cmmc
Is CMMC Still Required in 2026? What the Phase Pause Does and Doesn't Change
Yes. CMMC Phase 1 and your underlying NIST 800-171, DFARS, and SPRS obligations are still in force. Only the Phase 2-4 rollout schedule was suspended on July 13, 2026. Here is exactly what still applies to Hampton Roads defense contractors.
Yes, CMMC is still required in 2026. What changed on July 13, 2026 is that the DoD suspended the Phase 2 rollout schedule, which would have added Level 2 third-party assessment requirements to new contracts starting that November. Phase 1 self-assessment, NIST SP 800-171 obligations, DFARS 252.204-7012, and SPRS reporting are all still in force.
That is the answer most contractors are looking for. The rest of this article is the specifics.
If your Hampton Roads business handles a DoD contract and you saw “CMMC suspended” in a headline, you are not alone in wondering what that actually means for your obligations this quarter. The short version: less changed than the headline implies. For the full picture of what was and wasn’t paused, read The 2026 CMMC Pause: What It Means. This article breaks down, line by line, what still applies.
What “still required” means in practice
CMMC is not one requirement. It is a layered set of obligations, and the July 2026 announcement only touched one layer: the schedule for rolling out Phase 2 assessment requirements into new contracts.
Still required, unchanged by the pause:
- CMMC Phase 1, Level 1 self-assessment against 17 basic safeguarding practices for contractors handling Federal Contract Information (FCI), annual affirmation.
- NIST SP 800-171 Rev 2, the 110 security controls that any contract with DFARS 252.204-7012 has required since well before CMMC existed.
- SPRS score submission and affirmation. DFARS 252.204-7020 requires contractors handling CUI to have a current NIST SP 800-171 assessment score in the Supplier Performance Risk System, regardless of CMMC’s rollout status.
- 72-hour incident reporting, the DFARS 252.204-7012 obligation to report covered cyber incidents to the DoD within 72 hours of discovery.
- Existing contract clauses. If DFARS 252.204-7021 with a specific CMMC level is already written into your contract, that clause holds unless your contracting officer changes it.
Paused as of July 13, 2026:
- Phase 2 rollout, the schedule that would have started requiring Level 2 C3PAO third-party assessments in new contracts on November 10, 2026.
- Phase 3 and Phase 4 milestones, later-stage requirements, including Level 3 government-led assessments, frozen along with Phase 2.
Why the confusion is understandable
Headlines compress. “DoD suspends CMMC” reads like the whole program stopped. What actually happened is narrower: the DoD paused the next step in a multi-year rollout, while leaving the compliance obligations that predate CMMC (and that CMMC was built to formalize) exactly where they were. NIST SP 800-171 has applied to CUI-handling DoD contractors since DFARS 252.204-7012 took effect in 2017. CMMC’s job was to add teeth via mandatory assessment. The assessment mandate’s expansion paused. The underlying standard did not.
For contractors in Hampton Roads working shipbuilding support, base operations, or defense manufacturing contracts, this distinction is the difference between “we can stand down” and “we keep doing what we were already supposed to be doing.” It’s the latter. If you need the specifics on what Level 2 requires once assessment is back on the table, see CMMC Level 2 Requirements.
What could still change
The CMMC Reform Task Force has a 60-day mandate from the July 13, 2026 announcement, putting an initial report around mid-September 2026. A public RFI comment period runs through August 14, 2026. Possible outcomes include a revised assessment schedule, changes to cost-sharing or assessor requirements, or scope adjustments for small businesses. None of that has been finalized as of this writing, and any contractor-facing decisions should be verified against the DoD’s published rule and your own contracting officer’s guidance once the task force reports.
What this means for subcontractors specifically
If you are a Tier 2 or Tier 3 subcontractor working under a prime’s flow-down clause, your obligation is still whatever your prime’s contract requires of you, not a level you pick yourself. The pause doesn’t change flow-down mechanics. See CMMC for Subcontractors for how that determination works.
Where Helix Stax fits
Helix Stax works with small Hampton Roads defense contractors on cybersecurity compliance, NIST 800-171 gap assessments, SSP development, and CMMC readiness that holds up regardless of which phase is officially “live.” The requirements didn’t pause. Neither should your program.
If you’re not sure where your gaps are, the free Helix Score gives you a directional read in about three minutes. For a full picture, book the free 60-minute assessment.
Frequently asked questions about Helix Stax managed IT services
Yes. CMMC Phase 1 self-assessment continues, and the underlying NIST SP 800-171 requirements, DFARS 252.204-7012 obligations, and SPRS score submission remain in force for all covered contracts. What was suspended on July 13, 2026 is the Phase 2 rollout schedule that would have added Level 2 third-party assessment requirements to new contracts starting November 10, 2026.
Yes. SPRS self-assessment scoring and annual affirmation obligations under DFARS 252.204-7020 were not part of the July 2026 suspension. If your contract requires it, it still requires it.
If your contract already includes DFARS 252.204-7021 with a specified CMMC level, that clause still applies as written unless your contracting officer modifies it. The suspension paused the DoD's broader rollout schedule for adding new assessment requirements, it did not retroactively remove clauses already in existing contracts.
Not if you want to stay competitive for DoD work. The suspension removed a hard near-term deadline for Phase 2 assessments, but the control requirements, documentation expectations, and eventual assessment obligation have not gone away. Contractors who pause readiness work now typically restart from further behind once new milestones are set.
No. CMMC Level 1, which covers Federal Contract Information with 17 basic safeguarding practices, was not included in the July 2026 suspension and continues on its existing annual self-assessment schedule.
The task force could recommend adjustments to timelines, cost structure, assessor requirements, or scope. Its report is due within 60 days of the July 13, 2026 announcement. Until a revised rule or schedule is published, current requirements (Phase 1 active, Phase 2-4 suspended) remain the operative status.
No. 32 CFR Part 170, the CMMC Program rule finalized in October 2024, was not rescinded. The suspension paused implementation milestones, not the regulation establishing the program.