July 13, 2026: CMMC Phase II suspended pending a 60-day DoW review — NIST SP 800-171 and DFARS obligations still stand. Book a readiness call

For DoW subcontractors handling CUI — Level 2 is our specialty

CMMC Level 2:
Rapid Deployment.

On July 13, 2026 the Department of War suspended CMMC Phase II pending a 60-day reform review — the November 10 assessment deadline is off the table for now. What's not suspended: NIST SP 800-171, DFARS 252.204-7012, Phase 1 self-assessments, and the SPRS score every prime can see. The contractors who use this pause to get provably secure will be ready the day reformed requirements land — and inherit the work of those who treated it as a holiday.

Status — July 13, 2026: Phase II suspended; CMMC Reform Task Force reports to the DoW CIO within 60 days. Phase 1 self-assessments and NIST SP 800-171 obligations continue.

Why this is urgent

Suspended isn't the same as gone.

The DoW called it reform, not repeal: "prohibitive compliance costs" are being reworked into scalable security requirements. What survives the review is anchored in the same NIST SP 800-171 controls — and primes are still quietly ranking their supplier lists by who is provably secure today.

  • !Your DFARS clauses still bind. 252.204-7012 safeguarding obligations remain contractual, and NIST SP 800-171 compliance is still expected through self-assessments and government-led assessments.
  • !Your SPRS score is still visible. Primes and contracting officers see it today, suspension or not. A weak score costs you work before any new rule is even written.
  • !Reform is coming — on a 60-day clock. The CMMC Reform Task Force reports to the DoW CIO within 60 days. Contractors who are ready when the reformed requirements land win awards while everyone else restarts the scramble.

Level check

Which CMMC level do you need?

  • L1Level 1 — FCI only. 15 basic safeguarding requirements, annual self-assessment. We'll get it done quickly and correctly — and have you ready for the day your contracts graduate to CUI.
  • L2Level 2 — you touch CUI. This is our specialty. All 110 NIST SP 800-171 requirements — still contractually expected under DFARS even while Phase II assessments are suspended. The deepest work, the highest stakes — and exactly where we live.
  • L3Level 3 — critical programs. Level 2 plus enhanced requirements, assessed by the government (DIBCAC).

Not sure? Your contracts and DFARS 252.204-7012 clauses tell the story — we read them with you on the readiness call, free.

The deployment plan

From "where do we even start?" to assessment-ready

A defensible path, run by, with, and through your team — every step tracked in the Cyber Tackle Box™ so nothing lives in someone's inbox.

Readiness Call & Scoping — free

Thirty minutes. We identify your level, your CUI boundary, your current SPRS posture, and the real size of the job. You leave with a straight answer either way.

Gap Assessment

A control-by-control review against NIST SP 800-171's 110 requirements. You get a scored gap report, a prioritized remediation roadmap, and an honest SPRS score you can stand behind.

Remediation — by, with, and through your team

Policies, procedures, and technical controls implemented with your people so the knowledge stays. Pre-built policy templates and workbooks in the Cyber Tackle Box cut months off document drafting. Where you need specialized muscle — enclaves, MDR, IAM — our vetted partner network deploys with you.

Evidence & System Security Plan

Assessors don't grade intentions; they grade artifacts. We assemble your SSP, POA&M closure evidence, and control artifacts into an assessment-ready package, organized the way assessors expect to see it.

Assessment Prep — ready when they are

Mock-assessment walkthroughs run by instructors who teach the official CCA curriculum. When third-party assessments return under the reformed program, we help you schedule with an authorized C3PAO and stand with you through assessment week.

The Lionfish edge

We train the assessors. That changes everything.

Cyber AB Accredited Training Provider

We teach the official CCP and CCA certification courses. Your readiness work is guided by the same body of knowledge your assessor was trained on — no guessing what "good" looks like.

One system of record

The Cyber Tackle Box™ tracks every control, policy, task, and piece of evidence — with your workforce training in the same platform. Your assessor follows a trail, not a shoebox.

Veteran-owned, defense-native

SDVOSB, SAM-registered (CAGE 96LH8), founded by a Green Beret. We speak prime-contractor and contracting-officer fluently — and your supply-chain diversity story improves the day you engage us.

Straight answers

CMMC questions we answer every week

What just happened to CMMC Phase 2?

On July 13, 2026 the Department of War suspended CMMC Phase II requirements, effective immediately, pending a 60-day review by the CMMC Reform Task Force — which effectively cancels the November 10, 2026 third-party assessment deadline. The DoW CIO's stated reason: compliance costs were forcing innovative companies out of the defense industrial base. What did not change: Phase 1 self-assessments continue, NIST SP 800-171 compliance is still required, and DFARS 252.204-7012 remains contractually binding.

How long does Level 2 readiness really take?

For most small and mid-sized contractors: 1–3 months of gap assessment and planning, then 3–6 months of remediation and evidence building. Call it 6–12 months end to end. That's the whole argument for using the suspension window: it's the first time contractors can do this work calmly, at a sane pace, without panic pricing — and be finished before the reformed requirements arrive.

Do I need Level 1 or Level 2?

Handle only Federal Contract Information? Level 1 — 15 basic safeguarding requirements, annual self-assessment. Store, process, or transmit CUI? Level 2 — all 110 requirements of NIST SP 800-171, with third-party assessments expected to return in some form under the reformed program. Your DFARS clauses (especially 252.204-7012) are the tell; we review them with you free. Level 2 is our core specialty — it's where the real work (and the real risk to your contracts) lives.

What does this cost?

It depends on your posture, environment, and CUI footprint — anyone quoting a flat number before a gap assessment is guessing. What we can promise: a scoped, phased budget after the readiness call, remediation choices ranked by cost-effectiveness, and protection from the most expensive outcome in CMMC — failing the assessment and paying for it twice.

Phase II is suspended — can't I just wait and see?

That's exactly what most of the 300,000 companies in the DIB will do — and it's how they end up in the same scramble when the reformed requirements land. Primes are still ranking supplier lists by security posture today, your SPRS score is still visible, and your DFARS obligations never paused. This window is the cheapest, calmest chance to get ready that contractors will ever get.

Get in touch

Start your Level 2 Rapid Deployment

Tell us about your contracts and your timeline. A readiness call comes back to you within one business day.

  • 1We reply within one business day — usually faster.
  • 2A 30-minute call with someone who can actually answer your questions.
  • 3A straight recommendation — even if it's that you don't need us yet.

Prefer to skip the form? Book a time directly or call 1-877-732-6772.

Book a Free Readiness Call