Skip to main content
Business · Government · Public Safety
Freedom Tech — Technology Solutions for Business, Government & Public Safety
Compliance

CMMC Phase 2 Is Paused. Your Requirements Aren’t.

September 29, 2026 5 min readBy Matt Jones, President & CTO
Defense contractor reviewing compliance documentation

The Department of War paused CMMC third-party assessments. Here’s what changed, what didn’t, and what defense contractors should do while the rules are reviewed.

If you work on defense contracts, you’ve probably heard that CMMC was “suspended.” That’s partly true, and the part that isn’t true is the part that can cost you contracts. Here’s a plain-English summary as of September 29, 2026. We’ll update this article when the Department of War publishes its next decision.

What changed

On July 13, 2026, the Department of War paused Phase 2 of the CMMC rollout. Phase 2 was scheduled to begin on November 10, 2026, and would have required a third-party (C3PAO) assessment for most contracts involving Controlled Unclassified Information (CUI). Phases 3 and 4 are on hold too.

At the same time, the department opened a 60-day review by a CMMC Reform Task Force and asked industry for input. It received more than 1,100 comments. On September 3, a class deviation memo told contracting officers to remove CMMC third-party assessment requirements from contracts, turning the pause from a policy statement into a binding contracting rule. The task force delivered its report to the department’s Chief Information Officer on September 11. As of this writing, that report has not been made public.

What didn’t change

The pause covers the third-party assessments. It does not remove the security requirements themselves. These still apply:

  • DFARS 252.204-7012: safeguarding CUI, reporting cyber incidents, and meeting cloud security requirements.
  • NIST SP 800-171: the 110 security requirements for protecting CUI.
  • FAR 52.204-21: basic safeguarding for Federal Contract Information (FCI).
  • CMMC Phase 1: self-assessments, scores posted in SPRS, and annual affirmations by a senior official.

Those affirmations matter. When a company affirms compliance it hasn’t actually achieved, that can create False Claims Act exposure, and the Department of Justice has already brought cybersecurity cases on that basis.

Why you shouldn’t hit pause

Prime contractors are still responsible for protecting CUI across their supply chain, so many still expect subcontractors to show Level 2 readiness. The task force may change how and when assessments happen, but NIST 800-171 is the foundation under every version of CMMC so far. The work you do now carries forward whatever the final rules say. Companies that stop now will be scrambling when assessments resume.

What to do now

  1. Confirm what data you handle. Is it only FCI, or CUI too? That decides whether you’re working toward Level 1 or Level 2, and whether your email and files belong in commercial Microsoft 365, GCC or GCC High.
  2. Make sure your SPRS score is current and honest. If your score is out of date or optimistic, fix it before your next affirmation.
  3. Keep your System Security Plan and Plan of Action & Milestones up to date. Those documents are what any assessor, prime or contracting officer will ask for first.
  4. Keep closing gaps. Start with the controls that reduce the most risk: multi-factor authentication, access control, logging and incident response.
  5. Watch for the task force report. When it’s published, we’ll update this article with what it means for small contractors.

How Freedom Tech helps

Freedom Tech helps defense and federal contractors align their technology, security controls and documentation with NIST 800-171 and CMMC, including Microsoft 365 GCC and GCC High environments. If you’re not sure where you stand after the pause, schedule a conversation with our team.

Freedom Tech Technology Partner Evaluation Guide

Free Evaluation Guide

Technology Partner Evaluation Guide

A practical checklist for evaluating security, accountability, support, documentation, recovery readiness, and long-term fit before choosing a technology partner.

Get the Guide

Start With the Outcome.

Tell us what your organization needs to accomplish. We’ll help determine the right technology path. Call 910-920-0999 or request a consultation.

Technology Platforms We Work With

Cloud & Productivity

  • Microsoft
  • Google
  • Amazon Web Services

Computers & Devices

  • Apple
  • Dell
  • HP
  • Lenovo

Networking & Power

  • Ubiquiti UniFi
  • Cisco Meraki
  • SonicWall
  • WattBox

Security & Management

  • Datto
  • 1Password
  • Cisco Duo
  • Absolute
  • Splashtop

Communications & Video

  • Cisco
  • Yealink
  • Verkada

These are the brands we prefer, but we work with virtually any equipment or platform. Bring us the hard problems.