not treat written policies as proof that a requirement is operating effectively.

Keep your SSP accurate

Your System Security Plan should reflect the actual environment, scope, assets, connections, external providers and implemented safeguards.

The SSP is not an item that can simply be deferred on a CMMC POA&M.

Validate your SPRS information

Ensure that submitted scores, scope information and affirmations are current, supportable and consistent with the organization’s actual implementation.

Maintain physical CUI controls

Continue properly marking documents, devices and media. Maintain controlled areas, visitor procedures, access restrictions, storage practices and secure destruction processes where required by your information, agency guidance and contracts.

Review current solicitations and contracts

Do not assume that a requirement has disappeared until the solicitation is amended or the contract is modified.

Coordinate with primes and subcontractors

Confirm what information will flow down, what systems will handle it and which assessment status applies to each organization.

Preserve your assessment position

Organizations already working with a C3PAO should discuss scheduling options rather than immediately abandoning the engagement. Maintaining a prospective position may provide flexibility once the Department publishes its revised direction.

CMMC Phase 2 Suspension FAQ

Was CMMC canceled?

No. The Department suspended the transition to Phase 2 and other pending implementation milestones while it conducts a review. Phase 1 self-assessment requirements remain in place.

Was CMMC Level 2 suspended?

No. CMMC Level 2 Self may still be designated in applicable procurements. The suspended requirements primarily involve the Phase 2 expansion of Level 2 C3PAO certification and Level 3 DIBCAC assessments.

Do defense contractors still need to implement NIST SP 800-171?

Contractors subject to DFARS 252.204-7012 must continue protecting covered defense information and implementing applicable NIST SP 800-171 requirements.

Are CMMC self-assessments still required?

Yes, when required by the applicable solicitation or contract. The Department has specifically stated that Phase 1 self-assessment requirements remain in place.

Can contractors stop protecting or marking CUI?

No. The CMMC suspension did not repeal the CUI program, applicable agency policies, contract requirements or DFARS safeguarding obligations.

Can contractors put every unmet requirement on a POA&M?

No. CMMC permits POA&Ms only for limited requirements. Several critical cybersecurity and physical protection requirements cannot be deferred.

How long does a contractor have to close a CMMC POA&M?

A CMMC POA&M must be successfully closed within 180 days of the Conditional CMMC Status Date.

Should a contractor cancel a planned C3PAO assessment?

Not automatically. The contractor should first verify its current contractual obligations, review solicitation or contract amendments, consult the C3PAO agreement and evaluate the business value of continuing or postponing the assessment.

Will third-party CMMC certification return?

The Department has not yet announced the final outcome of its review. Third-party certification could return in its previous form, return in a narrower or risk-based form, or be replaced with a different verification model.

Contractors should avoid treating any of those possibilities as settled policy.

The Bottom Line

The CMMC Phase 2 suspension changes the timeline and method through which certain contractors would have been required to demonstrate compliance.

It does not eliminate the underlying responsibility to secure federal information.

Contractors handling CUI should continue:

  • Protecting and properly handling CUI.
  • Implementing NIST SP 800-171 Revision 2.
  • Maintaining accurate self-assessments and SPRS information.
  • Closing implementation gaps.
  • Following contractual DFARS clauses.
  • Managing subcontractor and supply-chain responsibilities.
  • Preparing for the Department’s revised verification model.

Pause the certification timeline—not your compliance program.

The Bottom Line: The contractors that use this period to complete implementation will be better positioned regardless of what the Department announces next. The contractors that interpret the suspension as permission to wait may find themselves further behind when new guidance is issued.

Operationalize CUI Protection Across Your Organization

Cybersecurity documentation alone does not ensure that employees consistently recognize and protect CUI during everyday operations.

Organizations also need practical methods for identifying documents, labeling devices and media, controlling work areas, managing visitors, protecting information in transit and supporting secure destruction.

CUI Supply provides marking and awareness products designed to help organizations build consistent CUI-handling practices across offices, facilities, production environments and contractor information systems.

Explore CUI cover sheets, labels, restricted-area signs, awareness products and compliance packs to help turn written policies into repeatable operational procedures.

New to Controlled Unclassified Information?
Understanding what qualifies as CUI is foundational to CMMC, DFARS, and NIST SP 800-171 compliance. Read our guide, CUI 101: What Controlled Unclassified Information Really Is—and Why It Matters.

Compliance notice: CUI Supply products support marking, awareness and physical handling processes but do not, by themselves, establish compliance with CMMC, NIST SP 800-171, DFARS or other legal and contractual requirements. Organizations should evaluate their specific contracts, agency guidance, information systems and assessment obligations.

Share information about your brand with your customers. Describe a product, make announcements, or welcome customers to your store.