inTech Consulting logo - Managed IT services and cybersecurity in the Pacific Northwest

Is CMMC Level 2 Certification Still Required After the Phase 2 Suspension?

No, not the third-party version. On July 13, 2026, the Department of War suspended CMMC Phase 2, the mandatory third-party (C3PAO) audit that was scheduled to take effect November 10, 2026. For now, contracting officers can only require Level 1 or Level 2 self-assessments, not outside certification.

That said, don’t read too much into this. NIST SP 800-171’s 110 controls and DFARS clause 252.204-7012 are still federal law for any contractor handling Controlled Unclassified Information (CUI). A CMMC Reform Task Force is reviewing the program right now, and its report is due around mid-September 2026. Most signs point to a redesign, not a repeal.

If you’re a Pacific Northwest aerospace supplier or DoD manufacturer, here’s the short version: the audit deadline moved. The underlying obligation to protect CUI didn’t.

Why the Pause Actually Happened

This wasn’t a policy retreat. It was a math problem. Over 120,000 small and mid-sized defense contractors needed third-party certification, and there were only about 100 approved C3PAO assessor organizations available to do the work nationwide. That’s a bottleneck no amount of urgency solves, and the Small Business Administration publicly welcomed the suspension as relief for smaller primes and subs who were staring down long assessment queues and rising costs.

Enforcement hasn’t gone anywhere in the meantime. DoD is enforcing NIST 800-171 compliance directly, and False Claims Act exposure for misrepresented compliance is still very much active. One contractor was recently ordered to pay over half a million dollars for exactly that kind of misrepresentation.

What This Means, Depending on Where You Are Today

1. Just Starting Your CMMC Journey

You still need to build toward the 110 controls in NIST 800-171. That part hasn’t paused. What has changed is the pressure: there’s no C3PAO audit deadline forcing you to rush. Use this window to build a proper System Security Plan (SSP) and Plan of Action and Milestones (POA&M), rather than racing a November deadline and leaving gaps you’ll end up paying for later. Our CMMC compliance team can help you map this out from scratch.

2. Mid-Readiness, With Gaps Identified

Keep going. The suspension removes the third-party audit requirement, not the control requirements your contracts already reference. Contracting officers can still require a Level 2 self-assessment today, and falling behind now just means starting from further back once the Reform Task Force publishes its findings.

3. Lined Up for a C3PAO Audit

Your scheduled assessment is on hold. Phase 2 and every later milestone are suspended, and contracting officers have been directed to remove Phase 2/3 language from existing contracts at the next administrative modification. That’s not a reason to stand down, though. Your documented controls, SSP, and POA&M still satisfy your current self-assessment obligation, and whatever reformed framework emerges will very likely lean on this same body of evidence.

4. Already Certified

You’re in the strongest position in the Defense Industrial Base right now. Certified primes are already fielding flow-down questions from subcontractors, and that edge doesn’t disappear just because the audit mandate paused. If anything, it’s a real differentiator while your competitors wait to see what happens next.

A Practical Framework for the Next 60 Days

  1. Assess your current control posture against NIST 800-171 Rev. 2, regardless of audit status.
  2. Document thoroughly. Keep your SSP and POA&M current, since self-assessment scores still get submitted to SPRS.
  3. Monitor the CMMC Reform Task Force’s RFI process and its September report. Don’t build plans around assumptions.
  4. Maintain SIEM, MDR, and access controls at Level 2 standards, supported by cybersecurity services, even without an audit forcing the issue.
  5. Position yourself to move fast. Use this pause to close gaps now, while there’s no deadline pressure, instead of scrambling later.

An Illustrative Scenario

Picture a 90-person aerospace machining supplier in Everett, WA, about six months into CMMC Level 2 prep, with roughly 70% of controls implemented and a C3PAO audit tentatively booked for October. With Phase 2 suspended, that audit comes off the calendar. But the company still needs a current Level 2 self-assessment score in SPRS to satisfy its prime’s flow-down requirements. The realistic path forward is to finish the remaining controls over the next 60 to 90 days, submit the self-assessment, and stay ready for whatever the Reform Task Force ultimately publishes. This is a representative example, not a specific client engagement.

What This Means for Your Business

Get Your CMMC Readiness Checklist
See exactly where your controls, SSP, and POA&M stand today, before the Reform Task Force’s report changes the requirements again. Download the CMMC Readiness Checklist.

Bottom Line

CMMC isn’t going away. The audit mechanism is being redesigned. NIST 800-171 and DFARS 252.204-7012 still govern anyone handling CUI, full stop. Pacific Northwest manufacturers and aerospace suppliers who keep building toward Level 2 during this window will be ready to move the moment the Reform Task Force’s findings land, instead of scrambling from behind everyone else.

inTech Consulting works with aerospace and DoD manufacturers across the Pacific Northwest on CMMC compliance readiness, SIEM and MDR, and 24/7 SOC monitoring, built for exactly this kind of regulatory shift.

Talk to Raj About Where You Stand
Book a free 30-minute readiness call to map your current compliance gaps against what’s likely coming next. Schedule with Raj.