• Link to LinkedIn
  • Link to Facebook
  • Link to X
  • Link to Youtube
  • Service: 866-692-9082
  • Customer Portal
  • Sales: 866-792-6638
  • Get A Quote Now
E-N Computers
  • Managed IT Services
    • Managed Services Plans
      • Fully Managed
      • Co-Managed
      • CMMC & Compliance
    • Support & Management
      • Help Desk Services
      • Onsite IT Services
      • Account Management
      • M365 Administration
    • Security & Compliance
      • Cybersecurity
      • IT Compliance Consulting
      • CMMC Consulting
    • Monitoring & Maintenance
      • Backups & Disaster Recovery
      • Patch Management
      • Network Monitoring & Incident Response
  • Professional IT Services
    • IT Consulting
      • CMMC Consulting
      • CMMC Gap Analysis
      • Cybersecurity
      • IT Consulting
    • On-Site & Staffing
      • Network Projects
      • Office IT Relocation
      • Security Cameras
      • IT Staff Augmentation
    • Telecommunications
      • Business VoIP Telephone Service
      • Business Internet Service
      • Electronic Fax Service
    • Emergency IT Services
  • Learning Center
    • Business-IT Strategy
    • Cybersecurity
    • IT Hiring & Staffing
    • Managed IT Services
    • Videos
    • E-Rate Resources
  • About
    • Testimonials
    • Team
    • Partners
    • Areas We Serve
    • Our Process
    • Careers
  • Pricing
    • Service Plans
    • Managed Services Pricing Calculator
    • Consulting
    • VoIP
    • Projects & Professional Services
  • Contact
  • Menu Menu
  • Managed IT Services
  • Professional Services
  • Learning Center
  • About
  • Pricing
  • Contact

CMMC compliance timeline and your real deadline

by Mustafa Mukhtar, MBA, ITIL
Consultant/Content Contributor, E-N Computers
20+ years of experience in IT management, project planning, enterprise systems and user support

Updated July 14, 2026

On July 13, 2026, the Pentagon suspended CMMC Phase 2 — the stage that would have required a third-party audit before you could win most contracts involving controlled unclassified information (CUI). The November 10, 2026 date everyone was racing toward is off the calendar, along with the later Phase 3 and Phase 4 milestones.

That doesn’t mean CMMC is gone, and it doesn’t mean you can stand procrastinate. Phase 1 self-assessments are still required, you’re still contractually bound to protect federal data, and the Pentagon is enforcing the underlying security standard while it reviews the program. Below is the full timeline — what already happened, what just got paused, and how to find the only deadline that actually matters for your business: your own.

QUICK ANSWER:

When is the CMMC deadline?

There’s no single CMMC deadline. Your real deadline depends on your own contracts — when your opportunities are solicited and awarded — not the DoD’s rollout calendar. The Phase 2 certification milestone once set for November 10, 2026 is suspended and under review, though self-assessment and SPRS requirements can still apply before award.

Table of Contents

  1. What’s the CMMC timeline now?
  2. Key CMMC dates and what they mean
  3. Top do’s and don’ts for CMMC right now
  4. Common questions about the CMMC compliance timeline
  5. Next steps
  6. Related articles

What’s the CMMC timeline now?

The CMMC Program rule (32 CFR) took effect December 16, 2024. The acquisition rule (48 CFR) took effect November 10, 2025, starting Phase 1 and letting the DoD write CMMC requirements — including Level 1 and Level 2 self-assessments — into new contracts.

Phase 2, which would have made third-party certification mandatory on November 10, 2026, is suspended as of July 13, 2026, along with Phases 3 and 4. During the review, the DoD is enforcing the NIST 800-171 security standard through self-assessments and select government-led checks.

There’s no hard third-party certification deadline right now — but a contract can still require a self-assessment and a posted SPRS score before award, so your real deadline is set by when your specific opportunities go out, not by the rollout calendar.

Key CMMC dates and what they mean

What already happened

December 16, 2024 — the CMMC Program rule took effect. The 32 CFR rule made CMMC official. From this point, protecting CUI stopped being a “maybe later” problem for defense contractors.

January 2025 — assessments became available. Organizations could begin undergoing official CMMC assessments through authorized assessors.

September 10, 2025 — the acquisition rule published. The DoD published the 48 CFR CMMC Acquisition Rule (DFARS Case 2019-D041) in the Federal Register, setting a November effective date.

November 10, 2025 — Phase 1 began. The 48 CFR rule became enforceable and DFARS clause 252.204-7021 became mandatory in nearly all DoD solicitations involving federal contract information (FCI) or CUI — except for mass-produced commercial items like standard laptops or unmodified networking gear. To be eligible for award, contractors had to have a current self-assessment or certification posted in SPRS, the federal contractor scoring system.

What just changed — Phase 2 suspended (July 13, 2026)

The Pentagon suspended the transition to Phase 2, which would have required a Level 2 certification from an accredited outside assessor before award on most contracts involving CUI. It also paused all pending and future CMMC milestones, and it stood up a CMMC Reform Task Force to review the program and report back within 60 days.

