On 2026-07-13 the Department of War suspended CMMC Phase 2 and launched a 60-day reform review. Phase 2 was the step that would have made third-party (C3PAO) assessment mandatory for Level 2 β so that mandate is on hold.
Status & updates
βΆ
CMMC Phase 2 was suspended β can I stop worrying about cybersecurity?
No. Suspension isn't repeal. The third-party-assessment rollout paused, but DFARS 252.204-7012, your NIST 800-171 self-score in SPRS, and False Claims Act risk all still apply.
A common reaction after the July 13 announcement: "CMMC Phase 2 is suspended β great, we can put the cybersecurity project on hold." That read is dangerous.
Suspension is not repeal. The cybersecurity obligations predate CMMC and still bind you today:
DFARS 252.204-7012 still requires NIST SP 800-171 for CUI, 72-hour incident reporting to DIBNet, and flow-down to subs. DFARS 7019/7020 still require a current self-assessment score posted in SPRS. And senior-official affirmations carry False Claims Act liability. Suspending the assessment rollout didn't touch any of that.
What actually paused: the Phase 2 milestone (was due 2026-11-10) that turns on mandatory C3PAO certification for Level 2. Existing CMMC requirements are being removed from solicitations/contracts by modification during the 60-day review. Phase 1 self-assessments stay in place.
Phase 2 (mandatory C3PAO for Level 2) is paused. Everything that already protected CUI still applies β do not stand down.
- What paused: the Phase 2 rollout (due 2026-11-10) that would make third-party certification mandatory for Level 2; now under a 60-day reform review.
- Still required: NIST SP 800-171 implementation under DFARS 252.204-7012; a current self-assessment score in SPRS (DFARS 7019/7020); 72-hour DIBNet incident reporting; flow-down to subcontractors.
- Still enforced: False Claims Act liability for false affirmations of compliance.
- Do: keep implementing 800-171 and keep your SPRS score current β the review is likely to reshape assessment, not the underlying duty to protect the data.
Levels & requirements
βΆ
Do I need CMMC Level 1, 2, or 3 β and what's the difference?
It's driven by the information you handle: FCI β Level 1 (17 practices, self-assessed); CUI β Level 2 (110 NIST 800-171 controls); the most sensitive programs β Level 3 (NIST 800-172).
A frequent question from small defense subs: "Everyone says get CMMC Level 2 β but do I actually need it, or is Level 1 enough?"
CMMC 2.0 has three levels (down from five in 1.0). Which one applies isn't about company size β it's driven by the kind of information your contract has you handle.
Pinning the model:
Level 1 β Federal Contract Information (FCI). 17 basic practices, self-assessed annually.
Level 2 β Controlled Unclassified Information (CUI). 110 practices = all of NIST SP 800-171 Rev. 2.
Level 3 β the most sensitive programs. 134 practices, built on NIST SP 800-172 (enhanced, anti-APT).
The trap is assuming "I'm small, so Level 1." The determinant is the data: if your contract involves CUI, you need Level 2 regardless of headcount. Check the contract clauses and the CUI markings β not your size. And the SBIR angle: a DoD SBIR/STTR award that touches CUI pulls you into Level 2 territory too.
Your level is set by the information you handle, not your size. FCI β Level 1; CUI β Level 2; most-sensitive β Level 3.
- Level 1 (FCI): 17 basic practices, self-assessed annually.
- Level 2 (CUI): 110 practices β the full NIST SP 800-171 Rev. 2 control set. This is where most contractors that touch CUI land.
- Level 3 (most sensitive): 134 practices layered on NIST SP 800-172.
- How to tell: read the contract clauses and CUI markings β the data drives the level. DoD SBIR/STTR work that involves CUI counts.
Assessment
βΆ
Can I self-assess, or do I need a third-party assessor (C3PAO)?
Level 1 is self-assessed annually. Level 2 normally needs a C3PAO every three years (some DoD-designated programs allow self). Either way, a current score goes in SPRS.
"Can I just self-assess and post a score, or do I have to pay an outside assessor?" β the question that decides your cost and timeline.
It depends on your level. Level 1 is a self-assessment, done annually. Level 2 generally requires a C3PAO β a certified third-party assessment organization β every three years.
Precise version: Level 1 β annual self-assessment + affirmation. Level 2 β C3PAO assessment every 3 years, except a subset of programs the DoD designates as self-assessment. Level 3 β assessed by the government (DIBCAC). Regardless of path, a current score and affirmation are posted in SPRS.
Timing caveat after July 13: the mandatory C3PAO trigger (Phase 2) is suspended pending the 60-day review β so today you aren't blocked from award for lack of a C3PAO cert. But the self-assessment score in SPRS is still required now, and the C3PAO requirement is paused, not gone. Don't confuse "not yet mandatory" with "not needed."
Level 1 self-assesses annually. Level 2 normally needs a C3PAO every three years β though the mandatory trigger is currently paused. A current SPRS score is required either way.
- Level 1: annual self-assessment + affirmation.
- Level 2: C3PAO assessment every 3 years, except DoD-designated self-assessment programs.
- Level 3: government-led assessment (DIBCAC).
- Now: the Phase 2 suspension means a C3PAO certification isn't yet a condition of award β but keep a current NIST 800-171 self-score in SPRS, because that requirement never paused.