The CMMC November 2026 Deadline Is Suspended
Phase II was suspended in July and made binding regulation on September 3. Self-assessment is the rule, the burden of proof moved onto you, and the Department has said the next version measures continuous verification. Here is what to do now.
November 10, 2026 is no longer the date. The Department suspended CMMC Phase II in July 2026, and on September 3 it made that suspension binding acquisition regulation. Third-party certification by a C3PAO is not a condition of award. Self-assessment is. If you came here looking for the countdown, the countdown is over, and what replaced it asks more of you, not less.
This page is the running reference. We update it as DoD guidance moves. Last updated: September 16, 2026.
What actually happened
- July 2026: after a 60-day review, a newly stood-up CMMC Reform Task Force recommended suspending Phase II. The Department announced it, effective immediately. More than 1,100 organizations had responded to the reform RFI, over 10,000 pages of it.
- September 3, 2026: the Principal Director for Defense Pricing, Contracting, and Acquisition Policy signed Revision 3 of DARS class deviation 2026-O0025. This is the part people keep missing. The July announcement was policy; Rev 3 is regulation. Contracting officers are now directed to accept Level 1 (Self) or Level 2 (Self) assessments, and the C3PAO requirement is stripped from solicitations and contracts for the duration.
- What did not change: Phase 1 is untouched. Your obligations under DFARS 252.204-7012 are untouched. All 110 NIST SP 800-171 practices still apply. The security bar did not move one inch. Only the question of who verifies it moved.
This is not a reprieve. Read what the CIO said.
At the Billington Cybersecurity Summit on September 9, DoW CIO Kirsten Davies explained the reasoning, and it is not the reasoning most contractors assumed:
"Compliance equals a point-in-time check of, 'Where are you right now?' We all know that cybersecurity is a dynamic process. It needs to be contiguous and continuous, and it needs to be at the pace of the threat in and of itself."
CMMC was not paused because it was too hard. It was paused because a once-every-three-years audit does not measure anything a modern adversary respects. That is a statement about what the next version will measure: whether you are secure right now, not whether you passed an assessment last spring. Every dollar you spend on monitoring that actually runs is a dollar spent ahead of the requirement. Every dollar spent on binder-ware to survive one afternoon with an assessor was always wasted, and is now visibly wasted.
The burden of proof moved onto you
Under Phase II, a C3PAO stood between your claims and the government. Their name went on the certificate. That buffer is gone, and two things follow immediately.
First: your SPRS score is a representation to the government, and the False Claims Act applies to it today. Not in 2027, not when the reform task force reports out. Today. A score you posted because a consultant told you it was defensible is a score you personally stand behind, with treble damages and qui tam relators as the enforcement mechanism. DOJ's Civil Cyber-Fraud Initiative has already shown it will take these cases. The removal of the assessor did not remove the liability; it removed the person you could point at.
Second: "we self-assessed" is now the whole of your defense. When something goes wrong, the question will be what evidence you had and when you had it. Self-assessment without continuous evidence is an assertion. Self-assessment with logs, alerts, hunt records, and an incident timeline is a record. One of those survives a subpoena.
What Level 2 still requires
110 security practices from NIST SP 800-171 Rev. 2, assessed with evidence. Unchanged. The ones that take real calendar time:
- A System Security Plan that reflects reality, roughly 80 pages that must match what is actually running, because now nobody is checking it for you before it matters
- MFA everywhere, enterprise-wide, and understand its limits: infostealer markets are now moving over a million logs containing credentials with active session cookies that carry the MFA claim, which is why the monitoring family below exists
- FIPS-validated encryption for CUI at rest and in transit
- Continuous monitoring, logging, and incident response with a track record. This is the family the CIO just told you the next version will be built around
- Vulnerability management on a cadence you can prove, and the adversary is running their own cadence against you: this year's Iranian-nexus campaign against U.S. targets weaponized CVE-2024-55591 and CVE-2026-1281 in exactly the perimeter appliances small contractors run and forget
Why continuous monitoring was always the real requirement
Two dates from this spring make the argument better than any consultant deck, and they make it more forcefully now than they did under Phase II.
On March 11, 2026 at 3:30 a.m. EDT, operators who had spent weeks quietly inside a major medtech company's identity layer issued a bulk wipe through the victim's own Intune console and destroyed roughly 200,000 systems before sunrise. Every early phase of that kill chain, the February password spraying, the phishing proxy at sso.bookairway.com, the Rclone exfiltration to ordinary cloud buckets, was detectable for weeks by anyone watching. A point-in-time assessment in January would have passed that company.
In April, CISA's AR26-113a documented the FIRESTARTER backdoor persisting inside a federal agency's Cisco firewall through reboots and patches while generating no log events at all. Finding it takes flow-to-authentication reconciliation and dormant account analysis, hunting, not alerting. No audit finds that. No checklist asks the question.
That is the standard your security is measured against by adversaries, and now, by the Department's own stated direction, the standard the next rule will measure too.
What to do with the runway you just got
Treat the suspension as time, not as relief. The contractors who use it to stand up monitoring that actually runs will meet the next requirement as a byproduct of operating. The contractors who read "suspended" as "cancelled" will meet it the way they were going to meet Phase II: badly, expensively, and late. Whatever the reform task force recommends has to move through further regulatory action before anything changes again, and none of that pauses the False Claims Act exposure sitting on your SPRS score in the meantime.
What we handle
ThreatHunter.ai carries the monitoring-heavy control families for DIB contractors: 24/7 hunt team coverage, audit log collection and review (3.3.x), incident response with your DFARS 72-hour DIBNet clock in mind (3.6.x), and system integrity monitoring (3.14.x), producing the continuous evidence that a self-assessment has to stand on. The compliance side is what our JAXBERT platform is built for: walking all 110 NIST SP 800-171 practices, your live SPRS score, your SSP and POA&M, and a self-attestation package you can actually defend. We are not a paperwork mill. We are the part of your 110 controls that has to actually operate at 3:30 a.m., with proof it did.
Frequently Asked Questions
Is CMMC cancelled?
No. Phase II third-party certification is suspended, not repealed. Phase 1 self-assessment requirements, DFARS 252.204-7012 obligations, and all 110 NIST SP 800-171 practices remain in force. A reform task force is reviewing the program, and any further change requires additional regulatory action.
Do I still need a C3PAO assessment?
Not as a condition of award. Revision 3 of DARS class deviation 2026-O0025, signed September 3, 2026, directs contracting officers to accept Level 1 (Self) or Level 2 (Self) assessments. Some primes may still require third-party assessment as a matter of their own flow-down; ask your contracting officer rather than assuming.
Does the suspension reduce my legal exposure?
It increases it. Your SPRS score is a representation to the government and the False Claims Act applies to it today. Under Phase II an assessor stood between your claims and the government. That buffer is gone. You are now the only one attesting.
Do I need CMMC certification if I only hold FCI, not CUI?
Level 1 self-assessment covers FCI-only contractors. Level 2 applies where CUI is involved. Check your contracts and ask your contracting officer, not your gut.
Does an MDR provider make me compliant?
No provider makes you compliant. A monitoring provider carries the audit, incident response, and system integrity families and supplies the continuous evidence your self-assessment stands on. The attestation is yours to make and yours to defend.