You get a single team handling cybersecurity, IT, AI consulting, and data integration services like EDI, filling the gaps in your team.
“Corsica is a one-stop shop for us. If I have a problem, I can go to my vCIO or a number of people, and you take care of it. That’s an investment in mutual success.”
– Greg Sopcak | Southern Michigan Bank & Trust
From 24/7 SOC services to MDR/SIEM, penetration testing and training, we’ve got you covered.
Get the expert support you need for your network, on-premises devices, VoiP, M365, Google Workplace, and everything in between.
Full support of compliance frameworks, including CJIS, HIPAA, CMMC, NIST, SOC 2, and more
Cut through the hype with smart strategies and right-fit AI solutions for your organization.
Take strategic steps with confidence as you collaborate with our expert business and vCIO consultants.
Get cloud security, integration, server virtualization, and optimization strategies to reduce your cloud costs.
Connect any data source to any other with robust solutions and managed services.
Stay ahead of the curve, eliminate waste, and grow revenue with next-generation technologies.
Expert consulting, implementation, integration, managed services, and cybersecurity for Microsoft products.
One program. One partner. Complete AI transformation.
It takes dedicated experience to use technology strategically in your industry. That’s why we specialize in certain verticals while offering comprehensive technology services.
From webinars and video tutorials to guides and blogs, we’ve got resources to help you and your team address any technology challenge.
On July 13, 2026, the Department of Defense announced the immediate suspension of CMMC Compliance Phase 2, which would have gone into effect November 10, 2026, affecting Level 2 compliance. This suspension also included all pending and future CMMC implementation milestones.
The Department of Defense is expected to announce the findings of a task force that was set to review the requirement. That announcement should come in mid-September 2026.
In the meantime, where do things stand?
Should defense contractors continue to pursue compliance with their Level 2 requirements? (Yes, absolutely, whether doing it in-house or working with a CMMC compliance consultancy. More on this below.)
Here’s everything you need to know.
Key takeaways:
CMMC Level 2 compliance requires the implementation of all 110 security controls from NIST SP 800-171 Rev. 2, organized across 14 control families and separated into 320 assessment objectives. (Note that while Rev. 2 has been superseded by Rev. 3 for NIST’s official standards, CMMC compliance is still based on Rev. 2.) These requirements apply to defense contractors and subcontractors that handle Controlled Unclassified Information (CUI).
Compliance must be documented in a System Security Plan (SSP), scored in SPRS, and verified either by self-assessment or by a C3PAO third-party assessment depending on the contract. Currently, during the Department of Defense’s Phase 2 review pause that went into effect July 2026, new solicitations designate self-assessment only.
A minimum score of 80% with a POA&M can earn conditional status, but higher-weighted controls must be fully implemented and POA&M items closed out within 180 days.
Control Family | Requirements | Focus |
Access Control (AC) | 22 | Limit system access to authorized users and functions |
Awareness & Training (AT) | 3 | Security awareness and role-based training |
Audit & Accountability (AU) | 9 | Logging, log review, and audit records |
Configuration Management (CM) | 9 | Baseline configurations and change control |
Identification & Authentication (IA) | 11 | User identity, MFA, password requirements |
Incident Response (IR) | 3 | Detect, report, and respond to incidents |
Maintenance (MA) | 6 | Controlled and monitored system maintenance |
Media Protection (MP) | 9 | Protect, sanitize, and control media with CUI |
Personnel Security (PS) | 2 | Screening and access removal on termination |
Physical Protection (PE) | 6 | Limit physical access to systems and facilities |
Risk Assessment (RA) | 3 | Risk assessments and vulnerability scanning |
Security Assessment (CA) | 4 | SSP, control assessments, remediation plans |
System & Communications Protection (SC) | 16 | Network boundaries, encryption, CUI in transit |
System & Information Integrity (SI) | 7 | Flaw remediation, malware protection, monitoring |
There are 110 controls and 320 assessment objectives in total, plus the supporting artifacts that assessors expect. Companies must produce an SSP, POA&M, SPRS score submission, and evidence for each objective.
This is a common point of confusion. NIST has updated their standard to Rev. 3, yet CMMC compliance is still based on Rev. 2. Therefore, defense contractors should build their compliance program around Rev. 2, not Rev. 3. In fact, building it around Rev. 3 is a common and expensive mistake.
CMMC Level 2 applies to Department of Defense contractors and subcontractors whose systems process, store, or transmit Controlled Unclassified Information (CUI). This includes manufacturers, engineering firms, IT service providers, and other suppliers throughout the defense industrial base (DIB), not just prime contractors.
The DoD estimates that these organizations make up over a third of the DIB, making Level 2 the most common CMMC requirement. Whether a given company needs it is determined by its specific contracts. The requirement appears in individual solicitations, awards, and option periods rather than applying as a blanket mandate, and prime contractors often flow the requirement down to subcontractors, sometimes ahead of DoD-wide milestones. Notably, external service providers such as MSPs and MSSPs that handle CUI on behalf of defense contractors can also fall within assessment scope.
