Where CMMC Stands Right Now (October 2026)
Here's the short version: the rollout schedule is paused, the obligations aren't. Phase 1 of CMMC has been live since November 10, 2025, and it still is. Phase 2 — the step that would have made third-party C3PAO certification mandatory on applicable contracts starting November 10, 2026 — was suspended on July 13, 2026, along with every later milestone.
The DoD (also styled the "Department of War" since September 2025) cited cost and limited assessor capacity. A CMMC Reform Task Force has been reviewing the program since July. As of early October 2026, its report hasn't been published and there is no replacement date for Phase 2. Anyone quoting you a new deadline is guessing.
What that means in practice: contracting officers are using only Level 1 (Self) or Level 2 (Self) requirements. But the underlying rules — DFARS 252.204-7012, NIST SP 800-171, SPRS scoring — never depended on Phase 2, and they still apply today.
Paused, Not Cancelled
DoD CIO Kirsten Davies has signaled that assessments will likely remain in some form, possibly with more emphasis on continuous monitoring, delta assessments, and operational technology (OT) security.
The CMMC Timeline: Key Dates
These are the dates that actually matter, in order, through October 2026.
| Date | What Happened | What It Means for You |
|---|---|---|
| Dec 16, 2024 | CMMC program rule (32 CFR Part 170) takes effect | Sets the three CMMC levels, the assessment types, and the rules for C3PAOs and assessors |
| Nov 10, 2025 | Phase 1 begins (48 CFR DFARS acquisition rule takes effect) | Level 1 and Level 2 self-assessments start appearing in solicitations. Still in effect. |
| July 13, 2026 | Phase 2 suspended | DoD CIO Kirsten Davies and USD(A&S) Michael Duffey suspend the November 10, 2026 Phase 2 transition and all later milestones. Contracting officers use only Level 1 (Self) or Level 2 (Self). |
| July 17, 2026 | CMMC Reform Task Force first meets | Starts a 60-day review of the program |
| Aug 14, 2026 | Task force RFI comment period closes | Roughly 1,100 responses submitted |
| Sept 3, 2026 | Class Deviation 2026-O0025, Revision 3 | Carries the pause into contract text department-wide |
| October 2026 | Task force report still pending | No report published and no new Phase 2 date. Keep watching. |
The Original Phase Schedule (Now on Hold)
The DFARS rule laid out a four-phase rollout, one phase per year. Here's what was originally scheduled and where each phase stands now. Phase 1 is the only one in effect.
| Phase | Originally Scheduled | What It Was Supposed to Add | Status (October 2026) |
|---|---|---|---|
| Phase 1 | Nov 10, 2025 | Level 1 (Self) and Level 2 (Self) requirements in solicitations | In effect |
| Phase 2 | Nov 10, 2026 (original) | Level 2 (C3PAO) certification required on applicable contracts | Suspended July 13, 2026; no new date |
| Phase 3 | November 2027 (original) | Level 3 (DIBCAC) requirements added | Also on hold pending the reform review |
| Phase 4 | November 2028 (original) | Full implementation across all applicable contracts | Also on hold pending the reform review |
Under the pause, C3PAO Level 2 and DIBCAC Level 3 requirements are being removed from solicitations, and from existing contracts at the next modification or option exercise.
Not sure what your contracts require right now?
Read the solicitation or contract — it states the CMMC level. Under the pause, that should be Level 1 (Self) or Level 2 (Self). If a prime is asking you for more than that, ask them what's driving it and get it in writing.
Learn the CMMC LevelsWhat Still Applies Right Now
None of this was paused. If you handle Controlled Unclassified Information (CUI) on a DoD contract, these obligations are live today:
- DFARS 252.204-7012: Safeguard covered defense information and report cyber incidents to DoD within 72 hours.
- NIST SP 800-171 Rev 2: All 110 requirements remain the standard for protecting CUI on DoD contracts.
- DFARS 252.204-7019 / -7020: Your NIST 800-171 assessment score must be posted in SPRS, and DoD can conduct Medium or High assessments.
- CMMC Phase 1: Level 1 (Self) and Level 2 (Self) requirements in solicitations, plus annual affirmations where CMMC clauses are in your contracts.
- False Claims Act exposure: Claiming compliance you don't have is a fraud risk. On September 1, 2026, Honeywell Aerospace settled for about $2.04 million over NIST 800-171 non-compliance (April 2020–December 2023). MORSECORP ($4.6 million) and Georgia Tech ($875,000) settled in 2025.
