CMMC Program Status:
What Is Known, What Is Pending.
CMMC changed materially in 2026. This page separates what is confirmed from what is still under review, so you can plan against facts rather than speculation. Last updated September 30, 2026.
Known
What Is Confirmed
These are matters of public record: regulatory actions the Department of War has taken, and requirements that were never paused.
Third-party Level 2 certification is suspended
The Department of War suspended CMMC Phase 2, third-party C3PAO certification as a condition of contract award, effective July 13, 2026. It had been scheduled to begin November 10, 2026.
The suspension is now a binding regulation, not an informal pause
On September 3, 2026, the Department issued Class Deviation 2026-O0025 Revision 3, directing contracting officers to remove third-party CMMC assessment requirements from contracts. A class deviation is formally harder to reverse than a policy memo, which is one signal this is not a brief pause.
Self-assessment and the underlying security requirements were never paused
Level 1 and Level 2 self-assessment, SPRS score submission, and the requirements underneath CMMC, DFARS 252.204-7012 (safeguarding, 72-hour incident reporting, 90-day image retention, subcontractor flow-down) and DFARS 252.204-7021, remain fully in force on applicable contracts.
A Reform Task Force is rewriting the program
Stood up the same day as the suspension, tied to Secretary Hegseth’s Acquisition Transformation System initiative. Its public comment period closed August 14, 2026, drawing more than 1,100 written responses, over 10,000 pages of material, and more than 3,000 attendees across listening sessions nationwide. More than half of respondents reportedly favored the pause and some form of reform.
Individual CMMC credentialing moved to a new body
Since April 1, 2026, ISACA operates as the CMMC Assessor and Instructor Certification Organization, administering the CCP, CCA, LCCA, and CCI individual certifications. Cyber AB retained RP/RPO registration, C3PAO accreditation, the Marketplace, and background checks. These are two different organizations doing two different jobs, and both remain active.
Enforcement has continued through the Department of Justice, not through CMMC certification
DOJ’s Civil Cyber-Fraud Initiative has kept pursuing False Claims Act cases tied to cybersecurity misrepresentation throughout the suspension, including a government-initiated DIBCAC assessment that led to a $507,144 settlement in June 2026, and a $2 million settlement with Honeywell Aerospace reported September 2, 2026. This is the active enforcement mechanism right now.
Pending
What Is Still Under Review
These are open questions. We are not going to guess at answers here, this section will be updated as the Department makes findings public.
When the Reform Task Force report will be released
The report was due to DoD CIO Kirsten Davies by September 11, 2026. As of this update it has not been made public. Cyber AB’s CEO has estimated early October 2026, but no confirmed release date has been announced.
What the reformed program will actually require
Reported themes under consideration include a shift toward continuous, dynamic compliance monitoring rather than point-in-time assessment, expanded scope into operational-technology resilience for manufacturing environments, and standardized CUI marking practices. None of this is finalized.
Whether existing Level 2 certifications will carry forward
Cyber AB has publicly advocated for preserving the value of the roughly 2,000 Level 2 certifications already issued, through reciprocity or standards-acceptance provisions in whatever program follows. Whether that happens is a Department decision, not yet made.
A revised timeline for Level 2 and Level 3
The original four-phase schedule assumed Level 2 C3PAO assessments beginning November 2026 and Level 3 DIBCAC assessments beginning November 2027. Both are now downstream of the Task Force’s findings, with no new dates published.
What This Means for You
Prepare for the Requirement, Not the Deadline
The suspension changes when a certificate is required. It does not change whether your NIST SP 800-171 posture, self-attestation, and SPRS score need to be accurate. That obligation is active today, and it is the one the Department of Justice is currently enforcing.
Work completed now toward a defensible gap assessment, SSP, and POA&M is not wasted. It reduces your False Claims Act exposure today, and it is the same work a C3PAO assessment will draw on whenever certification requirements resume in whatever form the Task Force recommends.
Talk to Us
If you are unsure what currently applies to your specific contracts, we can review your contract vehicles and current posture directly.
See Our CMMC Services →
Service-Disabled Veteran-Owned Small Business
GiaMetrics® is an SDVOSB verified through the U.S. Small Business Administration. Federal agencies and prime contractors can apply GiaMetrics work toward SDVOSB subcontracting goals under FAR Part 19.
Get Started
Have a Project? Let’s Talk.
We work with organizations at every stage, from those addressing governance for the first time to those with mature programs facing a new requirement. Tell us about your situation and we will outline a clear path forward.
Send Us a Message
Whether you are exploring your options or ready to start, we are here to help. All inquiries are confidential.