home / frameworks / cmmc / rollout-timeline

// CMMC hub

CMMC rollout timeline and the Phase 2 suspension

How the CMMC phased rollout was designed, what started on November 10, 2025, and what changed when Phase 2 was suspended in July 2026.

Two rules, one program

CMMC needed two separate rules. The program rule, 32 CFR part 170, was published in the Federal Register on October 15, 2024 at 89 FR 83092 and took effect on December 16, 2024. It defines the levels, assessments, and accreditation bodies. It doesn't put anything into contracts by itself.

The acquisition rule did that. Published on September 10, 2025 at 90 FR 43560, it amended DFARS parts 204, 212, 217, and 252 and finalized clause 252.204-7021. It took effect on November 10, 2025. Under 32 CFR 170.3(e), Phase 1 begins on the effective date of this acquisition rule, so Phase 1 started on November 10, 2025.

The 4 phases as written

The program rule sets out 4 phases, each starting one calendar year after the previous one. Counting from November 10, 2025, that put Phase 2 at November 10, 2026, Phase 3 at November 10, 2027, and Phase 4 at November 10, 2028. Those were targets. During the first 3 years, the DFARS clause applies only when a program office decides to include CMMC. From the fourth year, it applies to all contracts where the contractor's systems handle FCI or CUI, except awards solely for COTS items.

  • Phase 1: Level 1 (Self) and Level 2 (Self) as a condition of award, with Level 2 (C3PAO) at the Department's discretion
  • Phase 2: Level 2 (C3PAO) added for applicable contracts, and Level 3 at discretion
  • Phase 3: Level 2 (C3PAO) also required for option periods, and Level 3 for applicable contracts
  • Phase 4: full implementation, including option periods on older contracts

What happened in July 2026

On Monday, July 13, 2026, the Department announced that it was suspending Phase 2 and creating a CMMC Reform Task Force to carry out a 60-day review of the program. The Cyber AB responded 2 days later. Program offices were told not to designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during the suspension and to amend active solicitations that included them.

Several things did not change. Phase 1 self-assessment requirements stay in force, so contracts can still require Level 1 (Self) and Level 2 (Self) status in SPRS. DFARS 252.204-7012 still requires NIST SP 800-171 Rev. 2 and 72-hour cyber incident reporting. C3PAOs remain authorized to conduct Level 2 certification assessments for contractors that want one, and the Cyber AB reported nearly 2,000 contractors certified at Level 2 by mid-July 2026.

Status as of October 2026

The task force's request for information closed on August 14, 2026, and press reports say it drew more than 1,100 comments. Its report was due around September 11, 2026. As of October 11, 2026 the report had not been released publicly, and the Department had not announced a new date for Phase 2 or any change to the rule. Contractors are still waiting.

Any lasting change to the phases or levels would need a new rulemaking or a formal policy change published by the Department, and that would normally come with a public comment period. Contractors are watching for it. Until then, the safest assumption is that the Rev. 2 requirements and Phase 1 obligations apply, and that third-party certification will return in some form. Primes are already planning on that basis, and many still ask their subcontractors for evidence of readiness for a C3PAO assessment.

Resources

All CMMC resources

References

  1. DFARS: Assessing Contractor Implementation of Cybersecurity Requirements, 90 FR 43560 (September 10, 2025), Federal Register via govinfo.gov
  2. 32 CFR part 170, CMMC Program, Electronic Code of Federal Regulations
  3. Statement on the Department of War's suspension of CMMC Phase II requirements (July 15, 2026), The Cyber AB
  4. CMMC Reform Task Force updates, September 2026, Covington & Burling, Inside Government Contracts