MILESTONECUI Vault has achieved FedRAMP Moderate equivalency.FedRAMP Moderate equivalency achieved.Read the announcement

CMMC Phase 2 hits pause — here’s what actually changes (and what doesn’t)

The Pentagon just delayed the certification deadline everyone’s been racing toward. Your compliance obligations didn’t get the memo.

On July 13, 2026, the Department of War (the Pentagon’s new name following last year’s rebrand) suspended Phase 2 of the CMMC program — the phase that would have made third-party C3PAO certification mandatory starting November 10, 2026. The stated reasons: assessor capacity hasn’t scaled to meet demand, and compliance costs are, in the department’s own words, “structurally incompatible” with the current timeline.

If you’ve been sprinting toward a November certification, you can exhale — a little. But don’t put the program down. DFARS clause 252.204-7012 is still fully in force, which means contractors handling CUI must still:

  • Implement all 110 NIST SP 800-171 controls.
  • Report cyber incidents rapidly.
  • Complete self-assessments for Levels 1 and 2.
  • File annual affirmations through DoD’s Supplier Performance Risk System (SPRS).
Bottom line: the certification paperwork got pushed back. The underlying security requirements — and your legal exposure if you don’t meet them — did not. Contractors who quietly deprioritize NIST 800-171 because “CMMC got delayed” are reading this wrong.

A 60-day reform task force is rewriting the rulebook

Within days of the pause, the Department of War’s CIO stood up a CMMC Reform Task Force to conduct a top-to-bottom review of the program. Its charter names five priorities: rebuilding defense capabilities, empowering the acquisition workforce, cutting regulatory burden, improving technical execution, and strengthening lifecycle risk management. Translation: expect proposals aimed at making the program less painful for small and mid-sized contractors, without gutting the security bar.

  • Jul 13, 2026
    Phase 2 suspended — mandatory C3PAO certification postponed indefinitely.
  • Jul 20, 2026
    Reform Task Force chartered, RFI opened for industry input on reducing compliance burden.
  • Aug 14, 2026
    RFI comment period closed — input gathered from small, mid-size, and non-traditional defense contractors.
  • Mid-Sep 2026 (expected)
    Task force recommendations due to DoW leadership.
  • Mid-Oct 2026 (earliest)
    Formal determinations on program changes — any real changes still require rulemaking, not just a memo.

CUI rules are expanding far beyond the Pentagon

While CMMC dominates the headlines, the more consequential move this summer may be the FAR Council’s June 23, 2026 proposed rule — part of the broader “FAR overhaul” — which extends CUI safeguarding and NIST SP 800-171 obligations to civilian agencies (GSA, VA, DHS, and others) for the first time. If your contracts touch any federal agency, not just DoD, this is the rule to watch.

The proposal also upgrades the security baseline from NIST SP 800-171 Revision 2 to Revision 3 — a meaningful lift involving restructured control families and new parameters. The public comment period closed July 23, 2026; a final rule is expected to follow in the coming months.

RequirementBeforeProposed
Incident reporting window8 hours72 hours
Security baselineNIST SP 800-171 Rev. 2NIST SP 800-171 Rev. 3
Applies toDoD contractors onlyDoD + civilian agencies (GSA, VA, DHS, etc.)
Incident triggerIncludes “suspected” incidentsConfirmed incidents only
CUI identificationContractor’s burden to determineNew SF form, government identifies

What to do this week

No fire drills — just the habits that keep you audit-ready no matter how the rulemaking lands.

  • Keep your SPRS score current. Self-assessments and annual affirmations are still mandatory — don’t let the pause become an excuse to let this lapse.
  • Start a Rev. 3 gap assessment. The control changes are real work — get ahead of it instead of scrambling when the final rule lands.
  • Check your prime’s flowdown language. Several primes are holding subcontractors to CMMC-level requirements contractually, regardless of the federal pause.
  • Watch for the Task Force recommendations in mid-September. We’ll break down what they mean for you the week they drop.

Quick hits

  • Jul 2026
    Cyber AB town halls reinforce the message.
    Both June and July recaps urge contractors to stop treating November 10 as a hard deadline.
  • Jul 2026
    Primes are staying the course.
    Some large primes are telling suppliers the pause doesn’t change contractual flowdown expectations — plan accordingly.
  • Jun 2026
    Assessor eligibility widens.
    New Tier 3 equivalence pathways mean US citizenship is no longer a strict requirement to become a CMMC Level 2 assessor.

Not sure where your organization stands?

CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.

This briefing is a general-information summary of publicly reported CMMC and CUI developments. It is not legal advice; consult your compliance counsel before making contractual or certification decisions.
Talk to us about CUI Vault All issues