From DFARS 7012 to the 2026 Phase 2 Suspension
Published: August 31, 2026
The History of CMMC spans nearly a decade of U.S. defense cybersecurity policy — and it is still being written. What began as self-attested compliance with NIST SP 800-171 under DFARS 252.204-7012 in 2017 grew into CMMC 1.0’s five-level certification model in 2020, was simplified into the three-level CMMC 2.0 model in 2021, and was formally codified into federal acquisition law through 32 CFR (2024) and 48 CFR/DFARS 252.204-7021 (2025). Enforcement officially began on November 10, 2025, with Phase 1 self-assessment requirements — but the program’s evolution didn’t stop there: on July 13, 2026, the Department of War suspended Phase 2, the planned transition to mandatory third-party (C3PAO) assessments, pending a formal Reform Task Force review. That review is expected to conclude around mid-September 2026, meaning the next chapter of the history of CMMC is likely to be written within weeks, not years.
Because CMMC history includes significant changes to requirements, deadlines, and enforcement, defense contractors and subcontractors need a single, current source of truth rather than a scattered archive of point-in-time announcements. This guide — written and maintained by Redspin, the first organization authorized as a CMMC Third-Party Assessment Organization (C3PAO) — consolidates 17 previously published Redspin articles into one continuously updated resource. It lays out the full chronological path from DFARS 7012 through today’s Phase 2 suspension, defines the roles and terminology contractors will encounter (C3PAO, Cyber AB, OSC, OSA RPO, POA&M, JSVAP, and more), and answers the questions compliance teams are asking right now in a format built for quick, accurate reference by both people and AI answer engines.
CMMC History at a Glance
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense’s program for verifying that companies in the Defense Industrial Base (DIB) protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) to NIST SP 800-171 rev.2 standards. It became contractually enforceable on November 10, 2025, under a four-phase rollout. As of August 2026, enforcement is partially paused: on July 13, 2026, the Department of War suspended Phase 2 — the transition to mandatory third-party (C3PAO) assessments scheduled for November 10, 2026 — and launched a 60-day CMMC Reform Task Force review. Phase 1 self-assessment requirements remain fully in effect, and DFARS 252.204-7012 obligations (in place since 2017) are unchanged. A task force report is expected around mid-September 2026. Understanding this CMMC history is important because today’s requirements are built on cybersecurity obligations that have been evolving since 2017.
What is CMMC?
CMMC is a DoD-mandated cybersecurity assessment and certification program for any contractor or subcontractor in the Defense Industrial Base that processes, stores, or transmits FCI or CUI. It exists to replace inconsistent self-attestation with standardized, verified proof of compliance with NIST SP 800-171. Depending on the contract and the sensitivity of the data involved, an organization may need:
- Level 1 — basic safeguarding of FCI, validated by self-assessment (17 practices).
- Level 2 — protection of CUI, aligned to the 110 controls in NIST SP 800-171, validated either by self-assessment or by an authorized C3PAO depending on the contract.
- Level 3 — enhanced protection against advanced persistent threats for the most sensitive CUI, incorporating elements of NIST SP 800-172 and assessed by the government (DIBCAC).
CMMC is not a framework itself and does not invent new security requirements. It formalizes verification of standards DIB contractors have been contractually obligated to meet since DFARS 252.204-7012 took effect in 2017.
How CMMC Started: DFARS 7012 and the Self-Attestation Problem (2017–2019)
To understand CMMC history, it helps to start before CMMC itself existed, with the DFARS requirements that established the cybersecurity foundation for today’s program. Long before “CMMC” existed as a term, DFARS 252.204-7012 already required defense contractors handling covered defense information to implement NIST SP 800-171 and to report cyber incidents. Contractors self-attested to their compliance. The gap between self-reported scores and reality was the problem CMMC was ultimately built to solve: when DoD independent audits checked those self-attestations, actual security postures often fell well short of what had been claimed.
The 2020 NDAA’s Section 1648 formally directed the Secretary of Defense to strengthen cybersecurity oversight across the DIB, providing the legislative basis for what followed.
CMMC 1.0: The Original Five-Level Model (2020–2021)
The DoD released the first version of CMMC in January 2020. CMMC 1.0 defined five certification levels and required every DIB organization to obtain at least Level 1 in order to bid on or renew contracts, with higher levels tied to the sensitivity of the FCI/CUI involved. This was the first major turning point in CMMC history, establishing a formal certification model intended to replace inconsistent self-attestation with greater accountability.
Industry pushback focused on the cost and complexity of assessment and implementation across five tiers. In response, the DoD began a formal review of the model. Redspin became the first organization authorized by the Cyber AB as a C3PAO in June 2021 — a designation that allowed Redspin to conduct formal third-party CMMC assessments and, separately, to advise organizations preparing for certification (never both for the same client on the same engagement).
