CMMC Phase 2 Is Paused: What Defense Contractors and Subcontractors Still Need to Do

Business professionals reviewing cybersecurity and compliance requirements

CMMC Phase 2 has been suspended, but CMMC has not been cancelled.

The announcement changed the timeline for expanding third-party assessment requirements. It did not eliminate every cybersecurity requirement facing defense contractors and subcontractors.

Phase 1 self-assessment requirements remain in effect. Depending on the information your company handles and the requirements included in a solicitation or contract, your business may still need to complete a CMMC self-assessment, report its results in the Supplier Performance Risk System, affirm compliance and continue meeting applicable cybersecurity standards.

For contractors that were preparing for CMMC, the pause should be viewed as additional time to verify readiness, not a reason to stop.

What changed with the CMMC Phase 2 pause?

On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements. Phase II was originally scheduled to begin on November 10, 2026, and would have expanded requirements for third-party CMMC Level 2 assessments.

The Department also established a task force to review the program, with a stated focus on reducing unnecessary costs and compliance barriers for small, midsize and nontraditional businesses within the defense industrial base.

While that review is underway, the CMMC program remains in Phase 1.

Under the Department’s current guidance, applicable solicitations may require:

  • A CMMC Level 1 self-assessment
  • A CMMC Level 2 self-assessment

The suspension affects the planned expansion of third-party and government-led certification requirements. It does not remove the cybersecurity responsibilities that may already exist under Phase 1 or within a company’s contracts.

Is CMMC still required?

Yes. CMMC has not been eliminated.

Phase 1 self-assessment requirements remain in effect. Contractors and subcontractors may still need to satisfy a particular CMMC level as a condition of contract award when that requirement is included in an applicable solicitation or contract.

The current Phase 1 requirements depend largely on the type of federal information a business handles.

CMMC Level 1

CMMC Level 1 applies to the basic safeguarding of Federal Contract Information, commonly called FCI.

Under the current program, Level 1 requires:

  • An annual self-assessment
  • Compliance with the 15 safeguarding requirements in FAR 52.204-21
  • Submission of assessment results to the Supplier Performance Risk System, or SPRS
  • An affirmation of compliance following the assessment

Plans of Action and Milestones are not permitted for Level 1. The required practices must be met when the organization submits its assessment.

CMMC Level 2

CMMC Level 2 addresses the broader protection of Controlled Unclassified Information, commonly called CUI.

During the current pause, applicable Level 2 requirements are based on a self-assessment rather than a C3PAO certification assessment.

Level 2 currently requires:

  • A self-assessment every three years
  • Implementation of the 110 security requirements in NIST SP 800-171 Revision 2
  • Submission of assessment results to SPRS
  • An affirmation after the assessment and annually thereafter
  • Timely correction of any deficiencies permitted under an approved Plan of Action and Milestones

Whether your business requires Level 1 or Level 2 depends on the information it handles and the requirements incorporated into its contracts and solicitations.

What requirements remain in effect during the pause?

The CMMC Phase 2 suspension did not automatically remove existing contractual cybersecurity obligations.

Depending on your contracts, the requirements that remain may include:

  • Protecting FCI in accordance with FAR requirements
  • Protecting CUI in accordance with NIST SP 800-171
  • Meeting the obligations incorporated through DFARS clauses
  • Completing the appropriate CMMC self-assessment
  • Maintaining accurate assessment information in SPRS
  • Providing required annual affirmations
  • Reporting qualifying cybersecurity incidents
  • Meeting cybersecurity requirements flowed down by a prime contractor
  • Maintaining documentation that supports reported assessment results

Contractors should review the specific language in their current contracts and upcoming solicitations. A general announcement about the CMMC timeline does not override an existing contractual requirement.

Do subcontractors still need to pay attention to CMMC?

Yes.

CMMC does not apply only to large prime contractors. Cybersecurity requirements can flow down through the defense supply chain to subcontractors that handle FCI or CUI.

A subcontractor may be required to meet a specific CMMC level because of the information it receives, creates, stores, processes or transmits while performing work under a contract.

Smaller businesses should not assume they are exempt because they do not contract directly with the federal government. Prime contractors may also require suppliers to demonstrate cybersecurity readiness before allowing them to participate in an opportunity.

If you are unsure what information your company handles, begin by reviewing your contracts, data flows and the systems used to complete government-related work.

What should contractors do during the CMMC pause?

The pause creates an opportunity to prepare more carefully and avoid rushed, expensive decisions.

Contractors and subcontractors should use this time to take the following steps.

1. Review your contracts and upcoming opportunities

Identify the FAR and DFARS clauses included in your current contracts. Review upcoming solicitations for specific CMMC requirements.

Do not rely solely on a general description of the CMMC program. Your actual obligations are determined by the requirements included in your contracts and solicitations.

2. Determine whether your company handles FCI or CUI

Identify where federal information enters your organization and how it is received, stored, accessed, transmitted and destroyed.

This review should include:

  • Email
  • Cloud applications
  • File-sharing platforms
  • Workstations
  • Servers
  • Mobile devices
  • Backup systems
  • Vendors and outside service providers

Understanding where the information lives is essential to determining the proper scope of your cybersecurity environment.

3. Verify the scope of your self-assessment

A self-assessment should cover all systems, people, processes and facilities that store, process, transmit or provide security protection for applicable federal information.

An incorrect scope can lead to inaccurate assessment results, unnecessary expenses or overlooked security risks.

4. Review the evidence supporting your answers

A self-assessment is more than answering yes or no to a list of cybersecurity questions.

