CMMC Phase 2 is on pause, as a Defense Industrial Base (DIB) contractor here is why you should be concerned
The Department of Defense’s July 13, 2026 suspension of CMMC Phase II gives Defense Industrial Base contractors additional time, but it does not eliminate their cybersecurity obligations. Phase II originally scheduled to begin November 10, 2026, would have expanded the use of CMMC Level 2 certification assessments as a condition of contract award. Meanwhile, Phase I self-assessment requirements remain in effect, along with existing DFARS safeguarding, cyber-incident reporting, SPRS scoring, and subcontractor flow-down obligations. Contractors should view the pause as an opportunity to strengthen their System Security Plans, close Plans of Action and Milestones, and improve assessment evidence and not as a reason to suspend compliance activities. Our concern here is that many DIB contractors will see this time as a return to self assessments where any score was accepted by the SPRS system, however with the addition of the CMMC clauses this score has to be more accurate than ever, you must have a 88 passing score and only carry certain 1 point value controls on a POAM. This presents a significant risk to DIB contractors who upload a self assessment score without the added protections of a certified 3rd party assessor providing evidence to eMASS that reaffirms the score a contractor attests to in the SPRS system.
The pause also highlights an increasingly complicated standards landscape. Under DoD Class Deviation 2024-O0013, Revision 1, contractors subject to DFARS 252.204-7012 must continue using NIST SP 800-171 Revision 2 rather than the version in effect when a solicitation is issued. CMMC Level 2 is likewise codified around Revision 2’s 110 security requirements and associated assessment objectives. Therefore, current CMMC Level 2 assessments and DoD NIST SP 800-171 assessments remain based on Revision 2, even though NIST released Revision 3 in May 2024. The class deviation prevents contractors from being assessed against one revision while their contracts require another, but it also creates a temporary compliance baseline that will eventually need to be reconciled with newer federal requirements.
That reconciliation may become urgent under the proposed Revolutionary FAR Overhaul and its government-wide CUI clause, FAR 52.240-7. As drafted, the proposal would require contractors handling CUI on nonfederal systems to implement NIST SP 800-171 Revision 3 using standardized organizationally defined parameters, while CMMC Level 2 continues to measure Revision 2. (FAR Case 2026-001) Because the FAR rule is not yet final, it does not currently supersede the DoD class deviation or CMMC requirements; if finalized as written and incorporated into contracts, however, contractors could face overlapping Revision 2 and Revision 3 obligations until DoD issues conforming CMMC or DFARS changes. DIB organizations should continue preparing for CMMC under Revision 2 while building a documented Revision 2-to-Revision 3 crosswalk, evaluating Revision 3 gaps, and ensuring that new technology investments can support both baselines.