CMMC Deadline & Compliance Timeline: Complete Guide [2026]

SaltyCloud Research Team

Updated Oct 8, 2026 Read Time 14 min

CMMC Deadline & Compliance Timeline: What’s Required Now

The CMMC and deadlines have had a complicated relationship across the program’s entire timeline. From Executive Order 13556 to DFARS Clause 252.204-7012, CMMC 1.0 to CMMC 2.0, and the CMMC Final Rule (32 CFR) to Phase I self-assessment requirements, the CMMC program has a history full of shifting deadlines.

Most recently, the Department of Defense (DoD) paused its CMMC Phase II requirements on July 13, 2026, four months before they were scheduled to take effect on November 10, 2026. Phase I self-assessment requirements remain active for now, and the DoD has not said when or whether the later phases resume.

This guide covers the complete CMMC timeline and all of its deadlines, including the most recent suspension. It also explains what contractors can do until the DoD issues further guidance.

See all 149 CMMC Level 1 to Level 3 requirements and 457 assessment objectives in one workbook.
Compare NIST 800-171 references with mappings to NIST 800-53, CSF 2.0, SOC 2, ISO 27001, and HIPAA controls.

Access the NIST 800-53 Multi-Framework Crosswalk →

CMMC Timelines and CMMC Deadlines

The Cybersecurity Maturity Model Certification (CMMC) program has a timeline full of conflicting deadlines.

The DoD built the program to introduce CMMC requirements into defense contracts gradually, giving contractors and assessors time to prepare, and then suspended that schedule in July 2026.

A CMMC timeline is the dated record of how the program reached defense contracts, running from Executive Order 13556 in 2010 through the Phase 2 suspension in 2026. A CMMC deadline is the date one requirement comes due, such as the yearly Level 1 self-assessment or the annual affirmation an official signs.

A closer look at the CMMC timeline, the deadlines that still apply, and how long compliance work usually takes can help separate the three.

CMMC Timeline [2010 to 2026]

The CMMC timeline is the sequence of executive orders, federal rules, model versions, and rollout phases from 2010 to 2026. Each entry below marks a point where the program or the requirements behind it changed.

CUI and DFARS Foundations

  • November 4, 2010: Executive Order 13556 established a single government-wide program for Controlled Unclassified Information (CUI) and named the National Archives and Records Administration as its executive agent.
  • October 21, 2016: A Defense Federal Acquisition Regulation Supplement (DFARS) final rule put DFARS 252.204-7012 in essentially its current form, requiring contractors to safeguard covered defense information and report cyber incidents.
  • December 31, 2017: The deadline for full implementation of National Institute of Standards and Technology Special Publication 800-171 (NIST SP 800-171) passed. A December 30, 2015 interim amendment had set that date, and since compliance rested on each contractor’s own word, the DoD Inspector General later reported that contracting officials had no process for verifying those claims.
  • October 21, 2019: At a press briefing, Under Secretary of Defense for Acquisition and Sustainment Ellen M. Lord said the department had released CMMC model version 0.4 for public comment in September and received more than 2,000 comments.

CMMC Version 1.0

  • January 31, 2020: The DoD released CMMC version 1.0, a five-level maturity model that required third-party certification at every level.
  • September 29, 2020: An interim DFARS rule added the NIST SP 800-171 assessment and CMMC clauses, DFARS 252.204-7019, 252.204-7020, and 252.204-7021, effective November 30, 2020.

CMMC Version 2.0

  • November 4, 2021: The DoD announced CMMC 2.0, which cut five levels to three, renamed them Foundational, Advanced, and Expert, and returned Level 1 and some Level 2 contracts to self-assessment.
  • December 16, 2024: 32 CFR part 170, the CMMC Program rule, took effect and set the levels, assessment types, and affirmation requirements in federal regulation.
  • November 10, 2025: The CMMC acquisition rule took effect and Phase 1 began, letting contracting officers require Level 1 and eligible Level 2 self-assessments as a condition of award.
  • February 1, 2026: The Revolutionary FAR Overhaul class deviations took effect, directing contracting officers to a new DFARS part 240 for information security and supply chain security clauses.

