DoD has paused CMMC Phase 2, but the DoD CMMC rules already in contracts still apply. Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) programme was due to start on November 10, 2026. From that date, DoD planned to require a third-party CMMC Level 2 assessment as a condition of award on many contracts involving Controlled Unclassified Information (CUI). On July 13, 2026, the Department suspended Phase 2 and opened a 60-day review of the programme. As of late September 2026, DoD has not announced a new start date.
For small defense suppliers in Southern California, this is a pause, not a repeal. Most of your existing cybersecurity obligations are still in force, and primes are still asking about them.
What is paused in CMMC Phase 2
- New solicitations requiring a third-party CMMC Level 2 certification from a C3PAO
- New requirements for CMMC Level 3 assessments by DIBCAC
- The November 10, 2026 Phase 2 start date
What still applies while CMMC Phase 2 is paused
- DFARS 252.204-7012. If you handle CUI, you must still safeguard it and report cyber incidents to DoD within 72 hours.
- NIST SP 800-171. The 110 security requirements are still the standard for protecting CUI.
- SPRS. You still need a current NIST 800-171 self-assessment score in the Supplier Performance Risk System, and CMMC self-assessments require annual affirmations.
- CMMC Level 1 and Level 2 self-assessments. Contracts can still call for these under Phase 1, which began on November 10, 2025.
- Prime flowdowns. Primes can set their own cybersecurity requirements for subcontractors, whatever DoD’s timeline.
What to do now
In the meantime, keep going with your NIST 800-171 work. It typically takes 12 to 18 months to be ready for an assessment, and a firm that stops now risks being unready when the requirement returns. Make sure your System Security Plan and Plan of Action and Milestones are current, your SPRS score is accurate, and you can answer a prime’s cybersecurity questionnaire without delay.
GERC helps small defense suppliers with NIST 800-171, SPRS and CMMC readiness, SAM.gov registration and defense contracting across Southern California.
Need help? Call (909) 454-7076 or book a consultation.
Related services
- Teaming partners for prime contractors
- Benefit-cost analysis for grants
- BUILD (RAISE), INFRA and Mega grants
- Socioeconomic analysis for CEQA and NEPA
Ready to win government work?
GERC helps small businesses and nonprofits nationwide get registered, get certified and win contracts and grants. Tell us where you stand and we will map out your next steps, with no obligation.
Prefer to talk now? Call (909) 454-7076 or email info@gercconsulting.com.

