CMMC for software vendors: what the suspension changes
On 13 July 2026, DoD CIO Memo 26-P-1023 suspended the CMMC Phase 2 requirement for mandatory certification by an authorized third-party assessment organization. No replacement date has been published. Two readings of that are common and both are wrong: it is not the end of CMMC, and it is not permission to stop.
The step that was about to switch on
CMMC was designed to phase in over several years rather than switching on at once. Its second phase was the one with teeth for most software companies: on applicable contracts, certification by an authorized third-party assessment organization would have become the required path rather than one of two options.
Which level a company lands in is a question about data, not size. Level 1 covers basic safeguarding of Federal Contract Information and is met by an annual self-assessment. Level 2 covers Controlled Unclassified Information, is built on the NIST SP 800-171 requirement set, and is met either by self-assessment or by third-party certification depending on the contract. Level 3 adds a government-led assessment for the most sensitive programs.
Phase 2 is what would have removed the self-assessment option at Level 2 on applicable work. That is the step that is paused — and it is worth being precise about how narrow the step is, because the paragraph below is much longer than this one.
One step paused. The obligations did not.
Suspended 13 July 2026
- Mandatory certification by an authorized third-party assessment organization as the required path on applicable contracts — the CMMC Phase 2 step.
- Any program-wide date to plan backwards from. No replacement date has been published.
Source: DoD CIO Memo 26-P-1023. No replacement date has been published, and this page will not invent one.
Still in force, unchanged
- DFARS 252.204-7012
- Still obliges adequate security on covered contractor information systems, defined by reference to NIST SP 800-171 — the full requirement set, not a selection from it.
- NIST SP 800-171
- Unchanged. Where a requirement is not implemented, the clause anticipates a documented deviation rather than silence.
- The self-assessment
- The separate requirement to assess yourself against that standard and post the result in the government’s supplier performance system is still in force. That system is government-only; we have no visibility into it and never claim any.
- 72-hour incident reporting
- Untouched. The clock starts at discovery, not at confirmation, and companies that have never rehearsed the reporting path are the ones that miss it.
- The senior-official affirmation
- Still a representation to the government. False representations about cybersecurity compliance have already produced civil enforcement actions against contractors under the False Claims Act.
- Flowdown, and the solicitation itself
- A prime can still pass the requirement down by contract, and an applicable solicitation can still specify a certified assessment on its own terms.
A sequence ordered by your pipeline
With no government date to work back from, the ordering that is left is your own. None of these steps was waiting on Phase 2, which is why none of them changed on 13 July.
-
Settle which level your data puts you in
Federal Contract Information points at Level 1 and an annual self-assessment. Controlled Unclassified Information points at Level 2 and the NIST SP 800-171 requirement set. This is a data question, not a size question, and answering it wrong sets the price of everything after it.
-
Scope the environment that holds the data
The architectural decision — which systems touch the information, and which are kept out of the boundary — determines how much of your estate has to meet the standard. It is the cheapest decision to make early and the most expensive to revisit.
-
Implement, and document the deviations honestly
A documented gap with a plan behind it is a posture. An undocumented gap is a finding waiting to be made by someone else.
-
Keep the self-assessment and the affirmation current
Both survived the suspension, and both are statements the government can act on. Optimism in marketing copy is a reputational risk; optimism in an affirmation is a legal one.
-
Read the document, not the calendar
With no program-wide date, the requirement arrives in an applicable solicitation or a prime’s supply-chain questionnaire. Companies that already know their posture answer it; companies that do not, lose the subcontract to someone who could.
How CMMC is read here
The Federal Readiness Score has a Compliance Posture category, and CMMC is one of the signals it reads — alongside FedRAMP and SOC 2. The category reads publicly observable signals only, and its governing rule is that a government-published record and a company's own statement are never rendered as the same thing.
Three renderings, three different claims. A verified signal carries the source and the date we observed it. A self-attested signal is outlined and labelled self-reported, and never carries a check. No public signal either way renders as exactly that — not as a failure, and not as an absence of one.
