CMMC Readiness for Healthcare in the Phase 2 Pause
CMMC Phase 2 is suspended, but DFARS and Phase 1 self-assessments are not. What CMMC readiness still requires of healthcare organizations with DoD-funded work.
Accurate as of the July 13, 2026 Phase 2 suspension announcement. Further guidance was expected around mid-September 2026, following the 60-day review (Secureframe). Re-verify current status against Department of War / DoD CIO announcements and the Federal Register before making decisions.
If your health system, academic medical center, or research institute holds DoD-funded work, CMMC readiness probably slid down the priority list in July 2026. On July 13, 2026, the Department of War — referred to as the Department of Defense in earlier guidance — announced the immediate suspension of CMMC Phase 2 and held subsequent milestones in abeyance pending a 60-day review by a newly established CMMC Reform Task Force, which will also take industry feedback through a public request for information (WilmerHale; Skadden).
The headline said “paused.” A lot of leadership teams heard “deferred.” Those are not the same thing, and the difference is expensive.
Has CMMC been canceled?
No. What was suspended is a certification milestone, not a security obligation.
Phase 2 was scheduled to run November 10, 2026 through November 9, 2027, and would have allowed DoD solicitations and contracts to require Level 2 assessments with certificates issued by third-party assessment organizations (C3PAOs) (McDonald Hopkins). That is the piece that stopped. During the suspension, contracting offices continue accepting Level 1 and Level 2 self-assessments in place of the third-party certification requirements that were to begin in November (Industrial Cyber).
The Department framed the suspension as reducing certification-related burden — particularly for small and midsized businesses — rather than lowering the underlying security requirements (WilmerHale). Reporting also indicates the pause casts genuine uncertainty over the future structure of the program, not only its timing (Federal News Network). So the right posture is neither panic nor pause: it is to keep building the control and evidence base that any future version of the program will draw on.
What still applies right now?
The acquisition-side rule is final and in force, and Phase 1 obligations are live.
- The final rule amending Title 48 of the CFR to write CMMC into DoD contracts was published in the Federal Register on September 10, 2025 and was scheduled to take effect 60 days after publication, moving CMMC from policy framework into binding contractual force (BDO).
- Phase 1 runs November 10, 2025 through November 10, 2026, with the CMMC Program Office holding discretion over which contracts carry Level 1 or Level 2 self-assessment requirements (McDonald Hopkins).
- DFARS 252.204-7012 obligations and CMMC Phase 1 self-assessment obligations remain in effect despite the Phase 2 suspension (Crowell & Moring), and contractors are still expected to complete and upload their self-assessments while the review proceeds (Cybernines).
Here is the split we use when a CIO or compliance director asks what to tell the board.
| Settled today | Pending the Task Force outcome |
|---|---|
| The 48 CFR acquisition rule is in effect (BDO) | Whether and when Phase 2 third-party certification resumes (WilmerHale) |
| DFARS 252.204-7012 obligations continue (Crowell & Moring) | The future structure of the program (Federal News Network) |
| Phase 1 Level 1 / Level 2 self-assessments and uploads continue (McDonald Hopkins; Cybernines) | Later milestone dates, held in abeyance as of July 13, 2026 (WilmerHale; Skadden) |
| Self-assessments accepted in place of C3PAO certification during the suspension (Industrial Cyber) | Timing and content of guidance expected around mid-September 2026 (Secureframe) |
Note on later phases: the pre-suspension schedule described a Phase 3 beginning November 2027 that would extend Level 2 C3PAO requirements to contract option exercises and add mandatory Level 3 DIBCAC assessments (Scrut). Treat that as the schedule as it stood before July 13, 2026, not as a firm date.
Does CMMC apply to our research awards and subawards?
That depends on the paperwork, and it should be answered by reading the paperwork — not by assuming.
Whether CMMC obligations reach a specific award, subaward, or subcontract turns on the contract vehicle, whether Federal Contract Information or Controlled Unclassified Information is actually present, and the flow-down clauses in your agreements. For healthcare organizations, DoD-funded work often arrives at the edges: a single research protocol, a device or data-sharing arrangement, a training or workforce program, a subaward routed through a prime you did not negotiate with.
Our first engagement step is a documented applicability and data-flow review against 32 CFR Part 170 and the DFARS clause text, so you have a defensible answer in writing rather than a hallway opinion. If CUI is not in your environment, that conclusion is worth documenting too.
How long does CMMC Level 2 readiness take?
Longer than the pause. Compliance platform vendor Scrut estimates that achieving CMMC Level 2 compliance typically requires 6 to 12 months of dedicated work. That is a vendor estimate, not a DoD or NIST figure — but compare it to a 60-day review window with guidance expected around mid-September 2026 (Secureframe), and the arithmetic is straightforward.
Most contracts involving CUI were expected to require Level 2 C3PAO certification as a condition of award, which is why Phase 2 represented the shift from self-attestation to independent verification (Secureframe). The pause changed the timing of that shift. Organizations that treat it as a stop will be doing 6-to-12-month work on a compressed schedule if certification requirements resume.
Should we scope the whole environment or build a CUI enclave?
This is the architecture decision, and it is the one worth spending consideration-stage time on.
Full-environment scoping brings your existing systems up to the NIST SP 800-171 control set where CUI could travel. It avoids standing up new infrastructure, but in a hospital or research setting it tends to pull clinical, administrative, and academic systems into an assessment boundary you did not intend.
A scoped CUI enclave creates a defined boundary where the DoD-funded work lives, with the rest of the environment supported by clear separation and documented data flows. It is more work up front and requires user discipline, but it keeps one research award from dragging an entire campus or health system network into scope.
Microsoft’s GCC High often comes up in this conversation. We validate which workloads are in scope, and any export-control caveats, against current Microsoft documentation before recommending a boundary — not from memory or a slide.
One thing to be clear about: no product, cloud service, or provider is “CMMC certified,” and no tool makes an organization compliant. Assessments apply to the organization seeking certification. Technology supports controls in scope; it does not substitute for them.
What evidence should we be producing during the pause?
The documentation trail — because that is the asset that survives whatever the Task Force changes.
Concretely: a System Security Plan that matches how systems actually work, a POA&M with owners and dates, your self-assessment score with the artifacts behind each control, and repeatable evidence collection so the answer to “show me” takes hours instead of weeks. The underlying NIST SP 800-171 control set has not been relaxed, so the evidence you build now carries forward.
Where palmiq fits
palmiq Inc. has worked in healthcare and in the government and defense industrial base space since 2018, including CMMC, NIST 800-171, and GCC High environments. We are WOSB and EDWOSB certified, which is a procurement pathway rather than an award.
On the operations side, we run a 24/7 SOC with a 15-minute response SLA on critical issues. Across our MDR and EDR services specifically, we maintain a 99.9% threat neutralization rate and neutralize more than 1,200 threats monthly. We are an Acronis Platinum partner in the top 1% globally and a Microsoft Gold partner, and we build with Microsoft, Fortinet, CrowdStrike, SentinelOne, Sophos, Veeam, and Acronis.
The practical value we add during a regulatory pause is capacity. The Department’s own stated rationale for the suspension was cost and burden on smaller organizations. If “we cannot staff this internally” is the real constraint, a managed readiness program is a more honest answer than waiting for the rules to get easier.
Talk it through
If you hold DoD-funded work and are deciding between building readiness internally or bringing in a partner while the window is open, book a discovery call: https://palmiq.com/discovery-call. We will start with applicability and scope, so you know what you are actually on the hook for.