● Current status: Phase 2 suspended · under review
Next date: RFI closes Aug 14, 2026
Report expected: ~late Sept 2026
Where things stand
On July 13, 2026, DoD suspended CMMC Phase 2 and launched a 60-day reform review. As of July 19, 2026, nothing has been reversed or finalized — the program is paused while a task force gathers feedback. NIST 800-171 self-assessment, SPRS scoring, and DFARS 252.204-7012 all remain in force throughout. This page tracks the timeline and what each milestone means; we update it as the story develops.
If you're trying to plan around a moving target, this is the one-screen version: what's happened, what's next, and what each likely outcome would mean for a small contractor. No speculation dressed up as fact — we mark clearly what's confirmed versus what's still open.
The timeline
- Jul 13, 2026Phase 2 suspended. DoD CIO Kirsten Davies signs a memo suspending the Level 2 C3PAO certification mandate (was set for Nov 10, 2026) and opens a 60-day review. Reason cited: ~100,000+ DIB firms vs. ~100 approved assessors, and prohibitive cost for small business.
- Jul 16, 2026Reform task force meets. The review team begins work — ~60 days to gather feedback plus ~15 to write recommendations. DoD signals nationwide listening sessions aimed at small businesses.
- Aug 14, 2026 · nextRFI closes. A public Request for Information on SAM.gov (7 questions on cost, burden, meaningful controls, and self-assessment challenges) closes at 12:00 PM ET. This is where the DIB's input formally lands.
- ~Late Sept 2026Recommendations report. The task force's report to DoD leadership is expected. Outcomes could range "from an overhaul, to small tweaks here and there."
- Late 2026 / 2027Revised rule (expected). Any changes would flow into a revised rule after the review. Timing not set. We update this line the moment there's official word.
What hasn't changed the entire time
Throughout the review, the security standard is still enforced. If you handle FCI you owe a Level 1 self-assessment; if you handle CUI you owe NIST 800-171, a Level 2 self-assessment, and a current SPRS score. A false SPRS score still carries False Claims Act liability. The certification is suspended; the standard is not.
What each outcome would mean for you
▸ Minor tweaks
C3PAO certification returns largely as designed, with adjustments to cost, phasing, or scope. If you kept building 800-171, you're ready. Most likely to affect timing, not substance.
▸ Major overhaul
The verification model changes meaningfully — e.g., more reliance on self-assessment, tiered requirements by contract sensitivity, or a longer runway for small business. The underlying 800-171 controls almost certainly stay; how they're verified is what shifts.
▸ Return roughly as-is
The review reaffirms the program with minimal change and sets a new start date. Everyone who treated the pause as a reason to keep working is fine; everyone who stopped is behind.
Notice the common thread across all three: NIST 800-171 survives every scenario. The debate is about how you prove it, not whether you do it. That's why the honest move is to keep building the standard now, regardless of outcome.
What to do while you wait
- Keep your self-assessment current. It's required today, and it's the foundation every outcome builds on. See the small-business roadmap.
- Post an honest SPRS score. Know where you stand — the free estimator gives you a baseline in two minutes.
- Don't rush a C3PAO audit. It can't be required right now; spending on a formal cert audit is premature for most.
- Don't stop the security work. The contractors who keep going will be ahead the day a revised rule lands.
Stay ahead of the review — for free
Two ways to be ready whatever the outcome: see exactly where you stand against the 110 controls, or follow the honest small-business roadmap.