CMMC Timeline & Key Dates

Where the CMMC rollout stands as of October 2026 — and what's still required while Phase 2 is paused

Status update · October 2026CMMC Phase 2 is paused. On July 13, 2026 the DoD suspended the November 10, 2026 move to mandatory third-party (C3PAO) certification while a reform task force reviews the program. Self-assessments, NIST SP 800-171, SPRS scores and DFARS 252.204-7012 still apply. No new date has been set. Get your self-assessment and SPRS score in order →

Where CMMC Stands Right Now (October 2026)

Here's the short version: the rollout schedule is paused, the obligations aren't. Phase 1 of CMMC has been live since November 10, 2025, and it still is. Phase 2 — the step that would have made third-party C3PAO certification mandatory on applicable contracts starting November 10, 2026 — was suspended on July 13, 2026, along with every later milestone.

The DoD (also styled the "Department of War" since September 2025) cited cost and limited assessor capacity. A CMMC Reform Task Force has been reviewing the program since July. As of early October 2026, its report hasn't been published and there is no replacement date for Phase 2. Anyone quoting you a new deadline is guessing.

What that means in practice: contracting officers are using only Level 1 (Self) or Level 2 (Self) requirements. But the underlying rules — DFARS 252.204-7012, NIST SP 800-171, SPRS scoring — never depended on Phase 2, and they still apply today.

Cybersecurity roadmap planning

Paused, Not Cancelled

DoD CIO Kirsten Davies has signaled that assessments will likely remain in some form, possibly with more emphasis on continuous monitoring, delta assessments, and operational technology (OT) security.

The CMMC Timeline: Key Dates

These are the dates that actually matter, in order, through October 2026.

Date What Happened What It Means for You
Dec 16, 2024 CMMC program rule (32 CFR Part 170) takes effect Sets the three CMMC levels, the assessment types, and the rules for C3PAOs and assessors
Nov 10, 2025 Phase 1 begins (48 CFR DFARS acquisition rule takes effect) Level 1 and Level 2 self-assessments start appearing in solicitations. Still in effect.
July 13, 2026 Phase 2 suspended DoD CIO Kirsten Davies and USD(A&S) Michael Duffey suspend the November 10, 2026 Phase 2 transition and all later milestones. Contracting officers use only Level 1 (Self) or Level 2 (Self).
July 17, 2026 CMMC Reform Task Force first meets Starts a 60-day review of the program
Aug 14, 2026 Task force RFI comment period closes Roughly 1,100 responses submitted
Sept 3, 2026 Class Deviation 2026-O0025, Revision 3 Carries the pause into contract text department-wide
October 2026 Task force report still pending No report published and no new Phase 2 date. Keep watching.

The Original Phase Schedule (Now on Hold)

The DFARS rule laid out a four-phase rollout, one phase per year. Here's what was originally scheduled and where each phase stands now. Phase 1 is the only one in effect.

Phase Originally Scheduled What It Was Supposed to Add Status (October 2026)
Phase 1 Nov 10, 2025 Level 1 (Self) and Level 2 (Self) requirements in solicitations In effect
Phase 2 Nov 10, 2026 (original) Level 2 (C3PAO) certification required on applicable contracts Suspended July 13, 2026; no new date
Phase 3 November 2027 (original) Level 3 (DIBCAC) requirements added Also on hold pending the reform review
Phase 4 November 2028 (original) Full implementation across all applicable contracts Also on hold pending the reform review

Under the pause, C3PAO Level 2 and DIBCAC Level 3 requirements are being removed from solicitations, and from existing contracts at the next modification or option exercise.

Not sure what your contracts require right now?

Read the solicitation or contract — it states the CMMC level. Under the pause, that should be Level 1 (Self) or Level 2 (Self). If a prime is asking you for more than that, ask them what's driving it and get it in writing.

Learn the CMMC Levels

What Still Applies Right Now

None of this was paused. If you handle Controlled Unclassified Information (CUI) on a DoD contract, these obligations are live today:

Voluntary certification is still open. The Cyber AB confirmed in July 2026 that C3PAO Level 2 certification remains available on a voluntary basis. As of March 30, 2026 there were about 103 authorized C3PAOs and roughly 1,074 Level 2 certifications issued. Some primes still ask their suppliers for it, and a certificate is strong evidence if the requirement comes back.

What to Watch Next

How CMMC Shows Up in Contracts: DFARS 252.204-7021

CMMC requirements reach your contracts through DFARS 252.204-7021. The solicitation tells you which CMMC level applies, and you need that status in place (and posted) to be eligible for award.