The suspension makes that distinction more load-bearing, not less. With no mandate in effect, the supply of verifiable third-party certification records is not growing, so more of what a buyer will find about any vendor is that vendor's own claim. Rendering the two apart is the part of this that does not move.
The full category list, what each one reads, and what the score never claims are on the methodology page.
What is actually on the calendar
- 13 July 2026
The CMMC Phase 2 mandatory third-party certification requirement was suspended. This is the change everything else on this page follows from.
DoD CIO Memo 26-P-1023 dodcio.defense.gov
- No date published
A replacement date for the certification mandate. None exists. Reinstating a requirement of this kind is a rulemaking, and a rulemaking is published before it takes effect — so this is a page to watch rather than a date to plan against.
Rulemaking notices, CMMC program federalregister.gov
- In force today
DFARS 252.204-7012 — adequate security by reference to NIST SP 800-171, 72-hour cyber incident reporting, the external cloud service requirement, and flowdown. No end date, and none of it moved on 13 July.
DFARS 252.204-7012, current clause text acquisition.gov
- Whenever it arrives
The requirement an applicable solicitation, or a prime’s flowdown, actually states. Since the suspension this is the only CMMC date that is genuinely yours, and it is not on a public calendar.
The solicitation or subcontract in front of you
Every row names its publisher and the document identifier rather than deep-linking it. This site holds itself to citing a source it has opened and dated — the same standard the compliance badges above are rendered under — and that pass has not yet run against these three publishers. A URL we have not confirmed would be the one unsourced claim on a page whose entire argument is that the record is checkable.
What GovExpress is not
GovExpress is not a C3PAO. We are not an assessor, a 3PAO, a certification body, or a registered provider organization, and we do not conduct or prepare CMMC assessments.
No product makes an organization certified. Not ours, and not anyone else's. Certification comes from an assessment conducted under the program; software can tell you where you stand and what is missing, and that is a different claim entirely.
This page is informational and is not legal advice. It states the public federal record as of 12 September 2026; the controlling text is the clause in your contract and the terms of the solicitation in front of you.
Is CMMC certification still required?
Not as a program-wide mandate with a date attached. The CMMC Phase 2 requirement for mandatory certification by an authorized third-party assessment organization was suspended on 13 July 2026 by DoD CIO Memo 26-P-1023, and no replacement date has been published. That is narrower than it sounds: an applicable Department of War solicitation can still specify a certified assessment on its own terms, and a prime can still flow the requirement down by contract. The gate moved from the calendar to the document in front of you.
We are a subcontractor with no defense contract of our own. Does this reach us?
Usually, yes. CMMC requirements flow down, and so does DFARS 252.204-7012. A prime carrying a Level 2 obligation is required to pass the applicable requirement to subcontractors handling the same information, which is why the requirement typically arrives as a supply-chain questionnaire with a short turnaround rather than as a solicitation you had time to plan for.
Should we stop our CMMC work now that Phase 2 is suspended?
Stopping would be the expensive read. What was suspended is one step — who confirms your posture. What was not suspended is the posture itself: DFARS 252.204-7012 still obliges adequate security by reference to NIST SP 800-171, the separate self-assessment requirement is still in force, the 72-hour cyber incident reporting obligation is untouched, and the senior-official affirmation is still a representation to the government. The gap between having a security program and passing an assessment is measured in quarters, and no proposal window is that long.
Does a GovExpress score make us CMMC compliant?
No. GovExpress is a diagnostic built on public federal data. We are not an assessor, a C3PAO, a 3PAO, or a certification body, and no product — ours or anyone else’s — makes an organization certified. Only an assessment conducted under the program makes that true. What our Compliance Posture category does is read the publicly observable signals and keep verified records separate from a company’s own claims.
Check a vendor's posture in one search
Searching any federal vendor is free — the compliance overlay, the award record, and the readiness score, on public data. Start with a prime you are chasing, or with your own company.
Or take the long version
Six pages on what the suspension left standing: scoping, the level question, where the 110 requirements actually consume engineering time, and the five-step sequence above in detail. Delivered by email — we confirm the address before anything is sent.
Prefer to read the teaser first? See what is in the brief →