Program · Rollout · March 20, 2026

CMMC phased rollout: Phase 1 through Phase 4.

DoD published a four-phase rollout schedule for CMMC — then, on 13 July 2026, suspended Phase 2 and all future implementation milestones pending a 60-day Reform Task Force review. The phase descriptions below are summarized from DoD CIO program materials, annotated with current status.

Published March 20, 2026South Florida · Palm Beach · Broward · Miami-Dade
(561) 887-5470
Tag
Program
Citations
3
Type
Plain summary
Original
no control interpretation
No. 01

Summary and dates.

The four phases — and where they stand

Phase 1 — 10 Nov 2025 · IN FORCE
DoD began requiring Level 1 and Level 2 self-assessments in applicable contracts. Kicked off by the effective date of DFARS 252.204-7021. These obligations remain in force.
DoD CIO CMMC About page
13 Jul 2026 · SUSPENSION
DoD suspended Phase 2 and all future implementation milestones pending a 60-day Reform Task Force review. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171, and SPRS obligations remain in force.
DoD CIO announcement
Phase 2 — was 10 Nov 2026 · SUSPENDED
Would have begun requiring Level 2 certification assessments conducted by authorized C3PAOs in applicable contracts. Held in abeyance pending the reform review.
DoD CIO CMMC About page
Phase 3 — was 10 Nov 2027 · SUSPENDED
Would have begun requiring government-led Level 3 certification assessments where applicable. Held in abeyance pending the reform review.
DoD CIO CMMC About page
Phase 4 — was 10 Nov 2028 · SUSPENDED
Full implementation across all applicable DoD contracts and solicitations. Held in abeyance pending the reform review.
DoD CIO CMMC About page

Practical reading

The suspension is a pause pending reform, not a repeal. The underlying safeguarding requirements — DFARS 252.204-7012, NIST SP 800-171, SPRS scoring, and Phase 1 self-assessments — all remain in force, and primes continue to flow them down.

Specific contract requirements vary by program office and prime-contractor flowdown. Contractors should not assume that the program pause means absence of cybersecurity language in the next solicitation — and a reformed certification program is expected to emerge from the review.

No. 02

Sources and citations.

Primary references

DBIT Defense does not interpret control intent or republish substantive control text. All claims above link to primary sources for verification.

No. 03

Related insights.

Know where you stand
before the requirement
reaches the contract.

Start with a focused CMMC readiness assessment. We will send a written scoping summary within two business days, or a candid recommendation if it is not the right fit.

Or call directly (561) 887-5470Mon–Fri · 9am – 6pm ET · South Florida

Request a readiness assessment