Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

CMMC Phase 2: A Pause, Not a Pass

By Roma Patel on July 23, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

On September 10, 2025, the U.S. Department of Defense (DoD) issued the CMMC Procurement Rule, which made cybersecurity compliance a condition of doing business with that agency by requiring contractors and subcontractors to meet specified security standards before accessing Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). We previously covered the CMMC Procurement Rule and its requirements in detail here.

Less than a year later, on July 13, 2026, the DoD issued guidance pausing the next scheduled step in the CMMC rollout, which had been expected in November 2026 and would have expanded the use of more formal third-party and government-led assessments. The DoD’s memorandum ties the pause to DoD’s broader effort to reduce acquisition process, speed delivery of new capabilities, and avoid placing unnecessary burdens on small and non-traditional businesses in the Defense Industrial Base.

Contractors should understand that the CMMC Phase 2 suspension changes the assessment process, not the underlying cybersecurity obligations. In addition, the “Phase 2” pause should not be confused with CMMC Levels 1 and 2. The phases refer to the DoD’s rollout schedule, while the levels refer to the type and sensitivity of information a contractor handles and the corresponding cybersecurity requirements. During the suspension, program managers and requiring activities may include only CMMC Level 1 self-assessments or CMMC Level 2 self-assessments in procurement documents. They may not require Level 2 third-party assessments by a C3PAO or Level 3 assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) during this period.

Even so, the DoD stated that DFARS 252.204-7012 remains in effect, and that baseline compliance with NIST SP 800-171 Rev. 2 will continue to be enforced through self-assessments and select government-led assessments. That means federal contractors still need to be able to show that they are protecting federal information properly. Level 1 applies to FCI, such as non-public information provided by or generated for the government under a contract, and is tied to FAR 52.204-21, which sets basic safeguarding requirements for contractor information systems, such as limiting system access to authorized users, controlling physical access to systems, and using basic protections against malicious code. Level 2 applies where CUI is involved, such as technical drawings, specifications, or other sensitive government information that requires safeguarding, and remains aligned with NIST SP 800-171 Rev. 2, a more detailed set of security controls for protecting that information, including requirements for access control, incident response, system monitoring, and security assessment.

The guidance also affects live procurements. If a solicitation or requirements package included a Level 2 C3PAO or Level 3 DIBCAC requirement, DoD personnel must initiate amendments, and contracting officers or agreements officers must issue corresponding solicitation amendments “as soon as practicable.” Existing contracts or agreements containing those requirements are also to be modified.

Federal contractors should monitor solicitations, amendments, and contract modifications closely, but they should not pause cybersecurity work. The DoD’s Chief Information Officer is conducting a 60-day review of CMMC to ensure the Defense Industrial Base remains secure without imposing significant burdens on small and non-traditional businesses. Until the DoD issues further guidance after that review, contractors should keep policies, system security plans, plans of action, and self-assessment records current and supportable.  

Photo of Roma Patel Roma Patel

Roma Patel focuses her practice on a broad range of data privacy and cybersecurity matters. She handles comprehensive responses to cybersecurity incidents, including business email compromises, network intrusions, inadvertent disclosures and ransomware attacks. In response to privacy and cybersecurity incidents, Roma guides clients…

Roma Patel focuses her practice on a broad range of data privacy and cybersecurity matters. She handles comprehensive responses to cybersecurity incidents, including business email compromises, network intrusions, inadvertent disclosures and ransomware attacks. In response to privacy and cybersecurity incidents, Roma guides clients through initial response, forensic investigation, and regulatory obligations in a manner that balances legal risks and business or organizational needs. Read her full rc.com bio here.

Read more about Roma PatelEmail
Show more Show less
  • Posted in:
    Technology and AI
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo