On July 13, 2026, the Department announced that CMMC Phase II requirements would not take effect on November 10 as previously scheduled. The announcement did two things at once: it suspended the next implementation phase and started a broader review of the program. It did not switch off Phase I. For contractors already seeing CMMC language in solicitations, that distinction matters more than the headline.
The safest response is neither panic nor a blanket pause. Treat the July action as a change to rollout timing, then look separately at the cybersecurity clauses and assessment records attached to the work you actually pursue. A company can be affected by Phase I self-assessment requirements, DFARS 252.204-7012, a current NIST SP 800-171 DoD Assessment, or an SPRS affirmation even while Phase II is suspended.
The immediate change was narrow: Phase II, which had been scheduled to begin on November 10, 2026, was suspended. The Department's current CMMC page says implementation is paused in Phase I and that Phase I self-assessment requirements remain in place. That means old slide decks showing an automatic move into the next phase on the original date are no longer reliable planning documents.
What changed on July 13 — and what did not
The announcement did not repeal the CMMC rule, cancel every CMMC requirement in an active procurement, or erase cybersecurity duties already carried by DFARS clauses. It also did not make CUI protection optional. If a contract requires safeguarding under DFARS 252.204-7012, the obligation exists because of the contract clause, not because a future CMMC phase is approaching.
Phase I is the part to operationalize now
The current program page describes Phase I as focused on self-assessments. Level 1 uses the 15 safeguarding requirements from FAR 52.204-21 and calls for an annual self-assessment with affirmation. Level 2 Self is tied to the 110 NIST SP 800-171 Rev. 2 requirements, a self-assessment every three years, and annual affirmation. Those are concrete records a small contractor can manage today.
For a proposal team, the useful question is therefore not 'Is CMMC delayed?' It is 'What CMMC status does this solicitation require, for which system, and is the corresponding record current?' That framing prevents the implementation-phase announcement from being mistaken for a waiver of a solicitation requirement or an unrelated DFARS obligation.
Separate CMMC timing from DFARS duties
A contractor handling covered defense information can still have obligations under DFARS 252.204-7012, including implementation of the applicable NIST SP 800-171 baseline, cyber-incident reporting, cloud-service conditions, and subcontract flowdown. DFARS 204.73 can also require a current NIST SP 800-171 DoD Assessment at time of award. None of those duties should be removed from a remediation plan solely because Phase II moved.
This is especially important for organizations that had bundled everything into one project called 'CMMC.' Break that project into separate workstreams: contractual safeguarding, Basic Assessment and SPRS currency, Phase I CMMC status and affirmation, evidence maintenance, and any future third-party-assessment preparation. When one schedule changes, the rest of the work does not accidentally stop with it.
Triage current opportunities contract by contract
Build a one-page bid-readiness record for each live opportunity. Capture the solicitation number, the CMMC level stated in DFARS 252.204-7025 when present, the system or enclave proposed for performance, its CMMC UID if applicable, the latest assessment date, the latest affirmation date, and any open conditional-status deadline. A company-wide note that simply says 'CMMC ready' cannot answer those bid-specific questions.
Then check the record against the real technical boundary. If the sales team plans to use a different tenant, new remote-work path, acquired business unit, or external service provider, a valid record for the old enclave may not describe the system that will perform the new work. The July suspension does not cure a scope mismatch.
What to do with a planned C3PAO assessment
Organizations that were racing toward a C3PAO date because of the old Phase II calendar should revalidate the business reason before spending money. A scheduled assessment may still be valuable when a specific opportunity, customer commitment, or risk decision supports it, but the former November 2026 phase transition should no longer be treated as sufficient justification by itself.
Do not throw away the preparation work. A clean SSP, current asset inventory, traceable evidence, closed technical gaps, and a rehearsed evidence-retrieval process remain useful whether the next external event is a self-assessment, government review, customer diligence request, or a later CMMC rule change. What changes is the urgency driver, not the value of a well-maintained security program.
A sensible posture during the review period
Use the pause to reduce uncertainty in the parts you control. Keep Phase I records current, finish remediation that is independently required by contract, refresh evidence when systems change, and watch the Department's CMMC page for the outcome of the review. A secondary article can be a useful alert, but it should not be the event that changes your compliance baseline.
Set a recurring program-status review that matches the pace of your bids and architecture changes. For a small contractor, the review can be brief: check the official status page, compare active solicitations with the systems proposed for performance, look at upcoming assessment and affirmation dates, and record material system changes since the previous review. Keep the dated note with the bid-readiness register.
For spending decisions, separate three questions that were often bundled together before July: which technical gaps must be closed because of existing contract duties, which evidence work improves current Phase I readiness, and whether an external C3PAO event is actually required by a live opportunity. The first two can remain valuable even when the old Phase II date no longer drives the schedule.
A useful management memo can fit on one page: source and date reviewed, current implementation posture, opportunities examined, systems involved, records that must stay current, remediation that continues, external-assessment decision, owner, and next review trigger. This creates a defensible record of why the company kept, changed, or deferred a CMMC project after the suspension.
Do not assume a program-wide announcement automatically rewrites an existing solicitation or contract. If a procurement document appears inconsistent with the current implementation posture, route the question through the contracting channel rather than silently editing the requirement in your internal checklist.
For each live opportunity, keep that clarification with the proposal record. Note the solicitation version reviewed, the CMMC level or self-assessment path it states, the system proposed for performance, and the date the official program status was checked. That small record prevents a later reviewer from having to reconstruct whether the team relied on current source material or on an outdated rollout assumption.
A short working check
- ✓Read the July 13, 2026 primary announcement
- ✓Identify every active solicitation with a CMMC requirement
- ✓Verify current self-assessment/affirmation status in SPRS
- ✓Keep SSP and evidence current
- ✓Continue remediation of NIST SP 800-171 gaps
Common questions
Is CMMC canceled?
No. The July 2026 action suspends Phase II requirements; Phase I self-assessment requirements remain in place.
Should a contractor stop preparing for Level 2?
No. Existing DFARS and NIST obligations continue, and future solicitations may still require specific CMMC status. Preparation should be driven by actual contract data and current official rules.
Does the suspension remove DFARS 252.204-7012 duties?
No. The Phase II suspension does not eliminate safeguarding and incident-response duties that arise from an applicable contract clause.
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.



