CMMC 2.0 Timeline: Phase-by-Phase Rollout (Phase 2 Suspended)
The CMMC 2.0 rule (48 CFR) laid out a four-phase rollout over three years. Phase 1 self-assessment requirements are live. Phase 2 through Phase 4 (the third-party assessment schedule) are now under DoD review after the July 13, 2026 suspension. Here is what each phase means for your compliance timeline and budget.
Phase 2 is suspended pending a DoD review
The Department of Defense suspended CMMC Phase 2 (mandatory C3PAO certification for Level 2), which had been scheduled to take effect November 10, 2026, and established a CMMC Reform Task Force to conduct a top-to-bottom review of the program. The task force’s report is expected in late September or early October 2026. Phase 1 self-assessment requirements and DFARS 252.204-7012 safeguarding obligations remain in force; existing contracts that already carried Level 2 C3PAO or Level 3 assessment clauses are being amended to remove them. No new Phase 2 start date has been set. The Phase 2 to Phase 4 dates below are the pre-suspension plan, retained for reference.
Phase 1: Self-Assessment Requirements
- Level 1 self-assessments required in new solicitations for FCI-handling contracts
- Level 2 self-assessments required in new solicitations for CUI-handling contracts
- SPRS score submission required at time of contract award
- Level 3 self-assessment requirements begin for select programs
Phase 2: Mandatory C3PAO Certification (suspended)
As planned before the July 13, 2026 suspension, Phase 2 would have introduced:
- Mandatory C3PAO assessment for Level 2 in new solicitations
- Self-assessment alone no longer sufficient for Level 2 on new contracts
- Level 3 DIBCAC requirements for designated programs
- Existing contracts awarded under Phase 1 rules continuing under self-assessment until recompete
This phase is on hold pending the CMMC Reform Task Force review. If you handle CUI, the remediation work behind a Level 2 self-assessment is unchanged, and the C3PAO scheduling backlog runs 6 to 12 months, so a readiness baseline is still worth building now even without a confirmed deadline.
Phase 3: Option Exercises and Level 3
- C3PAO certification required for Level 2 option year exercises (not just new contracts)
- Full Level 3 DIBCAC requirements for all designated programs
- Subcontractors handling CUI must demonstrate Level 2 C3PAO certification
Phase 4: Full Applicability
- CMMC requirements apply to all DoD contracts, including existing ones
- No exceptions for legacy contracts without CMMC clauses
- All prime contractors and subcontractors must hold appropriate CMMC certification
Preparation Timeline by Level
| Phase | Level 1 | Level 2 | Level 3 |
|---|---|---|---|
| Gap Assessment | 1 - 2 weeks | 1 - 3 months | 2 - 4 months |
| Remediation | 2 - 8 weeks | 3 - 12 months | 12 - 24 months |
| Documentation (SSP) | 1 - 2 weeks | 2 - 4 months | 3 - 6 months |
| Assessment Scheduling | N/A | 6 - 12 months | Govt scheduled |
| Assessment Duration | 1 day (self) | 1 - 4 weeks | 2 - 6 months |
| Total | 2 - 5 months | 9 - 20 months | 24 - 48 months |
Preparation Checklist
Now (0 - 3 months)
- Determine your required CMMC level from contract requirements
- Conduct a gap assessment against NIST 800-171 (Level 2) or FAR 52.204-21 (Level 1)
- Budget for remediation, tools, and assessment fees
- Begin C3PAO selection and scheduling if Level 2 is required
Months 3 - 6
- Begin remediation of critical gaps (MFA, SIEM, EDR)
- Develop or update your System Security Plan (SSP)
- Implement required policies and procedures
- Start employee security awareness training
Months 6 - 12
- Complete technical remediation
- Finalize SSP and evidence packages
- Conduct internal mock assessment
- Document POA&M items if needed
- Confirm C3PAO assessment date
Months 12 - 18
- C3PAO pre-assessment review (if offered)
- Formal C3PAO assessment
- Address any conditional findings within 180 days
- Submit SPRS score and CMMC certification status