If you've been preparing your company for a CMMC Level 2 certification assessment, you may have heard some confusing news: the federal government has put CMMC Phase II on hold.
That part is true.
What isn't true is that CMMC has disappeared.
On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II, which had been scheduled to begin November 10, 2026. At the same time, officials launched a 60-day review of the program. Phase I self-assessment requirements remain in place.
TL;DR
- CMMC has not been canceled.
- The planned November 10, 2026 start of Phase II has been suspended.
- That pauses the broader rollout of mandatory third-party Level 2 certification assessments.
- Phase I self-assessments remain active.
- Existing contractual cybersecurity requirements for protecting Controlled Unclassified Information have not simply vanished.
- Companies that stopped preparing altogether could find themselves scrambling when the government announces what comes next.
Cybersecurity operations supporting protection of defense information
Here's what all of that means without the alphabet soup.
What exactly happened to CMMC Level 2?
The government suspended the transition to CMMC Phase II while it conducts a review of the program. Phase II had been scheduled to begin November 10, 2026 and would have expanded the use of Level 2 certification assessments performed by Certified Third-Party Assessment Organizations, better known as C3PAOs.
This distinction matters because headlines like "CMMC suspended" make it sound as though someone unplugged the entire program.
They didn't.
Think of it more like road construction where the next major section has been temporarily closed while engineers reconsider the design. The road behind you is still there. The rules already applying to your business don't evaporate because the next stage is being reconsidered.
The Department says it is reviewing CMMC with an eye toward reducing compliance barriers, particularly for small, medium-sized and nontraditional businesses, while maintaining cybersecurity protections.
Why did the government put Phase II on hold?
Cost and complexity are a major part of the story.
In announcing the suspension, the Department said the existing approach had created significant compliance costs and bureaucratic burdens that could discourage companies from participating in the Defense Industrial Base. Officials said the review will look for a more scalable approach while maintaining cybersecurity and operational resilience.
That concern isn't hard to understand from a small-business perspective.
Picture a 30-person manufacturer that makes a specialized component for a larger defense contractor. It doesn't have a Fortune 500 IT department. The owner may be trying to interpret NIST requirements, document policies, secure cloud services, train employees, prepare an assessment environment and keep production moving at the same time.
Cybersecurity still matters enormously.
But so does whether smaller suppliers can realistically navigate the process.
That's the tension the government is now reconsidering.
Does the hold mean you no longer need CMMC Level 2 security?
No. A pause in Phase II should not be interpreted as permission to stop protecting CUI or ignore existing contract requirements.
The government's current small-business cybersecurity guidance still describes CMMC Level 2 as protection for Controlled Unclassified Information (CUI) and ties Level 2 to the 110 security requirements in NIST SP 800-171 Revision 2.
Separate DFARS requirements also continue to matter. DFARS provisions require applicable contractors to provide adequate security for covered contractor information systems, and NIST SP 800-171 requirements remain part of that framework.
Here's the easier way to think about it:
The certification timetable changed. The need to protect sensitive defense information did not.
| CMMC issue |
Current status |
| CMMC program |
Still exists |
| Phase I requirements | Remain active |
| Level 1 self-assessment | Still applicable where required |
| Level 2 self-assessment | Still applicable where required |
| Phase II rollout scheduled for Nov. 10, 2026 | Suspended |
| Expanded mandatory Level 2 C3PAO certification rollout | On hold pending review |
| Protecting applicable CUI | Still required |
| Applicable NIST SP 800-171/DFARS obligations | Still matter |
| New Phase II start date | Not yet announced |
Sources: Department CMMC guidance and July 13 announcement.
What was CMMC Level 2 supposed to require?
Level 2 is aimed at organizations handling Controlled Unclassified Information.
CUI isn't classified information in the traditional "Top Secret" sense. But it is government information that still needs protection.
For example, depending on the contract, that could involve technical information, engineering data, specifications or other sensitive information connected with defense work. DFARS guidance specifically recognizes technical information such as engineering drawings, specifications, manuals, technical reports, data sets and software as examples within this broader environment.
Under the CMMC model, Level 2 requires implementation of the 110 NIST SP 800-171 Revision 2 security requirements. Depending on the solicitation and information involved, Level 2 was designed around either self-assessment or assessment by a C3PAO, along with annual affirmation requirements.
That is much more than installing antivirus software.
It reaches into areas such as access control, authentication, system configuration, incident response, employee practices, monitoring, documentation and how sensitive information moves through the organization.
What does the CMMC pause look like on a timeline?
Before the July announcement, Phase II was scheduled to start on November 10, 2026. The July 13 action suspended that transition and pending/future implementation milestones while the Department undertakes its review.