Your organization should be able to support its answers with evidence. Depending on the requirement, that evidence may include:

  • Written policies and procedures
  • System configurations
  • Access-control records
  • Security reports
  • Employee training records
  • Incident response documentation
  • Backup and recovery test results
  • Network diagrams
  • Screenshots
  • Logs
  • Interviews with responsible employees

A cybersecurity tool may help satisfy part of a requirement, but having the tool does not automatically prove that the entire requirement has been implemented correctly.

5. Confirm that your SPRS information is accurate

If your organization is required to report an assessment in SPRS, make sure the submitted information accurately reflects your current cybersecurity environment.

Reported scores should be supported by the required assessment methodology and available evidence. They should not be based on estimates, assumptions or an informal checklist.

6. Continue correcting known cybersecurity gaps

The Phase 2 pause does not make existing vulnerabilities less dangerous.

Continue addressing weaknesses such as:

  • Missing multifactor authentication
  • Unsupported software
  • Inconsistent patching
  • Excessive administrator access
  • Inadequate logging
  • Untested backups
  • Missing security policies
  • Incomplete employee training
  • Weak incident response procedures
  • Unprotected systems containing FCI or CUI

These improvements are not valuable only because of CMMC. They also reduce the likelihood that a cyberattack will disrupt operations, expose sensitive information or affect your ability to serve customers.

7. Monitor official guidance

The CMMC program is under review, and additional changes are possible.

Continue monitoring official announcements and be prepared to adjust your plan when the Department publishes updated guidance. Avoid making major compliance decisions based solely on rumors, social media commentary or outdated articles.

Can a contractor complete its own CMMC self-assessment?

Depending on the required CMMC level and current program phase, a contractor may be permitted to complete a self-assessment.

However, “self-assessment” does not mean informal or optional.

The organization is responsible for understanding the applicable requirements, evaluating them correctly, maintaining supporting evidence and reporting accurate results. For Level 2, the assessment should use the assessment objectives in NIST SP 800-171A rather than relying only on a general review of NIST SP 800-171.

Someone within the organization must also affirm continuing compliance. That makes accuracy important for both the business and the individual responsible for the affirmation.

An outside cybersecurity and compliance professional can help the organization identify gaps, understand technical requirements and determine whether its conclusions are supported before information is formally submitted.

Should contractors stop preparing while CMMC is under review?

No.

The final CMMC timeline or assessment process could change, but the need to protect federal information remains.

Stopping all preparation could leave your business with:

  • Unresolved cybersecurity vulnerabilities
  • Inaccurate or unsupported assessment results
  • Insufficient evidence
  • Outdated policies
  • Missed contract opportunities
  • Too little time to respond when new guidance is released

Instead, use the pause to focus on foundational improvements that will remain valuable regardless of how the program changes. Protecting sensitive information, controlling access, maintaining reliable backups, training employees and preparing for security incidents are sound business practices as well as compliance priorities.

How IntelliSystems helps with CMMC self-assessment readiness

IntelliSystems helps defense contractors and subcontractors understand their cybersecurity responsibilities and prepare for applicable CMMC Level 1 and Level 2 self-assessments.

Our CMMC Backstop service provides guidance, structure and technical insight for organizations completing their own assessments. It can help your business:

  • Understand which requirements may apply
  • Review its current cybersecurity environment
  • Identify potential gaps
  • Organize policies and supporting documentation
  • Evaluate whether assessment answers are adequately supported
  • Create a clearer plan for addressing deficiencies

IntelliSystems does not perform C3PAO certification assessments. We help businesses strengthen their cybersecurity and prepare for the self-assessment responsibilities that remain in place.


Frequently Asked Questions About CMMC Phase 2 Pause

Was CMMC cancelled?

No. CMMC Phase 2 was suspended, but the overall CMMC program was not cancelled. The program currently remains in Phase 1, and applicable Level 1 and Level 2 self-assessment requirements remain in effect.

Is CMMC Phase 1 still in effect?

Yes. Under current guidance, Phase 1 remains in effect. Applicable solicitations may require a Level 1 or Level 2 self-assessment.

Is the November 10, 2026, CMMC Phase 2 deadline still in effect?

No. The planned transition to CMMC Phase 2 on November 10, 2026, was suspended. Contractors should continue monitoring official guidance for a revised timeline or changes to the program.

Do contractors still need an SPRS score?

If an applicable contract or solicitation requires an assessment result to be entered in SPRS, that requirement remains. Contractors should make sure submitted information is current, accurate and supported.

Are CMMC Level 1 self-assessments still required?

Yes, when Level 1 is required by an applicable solicitation or contract. Level 1 requires an annual self-assessment and annual affirmation.

Are CMMC Level 2 self-assessments still required?

Yes, when Level 2 is required by an applicable solicitation or contract. During the current Phase 2 suspension, the Department may require a Level 2 self-assessment rather than a C3PAO certification assessment.

Does CMMC apply to subcontractors?

It can. CMMC requirements may flow down to subcontractors based on the information they handle and the requirements included in their agreements with prime contractors.

Should we stop preparing for CMMC?

No. Contractors should continue protecting applicable federal information, meeting existing contract requirements, maintaining accurate assessment records and addressing known cybersecurity gaps.

Find out whether your business is prepared

A self-assessment may be completed internally, but its answers should still be accurate, documented and defensible.

If you are unsure whether your current cybersecurity practices support the answers your company would provide, start with the free CMMC Backstop Self-Assessment from IntelliSystems.

If the results reveal potential gaps or questions, IntelliSystems can help you understand what to address next.


This article is provided for general informational purposes and does not constitute legal advice, a formal CMMC assessment or a guarantee of compliance or certification. CMMC requirements may change, and requirements vary based on contract language, the information an organization handles and other circumstances. Consult the applicable regulations, your contracting officer and qualified legal or compliance professionals regarding your organization’s specific obligations.

Categories
Archives