CMMC Phase 2 Suspended: What's Still Required in 2026
CMMC Phase 2 suspended on July 13, 2026. What universities and DoD-funded research institutions still owe, and the readiness work that pays off either way.
Status: current as of August 20, 2026. Last reviewed August 20, 2026. Next scheduled review: the week of September 14, 2026, after the CMMC Reform Task Force report is expected.
If your compliance calendar still has a November 10, 2026 countdown on it, that plan is out of date. CMMC Phase 2 was suspended on July 13, 2026, and the third-party assessment requirement everyone was preparing for is on hold while the Department reviews the program. The date that matters now is mid-September 2026, when a reform task force delivers its recommendations.
For universities, university-affiliated research centers, FFRDCs and state entities holding DoD-funded research contracts or subawards, the practical question is not “did we miss the deadline.” It is “what do we still owe, and what work is still worth doing.”
A naming note: sources published after mid-2026 refer to the Department of War, while the regulatory text most research offices have on file references the Department of Defense. Same organization. We use “the Department” below, and keep “DoD” only as the adjective attached to contracts, funding and awards, since that is how those documents are labeled.
Is CMMC Phase 2 still starting on November 10, 2026?
No. WilmerHale’s July 20, 2026 client alert reports that on July 13, 2026 the Department announced the immediate suspension of Phase 2 of CMMC assessment implementation, which had been scheduled to take effect November 10, 2026.
Greenberg Traurig (July 15, 2026) describes the July 13 memoranda as suspending upcoming CMMC implementation deadlines, including the planned Phase II transition that would have required contractors and subcontractors handling CUI to achieve Level 2 third-party assessments.
In practical terms, the audit gate is what moved. Secureframe’s CMMC timeline hub reports that during the review, new solicitations can designate only CMMC Level 1 (Self) or Level 2 (Self) — self-assessment, in other words, is the path currently in front of you.
Was CMMC canceled in 2026?
No. What paused is a phase of the rollout, not the program.
Per the CMMC.com FAQ, as of July 13, 2026 the phased rollout beyond Phase 1 is on hold, while Phase 1 self-assessment requirements, the program itself, and the security requirements underneath it remain in force. Phase 1 enforcement began as planned on November 10, 2025, requiring CMMC Level 1 or Level 2 self-assessments on certain contracts (Secureframe’s CMMC timeline hub).
Reading the pause as a cancellation is the costliest mistake available this year. It is also, plainly, a misreading.
What is still required after CMMC Phase 2 was suspended?
Nearly everything except the third-party audit gate.
Secureframe’s CMMC timeline hub reports that Level 2 (C3PAO) requirements are being removed from active solicitations and existing contracts during the review, and that DFARS 252.204-7012 and NIST SP 800-171 Rev 2 remain in effect. Greenberg Traurig adds one more piece: the Department will not grant CMMC waivers during the review period.
So yes — NIST 800-171 is still required in 2026, and so is your DFARS clause, the incident reporting obligation in 252.204-7012, your SPRS self-assessment score and every CUI-handling term already written into an award or subaward.
WilmerHale notes the Department has emphasized that it is reducing certification-related burdens, not lowering the underlying cybersecurity baseline. Primes read it that way too. Secureframe reports that Elbit issued a supplier notice on July 16, 2026 urging suppliers to keep focusing on existing cybersecurity requirements and to keep maturing their programs while the Phase II transition is on hold.
Does CMMC apply to universities with DoD research contracts?
Yes, where the contract says so. CASRAI’s guide for universities and research institutions makes the point plainly: CMMC applies wherever the contract does, and DoD-funded research contracts and subcontracts are contracts — an institution does not need to consider itself a defense contractor for the requirements to reach it.
CohnReznick’s CMMC FAQ for higher education institutions is equally direct: institutions supporting DoD-funded research remain responsible for protecting CUI and FCI and for meeting applicable contractual requirements, even though Phase II third-party certification is suspended during the review.
That reach is wider than most campuses assume, because it follows awards and subawards into departments and labs that have never dealt with a contracting officer’s cybersecurity clause before.
