Main guide

CMMC After the Phase II Suspension: What Contractors Must Do Now (2026)

Last verified: First published: Next scheduled review:

Quick answer: A Phase II suspension pauses or reshapes parts of the certification rollout calendar—it does not erase DFARS cyber obligations, the need for an honest NIST SP 800-171 self-assessment, or the risk of signing an indefensible SPRS score. As of 14 September 2026, Class Deviation 2026-O0025 Revision 3 implements that pause in contracting instructions (Level 1/2 Self permitted; 800-171 Rev 2 via DFARS 252.204-7012 remains). The Reform Task Force report is not yet public.

Key takeaways

  • Suspension is not a free pass on safeguarding CUI or reporting SPRS scores when contracts require them.
  • Self-assessment quality and signature risk matter more—not less—when formal certification timelines wobble.
  • Use the pause to fix optimistic scoring, evidence gaps, and SSP drift before enforcement windows return.
  • 3 Sep 2026 class deviation writes the Phase 2 pause into contracting instructions; it is not a repeal of 32 CFR Part 170.
  • Task Force report not yet public as of 14 Sep 2026—watch primary sources, not rumor chains.

Why this guide exists

After a major CMMC policy jolt, a lot of advice online is recycled and slow to update. This page is a living map of what still binds you, what changed in practice, and how to stay defensible while formal pathways move—written for small and mid-size subcontractors, not enterprise GRC teams.

What a “Phase II suspension” is (and is not)

Is: a disruption to the expected cadence of CMMC Level 2 certification enforcement / pathway assumptions that many contractors planned around.

Is not: automatic relief from:

  • DFARS clauses that already require safeguarding covered defense information and cyber incident reporting
  • Contractual requirements to implement NIST SP 800-171
  • SPRS score submission when the solicitation or contract says so
  • Downstream prime flow-downs that still expect a score and a story

If your business development team heard “CMMC is paused, so we can ignore cyber,” correct that narrative in writing.

The posture that still wins: defensible self-assessment

Whether the near-term path emphasizes self-assessment, C3PAO certification, or a hybrid, one constant remains: someone may have to stand behind a score.

That is the DefensibleScore wedge:

  1. Accuracy — controls marked implemented are actually implemented.
  2. Evidence — you can show it without theater.
  3. Scoring integrity — weights and POA&M rules are applied correctly.
  4. Signature courage — a knowledgeable person can sign without inventing maturity.

If any of those four fail, the number in SPRS is a liability, not an asset. Read Your SPRS Score & the False Claims Act before anyone signs.

What to do now (practical sequence)

1. Freeze fantasy, inventory reality

Document in-scope systems, users, locations, and CUI entry/exit points. Unknown scope is the root of optimistic scoring.

2. Align the SSP with operations

Your System Security Plan should describe the environment you run—not the environment you wish you had next fiscal year. See Is Your SSP CUI?.

3. Re-score with discipline

Walk how to calculate your SPRS score and challenge every high-weight “implemented.”

How scoring works in practice: you still measure against the 110 NIST SP 800-171 requirements. Need them walked through? Start with the free Defensibility Check (no CUI). Prefer the free authority source only? Use the official NIST SP 800-171 publication.

4. Separate “still required” from “cert path”

Use Is CMMC still required after the suspension? for a plain yes/no, then map your contracts.

5. Know self-assessment vs C3PAO

Self-assessment vs. C3PAO explains what the suspension shifted in practice—and what remains your job either way.

6. Plan Rev 2 → Rev 3 without panic

NIST 800-171 Rev 2 vs Rev 3 keeps transition anxiety from becoming endless rewrites.

7. If you are local to East Tennessee

National tools do not show up on-site in the Tri-Cities. See CMMC help in the Tri-Cities & East Tennessee.

Alphabet soup?

Plain definitions of SPRS, CUI, C3PAO, POA&M, DFARS, and more: CMMC & DFARS glossary.

Further reading & tools

Need Page
Yes/no: still required? Is CMMC Still Required?
SPRS still needed? Do I Still Need a SPRS Score in 2026?
Signature risk SPRS & the False Claims Act
Scoring mechanics How to Calculate Your SPRS Score
Assessment path Self-Assessment vs C3PAO
SSP depth Is Your SSP CUI?
Baseline shift Rev 2 vs Rev 3
Local help East Tennessee CMMC
Free check Defensibility Check

Where things stand (14 September 2026)

Signal Status
Phase II suspension framing Still holds: pause ≠ repeal of DFARS / 800-171 / SPRS duties
Contracting instruction Class Deviation 2026-O0025, Revision 3 (3 Sep 2026) implements the 13 July CIO memo in acquisition text
What COs are told to do Permit Level 1 (Self) or Level 2 (Self); keep NIST SP 800-171 Rev 2 via DFARS 252.204-7012; remove or revise C3PAO / Phase 2 requirements in new and existing solicitations and contracts
32 CFR Part 170 / CMMC program rule Not repealed — a class deviation is not a Federal Register repeal
Reform Task Force RFI Closed 14 August 2026
Task Force report Not yet public as of 14 Sep 2026 (60-day review window ran ~13 Jul–11 Sep; public release is the CIO’s call)
CIO public remarks (9 Sep, Billington) 1,100+ RFI responses / 10,000+ pages; majority support for hold + reform; small/mid shops hit hard; interest in moving beyond point-in-time checks; CUI marking friction and OT/manufacturing gaps called out. Remarks ≠ new rule.

Primary memo (PDF): Class Deviation 2026-O0025, Revision 3. RFI archive: closed / what’s next. Prefer primary sources over social summaries.

How we stay current

Policy details move. When Task Force outputs, rulemakings, or DoD guidance shift the ground truth, this guide gets a new Last verified date and a visible Next scheduled review (currently targeting early October 2026 while we wait for a public Task Force report—confirm primary dates). Prefer primary sources over social media summaries.

Next action

Run the free SPRS Score Defensibility Check—a short check (no CUI required) that surfaces optimism and signature risk before you invest in a full remediation cycle.

Frequently asked questions

Did the Phase II suspension cancel CMMC?

No. Treat a suspension as a change to timing and pathway details, not a repeal of cybersecurity expectations for covered contractors. Confirm current rule text and your contract clauses.

Did the September class deviation cancel CMMC?

No. Class Deviation 2026-O0025 Revision 3 (3 Sep 2026) tells contracting officers to implement the 13 July CIO memo: requiring activities may include Level 1 (Self) or Level 2 (Self); baseline NIST SP 800-171 Rev 2 via DFARS 252.204-7012 remains; C3PAO / Phase 2 requirements are to be removed or revised in solicitations and existing contracts. 32 CFR Part 170 has not been repealed.

Do I still need a SPRS score?

If your contracts or solicitations require a current NIST SP 800-171 assessment score in SPRS, that obligation is independent of marketing headlines about Phase II. See our guide on whether you still need a SPRS score in 2026.

What should I do first during the pause?

Re-validate scope and CUI flows, rebuild an honest self-assessment with evidence, fix scoring math, and only then decide what you can sign. Run a free non-CUI Defensibility Check to surface optimism risk.

What this page is / is not: readiness and advisory guidance only. Not legal advice, not a C3PAO assessment, and not a CMMC certification. CUI designation is driven by government requirements and contract language—not by this site. Prefer primary sources when policy text conflicts with any blog (including ours).