CMMC 2.0 Timeline: Phase-by-Phase Rollout (Phase 2 Suspended)

The CMMC 2.0 rule (48 CFR) laid out a four-phase rollout over three years. Phase 1 self-assessment requirements are live. Phase 2 through Phase 4 (the third-party assessment schedule) are now under DoD review after the July 13, 2026 suspension. Here is what each phase means for your compliance timeline and budget.

Update · July 13, 2026

Phase 2 is suspended pending a DoD review

The Department of Defense suspended CMMC Phase 2 (mandatory C3PAO certification for Level 2), which had been scheduled to take effect November 10, 2026, and established a CMMC Reform Task Force to conduct a top-to-bottom review of the program. The task force’s report is expected in late September or early October 2026. Phase 1 self-assessment requirements and DFARS 252.204-7012 safeguarding obligations remain in force; existing contracts that already carried Level 2 C3PAO or Level 3 assessment clauses are being amended to remove them. No new Phase 2 start date has been set. The Phase 2 to Phase 4 dates below are the pre-suspension plan, retained for reference.

Live NowNovember 2025

Phase 1: Self-Assessment Requirements

  • Level 1 self-assessments required in new solicitations for FCI-handling contracts
  • Level 2 self-assessments required in new solicitations for CUI-handling contracts
  • SPRS score submission required at time of contract award
  • Level 3 self-assessment requirements begin for select programs
SuspendedNovember 10, 2026

Phase 2: Mandatory C3PAO Certification (suspended)

As planned before the July 13, 2026 suspension, Phase 2 would have introduced:

  • Mandatory C3PAO assessment for Level 2 in new solicitations
  • Self-assessment alone no longer sufficient for Level 2 on new contracts
  • Level 3 DIBCAC requirements for designated programs
  • Existing contracts awarded under Phase 1 rules continuing under self-assessment until recompete

This phase is on hold pending the CMMC Reform Task Force review. If you handle CUI, the remediation work behind a Level 2 self-assessment is unchanged, and the C3PAO scheduling backlog runs 6 to 12 months, so a readiness baseline is still worth building now even without a confirmed deadline.

Under reviewNovember 2027 (pre-suspension plan)

Phase 3: Option Exercises and Level 3

  • C3PAO certification required for Level 2 option year exercises (not just new contracts)
  • Full Level 3 DIBCAC requirements for all designated programs
  • Subcontractors handling CUI must demonstrate Level 2 C3PAO certification
Under reviewNovember 2028 (pre-suspension plan)

Phase 4: Full Applicability

  • CMMC requirements apply to all DoD contracts, including existing ones
  • No exceptions for legacy contracts without CMMC clauses
  • All prime contractors and subcontractors must hold appropriate CMMC certification

Preparation Timeline by Level

PhaseLevel 1Level 2Level 3
Gap Assessment1 - 2 weeks1 - 3 months2 - 4 months
Remediation2 - 8 weeks3 - 12 months12 - 24 months
Documentation (SSP)1 - 2 weeks2 - 4 months3 - 6 months
Assessment SchedulingN/A6 - 12 monthsGovt scheduled
Assessment Duration1 day (self)1 - 4 weeks2 - 6 months
Total2 - 5 months9 - 20 months24 - 48 months

Preparation Checklist

Now (0 - 3 months)

  • Determine your required CMMC level from contract requirements
  • Conduct a gap assessment against NIST 800-171 (Level 2) or FAR 52.204-21 (Level 1)
  • Budget for remediation, tools, and assessment fees
  • Begin C3PAO selection and scheduling if Level 2 is required

Months 3 - 6

  • Begin remediation of critical gaps (MFA, SIEM, EDR)
  • Develop or update your System Security Plan (SSP)
  • Implement required policies and procedures
  • Start employee security awareness training

Months 6 - 12

  • Complete technical remediation
  • Finalize SSP and evidence packages
  • Conduct internal mock assessment
  • Document POA&M items if needed
  • Confirm C3PAO assessment date

Months 12 - 18

  • C3PAO pre-assessment review (if offered)
  • Formal C3PAO assessment
  • Address any conditional findings within 180 days
  • Submit SPRS score and CMMC certification status

Frequently Asked Questions

Is CMMC mandatory right now, and what changed in July 2026?
Phase 1 is in effect: since November 2025 new DoD solicitations require Level 1 and Level 2 self-assessments, and DFARS 252.204-7012 safeguarding duties continue. Phase 2, which would have made third-party C3PAO certification mandatory for Level 2, was scheduled for November 10, 2026 but the Department of Defense suspended it on July 13, 2026 and stood up a CMMC Reform Task Force to review the program. The task force report is expected in late September or early October 2026. Until DoD amends 32 CFR Part 170 or the DFARS rule, no new Phase 2 start date is set.
What if my contract does not mention CMMC yet?
CMMC self-assessment requirements are being phased into new solicitations and contract modifications under Phase 1. Even if your current contract does not mention CMMC, future recompetes and new bids may require it. The Phase 2 through Phase 4 third-party-assessment schedule is now under review, so the later phase dates below are the pre-suspension plan, not confirmed deadlines. Preparing your NIST SP 800-171 baseline now is still worthwhile because the underlying safeguarding obligation has not changed.
How long should I budget for CMMC preparation?
Level 1: 2 to 5 months. Level 2: 9 to 20 months (including a 6 to 12 month C3PAO scheduling backlog). Level 3: 24 to 48 months. Even with Phase 2 suspended, the remediation work behind a Level 2 self-assessment is unchanged, so building the NIST SP 800-171 baseline now protects both the current self-assessment obligation and any reinstated C3PAO requirement.

Updated 2026-09-14