Secani
Secani
  • Company
  • Roadmap
Request demo

Summarize with AI

Open in ChatGPTOpen in ClaudeOpen in PerplexityOpen in MistralOpen in Grok
SIBB Startups
Berlin
Co-funded by the European Union
Secani

Jonathan Bezdek

Wörther Straße 9

10435 Berlin


hello@secani.com

Product

  • Security
  • Roadmap
  • Documentation
  • OSCAL

Legal

  • Privacy Policy
  • Terms
  • Cookie settings
  • Legal Notice

Company

  • Company
  • Contact
  • Blog

Support

  • Help

CMMC Phase 2 is suspended. Phase 1 obligations remain.

Jonathan BezdekCTO
9 min read
July 28, 2026

On this page

Short answerWhat was decided on July 13, 2026What was suspendedWhat still appliesWhat this means for Level 1What this means for Level 2What this means for German and European suppliersConcrete next stepsTimelineOfficial sourcesFAQ

Current CMMC status

Updated July 28, 2026
Phase II status: Suspended
Phase I self-assessments: Remain in effect

Short answer

The Department of War suspended CMMC Phase II effective July 13, 2026, while it conducts a 60-day review. Phase I remains in force. Contracting officers may still require Level 1 Self or Level 2 Self, and existing DFARS cybersecurity, assessment, incident-reporting, and data-protection duties continue independently of the Phase II pause.

What was decided on July 13, 2026

On July 13, 2026, the Department of War announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification program until further notice. The official announcement says the Department is using a 60-day period to review the program and reduce unnecessary barriers while preserving protection for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). That 60-day period is a review and reporting timeline, not a promised end date or restart date for the suspension.

Phase II had originally been scheduled to begin on November 10, 2026. The suspension changes what CMMC status a contracting officer may designate during the review; it does not repeal the CMMC rules or erase contract clauses already in effect. The official implementation memorandum directs acquisition teams how to implement that distinction.

What was suspended

During the suspension, new or amended solicitations and contracts may designate only:

  • CMMC Level 1 Self
  • CMMC Level 2 Self

The implementation memorandum directs contracting officers to remove or amend designations for:

  • CMMC Level 2 C3PAO, the certification assessment performed by an authorized third-party assessment organization
  • CMMC Level 3 DIBCAC, the government-led assessment for the highest CMMC level

This is a pause in Phase II assessment designations. It is not a general suspension of all CMMC activity, does not itself invalidate an existing C3PAO certificate, and does not prohibit voluntary preparation. Existing solicitations and contracts change through formal amendments or modifications. Contractors should follow the operative contract and contracting officer instructions until such a change is issued.

What still applies

Phase I self-assessment designations remain available. The updated official CMMC overview continues to describe the phased program and the assessment requirements attached to each level.

Separate contractual duties also remain relevant:

  • DFARS 252.204-7012 still governs safeguarding covered defense information, cyber-incident reporting, malicious-software submission, preservation, access, and relevant subcontractor flowdown when the clause applies.
  • DFARS 252.204-7020 still governs NIST SP 800-171 DoD assessment requirements, access for assessments, and flowdown when applicable.
  • The Department may continue select government assessments outside the suspended Level 2 C3PAO and Level 3 designation path.

The practical rule is simple: determine obligations from the current solicitation, award, clauses, data handled, systems in scope, and flowdowns—not from a headline about Phase II alone.

What this means for Level 1

Level 1 Self remains available during the suspension. It applies where contractor information systems process, store, or transmit FCI and requires an annual self-assessment against the 15 safeguarding requirements in FAR 52.204-21, followed by an annual affirmation.

Level 1 does not permit plans of action and milestones (POA&Ms). Every applicable requirement must be met for the required Level 1 status. Organizations should keep the assessment scope, results, affirmation, and supporting evidence aligned with the systems that actually handle FCI.

What this means for Level 2

Level 2 Self may still be designated. It is based on the 110 security requirements in NIST SP 800-171 Revision 2, with reassessment every three years and an annual affirmation.

Limited POA&Ms are permitted only under the CMMC rules' conditions. Items placed on a permitted POA&M must be closed within 180 days and cannot include requirements excluded from POA&M use. A Level 2 Self designation therefore remains a substantive evidence exercise, not a registration step.

Level 2 C3PAO designations are the portion suspended. Contractors should not assume that past preparation is wasted: the same CUI boundary, NIST SP 800-171 implementation, evidence quality, supplier controls, and incident processes underpin current contractual compliance and any later assessment.

A dedicated CMMC Level 2 requirements guide with a structured control-by-control view is planned.

