Skip to main content

CMMC 48 CFR Phase 2 60-Day Pause FAQs: What Defense Contractors Need to Know About the DoW Pause

Get clear answers about the CMMC Phase 2 pause, C3PAO assessments, ongoing NIST SP 800-171 and DFARS requirements, and what comes next for defense contractors.

Following the recent announcement by the Department of War (DoW), organizations in the Defense Industrial Base (DIB) are asking exactly what the CMMC Phase 2 60-day pause is and what it means for them. In this article, our experts give answers to the most common questions about the CMMC Phase 2 assessment pause, C3PAO certifications, NIST 800-171 compliance, DFARS obligations, and what the 60-day DoW review means for defense contractors and subcontractors.

1. What does the CMMC Phase 2 pause mean?

Answer: The Department has paused the 48 CFR Phase 2 rollout for a 60 day review period. Phase 2 would have required independent CMMC Level 2 assessments conducted by authorized C3PAOs, such as NSF, for applicable contracts where CMMC certification requirements were scheduled to begin appearing in solicitations and contracts starting November 10, 2026.

2. Is NSF still conducting CMMC assessments?

Answer: Yes. All CMMC program elements remain operational and available, including Level 2 certification assessments conducted by C3PAOs.

3. Can I still book a CMMC assessment with NSF?

Answer: Yes. These can still be booked.

4. We have already scheduled a CMMC assessment with NSF, what should we do?

Answer: We recommend maintaining any currently scheduled assessment dates to preserve momentum and ensure you retain your reserved assessment window.

5. Does the pause mean CMMC has been canceled?

Answer: No. Although it has been referred to as a "CMMC Phase 2 Suspension", Phase 2 implementation requirements are merely paused while a 60‑day review is conducted.

6. Does the pause mean DFARS 252.204‑7012 obligations have been removed?

Answer: No. Contractors must still comply with DFARS 252.204‑7012 requirements and continue safeguarding Covered Defense Information and Controlled Unclassified Information (CUI).

7. Does the CMMC pause affect NIST 800-171?

Answer: No. NIST SP 800‑171 requirements remain in place and contractors handling CUI are still expected to implement and maintain the required controls.

8. Should we continue preparing for our CMMC assessment?

Answer: Yes. We encourage organizations to continue advancing their CMMC readiness efforts until further information is available. Maintaining a strong cybersecurity posture remains a business imperative. Organizations that continue investing in cybersecurity and compliance efforts will be well positioned to meet current contractual obligations and maintain a competitive advantage in the marketplace.

9. What happens to active solicitations that already require a C3PAO assessment?

Answer: The DoW has directed contracting activities to amend affected solicitations and remove Level 2 (C3PAO) and Level 3 (DIBCAC) assessment requirements during the suspension period.

10. My organization has already passed its CMMC assessment. Is our certification still valid?

Answer: Yes, these remain valid. CMMC certificates still serve as a market differentiator and competitive advantage.

11. My organization is required to be CMMC Level 2 certified by the Primes. Can they still require this?

Answer: Yes. The pause to the CMMC 48 CFR Phase 2 rollout doesn’t negate any contractual requirements from your Primes if they require your organization to be CMMC Level 2 certified regardless of the pause.

NSF will continue to provide updates on the CMMC 48 CFR Phase 2 pause as further information becomes available.

In the meantime, organizations should remain focused on protecting Controlled Unclassified Information (CUI), meeting applicable cybersecurity requirements, and maintaining a strong security posture. Whatever the outcome of the current review, NSF is here to help organizations navigate and remain prepared for what's ahead.

A proactive approach to CMMC and cybersecurity can also deliver a valuable business benefit - helping organizations demonstrate trust, reduce risk, and stand out in an increasingly competitive marketplace.

Learn more about NIST 800-171

Protect the confidentiality of controlled unclassified information in your nonfederal systems and organization.

Got CMMC questions?

Talk to one of our experts.

What’s New with NSF

  • NSF Awards World-First Community Catch Certification to Orkney Crab Fishery

    July 13, 2026
    Milestone certification sets a new benchmark for small-scale fishery sustainability and social responsibility.
    Read the Story
  • NSF To Offer In-Person GMP and Regulatory Compliance Courses at SupplySide Global 2026

    July 13, 2026
    NSF is offering a comprehensive GMP and regulatory compliance training program of classroom-based courses for dietary supplement industry professionals at SupplySide Global 2026.
    Read the Story
  • NSF Issues First-Ever MSC Certification for an Eel Fishery to Perupez S.A.C. and Sakana del Peru

    June 19, 2026
    Third-party certification plays a key role in independently verifying the sustainability of seafood operations.
    Read the Story
  • NSF at Newtopia Now

    June 18, 2026
    NSF is proud to be part of Newtopia Now.
    Read the Story