Compass IT Compliance (May 5, 2026) reports that most institutions entering 2026 still have unresolved data discovery and shared-responsibility gaps, and that the differentiator is counsel review of flow-down clauses plus research administrators trained to flag CUI at the proposal stage rather than at closeout. None of that is excused by the pause.
Should we still book a C3PAO assessment during the pause?
Separate two decisions that get blurred together: the audit and the controls.
On the audit: Level 2 (C3PAO) language is being removed from active solicitations and existing contracts during the review, so a new booking is not something a current solicitation is likely to compel. What happens to assessments already scheduled, paid for or in progress — refunds, credit, or the standing of an assessment completed during the pause — we could not confirm against a primary source, and we are not going to guess. Ask your C3PAO directly, and confirm contract-specific obligations with your contracting officer and counsel.
On the controls: canceling readiness work is a different decision entirely, and a worse one. Every workstream below holds its value regardless of how the program is reshaped.
When will the CMMC Reform Task Force release its recommendations?
The task force, established under the Department CIO, has 60 days to deliver recommendations — on or about September 13, 2026, per CyberNINES (July 20, 2026). The public RFI comment window has already closed; comments were due by 12:00 PM ET on Friday, August 14, 2026, according to Subject to Inquiry (July 14, 2026).
ClearanceJobs reported on August 17, 2026 that the task force is now weighing whether to restructure, scale back or alter the program, including the future of third-party audits. Some practitioners — Fisch Solutions, July 20, 2026 — speculate that a reformed framework could lean more on managed cybersecurity services and self-attestation than on a full C3PAO regime. That is commentary, not announced policy, and it is not a reason to deprioritize assessment readiness.
The next few weeks are a “get ready for the report” window, not a feedback window.
What readiness work still pays off under any outcome?
Six workstreams that survive whatever the task force recommends:
- CUI and FCI data discovery and boundary definition. You cannot scope what you have not found. Start with awards and subawards, not with systems.
- Flow-down clause review by counsel. Existing subcontract obligations did not pause. Know what you already signed.
- SSP and POA&M accuracy. Documents that describe the environment you actually run, not the one you intended to build.
- SPRS self-assessment score defensibility. Be able to show the arithmetic and the evidence behind every claimed control.
- Enclave design. Microsoft GCC High is one architectural option for reducing in-scope surface area; whether it fits depends on the specific data types and contract clauses in play. It is not an automatic answer.
- Evidence generation. Endpoint and identity controls, logging retention, and backups you have actually restored from — with artifacts an assessor could read.
Does any of this apply to K-12 districts or E-Rate projects?
No. CMMC is a DoD contracting requirement. It reaches a K-12 district or a state agency only through an actual DoD contract or subaward. E-Rate and general district cybersecurity obligations are separate programs with separate requirements, and treating them as the same thing creates confusion in both directions.
If you came here from a K-12 context, that work is a real track for us — it is just a different one. palmiq supports K-12 and E-Rate network and security projects separately from CMMC readiness, and the two should be planned and budgeted separately.
Where palmiq fits
palmiq provides readiness and implementation support — not certification. We are not a C3PAO or an authorized CMMC assessor, and we do not issue assessments. What we do is build and operate the technical layer underneath your compliance posture: identity and endpoint controls, logging, secure enclaves, and recoverable backup, backed by a 24/7 SOC and a 15-minute response SLA on critical issues. Our implementation stack includes Microsoft, Fortinet, Sophos, CrowdStrike, SentinelOne, Acronis and Veeam.
palmiq Inc. was founded in 2018 and is WOSB and EDWOSB certified.
This article is general information, not legal advice. Confirm any specific obligation under DFARS 252.204-7012, an existing flow-down or an in-flight solicitation with your contracting officer and counsel.
If your subawards are where the risk sits, our session on CMMC flow-down and annual affirmation covers what subcontractors and subaward recipients still owe: Webinar: CMMC Flow-Down for Subcontractors.