What that looks like during the pause:

Why Keep Going While Phase 2 Is Paused

Pausing the schedule is not the same as dropping the requirement. Contractors who stop work now are making a bet they don't need to make:

How Long Getting Ready Actually Takes

Whether you're tightening up a self-assessment or pursuing voluntary C3PAO certification, the work isn't instantaneous. Most contractors need 6–12+ months depending on their current posture. Here's a rough breakdown of each step.

Step Typical Duration Key Activities
Assessment & Planning 2-4 weeks Gap analysis, identify controls to implement, scope definition
Control Implementation 3-6 months Deploy tools, configure systems, build processes, train staff
Evidence Preparation 4-8 weeks Document compliance, collect policy evidence, prepare for audit trail
Self-Assessment & SPRS Update 1-3 weeks Score all 110 requirements honestly, post the score in SPRS, complete affirmations
Voluntary C3PAO Assessment (optional) Varies with assessor availability Third-party assessor validates controls; findings may require remediation before certification

6-Month Preparation Roadmap

If a prime is asking for proof within six months, or your self-assessment score needs serious work fast, this is the minimum viable path. You'll need to move quickly and accept higher risk.

Timeline planning board

Months 1-2: Foundation

Week 1-2: Conduct gap analysis. Identify which controls you lack. Week 3-4: Procure tools (EDR, MFA, encryption, backup solutions). Budget: $15K-40K depending on size.

Months 3-4: Implementation Sprint

Months 5-6: Assessment & Evidence

12-Month Preparation Roadmap

A 12-month timeline allows for more thorough implementation, staff training, and confidence-building — and it's a realistic pace for most small and mid-size contractors right now.

Months 1-3: Assessment & Design

Months 4-9: Implementation & Hardening

Months 10-12: Validation

18-Month Preparation Roadmap

An 18-month timeline is ideal for mature implementation, organizational change management, and building a sustainable compliance program that holds up whatever the task force decides.

Months 1-4: Assessment, Training, and Governance

Months 5-12: Implementation & Optimization

Months 13-18: Maturity & Validation

Preparing Your Supply Chain

If you're a prime contractor, your subs' security is your problem too — CUI you flow down still has to be protected under DFARS 7012. The pause doesn't change that, and the smallest suppliers are usually the furthest behind.

Use the breathing room: tell your subs what you actually expect (an honest SPRS score, NIST 800-171 progress, and whether you want voluntary certification), offer guidance and resources, and consider helping smaller subs with funding or expertise.

Know where you stand today

Don't wait for the task force report to find out how far you have to go. Use our readiness assessment to check your current posture against NIST 800-171 and get a personalized implementation timeline.

Start Your Readiness Assessment

Key Takeaways

Frequently Asked Questions

When do I have to be CMMC certified?

Right now there's no date. The DoD suspended Phase 2 — the planned November 10, 2026 move to mandatory C3PAO certification — on July 13, 2026, and no new date has been set. Solicitations currently use only Level 1 (Self) or Level 2 (Self). Some primes may still ask suppliers for certification, and the requirement is likely to return in some form, so check your contracts and your prime's expectations.

Is CMMC cancelled?

No. The rollout schedule is paused, not the program. Phase 1 self-assessments remain in effect, and DFARS 252.204-7012, NIST SP 800-171, and SPRS scoring still apply. A reform task force is reviewing the program; as of October 2026 its report has not been published.

Can I self-assess my CMMC compliance?

Yes — for now, that's what solicitations call for. Contracting officers are using only Level 1 (Self) or Level 2 (Self), with results posted in SPRS and backed by affirmations. Your self-assessment has to be honest: an inflated score is a False Claims Act risk. Third-party C3PAO certification is currently voluntary.

How much does a CMMC assessment cost?

It depends on your scope, size, and starting point. A self-assessment is mostly internal time plus any consultant help. A voluntary C3PAO Level 2 assessment is a significant outside expense on top of the cost of fixing your gaps. See our cost breakdown for detailed ranges.

Do CMMC certificates expire?

Yes. A Level 2 C3PAO certification is valid for 3 years, after which you need a new assessment. Plan your re-assessment schedule so a certificate doesn't lapse if the requirement returns.

Can a C3PAO conduct assessments of companies they've consulted?

No. CMMC rules require separation of church and state: if a firm helped you implement controls, a different C3PAO must perform your assessment. This prevents conflicts of interest and ensures objective evaluation.

What if I fail my CMMC assessment?

The C3PAO will identify the specific controls that need remediation. You fix those issues and work with the assessor on next steps. Most contractors find gaps during an assessment — the best insurance is a thorough internal or mock assessment beforehand.