60 Days to Act: CMMC 2.0 Timeline for DoD Contractors

Hands arranging CMMC timeline milestone cards

The CMMC 2.0 timeline hit a wall on July 13, 2026, when the Department of War suspended CMMC Phase II third-party assessment requirements. Phase I self-assessment obligations stay in effect. So does everything under NIST SP 800-171 and DFARS 252.204-7012. Treat this pause as a preparation window, not a break.


TL;DR:

  • Contractors must still comply with NIST SP 800-171 controls and report cyber incidents, despite the suspension of third-party assessments.
  • Level 1 and Level 2 self-assessments remain in effect, with certification validity and POA&M requirements unchanged during the pause.
  • The upcoming mid-September review will be a critical decision point, but it does not guarantee a resumption of Phase II assessments.
  • Contractors should prioritize fixing SPRS scores, documenting controls, and reassessing vendor contracts instead of spending on third-party assessments.
  • Active solicitations should be monitored for assessment requirement changes, and preparing evidence now can reduce future costs if assessments resume.

Table of Contents

Where the CMMC 2.0 Timeline Stands Right Now

Let’s walk through how we got here, because the dates matter for anyone trying to plan budgets, staffing, or contract bids.

The final CMMC 2.0 rule became effective on December 16, 2024. Phase I kicked off on November 10, 2025, requiring self-assessments for applicable contracts. Phase II, which would have layered in mandatory third-party assessments through Certified Third-Party Assessment Organizations, was originally targeted for November 10, 2026.

That target no longer holds. On July 13, 2026, the DoD press release announcing the suspension pulled Phase II off the calendar with immediate effect, launching a 60-day Reform Task Force review.

Here’s the sequence worth keeping on your desk:

  • December 16, 2024: Final CMMC 2.0 rule takes effect
  • November 10, 2025: Phase I self-assessment requirements begin
  • November 10, 2026: Original target date for Phase II third-party assessments (now suspended)
  • July 13, 2026: DoD suspends Phase II requirements, launches 60-day review
  • Mid-September 2026: Expected window for the Reform Task Force’s report

That mid-September window is the next real checkpoint. Nothing in the announcement guarantees a specific outcome, but it does guarantee a decision point. Contractors who treat the next eight weeks as dead time are making a mistake.

What Compliance Obligations Remain Active During the Pause?

Nothing about the suspension touches your underlying legal obligations. DFARS clause 252.204-7012, Acquisition, still requires contractors handling Covered Defense Information to implement NIST SP 800-171 controls and report cyber incidents within 72 hours of discovery. That clause was never contingent on CMMC’s third-party assessment machinery.

Here’s what stays on the books:

  • Level 1 covers 15 FAR-based controls, requiring an annual self-assessment
  • Level 2 maps to 110 NIST SP 800-171 controls, requiring self-assessment every three years plus an annual affirmation in between
  • CMMC status certifications remain valid for three years once issued
  • POA&M items must still follow DoD-approved timelines, and unresolved high-weight controls can block a passing score

Level 2 requires mapping to 110 distinct NIST SP 800-171 controls across 14 control families, and every one of them still applies regardless of what happens with third-party assessors.

Skadden’s analysis of the suspension makes a point contractors shouldn’t skip past: the pause is administrative, not legal. Posting inaccurate scores to the Supplier Performance Risk System (SPRS) still exposes a contractor to False Claims Act liability. A paused program doesn’t pause a federal fraud statute.

What Compliance Obligations Remain Active During the Pause? — overview diagram

Your CMMC Compliance Deadline Checklist: 6 Priorities for This Window

Here’s what deserves attention now, in rough priority order.

  1. Correct your SPRS score first. If your posted score doesn’t match your actual environment, fix it before anything else. This is the single highest legal-risk item on the list.
  2. Update your SSP and POA&M with evidence. Every control claim needs a documented artifact behind it, not just a checkbox.
  3. Run an internal gap assessment against NIST SP 800-171 Rev 2. Triage findings into critical, high, and medium buckets, then assign 30/60/90-day owners.
  4. Reassess assessor and vendor contracts. If you had a C3PAO engagement scheduled, decide whether to hold, renegotiate, or reallocate that budget toward remediation instead.
  5. Loop in your primes and subcontractors. If you’re a sub, your prime’s contract language may shift; if you’re a prime, your subs need to hear about changes as soon as you do.
  6. Watch active solicitations for amended language. Requirements referencing Level 2 (C3PAO) or Level 3 (DIBCAC) assessments are being stripped out in real time.

