CMMC After the Phase 2 Pause
The verification mechanism was suspended in July 2026. The security obligations underneath it were not.
What was suspended
- Third-party C3PAO certification as a condition of award.
- The Phase 2 milestone of November 10, 2026.
- Phases 3 and 4, and all later implementation milestones.
What is still in force
- Phase 1 self-assessments.
- DFARS 252.204-7012.
- NIST SP 800-171 Rev 2.
- SPRS score submission.
- Annual affirmation.
- Prime and subcontractor flow-down.
- False Claims Act exposure.
The suspension changed how compliance is verified. It did not change what a contract requires of you, and it did not withdraw a clause from any award you already hold.
The record, in order
-
December 16, 2024
32 CFR Part 170 takes effect, establishing the CMMC program.
-
November 10, 2025
The 48 CFR acquisition rule takes effect and Phase 1 begins.
-
July 13, 2026
Phase 2 and all later phases suspended, USD(A&S) Memorandum 26-P-1023.
-
Mid-September 2026
CMMC Reform Task Force report expected to the DoW CIO.
A note on what centrexIT does here: this page is reference, not a service pitch. We do not access CUI, stand up or support enclaves, or perform CMMC assessment work. We run the systems outside that boundary.
Check your own position
CMMC Pause Reality Check
Nine questions on what the suspension changed for your contracts, and what is still in force.
Coming SoonCUI Scope Mapper
Map where Controlled Unclassified Information actually lands across your systems, and what that puts in scope.
Coming SoonYou Call. We Answer. It Works.
centrexIT runs IT for defense contractors outside their CMMC assessment boundary. We do not handle CUI and we do not deliver CMMC compliance work. If you need an enclave and do not have one, we can procure the licensing and bring in a partner qualified to stand it up. If you want to talk about the rest of your environment, a short conversation tells you where you stand.
Get Your Free Assessment