The stated reason was cost and burden on smaller firms. DoW officials said the third-party assessment requirement was too expensive and slow for small and mid-size businesses to meet on the original timeline, and the Small Business Administration reported that compliance costs were pushing companies out of the defense supply chain.

What’s on hold

These milestones were on the calendar and are now suspended until further notice:

  • Phase 2 (was November 10, 2026) — mandatory third-party Level 2 certification for most CUI contracts.
  • Phase 3 (was November 10, 2027) — Level 3 government-led assessments for the most sensitive programs.
  • Phase 4 (was November 10, 2028) — full implementation across all applicable DoD contracts.

What hasn’t changed — your obligations

The suspension paused the certification mechanism, not the duty underneath it:

  • You’re still bound by DFARS 252.204-7012 to safeguard covered defense information.
  • All 110 NIST 800-171 controls are still the standard you’re measured against.
  • Phase 1 self-assessments and your SPRS score still apply, and the DoD says it will keep checking them through self-assessments and select government-led assessments.
  • Legal exposure is unchanged. The Justice Department’s civil cyber-fraud enforcement, which uses the False Claims Act against firms that overstate their compliance, is still active.
  • Primes are still flowing requirements down. If a prime sends you CUI, the obligation travels with it, regardless of the federal timeline.

CMMC compliance dates at a glance

  • 2024

    December 16

    CMMC Final Rule became effective

  • January

    Official assessments became available

    2025

  • 2025

    September 10

    acquisition rule (48 CFR) published

  • November 10

    Phase 1 began; self-assessment and SPRS score required for award

    2025

  • 2026

    July 13

    Phase 2 suspended; Phases 3 and 4 paused; 60-day reform review begins

  • August 14

    deadline for industry responses to the DoD’s request for information

    2026

  • 2026

    Gauge Gauge

    September

    CMMC Reform Task Force report expected

  • Phase 2, 3, and 4 dates — suspended, pending the review

    Light-down Light-down

    2026-2028

Top do’s and don’ts for CMMC right now

Do

  • Keep your self-assessment and SPRS score current. This is the active requirement today. A contract can still require a passing self-assessment posted in SPRS before award, and an out-of-date score can cost you an opportunity.
  • Use your free consultation. Schedule a 30-minute session with one of our engineers. Some businesses learn they only need Level 1, not Level 2. You can also take advantage of free or low-cost CMMC training.
  • Know your level. Level 1 (self-assessment) covers FCI. Level 2 covers CUI. If you sell purely commercial off-the-shelf products, like office furniture, you’re generally exempt — but if you handle CUI, compliance still applies.
  • Start with a gap analysis. Measure what you have in place against the 110 controls and find what’s missing. Catching gaps early gives you room to fix them without a scramble later.
  • Budget for the work. Compliance is an investment, not just an IT purchase. E-N Computers can assess where you stand, find the gaps, and build a cost-effective roadmap — including where government grants might help.
  • Consider CMMC managed IT services. Outsourcing the day-to-day keeps your controls current between assessments instead of letting them drift. See the details.
  • Stay updated. The program is under active review, so watch for changes. The best sources are the DoD CIO’s CMMC page, the Federal Register, and The Cyber AB.

Don’t

  • Don’t treat the suspension as the finish line. “Suspended” is not “canceled.” If your program lapses and a reformed requirement lands, you’ll be scrambling again — with a gap in your SPRS history that a contracting officer can see.
  • Don’t treat the rollout calendar as your deadline. It’s a DoD schedule, not your compliance date. Your real deadline is tied to your own contracts (see below).
  • Don’t cancel a certification project you’ve already started. The work to meet NIST 800-171 is exactly what a reformed program will measure you against, so it isn’t wasted. You can slow down and do it right — you don’t have to stop.
  • Don’t start late. If you’re beginning from scratch, expect 12–18 months. The longest part is implementing controls and writing documentation, not the assessment itself. Companies already aligned with NIST 800-171 have a shorter road.

Common questions about the CMMC timeline

Is CMMC canceled? No. Phase 2 and the later phases are suspended while the DoD reviews the program, but the duty to protect federal data, the NIST 800-171 standard, and Phase 1 self-assessments all remain in force. Officials have said the review could lead to significant changes, so the program’s shape may look different when it resumes — but the underlying security requirement isn’t going anywhere.

Do I still need to self-assess? Yes. Phase 1 self-assessments stay in place, and a contract can still require a current self-assessment and SPRS score before award. During the review, the DoD is enforcing NIST 800-171 through self-assessments and select government-led assessments.

Should I stop preparing or cancel my third-party assessment? Don’t stop preparing. If you’d booked a C3PAO audit for the old November deadline, you can step back from that scramble — but keep the underlying readiness work going. If your assessor will convert a scheduled audit into a mock assessment, that’s a useful way to check your self-assessment score without paying for a certification you may not need yet.

Is there a final compliance deadline? Not a single universal one — and even less so now. Your real deadline is tied to when your specific opportunities are solicited and awarded, a window called Procurement Administrative Lead Time (PALT). For many small contractors chasing sub-$10M awards, that can be 90 days or less from solicitation to award — far too short to start implementing from scratch. Most contractors need to begin 12–18 months ahead.

