CMMC Phase 1 Suspension: What Dallas Contractors Should Do Now

The Department of War has suspended the CMMC transition in Phase 1 while it reviews the program. Contractors should follow solicitation clauses and maintain evidence without assuming a November 2026 Phase 2 deadline.

Back to Blog
(Updated )
3 min read
Isometric illustration of defense industrial cybersecurity compliance, a shield protecting an aerospace and manufacturing facility behind layered security rings

CMMC Phase 2 is not currently advancing on the original November 10, 2026 schedule. The Department of War says it has suspended the transition in Phase 1 while it reviews implementation.

Current as of 2026-08-15

The current CMMC FAQ says applicable procurements began November 10, 2025, implementation remains in Phase 1, and transition to Phase 2 is suspended. A solicitation and contract clause—not an old planned timeline—controls an individual contractor’s requirement.

Decision summary

  • Do not plan around a guaranteed November 10, 2026 Phase 2 start while the transition is suspended.
  • Read every solicitation and contract for the exact CMMC level and assessment requirement.
  • Continue maintaining required NIST SP 800-171 controls, assessment evidence, POA&M governance, and affirmations.
  • Treat assessment costs, assessor counts, and scheduling estimates as vendor data unless officially sourced.

What Phase 1 means now

The current FAQ describes Phase 1 as focused on Level 1 and Level 2 self-assessments. It also says the Department is reviewing the program and has suspended transition to Phase 2. Historic briefing material can explain the original plan, but it cannot override the current FAQ or the contract.

Resolve the requirement from the acquisition record

DFARS 204.7504 describes when CMMC solicitation provisions and contract clauses apply. Contractors should record the solicitation, clause, required level, assessment type, affirmation owner, and due date for each opportunity.

Use the pause to improve evidence

  • Confirm the CUI boundary and system-security-plan scope.
  • Map each requirement to an owner, implementation, and current evidence.
  • Reconcile SPRS information with current practice.
  • Review POA&Ms for eligibility, dates, owners, and closure evidence.
  • Validate subcontractor flow-down and evidence responsibilities.
  • Run an independent readiness review before a contractual assessment is due.

Avoid false certainty about cost and capacity

Public vendor estimates for assessment cost, assessor availability, or lead time can change and are not universal. Build a transparent estimate from scope, enclave complexity, remediation, documentation, assessor quote, and business interruption. Obtain current bids when a certification assessment is actually required.

Legal and contractual boundary

This article is operational guidance, not legal advice or a certification representation. Contracting officers, qualified counsel, and authorized assessors should resolve disputed obligations.

For related guidance from ITECS, see ITECS CMMC compliance guidance.

Sources and update trigger

Review trigger: Recheck the official FAQ, DFARS clauses, and the specific solicitation before every bid and whenever the Department announces the next transition decision.

continue reading

More ITECS blog articles

Browse all articles

About ITECS Team

The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.

View full profile and articles

Share This Article

Continue Reading

Explore more insights and technology trends from ITECS

View All Articles