CMMC Phase 2 Is Suspended: Why Your C3PAO Readiness Window Is Still Open

Share:
CMMC Phase 2 is suspended, but Level 2 obligations remain. Learn what still applies, how to stay C3PAO-ready, and what evidence to prepare now.

Defense contractors that handle Controlled Unclassified Information (CUI) spent much of 2026 planning around November 10, the date CMMC Phase 2 was scheduled to make third-party Level 2 certification a condition of award. On July 13, 2026, the Department of War (DoW) suspended that transition and opened a 60-day program review. The pause removed a calendar date, but it did not remove the underlying obligations, and it left contractors unsure when verification will return and in what form. That uncertainty carries its own risk. Organizations that stop preparing may later face a compressed timeline and limited assessor capacity, while those that keep building evidence stay positioned for any outcome. This article explains what changed, what still applies, and how to use the pause productively.

What Happened to CMMC Phase 2 and the November 10 Date?

The DoW suspended the transition to CMMC Phase 2 on July 13, 2026, so Level 2 C3PAO certification will not become a condition of award on November 10, 2026 as originally scheduled. Phase 1 began on November 10, 2025 and introduced Level 1 and Level 2 self-assessment requirements. Phase 2 was meant to add independent certification for most contracts involving CUI.
A CMMC Reform Task Force, reporting to the DoW Chief Information Officer, was given 60 days to review the program. That review ended on September 11, and the recommendations went to the CIO, with publication timing left to her. A class deviation dated September 3 directs contracting officers to remove or revise Level 2 (C3PAO) and Level 3 requirements in solicitations and contracts. Confirm the latest status before acting, because the Task Force report could change timing, scope, or the assessment model.

What Still Applies to Defense Contractors During the Suspension?

Phase 1 self-assessment requirements and the underlying security obligations remain fully in force. The suspension changes when third-party verification applies, not whether contractors must protect CUI.

  • The CMMC program rule, 32 CFR Part 170, has not been repealed.
  • DFARS 252.204-7012 and NIST SP 800-171 safeguarding obligations continue to apply.
  • Program managers may now designate only Level 1 (Self) or Level 2 (Self).
  • The Cyber AB stated that C3PAOs can still assess and certify on a voluntary basis.
  • Primes may keep their own C3PAO requirements, so subcontract flow-down language still deserves a careful read.

Does the Pause Change the Security Standard?

Based on the DoW’s stated aims, the review targets compliance cost and burden, particularly for small and non-traditional contractors, and the department has said it intends to keep enforcing baseline requirements. Treat any change to the control set as unconfirmed until the Task Force recommendations become formal policy.

Why Is the C3PAO Readiness Window Still Open?

The window remains open because the suspension changes timing, not the control set, and some form of verification may return. Observers expect verification to come back, possibly with narrower scope, a longer phase-in, or more reliance on self-assessment with spot checks.

Self-assessment also carries more weight now. A hypothetical contractor that submitted an optimistic SPRS score in Phase 1 could face questions if an assessment later contradicts it, and inaccurate affirmations can create False Claims Act exposure. When third-party requirements return, assessor scheduling will become a constraint, and organizations with mature evidence will move faster than those starting from scratch.

How Should Organizations Prepare for a C3PAO Assessment Now?

Organizations should prepare by validating scope, aligning documentation with actual practice, and testing evidence against all 110 NIST SP 800-171 Rev 2 practices. Work in this order:

  1. Finish CUI scoping. Document where CUI is stored, processed, and transmitted, and define the assessment boundary.
  2. Verify the SPRS score. Recalculate it from current implementation status, not from earlier assumptions.
  3. Update the System Security Plan (SSP) so it describes what the environment does today.
  4. Maintain a Plan of Action and Milestones (POA&M) with owners and dates for each open gap.
  5. Collect evidence for each practice and map it to the control it supports.
  6. Run an independent mock assessment to find weaknesses before an assessor does.
  7. Review cloud and managed service providers that touch CUI, and confirm their responsibilities in writing.

What Evidence Do Assessors Expect for CMMC Level 2?

Assessors expect proof that each practice is implemented and operating, gathered through examining documents, interviewing personnel, and testing systems. These methods follow NIST SP 800-171A.

Typical evidence includes:

  • Policies and procedures tied to specific practices
  • System configurations and access control records
  • Authentication and multifactor settings
  • Audit logs and records showing reviews took place
  • Training records and incident response test results

The evidence must be accurate, not aspirational. A policy that exists on paper but is not followed in practice is a finding waiting to happen.

What Are the Most Common Gaps in CMMC Level 2 Readiness?

The most common gaps involve unclear scope, documentation that does not match reality, and weak operational evidence. Frequent examples include:

  • A CUI boundary that grew informally through email, file sharing, and collaboration tools
  • An SSP written once and never updated after infrastructure changes
  • Multifactor authentication applied inconsistently across remote and privileged access
  • Encryption that protects CUI without using FIPS-validated cryptography
  • Logs collected but never reviewed
  • Unclear responsibility between the contractor and its cloud or managed service providers

What Should Organizations Do Next?

Organizations should treat the pause as a preparation period, not a stand-down. Confirm contract flow-down requirements, finish CUI scoping, validate the SPRS score, and close open POA&M items by risk.

If gaps surface, a CMMC readiness and gap assessment helps establish an evidence-backed baseline, prioritize remediation, and prepare for a formal assessment whenever it returns. Ampcus Cyber supports this through CMMC / NIST SP 800-171 readiness, which fits organizations that need an independent view of their posture before they attest again or commit to a certification date.

Staying Assessment-Ready While CMMC Phase 2 Is Paused

CMMC Phase 2 is suspended, not cancelled, and the obligations that matter most have not moved. Contractors that use this period to tighten scope, correct documentation, and build verifiable evidence reduce compliance risk and protect award eligibility. Those that wait for a new date may face the same pressure later with less time.

Assess your CMMC Level 2 readiness before the next announcement. Speak with Ampcus Cyber about an evidence-based gap assessment against NIST SP 800-17.

People Also Ask

Is CMMC Phase 2 still happening on November 10, 2026?

Do I still need a C3PAO assessment?

Is CMMC canceled?

What is the CMMC Reform Task Force?

Should contractors keep preparing for certification?

Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.

No related posts found.

Contact Us
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.