Do primes and subcontractors have different deadlines? There’s no single date for either. It comes down to when a requirement lands in a specific contract — and primes often set their own deadlines for subs, regardless of the federal timeline.

Can I bid while working toward compliance? Sometimes. If you provide services that don’t involve handling CUI, you may still qualify. If you handle sensitive data like defense equipment drawings, you’ll generally need to meet the required level before you can bid.

How do I find my actual deadline? Look up your customer’s long-range acquisition forecast. DoD components publish these publicly on their Office of Small Business Programs sites. They show anticipated solicitation and award quarters, which lets you work backward and figure out how much runway you really have.

Where this leaves you

The suspension bought time, not a pass. The smart move is to use it: get your self-assessment honest, close the gaps you’ve been putting off, and keep your documentation current so you’re ready no matter which version of the rules comes out of the review.

If you’re not sure where the suspension leaves you — whether your self-assessment would hold up, whether your SPRS score reflects what’s really in place, or whether to keep going on a project you’d already started — that’s worth a short conversation. E-N Computers works with defense contractors across Virginia and the DC metro area on exactly these questions, and we manage the compliance work so it stays current instead of going stale between assessments.

References

  • U.S. Department of Defense CIO: CMMC Overview
  • Federal Register: CMMC Program Final Rule (32 CFR)
  • National Institute of Standards and Technology: NIST SP 800-171
  • The Cyber AB: Official website

Complimentary review with an experienced engineer

Are you ready for CMMC?

IT maturity assessment

Get a free strategic consultation to start or streamline your journey toward CMMC compliance.

Reserve an appointment

Next steps

If your business works with the DoD, now is the time to start your CMMC compliance journey. The process can be complex, but getting ahead of the deadlines will help you stay eligible for contracts without unnecessary stress.

Need help with CMMC compliance? Contact our team to learn how we can assist you in preparing for certification and securing your DoD contracts.

Related articles:

Learn more about CMMC

Guides, case studies, and tools for defense contractors navigating compliance

CMMC Managed IT

Virginia CMMC Managed IT Services

Best CMMC managed IT services providers in the DMV

Best Virginia CMMC managed IT services providers

Finding help

Best CMMC consultants

Best CMMC RPOs near Washington, DC

Best Virginia Registered Practitioner Organizations

Case Study: Virginia Government Contractor Nears CMMC Compliance

CMMC Gap Analysis

Best CMMC assessors near Washington, DC

CMMC consulting services for small and medium-sized businesses

Virginia CMMC consulting services

Washington, DC CMMC consulting services

Understanding CMMC

The Ultimate Guide to CMMC

The Ultimate Guide to DFARS and NIST 800-171 (in plain English)

What is FCI and should I worry about it?

What is CUI and should I worry about it?

CMMC compliance deadlines: Key dates and what they mean

Is CMMC worth the cost?

Tools & training

How to buy GCC High and what’s involved

We found the best GRC tool for CMMC

What is Microsoft GCC High and do I need it?

Best CMMC training resources

CMMC Level 1 guide as audio book

CMMC Level 2 guide as audio book

CUI enclaves in CMMC compliance: Are they right for your business?

Search Search

Categories

  • Best of
  • Business-IT Strategy
  • Compliance
  • Cybersecurity
  • Internet, Telephone, & VoIP
  • IT Hiring
  • Managed IT Services
  • Tech Tools & Tips
  • Uncategorized

Recent Posts

  • What is the cost of managed IT services for an accounting firm in Virginia? July 31, 2026
  • What is the cost of managed IT for manufacturing firms in 2026? July 31, 2026
  • How much does managed IT cost for engineering design firms in 2026? July 28, 2026
  • Reg S-P compliance after June 3: what SEC examiners will look for July 14, 2026
  • CMMC Phase 2 is suspended. What Virginia defense contractors should do now. July 14, 2026
EN Computers logo

Industries

Accounting & CPA

Construction & Architecture

Defense Contractors

Education (K-12)

Financial Services

Government Contractors

Healthcare

Investment Advisors

Law Firms

Manufacturers

Marketing & Advertising

Nonprofit Organizations

 

 

Locations

Waynesboro, VA
Corporate HQ

215 Fifth St.
Waynesboro, VA 22980

Sales: 540-217-6261
Service: 540-885-3129
Accounting:  540-217-6260
Fax: 703-935-2665

Washington D.C.
1126 11th ST. NW
Suite 603
Washington, DC 20001-4366

Sales: 202-888-2770
Service: 866-692-9082

VA DCJS # 11-6604

Locations

Harrisonburg, VA
45 Newman Ave.
Harrisonburg, VA 22801

Sales: 540-569-3465
Service: 866-692-9082

Richmond, VA
3026A W. Cary St.
Richmond, VA 23221

Sales: 804-729-8835
Service: 866-692-9082

Website by Abstrakt Marketing Group © 2026
  • Privacy Policy
  • Sitemap
  • Linkedin
  • Facebook
  • Youtube
Scroll to top Scroll to top Scroll to top