There is no single universal deadline. CMMC Level 2 requirements attach to individual contracts as they appear in solicitations, awards, and option periods, following a phased rollout that began November 10, 2025. Since that date, applicable new contracts have required Level 1 or Level 2 self-assessments at time of award, and those Phase 1 requirements remain in force today.
The major upcoming milestone is Phase 2, which would have made third-party (C3PAO) certification a condition of award for most CUI-handling contracts starting November 10, 2026. However, this milestone was administratively paused on July 13, 2026, when the DoD launched a 60-day reform task force review. Further guidance is expected around mid-September 2026.
The pause is administrative, not a rule change: 32 CFR Part 170 and the DFARS rule remain unamended, and the underlying NIST 800-171 obligations still apply. Also note that prime contractors can flow requirements down to subcontractors ahead of these DoD-wide dates.
Phase | Original Start Date | Requirement | Current Status |
Phase 1 | Nov 10, 2025 | Level 1 or Level 2 self-assessments required in applicable new contracts | Active — still mandatory |
Phase 2 | Nov 10, 2026 | Level 2 C3PAO certification as condition of award for applicable CUI contracts | Suspended (July 13, 2026) pending DoD review |
Phase 3 | Nov 10, 2027 | C3PAO certification required for all applicable contracts; Level 3 (DIBCAC) assessments roll out | On hold pending review |
Phase 4 | Nov 10, 2028 | Full implementation — CMMC in all applicable DoD contracts | On hold pending review |
Yes, as of this writing, the suspension remains in effect, though it’s narrower than the phrase “CMMC Level 2 is suspended” might imply. On July 13, 2026, the DoD announced the immediate suspension of Phase 2, which would have made third-party C3PAO certification a condition of contract award starting November 10, 2026. This suspension also included all pending and future CMMC implementation milestones. Concurrently with the suspension, the DoD launched a Reform Task Force conducting a 60-day review, with its report expected in mid-September.
What’s paused is the third-party assessment expansion. New Level 2 (C3PAO) and Level 3 designations are suspended, and existing contracts containing those requirements are being amended to remove them by modification.
What is not suspended is significant:
These and the underlying NIST SP 800-171 Rev. 2 requirements all remain fully in force, and contracting officers are still forbidden to award a contract without current CMMC status in SPRS.
The rules themselves (32 CFR Part 170 and DFARS) remain unamended. This is an administrative pause pending the review’s outcome.
In the meantime, there’s one notable shift. With the third-party assessor removed, legal weight has moved onto contractors’ own self-attestations, which are the express target of DOJ’s Civil Cyber-Fraud Initiative. Therefore, “suspended” emphatically does not mean compliance is optional. Expect this answer to change when the task force releases its report.
No one knows yet, but the answer is most likely yes, and it should arrive soon. The CMMC Reform Task Force is due to deliver its recommendations to the DoD CIO on or about September 13, 2026, and the outcome could range from a narrowly restructured Phase 2 to a wholesale redesign. DoD officials have declined to rule out ending the program entirely.
That said, the signals lean toward reinstatement in some modified form rather than elimination. Communications from the DoD and prime contractors indicate that the assessment transition is expected to return, though possibly different from what the current rules codified. The task force’s mandate is to recommend a framework that lowers barriers for small and mid-sized businesses and replaces “prohibitive third-party compliance models with scalable, realistic security measures.” We can interpret this as reform language, not repeal language.
Two structural points reinforce this interpretation:
Worth noting for planning purposes: even after the report lands mid-September, formal determinations may not come until mid-October at the earliest, and possibly not until late 2026 or early 2027.
Absolutely. It’s critical to understand that “suspended” overstates the situation. The only thing on hold is the third-party (C3PAO) certification mandate. The substantive compliance obligation never went away. Contractors handling CUI remain contractually bound by DFARS 252.204-7012 to implement all 110 NIST SP 800-171 Rev. 2 controls. They still must submit current SPRS scores and annual affirmations to remain award-eligible.
Contractors also remain subject to government audits, with self-attestations now carrying more legal weight, not less, since inaccurate scores are the express target of DOJ’s Civil Cyber-Fraud Initiative and False Claims Act enforcement.
Meanwhile, prime contractors can still flow requirements down regardless of the DoD-wide pause, and voluntary C3PAO assessments remain available for those wanting a competitive differentiator. Likewise, the reform review is widely expected to return third-party assessment in some form, meaning contractors who pause remediation now risk falling behind when the new timeline emerges. Those who maintain momentum are positioned for award eligibility today and certification later.
CMMC consultancies typically offer practical guidance here: separate certification-specific spend, which can reasonably wait for the task force outcome, from control-implementation spend—which should continue without interruption. Contractors must complete the security work either way.
Defense contractors must not fall behind in their CMMC compliance efforts. DoD hitting pause on Phase 2 is a welcome breather, giving companies time to work on compliance, rather than a lifting of the requirements. If you need help with CMMC compliance, get in touch with us. We maintain deep expertise in this regulatory framework, and we’ve helped many defense contractors on their journey. Contact us, and let’s take the next step in CMMC compliance today.
Contact us today to get the outside perspective you need for the next step on your journey.
We’ll respond within 1 business day, or you can grab time on our calendar.