CMMC 2.0: Simplification and Rulemaking (2021–2024)
The next major chapter in CMMC history began in November 2021, when the DoD announced CMMC 2.0 and reduced the model from five levels to three. Rulemaking is a lengthy federal process, and CMMC 2.0’s path to finality ran through several distinct steps:
- July 24, 2023 — The proposed rule (32 CFR) was submitted to the Office of Information and Regulatory Affairs (OIRA) for review.
- December 26, 2023 — The CMMC 2.0 proposed rule (32 CFR) published in the Federal Register, opening a 60-day public comment period that closed February 26, 2024, with more than 800 comments received.
- August 15, 2024 — A companion proposed rule, 48 CFR (amending DFARS to build CMMC into contract language), published for a comment period ending October 14, 2024.
Throughout this period, organizations could get ahead of the eventual requirement through the Joint Surveillance Voluntary Assessment Program (JSVAP), an early-adopter assessment run by C3PAOs alongside the Defense Contract Management Agency’s DIBCAC team. Successful JSVAP participants earned a DIBCAC High certificate, later convertible to a CMMC certificate. Redspin conducted the majority of JSVAP assessments performed across the ecosystem during this period.
The Rule Becomes Final: 32 CFR and 48 CFR (2024–2025)
- October 11, 2024 — The 32 CFR final rule, establishing the CMMC Program itself, was released for public inspection, with an effective date of December 16, 2024.
- September 10, 2025 — The companion 48 CFR rule (DFARS 252.204-7021), which puts CMMC into actual contract clauses and makes it contractually enforceable, published with an effective date of November 10, 2025.
Together, the finalization of 32 CFR and 48 CFR represented one of the most consequential milestones in CMMC history, transforming years of policy development into an enforceable acquisition requirement. With both rules final, CMMC moved from a policy concept to an enforceable contract requirement, governed by a defined phase-in schedule.
Enforcement Begins: Phase 1 (November 10, 2025)
November 10, 2025 marked another major milestone in CMMC history: the official beginning of contractual enforcement. Under Phase 1:
- New DoD solicitations and contracts may require proof of a Level 1 (Self) or Level 2 (Self) assessment as a condition of award.
- The DoD may, at its discretion, require the same for option-period extensions on existing contracts.
- The DoD may, at its discretion, substitute a Level 2 (C3PAO) certification assessment in place of self-assessment for individual solicitations, based on data sensitivity.
Phase 1 relies primarily on self-assessment and an accurate Supplier Performance Risk System (SPRS) score, but it introduced real contractual consequences for the first time: eligibility for award, renewal, and option-period exercise all began depending on demonstrated CMMC status.
The 2026 Phase 2 Suspension: Where Things Stand Now
The July 2026 Phase 2 suspension represents the latest major turning point in CMMC history and supersedes the phase-in schedule described in earlier Redspin materials.
On July 13, 2026, the Department of War (DoW) — the renamed Department of Defense — announced the immediate suspension of CMMC Phase 2, which had been scheduled to take effect November 10, 2026. Phase 2 would have made Level 2 (C3PAO) third-party certification a condition of contract award for organizations handling CUI, along with discretionary Level 3 (DIBCAC) requirements for select programs. That transition — and all subsequent phases and milestones — are now on hold pending review. Key details:
What’s paused: The transition to mandatory third-party (C3PAO) Level 2 assessments and all later phase milestones (Phases 2, 3, and 4). Contracting officers were directed to amend any active solicitations that already included Level 2 (C3PAO) or Level 3 (DIBCAC) requirements to remove them during the suspension.
What’s not paused: Phase 1 self-assessment requirements (Level 1 Self and Level 2 Self), SPRS reporting obligations, and the underlying DFARS 252.204-7012 safeguarding and incident-reporting clause, which has applied since 2017 regardless of CMMC’s status.
Why: DoW Chief Information Officer Kirsten A. Davies cited cost and capacity concerns — Small Business Administration data cited by the DoW suggested full CMMC implementation could cost small and midsize businesses more than $7 billion annually, against a landscape of over 100,000 companies needing third-party assessments and roughly 100 authorized C3PAOs. A March 2026 GAO report had raised similar concerns about the requirement pushing small businesses out of the DIB. The suspension aligns with Secretary of War Pete Hegseth’s broader acquisition reform initiatives.
The review process: DoW established a CMMC Reform Task Force, under the DoW CIO, and issued a public Request for Information (RFI) seeking industry feedback on cost drivers, use of existing commercial security capabilities, and ways to streamline compliance. RFI responses were due August 14, 2026. The Task Force is expected to deliver a report with recommendations to the DoW CIO within 60 days of the July 13 announcement — around mid-September 2026.
