Skip to content

cmmc

The 2026 CMMC Pause: What Defense Contractors Should Do During the Phase 2-4 Suspension

On July 13, 2026, the DoD suspended the CMMC Phase 2 rollout and froze Phases 3 and 4 pending a 60-day reform review. NIST 800-171, DFARS 252.204-7012, and SPRS obligations did not change. Here is what Hampton Roads defense contractors should do with the extra runway.

By Wakeem Williams Last updated:
Defense contractor reviewing a compliance timeline on a laptop in an office
Photo: Pexels

On July 13, 2026, the DoD suspended the rollout of CMMC Phase 2, which was set to require Level 2 third-party assessments in new contracts starting November 10, 2026. Phases 3 and 4 are frozen too, while a new CMMC Reform Task Force reviews the program. Nothing about your NIST SP 800-171 obligations, your SPRS score, or your DFARS 252.204-7012 duties changed.

That is the answer most contractors are looking for. The rest of this article is the specifics, and what to do with the runway you just got.

If you run a defense contract in Hampton Roads, this news probably reached you as a headline before it reached you as a decision. Some contractors read it as “CMMC is dead.” Others read past the headline and kept working. The second group is going to be in a much better position in six months. This article walks through what the suspension actually covers, what it does not touch, and why the smartest move during a pause is usually to keep going, not stop. For the underlying control set this pause affects, see the CMMC Level 2 requirements breakdown.

What the DoD actually paused on July 13, 2026

The announcement suspended the phased implementation schedule for CMMC, specifically the Phase 2 milestone that would have started requiring Level 2 C3PAO third-party assessments in new DoD contracts on November 10, 2026. Phase 3 (Level 3 government-led assessments) and Phase 4 (full program maturity) were frozen along with it.

What was not suspended: CMMC Phase 1, which covers Level 1 self-assessment for contractors handling Federal Contract Information. That phase and its 17 basic safeguarding practices continue on schedule.

The DoD stood up a 60-day CMMC Reform Task Force alongside the announcement, reporting to the DoD Chief Information Officer. Public reporting cited cost burden on small and mid-size contractors and questions about assessor capacity as the stated reasons. A public comment period (RFI) runs through August 14, 2026, meaning industry input is still shaping what comes next. None of this is a rule repeal. 32 CFR Part 170, the CMMC Program rule, is still on the books.

What did not change

This is the part that gets lost in the headlines, and it is the part that matters for your actual work this quarter.

NIST SP 800-171 Rev 2 is unchanged. If your contracts carry DFARS 252.204-7012, you are still contractually obligated to implement those controls, whether or not a formal CMMC assessment clause has landed in your contract yet. Your System Security Plan requirement did not pause. Your annual SPRS self-assessment score and affirmation obligation did not pause. Your 72-hour incident reporting obligation under DFARS 252.204-7012 did not pause.

For a full picture of what’s unaffected versus what shifted, see Is CMMC Still Required in 2026?

Why this is a runway, not a reprieve

Most contractors treat a compliance deadline like a wall: nothing happens until it’s close, then everything happens at once. A paused deadline removes the wall but keeps the distance. The work is the same work. What changed is that you are no longer racing a specific date.

That is exactly the situation where on-demand security leadership earns its cost. A virtual CISO (vCISO) can spend this window building the SSP, closing control gaps, and running the self-assessment cycle at a sustainable pace, instead of the compressed scramble a hard deadline usually forces. When the reform task force publishes new milestones (and it will), contractors who used the pause well show up with a program instead of a panic. Contractors who used the pause to stop show up needing the same 6 to 12 months they would have needed in July, except now on a shorter runway. If you’re weighing whether a vCISO fits a smaller shop, read Do Small Defense Contractors Need a vCISO for CMMC?

A composite scenario, built from patterns we see across Hampton Roads defense subcontractors: a 40-person marine engineering firm supporting base operations had a CMMC Level 2 self-assessment roughly 60% complete when the pause hit. Leadership’s first instinct was to shelve the project until “CMMC comes back.” Instead, they kept the gap remediation moving at half the original pace, using the freed-up deadline pressure to fix root-cause issues (a flat network, no MFA on remote access) rather than the fastest workaround. They will likely finish ahead of wherever the new Phase 2 milestone lands, at lower cost than a compressed sprint would have required.

What to do right now

Three things, in order of priority.

First, don’t let your SPRS score go stale. If you have not run a self-assessment in the last 12 months, that is your most exposed gap regardless of what CMMC phase is active.

Second, keep building toward Level 2 if your contracts involve CUI. The controls are not going away. The CMMC readiness checklist covers what to have documented before any assessment, self or third-party.

Third, watch the reform task force output. The RFI comment period closes August 14, 2026, and the task force report is due within 60 days of the July announcement. Expect a revised timeline to follow, not an immediate one. The CMMC rollout timeline after the pause tracks what’s known and what’s still an open question.

Where Helix Stax fits

Helix Stax is a full-stack IT consulting firm based in Hampton Roads. During this pause, the useful work isn’t waiting, it’s using the extra time to build a compliance program that survives contact with whatever the reform task force produces. That means an honest gap assessment against NIST SP 800-171, a System Security Plan that matches your actual environment, and the MFA, logging, and network segmentation to back it up, not just the paperwork.

If you want a directional read on where you stand, the free Helix Score takes about three minutes. If you want the fuller picture before deciding how to spend this window, book the free 60-minute assessment and get a clearer view of the gaps before the next milestone lands.

The pause is real. The work still due after it isn’t going anywhere.

Questions

Frequently asked questions about Helix Stax managed IT services

No. The DoD suspended the rollout of CMMC Phase 2, which was set to take effect November 10, 2026, and froze the later Phase 3 and Phase 4 milestones. CMMC Phase 1 remains active. The underlying rule, 32 CFR Part 170, was not rescinded. A CMMC Reform Task Force is reviewing the program's cost and structure, not deciding whether it exists.

The DoD paused the phased rollout schedule that would have started requiring CMMC Level 2 third-party (C3PAO) assessments and Level 3 government assessments in new contracts. Phases 2, 3, and 4 are frozen. Phase 1 self-assessment for Federal Contract Information continues unchanged.

Yes. NIST SP 800-171, DFARS 252.204-7012, your System Security Plan, SPRS score submission, and annual affirmation requirements are unaffected by the Phase 2 suspension. Contractors who let these lapse during the pause will be behind when the reform review concludes.

It is a task force the DoD stood up alongside the July 13, 2026 suspension announcement, tasked with reviewing CMMC's cost burden on small and mid-size contractors, assessor capacity, and program structure. Its report is due within 60 days of the announcement. A public RFI comment period runs through August 14, 2026.

No. The pause removes a hard deadline, not the requirement. Contractors who keep building their SSP, closing control gaps, and running self-assessments during this window will be ahead of the field once new milestones are set. Contractors who stop will be relearning the same material later, on a shorter clock.

The task force report is due within 60 days of the July 13, 2026 announcement, which puts initial findings around mid-September 2026. That does not mean new milestones land immediately after. Expect a comment period, possible rule revisions, and a republished schedule, which historically has taken additional months.

No. Level 1, which covers Federal Contract Information with 17 basic safeguarding practices and annual self-assessment, was not part of the suspension. It continues on its existing schedule.

Public statements from the DoD and the Small Business Administration cited cost concerns for small and mid-size contractors and questions about assessor capacity as reasons for the suspension. The task force is reviewing whether the program's structure needs to change before the next rollout phase begins.