CMMC Status Update

As of 31 August 2026, CMMC is in an unusually important transition period. The headline is that CMMC has not been cancelled, but the Department of War CIO has suspended the transition to Phase 2, while retaining Phase 1, NIST SP 800-171 Rev. 2 obligations, SPRS reporting and affirmation, and the ability to conduct select government-led assessments. The newest development this week is that DoW CIO Kirsten Davies publicly discussed the reform effort at DIBX on 26 August.

Current CMMC status

Comparison of Current status and What it means for the DIB
TopicCurrent statusWhat it means for the DIB
CMMC Phase 1ActiveContractors must continue applicable Level 1 and Level 2 self-assessments.
Phase 2 transitionSuspendedThe 10 November 2026 Phase 2 milestone will not occur as originally planned.
Level 1 self-assessmentActiveAnnual self-assessment and affirmation; results entered in SPRS.
Level 2 self-assessmentActiveNIST 800-171 Rev. 2 requirements remain applicable. Self-assessment every three years plus annual affirmation.
Level 2 C3PAO requirementPaused as an implementation requirementProgram offices are not moving forward with Phase 2 C3PAO certification requirements during the review.
Level 3 / DIBCAC certification requirementPaused as Phase 2 implementationThe scheduled expansion to mandatory Level 3 DIBCAC certification is on hold.
Government assessmentsStill possibleDoW specifically says it will use self-assessments and select government-led assessments during the interim.
DFARS 252.204-7012ActiveContractors handling covered defense information still have contractual safeguarding obligations.
NIST SP 800-171 Rev. 2ActiveThe 110 security requirements remain the principal CUI baseline during the pause.
SPRSActiveSelf-assessment results and applicable affirmations remain important.
CMMC Reform Task ForceActiveConducting the top-to-bottom CMMC review.
CMMC Reform RFIClosedIndustry comments closed 14 August.

The DoW CIO’s current CMMC page explicitly describes the program as “paused in Phase 1” and says that during the pause the Department will enforce NIST 800-171 Rev. 2 through self-assessments and select government-led assessments.

The DIBCAC distinction is important

The planned Phase 2 requirement for Level 3 DIBCAC certification assessments is suspended along with the other Phase 2 implementation milestones. Program offices are not simply proceeding toward 10 November as previously planned.

However, that does not mean DIBCAC has stopped assessing contractors. The DoW CIO specifically retains the ability to conduct select government-led assessments. Existing authorities for government assessments under DFARS 252.204-7012 and 7020 remain relevant, and the CMMC regulation itself continues to describe DIBCAC’s assessment responsibilities.

Key distinction

Mandatory DIBCAC certification as part of the scheduled CMMC Phase 2 rollout is paused. Government cybersecurity assessment authority is not.

For defense contractors, “CMMC is paused” should not be interpreted as “we no longer need to be capable of passing a government review of our 800-171 implementation.”

Bottom line for the DIB

  • CMMC is not cancelled. Phase 1 remains in effect and the transition to Phase 2 is suspended.
  • Your cybersecurity obligations remain. DFARS 252.204-7012 and NIST SP 800-171 Rev. 2 are still enforceable.
  • Self-assess and report in SPRS. Level 1 annually, Level 2 every three years, plus annual affirmation.
  • Government assessments are still possible. Be prepared for select government-led assessments at any time.
  • Reform is underway. The CMMC Reform Task Force is reviewing the entire program. Industry input through the RFI is now closed.
  • Stay informed. Watch for the Task Force’s recommendations, expected mid-September, and future policy updates.

This update is compiled from third-party resources and public information available as of 31 August 2026. Policies and requirements are subject to change. Intuitus is not affiliated with the Department of War, DIBCAC, or any government entity. Always refer to official sources for authoritative guidance.

Start the conversation

Talk to a cybersecurity engineer — not a sales rep.

Tell us your industry and where you are today. We’ll route you to the right specialist and a practical next step — no pressure, no jargon.