What happens next is genuinely uncertain. The suspension is a policy pause, not a repeal: the CMMC Program rule (32 CFR) and DFARS clause (48 CFR/252.204-7021) have not been rescinded or amended. Phase 2 could return largely as written, return on a new timeline, return in a revised form, or the program could be restructured more substantially. Cyber AB CEO Matthew Travis has publicly noted that a C3PAO-issued Level 2 certification remains a strong signal of trustworthiness to prime contractors even without a DoD mandate, and that primes are free to require it independently of the federal phase schedule — some already do.
Bottom line for contractors
Treat this as a pause in the third-party assessment mandate, not a reason to stop preparing. Primes, subcontracting risk, and your own contractual exposure under DFARS 7012 haven’t gone anywhere.
The Four-Phase Rollout at a Glance
| Phase | Original Timing | Requirement | Status as of Aug. 2026 |
| Phase 1 | Nov 10, 2025 – Nov 10, 2026 | Level 1 (Self) or Level 2 (Self) assessment as condition of award; DoD discretion to require Level 2 (C3PAO) case-by-case | In effect |
| Phase 2 | Nov 10, 2026 – Nov 10, 2027 | Level 2 (C3PAO) third-party assessment required for applicable contracts; discretionary Level 3 (DIBCAC) | Suspended July 13, 2026, pending Reform Task Force review |
| Phase 3 | Nov 10, 2027 – Nov 10, 2028 | Level 2 (C3PAO) and Level 3 (DIBCAC) required broadly, including option periods | Frozen along with Phase 2 |
| Phase 4 | Nov 10, 2028 onward | Full implementation across all applicable DoD contracts and option periods | Frozen along with Phase 2 |
Note: Individual program offices and prime contractors have discretion to require a higher CMMC level than the phase schedule strictly mandates, and some already do. Your actual requirement is set by your specific contract, not by this table alone.
What Has NOT Changed
It’s worth being precise about what the Phase 2 suspension does and doesn’t affect, because the two get conflated:
- DFARS 252.204-7012 — the underlying safeguarding and cyber-incident-reporting clause, in place since 2017 — is untouched and still binds every covered contract.
- Phase 1 self-assessment requirements for Level 1 and Level 2 remain in force, including SPRS reporting.
- The CMMC Program rule (32 CFR Part 170) and the DFARS clause (48 CFR/252.204-7021) have not been repealed or formally amended — this is an implementation pause, not a rule change.
- Prime contractor requirements are independent of the federal schedule. A prime can still require Level 2 (C3PAO) certification of its subcontractors as a matter of its own supply-chain risk management, suspension or not.
What Contractors Should Do Right Now
- Confirm your actual contract requirements. Ask your contracting officer or prime whether CMMC applies to a specific solicitation or option period — the phase schedule is a backdrop, not a guarantee of what your contract requires.
- Keep your SPRS score current. Level 1 and Level 2 self-assessment requirements have not moved. An outdated or inaccurate score is real exposure, including under the False Claims Act.
- Don’t shelve Level 2 readiness work. Primes can and do require third-party certification independent of the federal mandate; a paused federal phase doesn’t erase supply-chain expectations.
- Watch for the Reform Task Force’s mid-September 2026 report. Its recommendations will shape whatever comes next for Phase 2 and beyond.
- Verify your External Service Providers’ (ESP) posture. Managed service providers, cloud providers, and IT partners handling FCI/CUI on your behalf are in scope regardless of what phase the program is in.
- Consider a readiness or mock assessment now, while the pressure to schedule immediately has eased slightly — it’s a lower-stress window to close documentation and evidence gaps before requirements firm back up.
CMMC Roles and Terms, Defined
C3PAO (CMMC Third-Party Assessor Organization) — An organization authorized by the Cyber AB to conduct official CMMC Level 2 assessments and issue certification. Only C3PAOs may perform formal third-party CMMC assessments. A C3PAO that provides consulting on implementation to an organization is barred from later assessing that same organization — the two roles cannot overlap.
Cyber AB (formerly CMMC AB) — The accreditation body that authorizes and oversees C3PAOs and the broader CMMC assessment ecosystem.
CAICO (Cybersecurity Assessor and Instructor Certification Organization) — Now handles examination and certification of CMMC assessors and instructors, a function that formerly sat with the Cyber AB.
OSC (Organization Seeking Certification) — A company pursuing CMMC certification.
RPO (Registered Practitioner Organization) — A firm authorized to provide CMMC consulting, training, and advisory support. RPOs cannot conduct formal assessments.