Voluntary certification is still open. The Cyber AB confirmed in July 2026 that C3PAO Level 2 certification remains available on a voluntary basis. As of March 30, 2026 there were about 103 authorized C3PAOs and roughly 1,074 Level 2 certifications issued. Some primes still ask their suppliers for it, and a certificate is strong evidence if the requirement comes back.
What to Watch Next
- The task force report. It's the next real signal. Davies has indicated assessments will likely stay in some form — watch for continuous monitoring, delta assessments, and OT security in whatever comes out.
- Any new rule or class deviation. A new Phase 2 date or a changed requirement would have to show up in rulemaking or in a further revision to Class Deviation 2026-O0025. Until then, there's no new date.
- The FAR CUI rule. Proposed June 23, 2026 (comments closed July 23, 2026), it would extend CUI safeguarding to civilian-agency contractors, reference NIST SP 800-171 Rev 3, require incident reporting within 72 hours, and use a new standard form identifying CUI. It's proposed only — not final.
How CMMC Shows Up in Contracts: DFARS 252.204-7021
CMMC requirements reach your contracts through DFARS 252.204-7021. The solicitation tells you which CMMC level applies, and you need that status in place (and posted) to be eligible for award.
What that looks like during the pause:
- New solicitations should specify only Level 1 (Self) or Level 2 (Self)
- C3PAO Level 2 and Level 3 requirements are being pulled from existing contracts at the next modification or option
- Self-assessment results go into SPRS, backed by an affirmation from a senior company official
- Your separate DFARS 7012 and 7019/7020 obligations continue either way
Why Keep Going While Phase 2 Is Paused
Pausing the schedule is not the same as dropping the requirement. Contractors who stop work now are making a bet they don't need to make:
- False Claims Act risk is unchanged. Your SPRS score and affirmations are representations to the government. The Honeywell settlement came down weeks after the pause.
- Primes still set their own bar. Some primes may keep asking suppliers for certification or evidence of NIST 800-171 implementation, pause or no pause.
- Your SPRS score is visible. Contracting officers and primes can see it. A low or stale score is a competitive problem today.
- The requirement is likely to return in some form. When it does, the companies already done will be the ones bidding.
- Remediation takes time. Closing real NIST 800-171 gaps typically takes 6–12+ months. You can't compress that once a new date is announced.
How Long Getting Ready Actually Takes
Whether you're tightening up a self-assessment or pursuing voluntary C3PAO certification, the work isn't instantaneous. Most contractors need 6–12+ months depending on their current posture. Here's a rough breakdown of each step.
| Step | Typical Duration | Key Activities |
|---|---|---|
| Assessment & Planning | 2-4 weeks | Gap analysis, identify controls to implement, scope definition |
| Control Implementation | 3-6 months | Deploy tools, configure systems, build processes, train staff |
| Evidence Preparation | 4-8 weeks | Document compliance, collect policy evidence, prepare for audit trail |
| Self-Assessment & SPRS Update | 1-3 weeks | Score all 110 requirements honestly, post the score in SPRS, complete affirmations |
| Voluntary C3PAO Assessment (optional) | Varies with assessor availability | Third-party assessor validates controls; findings may require remediation before certification |
6-Month Preparation Roadmap
If a prime is asking for proof within six months, or your self-assessment score needs serious work fast, this is the minimum viable path. You'll need to move quickly and accept higher risk.
Months 1-2: Foundation
Week 1-2: Conduct gap analysis. Identify which controls you lack. Week 3-4: Procure tools (EDR, MFA, encryption, backup solutions). Budget: $15K-40K depending on size.
Months 3-4: Implementation Sprint
- Deploy security tools across all systems
- Configure multi-factor authentication, encryption, audit logging
- Build security policies and procedures
- Train all staff on new processes
- Create compliance documentation templates
Months 5-6: Assessment & Evidence
- Prepare evidence: policy docs, system screenshots, access lists, audit logs
- Conduct an internal assessment against all 110 requirements
- Remediate critical findings and update your plan of action
- Post an accurate, updated score in SPRS
- If you're pursuing voluntary certification, engage a C3PAO and book early
12-Month Preparation Roadmap
A 12-month timeline allows for more thorough implementation, staff training, and confidence-building — and it's a realistic pace for most small and mid-size contractors right now.