An enterprise cybersecurity checklist covering foundational controls can help structure the gap assessment step if you don’t already have an internal framework.

Pro Tip: Lock in SSP updates with artifact links as you go, not at the end. If Phase II resumes in any form, an assessor’s job gets faster and cheaper when your evidence trail is already built, and that shows up directly in your assessment cost.

How Long Does CMMC Readiness Actually Take?

Ranges vary widely depending on where you’re starting, but industry benchmarks give a useful frame.

  • Level 1 readiness: typically 30 to 90 days for organizations with modest FCI exposure
  • Level 2 readiness: often 8 to 18 months, depending on SSP maturity and remediation backlog
  • Contractor size, subcontractor dependencies, and staffing all shift these numbers in either direction
  • Assessor scarcity has been part of the reason DoD paused Phase II in the first place, and that scarcity won’t disappear overnight

Managed remediation sprints tend to compress the Level 2 range meaningfully, mainly by parallelizing documentation work that internal teams usually do sequentially.

What Contractors Should Watch in Solicitations and Contracts

Program managers have been directed to stop requiring Level 2 (C3PAO) or Level 3 (DIBCAC) assessments in active and upcoming solicitations. Only Level 1 or Level 2 self-assessment language should appear going forward, until the review concludes.

Practical watch points:

  • Review option-year exercises on existing contracts for outdated assessment clauses
  • Flag RFP amendments that still reference third-party CMMC requirements as likely errors worth raising with the contracting officer
  • Document your current compliance posture in proposals anyway. If Phase II requirements return in some form, you want a paper trail showing continuous readiness, not a scramble.

What Might the CMMC Reform Task Force Recommend?

Three outcomes seem plausible from the 60-day review: a scaled-back Phase II with fewer mandatory third-party assessments, a delayed resumption date, or structural changes to how assessments get scheduled and priced. Insider reporting points to a mid-September 2026 deliverable as the next real signal.

Until that report lands, hold off on major third-party assessment spending. Put the budget toward remediation and documentation instead. Whatever the task force recommends, better SSP evidence and cleaner SPRS data help under every scenario, so that spending is never stranded.

A Contractor’s Take on the CMMC 2.0 Suspension

A Contractor's Take on the CMMC 2.0 Suspension — overview diagram

The suspension is a gift if you use it right and a trap if you don’t. Contractors who read “suspended” as “optional” are the ones who’ll get caught flat when the task force reports back. The smarter move is treating this as free runway: fix your SPRS data, harden your SSP, and knock out remediation in sprints while nobody’s assessor clock is ticking.

Managed support earns its cost when internal teams are stretched thin, when you need documentation fast for an upcoming award, or when compressing an 18-month timeline into something workable actually changes your competitive position. If any of that sounds familiar, a short readiness conversation is worth more than another month of guessing.

— Alden

Get a CMMC Readiness Review From Total Cyber

Total Cyber is a veteran-owned firm built for exactly this moment: a compliance pause that rewards contractors who keep working and punishes the ones who coast. We handle managed cybersecurity services, compliance consulting, SSP and POA&M development, and SPRS accuracy reviews, all aimed at closing gaps before the next milestone hits.

Total Cyber

If your internal team is stretched thin or you need documented evidence fast for an upcoming award, that’s exactly where a managed partner compresses the timeline instead of just tracking it. We also run cyber awareness training to shore up the human-side controls NIST SP 800-171 requires, since technical fixes alone rarely close a gap assessment.

The next step is simple: book a 30-minute readiness review through our discovery-call form, and we’ll walk through where your SSP, POA&M, and SPRS data actually stand today.

Sources

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Share this post!

Learn How We Can Secure Your Business