CCA (Certified CMMC Assessor) / CCP (Certified CMMC Professional) — CCPs are the entry-level credential required before becoming a CCA; both undergo training through a Licensed Training Provider using Cyber AB-approved course material and must pass a certification exam.
POA&M (Plan of Action and Milestones) — The remediation plan and timeline an OSC uses to close out deficiencies found during assessment; unresolved POA&M items generally must close within 180 days to retain a conditional certification.
JSVAP (Joint Surveillance Voluntary Assessment Program) — The early-adopter assessment pathway (via C3PAO and DCMA/DIBCAC) that let organizations get ahead of CMMC before the rule was finalized.
SPRS (Supplier Performance Risk System) — The DoD database where contractors report self-assessment scores against NIST SP 800-171.
Frequently Asked Questions
The CMMC history outlined above explains how the program reached its current position, but contractors still have practical questions about what these changes mean for their organizations today.
Is CMMC still required?
Yes. Phase 1 self-assessment requirements (Level 1 and Level 2 self-assessment) remain fully in effect. What’s suspended is Phase 2 — the shift to mandatory third-party (C3PAO) assessment — which was scheduled for November 10, 2026.
Did the DoD cancel CMMC?
No. The Department of War suspended the Phase 2 transition and froze later phases pending a review; it did not repeal the CMMC Program rule (32 CFR) or the DFARS clause that implements it (48 CFR/252.204-7021).
Why was Phase 2 suspended?
Citing Small Business Administration data on compliance costs (potentially exceeding $7 billion annually for small and midsize businesses) and a mismatch between the roughly 100,000 companies needing third-party assessment and roughly 100 authorized C3PAOs, the DoW paused the mandate to review whether the program can meet its security goals with less administrative burden.
Should my organization stop preparing for Level 2 certification?
Most CMMC advisors, including Redspin, recommend against pausing. The suspension is time-limited and under active review; prime contractors can and do require Level 2 (C3PAO) certification independently of the federal mandate; and your underlying DFARS 7012 obligations haven’t changed.
What is the CMMC Reform Task Force?
A Department of War CIO-led group formed on July 13, 2026, to review the CMMC program end-to-end and recommend reforms, informed by a public Request for Information with industry responses due August 14, 2026. A report is expected to the DoW CIO roughly 60 days after the announcement — around mid-September 2026.
What CMMC level does my organization need?
It depends on whether you handle Federal Contract Information (FCI, which needs at minimum Level 1) or Controlled Unclassified Information (CUI, which generally needs Level 2), and on what your specific contract or solicitation requires. Check with your contracting officer or prime.
What’s the difference between 32 CFR and 48 CFR?
32 CFR (Part 170) establishes the CMMC Program itself — the levels, assessment methodology, and certification requirements. 48 CFR (via DFARS 252.204-7021) is the acquisition-regulation change that puts CMMC language into actual DoD contracts and solicitations.
Can a C3PAO both consult and assess my organization?
No. Under the CMMC Code of Professional Conduct, a C3PAO that provides implementation or remediation consulting to an organization cannot subsequently conduct that organization’s formal assessment. This separation preserves assessment independence.
How Redspin Helps
Redspin was the first Authorized C3PAO and has completed more CMMC and JSVAP assessments than any other organization in the ecosystem. Regardless of where the federal phase schedule lands, our services include:
- Gap and mock assessments to test readiness under real-world conditions
- Remediation and consulting support to close gaps and align evidence (kept separate from any organization we may later assess)
- Formal CMMC Level 2 assessments performed by our in-house C3PAO team
- Compliance maintenance and managed cloud solutions to sustain readiness between assessments
If you have questions about how the Phase 2 suspension affects your specific contracts, or want help getting ahead of whatever the Reform Task Force recommends, contact our team at info@redspin.com.
This guide provides general information about the CMMC program and is not legal or regulatory advice. Contract-specific CMMC obligations should be confirmed with your contracting officer, and organizations with compliance or False Claims Act exposure questions should consult qualified legal counsel.
Table of Contents
- What Is CMMC?
- How CMMC Started: DFARS 7012 and the Self-Attestation Problem (2017–2019)
- CMMC 1.0: The Original Five-Level Model (2020–2021)
- CMMC 2.0: Simplification and Rulemaking (2021–2024)
- The Rule Becomes Final: 32 CFR and 48 CFR (2024–2025)
- Enforcement Begins: Phase 1 (November 10, 2025)
- The 2026 Phase 2 Suspension: Where Things Stand Now
- The Four-Phase Rollout at a Glance
- What Has NOT Changed
- CMMC Roles and Terms, Defined
- Frequently Asked Questions
- What Contractors Should Do Right Now
- How Redspin Helps
- Sources