Months 1-3: Assessment & Design
- Deep-dive self-assessment of all 110 controls
- Engage a CMMC consultant for 2-3 weeks to design your roadmap
- Identify which tools/vendors you'll use
- Create detailed implementation plan with timelines and owners
- Budget planning and vendor selection
Months 4-9: Implementation & Hardening
- Deploy all required controls systematically
- Conduct monthly internal audits to verify implementation
- Refine policies based on lessons learned
- Run simulated incident response exercises
- Train and re-train staff continuously
Months 10-12: Validation
- Independent mock assessment by a consultant or C3PAO pre-assessment service
- Remediate any findings
- Update your SPRS score and affirmation
- Optional: schedule a voluntary C3PAO assessment
18-Month Preparation Roadmap
An 18-month timeline is ideal for mature implementation, organizational change management, and building a sustainable compliance program that holds up whatever the task force decides.
Months 1-4: Assessment, Training, and Governance
- Establish a compliance steering committee with executive oversight
- Conduct full CMMC readiness assessment
- Develop detailed business case for tooling and staffing investment
- Train IT and security teams on NIST 800-171 and CMMC
- Create security governance structure and policies
Months 5-12: Implementation & Optimization
- Months 5-8: Deploy foundational controls (access, encryption, backup)
- Months 9-12: Deploy advanced controls (monitoring, incident response, risk management)
- Conduct monthly compliance audits
- Optimize workflows based on audit findings
- Test disaster recovery and incident response procedures
Months 13-18: Maturity & Validation
- Run full pre-assessment with external consultant
- Remediate findings; document evidence of compliance
- Update SPRS and affirmations
- Optional: conduct a C3PAO readiness review and voluntary assessment
Preparing Your Supply Chain
If you're a prime contractor, your subs' security is your problem too — CUI you flow down still has to be protected under DFARS 7012. The pause doesn't change that, and the smallest suppliers are usually the furthest behind.
Use the breathing room: tell your subs what you actually expect (an honest SPRS score, NIST 800-171 progress, and whether you want voluntary certification), offer guidance and resources, and consider helping smaller subs with funding or expertise.
Know where you stand today
Don't wait for the task force report to find out how far you have to go. Use our readiness assessment to check your current posture against NIST 800-171 and get a personalized implementation timeline.
Start Your Readiness AssessmentKey Takeaways
- Phase 1 (self-assessments in solicitations) has been in effect since November 10, 2025 and still is
- Phase 2 was suspended on July 13, 2026; the originally scheduled Phase 3 and Phase 4 dates are also on hold, and no new date has been set
- DFARS 7012, NIST SP 800-171, SPRS scoring and affirmations still apply — and so does False Claims Act exposure
- Voluntary C3PAO certification is still available, and some primes still ask for it
- Watch the task force report, any new rule or class deviation, and the proposed FAR CUI rule
- Real remediation takes 6–12+ months, so the pause is time to get ready, not a reason to stop
Frequently Asked Questions
When do I have to be CMMC certified?
Right now there's no date. The DoD suspended Phase 2 — the planned November 10, 2026 move to mandatory C3PAO certification — on July 13, 2026, and no new date has been set. Solicitations currently use only Level 1 (Self) or Level 2 (Self). Some primes may still ask suppliers for certification, and the requirement is likely to return in some form, so check your contracts and your prime's expectations.
Is CMMC cancelled?
No. The rollout schedule is paused, not the program. Phase 1 self-assessments remain in effect, and DFARS 252.204-7012, NIST SP 800-171, and SPRS scoring still apply. A reform task force is reviewing the program; as of October 2026 its report has not been published.
Can I self-assess my CMMC compliance?
Yes — for now, that's what solicitations call for. Contracting officers are using only Level 1 (Self) or Level 2 (Self), with results posted in SPRS and backed by affirmations. Your self-assessment has to be honest: an inflated score is a False Claims Act risk. Third-party C3PAO certification is currently voluntary.
How much does a CMMC assessment cost?
It depends on your scope, size, and starting point. A self-assessment is mostly internal time plus any consultant help. A voluntary C3PAO Level 2 assessment is a significant outside expense on top of the cost of fixing your gaps. See our cost breakdown for detailed ranges.
Do CMMC certificates expire?
Yes. A Level 2 C3PAO certification is valid for 3 years, after which you need a new assessment. Plan your re-assessment schedule so a certificate doesn't lapse if the requirement returns.
Can a C3PAO conduct assessments of companies they've consulted?
No. CMMC rules require separation of church and state: if a firm helped you implement controls, a different C3PAO must perform your assessment. This prevents conflicts of interest and ensures objective evaluation.
What if I fail my CMMC assessment?
The C3PAO will identify the specific controls that need remediation. You fix those issues and work with the assessor on next steps. Most contractors find gaps during an assessment — the best insurance is a thorough internal or mock assessment beforehand.