The chart does not suggest Phase II will begin later this year. As of this article's August 28, 2026 update, the old November milestone is suspended; contractors should wait for official guidance rather than assuming a replacement date.
Should companies stop spending money on CMMC preparation?
For most businesses handling CUI, completely stopping would be a risky interpretation of the announcement.
There is a difference between not rushing into an assessment that is no longer required on the old timetable and abandoning cybersecurity work your contracts may already require.
This pause may actually be useful.
Instead of treating CMMC like a mad dash toward a certificate, companies can look at the underlying environment:
- Where does our CUI actually live?
- Who can access it?
- Are we protecting accounts with appropriate authentication?
- Are systems properly configured and monitored?
- Do our policies describe what we actually do?
- Do employees understand their responsibilities?
- Does our NIST SP 800-171 assessment reflect reality?
- Can we prove the controls we claim to have implemented?
That last question matters.
A policy sitting in a folder isn't the same thing as a working security control.
What should defense contractors do during the government hold? Use the pause to improve readiness, not to forget about it. Contractors should first determine what their current contracts and solicitations actually require, then keep working on the cybersecurity obligations that remain applicable.
A sensible checklist looks like this:
1. Review your current contracts.
Don't make a compliance decision based on a headline. Identify the clauses and cybersecurity requirements that actually apply to your organization.
2. Confirm whether you handle CUI.
You can't properly scope a CMMC environment until you know where sensitive information enters, where it is stored, who touches it and where it leaves.
3. Review your NIST SP 800-171 posture.
Applicable contractors should know where they meet requirements and where gaps remain.
4. Check your self-assessment and SPRS obligations.
Phase I did not disappear with the Phase II suspension. The Department expressly says Phase I self-assessment requirements remain in place.
5. Keep your evidence organized.
Policies, configurations, logs, diagrams, training records and other evidence are much easier to maintain continuously than recreate shortly before an assessment.
6. Watch official CMMC guidance.
Don't build your strategy around rumors about what the revised program "will" look like. The government is reviewing it now.
Could CMMC Level 2 certification come back? Yes, the current action is a suspension and review, not an announcement that Level 2 cybersecurity has been eliminated.
What nobody should do, however, is pretend to know exactly what the revised certification structure will look like before the government finishes its work.
The Department announced a comprehensive review intended to reduce barriers while retaining cybersecurity protections. That creates the possibility of changes to implementation, assessment or compliance mechanics. Until official guidance arrives, predictions are just predictions.
For a business owner, that's actually the most important takeaway.
Prepare for the security requirement, not just the test.
If your systems genuinely protect CUI, your documentation is current and your organization understands its responsibilities, adapting to whatever comes next should be far easier than starting from scratch.
What should you remember about the CMMC Level 2 hold?
CMMC has been confusing enough without turning a government pause into another round of rumors.
The simple version is this:
Phase II is suspended. Phase I remains active. The old November 10, 2026 Phase II rollout date is no longer the deadline businesses were preparing around. But applicable cybersecurity and CUI-protection responsibilities remain important.
For defense contractors and subcontractors, this isn't a reason to panic.
It isn't a reason to throw away the work you've already done either.
It's a chance to get the fundamentals right.
People Also Ask
Is CMMC Level 2 canceled in 2026?
No. The government announced the suspension of CMMC Phase II implementation, not the cancellation of the entire CMMC program. Phase I self-assessment requirements remain active while the Department conducts its review. Businesses should continue monitoring official guidance rather than assuming CMMC requirements have disappeared.
Is the November 10, 2026 CMMC Level 2 deadline still in effect?
The planned Phase II transition scheduled for November 10, 2026 has been suspended. The Department announced the suspension on July 13 and placed pending and future implementation milestones on hold while reviewing the program. Businesses should not invent a replacement deadline until the government publishes one.
Do contractors still need NIST SP 800-171?
Applicable defense contractors handling covered information continue to have cybersecurity obligations under their contracts. Government guidance states that CMMC Level 2 is based on the 110 security requirements in NIST SP 800-171 Revision 2, while DFARS provisions continue to address safeguarding covered defense information.
What is a C3PAO?
A C3PAO is a Certified Third-Party Assessment Organization authorized within the CMMC ecosystem to conduct applicable certification assessments. Phase II would have expanded requirements for Level 2 C3PAO assessments, but that implementation stage is currently suspended while the government reviews CMMC.
Should I continue preparing for CMMC Level 2?
If your organization handles CUI or has applicable contractual cybersecurity obligations, maintaining security readiness remains sensible. Review your contracts, confirm your CUI scope, maintain applicable NIST SP 800-171 controls and self-assessment obligations, and follow official government updates rather than preparing around a now-suspended Phase II date.