Live webinar · Free · 45 minutes
CMMC Phase 2 Suspended: Webinar for Research Institutions Current as of August 20, 2026 — the November 10, 2026 Phase 2 date was suspended on July 13, 2026
If your plan says "book a C3PAO before November 10, 2026," that plan is out of date — the Department suspended the Phase 2 transition on July 13, 2026, and Level 2 (C3PAO) requirements are being removed from active solicitations. This session gives research administrators, campus CISOs, sponsored programs staff and state agency IT leaders the corrected timeline, a plain list of what did not pause, and the readiness work that holds its value no matter how the CMMC Reform Task Force reshapes the program.
- A corrected timeline you can plan againstWe walk the actual sequence: Phase 1 in effect since November 10, 2025 (Secureframe CMMC timeline hub); Phase 2 suspended July 13, 2026, with a 60-day Task Force review launched the same day (WilmerHale, July 20, 2026); RFI comments closed at 12:00 PM ET on August 14, 2026 (Subject to Inquiry, July 14, 2026); recommendations due to the Department CIO on or about September 13, 2026 (CyberNINES, July 20, 2026).
- A plain list of what the pause does not pausePhase 1 self-assessment requirements, the program itself, and the security requirements underneath it remain in force (CMMC.com FAQ). DFARS 252.204-7012 and NIST SP 800-171 Rev 2 remain in effect (Secureframe CMMC timeline hub), and the Department has emphasized that it is reducing certification-related burdens, not lowering the underlying cybersecurity baseline (WilmerHale, July 20, 2026).
- A scoping method built for research institutionsCMMC applies wherever the contract applies, and DoD-funded research contracts and subcontracts are contracts; an institution does not have to think of itself as a defense contractor for the requirements to reach it (CASRAI). We show how to trace scope through subawards, university-affiliated research center (UARC) and federally funded research and development center (FFRDC) arrangements, and prime flow-downs.
- A no-regrets readiness roadmapSix workstreams that pay off under any Task Force outcome: CUI and FCI data discovery and boundary definition; enclave strategy, with Microsoft GCC High discussed as one architectural option rather than a default, since tenant choice depends on the data types and contract clauses in scope; System Security Plan and POA&M (plan of action and milestones) accuracy; defensibility of your SPRS (Supplier Performance Risk System) self-assessment score; endpoint, identity and logging controls; and recoverable backup with evidence you can show.
- A clear line between readiness and certificationpalmiq provides readiness and implementation support. We are not a C3PAO or an authorized assessor, and we say so plainly so you know which questions we can close and which belong with your contracting officer, counsel or an assessment body.
Reserve your seat
Free · 45 minutes · 12 seats per session
No sales sequence. One reminder before the session, and the recording after.
What we actually cover
What people bring to this session.
Was CMMC canceled?
No. The July 13, 2026 memoranda suspended the planned November 10, 2026 transition to Phase 2, which would have required contractors and subcontractors handling CUI to achieve Level 2 third-party assessments, and paused pending and future Phase 2 milestones in Department solicitations and contracts; during the review the Department will not grant CMMC waivers (Greenberg Traurig, July 15, 2026). During the review, new solicitations can designate only Level 1 (Self) or Level 2 (Self) — self-assessment rather than a third-party audit — and Level 2 (C3PAO) requirements are being removed from active solicitations and existing contracts (Secureframe CMMC timeline hub).
If the audit is off, do we still owe NIST 800-171?
Yes. DFARS 252.204-7012 and NIST SP 800-171 Rev 2 remain in effect, and the Department has emphasized that it is reducing certification-related burdens, not lowering the underlying cybersecurity baseline (WilmerHale, July 20, 2026). We separate "the audit" from "the controls" and show which of your obligations were never touched by the memoranda.
We are a university, not a defense contractor — does this reach us?
Institutions supporting DoD-funded research remain responsible for protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) and for meeting applicable contractual requirements despite the Phase 2 suspension (CohnReznick CMMC FAQ for Higher Education Institutions). We cover where the obligation enters the institution and who on campus is usually the first to see it.
Can we stand down until the report lands?
No — and at least one prime has said the same to its suppliers. Elbit issued a supplier notice on July 16, 2026 urging suppliers to keep focusing on existing cybersecurity requirements and maturing their programs while the Phase 2 transition is on hold, noting that organizations that keep maturing will be better positioned when the revised assessment timeline is announced (reported by Secureframe). Higher-ed practitioners also report unresolved data discovery and shared-responsibility gaps at most institutions entering 2026, with the differentiator being counsel review of flow-down clauses and research administrators trained to flag CUI at the proposal stage rather than at closeout (Compass IT Compliance, May 5, 2026). Those gaps do not close on their own during a pause.
Before you register
Common questions
- Does this apply to our K-12 district or our E-Rate projects?
- No. CMMC is a DoD contracting requirement. This session is scoped to research universities, UARCs, FFRDCs and state entities holding DoD contracts or subawards. K-12 and E-Rate are separate programs with separate requirements, and we do not blur them.
- Is palmiq a C3PAO or an authorized CMMC assessor?
- No. palmiq is a managed IT, cybersecurity and cloud services provider, founded in 2018, working as the implementation layer rather than the audit layer. Nothing in this session is legal advice, and anything specific to your contracts should be reviewed with your contracting officer and counsel.
- What happens to an assessment we already have scheduled or in progress?
- We will not speculate. The public reporting we have reviewed does not settle questions about refunds, credit toward future assessments, or the standing of assessments completed during the pause. We will tell you what is documented, name what is not, and point you to who can answer.
- Will you tell us what the Task Force is going to decide?
- No. Coverage on August 17, 2026 framed the Task Force as weighing whether to restructure, scale back or alter the program, including the future of third-party audits (ClearanceJobs). Some practitioners speculate a reformed framework would lean more on managed services and self-attestation than a full C3PAO audit regime (Fisch Solutions, July 20, 2026) — we present that as commentary, not policy, and it is not a reason to deprioritize assessment readiness. Because recommendations are due on or about September 13, 2026, session material carries a status date and is reviewed before each delivery.
Rather talk it through first? Call 703-336-9700, or see the other sessions.