CMMC Phase 2 is Suspended, You’re Security is Not
The Department of Defense has suspended the CMMC Phase 2 transition that was set to take effect on November 10, 2026. For contractors handling CUI (Controlled Unclassified Information), this means a third-party CMMC Level 2 assessment won't be required for now, and subcontractors can continue after completing a self-assessment.
It's important to be clear about what's actually delayed. The piece being paused is the audit itself, not the security requirements needed. While the Phase 1 self-assessment requirements remain fully in effect, the formal assessment outlined in for level 2 contractors to be performed by a C3PAO (Certified third-party Assessor Organization) has been delayed.
The Work Doesn't Stop
Under DFARS clause 252.204-7012, defense contractors and subcontractors are still responsible for protecting sensitive data as defined in the clause. To hold a government contract, a business must attest to a specific level of cybersecurity, and that contractual commitment hasn't changed. Only the third-party verification has.
In other words, signing a contract that says you're secure, without actually being secure, is a big problem. It is still your responsibility to ensure your business fulfills the requirements outlined in a contract, regardless of having to provide proof. You wouldn't not pay taxes because you might not be audited, right?
Why the Delay Happened
The reasoning behind the pause is a reasonable one. Regulators recognized that the cost and bureaucratic burden of the original requirement risks straining businesses and potentially discouraging others from renewing or pursuing government contracts in the first place. Between assessment costs, the implementation, and the logistics of a third-party audit, the expectations were proving difficult to clear on schedule.
A review is currently underway during this suspension to re-evaluate whether a third-party assessment is the right model, and when an independent audit should apply. The most important takeaway isn't the timeline; it's making sure you understand exactly where your business stands today.
Where This Leaves You
If you're already in the process of building toward CMMC compliance, keep going. The suspended piece only applies to the audit, not the requirement behind it. If you haven't started, the self-assessment requirements have been in effect since November 2025, and security obligations never paused. If your business handles FCI or CUI and you haven't begun that work, you're already behind.
Not sure where your business falls, or what level applies to the data you handle? That's exactly where we come in. AdvanTech works with contractors and their vendors to map out where CUI and FCI actually live in their environment, assess current security posture against the required controls, and build a realistic path forward, audit or not audit. Reach out to our team to get started.