What this means for German and European suppliers

CMMC scope follows US government contract clauses, the information handled, the systems that process, store, or transmit that information, and subcontract flowdowns—not the supplier's country. A German or European company can therefore be in scope when a prime contract or subcontract requires CMMC and its own systems handle FCI or CUI.

Conversely, the 2025 DFARS final rule explains that a subcontractor working only inside the prime contractor's systems, without processing, storing, or transmitting FCI or CUI on its own systems, would not need a separate CMMC assessment for those systems. The actual architecture and contract language must support that conclusion.

European suppliers should map the US contractual boundary separately from GDPR, NIS2, ISO 27001, or national security requirements. Those regimes may overlap operationally, but none substitutes automatically for a required CMMC status or DFARS obligation. A dedicated CMMC overview and checker for structuring an initial applicability review are planned.

Concrete next steps

  • Re-read each active solicitation, award, modification, and relevant subcontract. Record the current CMMC level and assessment type exactly as written.
  • Ask the contracting officer or prime contractor to confirm amendments where a Level 2 C3PAO or Level 3 DIBCAC designation appears.
  • Do not stop Phase I work. Maintain Level 1 Self or Level 2 Self evidence, reassessment dates, and annual affirmations where required.
  • Validate the FCI/CUI system boundary, including cloud services, remote administration, corporate shared services, and supplier connections.
  • Reconcile SPRS records and applicable NIST SP 800-171 DoD assessment results with the legal entity and covered information systems.
  • Keep DFARS 252.204-7012 incident reporting and evidence-preservation procedures operational.
  • Review subcontract flowdowns and document whether each supplier handles FCI or CUI on its own systems.
  • Track official updates through the CMMC resources and documentation page.

This article provides general information, not legal advice. Contract-specific questions should be resolved with the contracting officer, prime contractor, and qualified counsel.

Timeline

  • December 16, 2024: The 32 CFR CMMC program rule became effective.
  • November 10, 2025: The DFARS CMMC acquisition rule and Phase I took effect.
  • July 13, 2026: The Department announced the immediate Phase II suspension and a 60-day review.
  • November 10, 2026: Phase II had been scheduled to begin on this date before the suspension.
  • July 28, 2026: This article and status summary were last updated.

Official sources

  • Department announcement: Phase II suspension, July 13, 2026
  • DoD CIO memorandum: Implementing the Suspension of CMMC Phase II
  • DoD CIO: About CMMC
  • DoD CIO: CMMC resources and documentation
  • DFARS 252.204-7012
  • DFARS 252.204-7020
  • NIST SP 800-171 Revision 2
  • 2025 DFARS final rule

FAQ

Is CMMC cancelled?

No. The Department suspended Phase II, not the CMMC program. Phase I self-assessment designations remain available, and underlying FAR and DFARS obligations continue where included in the contract.

Can a contracting officer still require a C3PAO assessment?

The implementation memorandum directs contracting officers to remove or amend CMMC Level 2 C3PAO designations during the Phase II suspension. Confirm the operative solicitation or contract language with the responsible contracting authority.

Does a Level 2 Self assessment still matter?

Yes. Level 2 Self may still be designated during the suspension. It requires assessment against all 110 NIST SP 800-171 Revision 2 requirements, subject only to the CMMC rules' limited POA&M provisions, plus triennial reassessment and annual affirmation.

Does the suspension remove DFARS 252.204-7012 duties?

No. Safeguarding, cyber-incident reporting, preservation, access, and flowdown duties under DFARS 252.204-7012 continue when that clause applies.

Are suppliers outside the United States exempt?

No geographic exemption should be assumed. Applicability depends on the contract and flowdowns, the information involved, and whether the supplier's systems process, store, or transmit FCI or CUI.

Should contractors stop preparing for Level 2 certification?

The Department has not provided a basis for predicting the outcome of the review. Organizations should make a risk-based decision while continuing to meet current contract requirements and protect FCI and CUI.

Build auditable compliance workflows

Secani connects scopes, evidence, tasks, and AI agents in one shared workspace.

Request demo

Related posts

All posts
Regulatory
NIS2: Germany's grace period is ending

Only about a third of affected companies registered with the BSI on time. Until the end of July 2026 this can be fixed – after that, it gets expensive.

Read
OSCAL
Beyond Spreadsheet Crosswalks

OLIR provides mapping content and governance. OSCAL provides the machine-readable structure for using those mappings in gap analysis, evidence reuse, and change-impact workflows.

Read
OSCAL
We counted every constraint in OSCAL 1.2.2. All 348 of them.

Every OSCAL validator claims to validate OSCAL. We enumerated all 348 constraint occurrences in the NIST sources, proved or excluded each one, and then ran the comparison against the Java CLI for real.

Read