Skip to main content

CMMC 48 CFR Phase 2 60-Day Pause FAQs: What Defense Contractors Need to Know About the DoW Pause

Get clear answers about the CMMC Phase 2 pause, C3PAO assessments, ongoing NIST SP 800-171 and DFARS requirements, and what comes next for defense contractors.

Following the recent announcement by the Department of War (DoW), organizations in the Defense Industrial Base (DIB) are asking exactly what the CMMC Phase 2 60-day pause is and what it means for them. In this article, our experts give answers to the most common questions about the CMMC Phase 2 assessment pause, C3PAO certifications, NIST 800-171 compliance, DFARS obligations, and what the 60-day DoW review means for defense contractors and subcontractors.

1. What does the CMMC Phase 2 pause mean?

Answer: The Department has paused the 48 CFR Phase 2 rollout for a 60 day review period. Phase 2 would have required independent CMMC Level 2 assessments conducted by authorized C3PAOs, such as NSF, for applicable contracts where CMMC certification requirements were scheduled to begin appearing in solicitations and contracts starting November 10, 2026.

2. Is NSF still conducting CMMC assessments?

Answer: Yes. All CMMC program elements remain operational and available, including Level 2 certification assessments conducted by C3PAOs.

3. Can I still book a CMMC assessment with NSF?

Answer: Yes. These can still be booked.

4. We have already scheduled a CMMC assessment with NSF, what should we do?

Answer: We recommend maintaining any currently scheduled assessment dates to preserve momentum and ensure you retain your reserved assessment window.

5. Does the pause mean CMMC has been canceled?

Answer: No. Although it has been referred to as a "CMMC Phase 2 Suspension", Phase 2 implementation requirements are merely paused while a 60‑day review is conducted.

6. Does the pause mean DFARS 252.204‑7012 obligations have been removed?

Answer: No. Contractors must still comply with DFARS 252.204‑7012 requirements and continue safeguarding Covered Defense Information and Controlled Unclassified Information (CUI).

7. Does the CMMC pause affect NIST 800-171?

Answer: No. NIST SP 800‑171 requirements remain in place and contractors handling CUI are still expected to implement and maintain the required controls.

8. Should we continue preparing for our CMMC assessment?

Answer: Yes. We encourage organizations to continue advancing their CMMC readiness efforts until further information is available. Maintaining a strong cybersecurity posture remains a business imperative. Organizations that continue investing in cybersecurity and compliance efforts will be well positioned to meet current contractual obligations and maintain a competitive advantage in the marketplace.

9. What happens to active solicitations that already require a C3PAO assessment?

Answer: The DoW has directed contracting activities to amend affected solicitations and remove Level 2 (C3PAO) and Level 3 (DIBCAC) assessment requirements during the suspension period.

10. My organization has already passed its CMMC assessment. Is our certification still valid?

Answer: Yes, these remain valid. CMMC certificates still serve as a market differentiator and competitive advantage.

11. My organization is required to be CMMC Level 2 certified by the Primes. Can they still require this?

Answer: Yes. The pause to the CMMC 48 CFR Phase 2 rollout doesn’t negate any contractual requirements from your Primes if they require your organization to be CMMC Level 2 certified regardless of the pause.

NSF will continue to provide updates on the CMMC 48 CFR Phase 2 pause as further information becomes available.

In the meantime, organizations should remain focused on protecting Controlled Unclassified Information (CUI), meeting applicable cybersecurity requirements, and maintaining a strong security posture. Whatever the outcome of the current review, NSF is here to help organizations navigate and remain prepared for what's ahead.

A proactive approach to CMMC and cybersecurity can also deliver a valuable business benefit - helping organizations demonstrate trust, reduce risk, and stand out in an increasingly competitive marketplace.

Learn more about NIST 800-171

Protect the confidentiality of controlled unclassified information in your nonfederal systems and organization.

Got CMMC questions?

Talk to one of our experts.

What’s New with NSF

  • Young beautiful athlete woman training on outdoors exercise bike in park and eating energy bar.

    NSF Drives Industry Conversations at SupplySide Global 2026 - Las Vegas, Oct. 26–30

    September 17, 2026
    NSF returns to SupplySide Global with expert-led training and trusted certification solutions. Visit Booth 4741 to discover how NSF and Cambium Analytica help brands build trust, increase consumer confidence and stand out in a competitive marketplace.
    Read the Story
  • NSF Welcomes Hanjun Kwon, Managing Director, APAC

    September 14, 2026
    Experienced business leader to drive sustainable growth, organizational development and operational excellence across the Asia-Pacific region.
    Read the Story
  • A mother and her son standing in the kitchen as she prepares food for lunch. He is eating a strawberry while he watches. Mom is Caucasian, in her 30s and the boy is mixed race Black and Caucasian, 3 years old. The focus is on the woman.

    NSF to Exhibit and Present at PACK EXPO International

    September 11, 2026
    NSF is proud to be part of PACK EXPO International 2026, the premier event bringing together packaging and processing leaders from across industries.
    Read the Story
  • Information Systems Security Association (ISSA) Welcomes NSF’s Brian Schultz into the 2026 Hall of Fame

    September 10, 2026
    Lifetime achievement recognition honors exceptional leadership and lasting contributions to the cybersecurity profession.
    Read the Story