CMMC Phase 2 Pause

  • July 13, 2026: The DoD suspended Phase 2 and every milestone after it, pending a 60-day review by a newly created CMMC Reform Task Force.
  • August 14, 2026: Comments on the reform request for information closed, drawing more than 1,100 responses.
  • September 3, 2026: Class Deviation 2026-O0025, Revision 3 turned the pause into binding contract language, directing contracting officers to remove or revise CMMC requirements in new and existing solicitations and contracts.

As of October 2026, the Task Force’s report remains unpublished, and the DoD CIO’s CMMC page still lists implementation as paused in Phase 1.

CMMC Deadlines

Four recurring deadlines still apply during the suspension, and none of them depend on Phase 2 resuming. They come from 32 CFR part 170 and the contract clauses, not from the phase schedule.

  • Annual Level 1 self-assessment: Level 1 status expires after a year under 32 CFR 170.15, so a contractor handling only Federal Contract Information (FCI) reassesses and reposts every twelve months.
  • Annual affirmation: An affirming official signs a statement of continuing compliance each year, on the anniversary of the last affirmation.
  • Three-year Level 2 self-assessment: Level 2 (Self) status lasts three years, and the yearly affirmation keeps it current in between.
  • 180-day Plan of Action and Milestones (POA&M) closeout: A contractor holding conditional CMMC status must remediate every unmet requirement, run a closeout self-assessment, and post the results to the Supplier Performance Risk System (SPRS) within 180 days of the conditional status date, or that status expires.

CMMC Compliance Timelines

The duration of a CMMC compliance timeline tends to be different for every organization, since no rule sets how long the work should take. Typically, the length depends on:

  • How many systems handle FCI or CUI
  • How much of NIST SP 800-171 Rev. 2 is already in place
  • How long remediation takes once the gaps are known

A contractor already meeting DFARS 252.204-7012 may need only a few weeks to document a Level 2 self-assessment. One starting from a low SPRS score more often spends a year or more closing requirements before the score reflects full implementation.

Because the 180-day closeout window starts at the conditional status date rather than at the start of the project, remediation planning usually sets the pace.

What Does CMMC Require Right Now?

Defense contracts can still require CMMC Level 1 and Level 2 self-assessments during the suspension. Meanwhile, the DFARS 252.204-7012 security duties already written into existing contracts continue unchanged.

CMMC Self-Assessments

As of October 2026, the DoD may require defense contractors to complete only CMMC Level 1 or Level 2 self-assessments during the suspension. In its July 13, 2026 announcement, the DoD kept Phase 1 requirements in force and suspended Phase 2 and all future CMMC implementation milestones.

Binding during the suspension Suspended CMMC designations
CMMC Level 1 (Self) CMMC Level 2 (C3PAO)
CMMC Level 2 (Self) CMMC Level 3 (DIBCAC)
Applicable DFARS 252.204-7012 safeguarding requirements Original November 2026 Phase 2 transition

Certified Third-Party Assessment Organizations (C3PAOs) conduct Level 2 assessments, and the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) conducts Level 3 assessments.

The DoD’s implementation procedures explain how to remove both from active solicitations and existing contracts.

  • Active solicitations: The responsible DoD program manager must initiate the amendment, and the contracting officer must issue it as soon as practicable.
  • Existing contracts: The contracting officer must remove those requirements before exercising the next option period or during the next scheduled administrative modification.

The DoD made these instructions binding on September 3, 2026, through Class Deviation 2026-O0025, Revision 3. It also kept NIST SP 800-171 Rev. 2 as the baseline standard under DFARS 252.204-7012.

The deviation stays in effect until the DoD cancels it or adds it to the acquisition regulations.

Government-Led Assessments

Although CMMC Level 3 designations in contracts are suspended, some government-led NIST SP 800-171 assessments may continue. DoD Medium and High assessments, for example, check how well a contractor has implemented NIST SP 800-171 under DFARS 252.204-7020, a separate authority from CMMC. Even though the DoD conducts both, a Medium or High assessment doesn’t count as a CMMC Level 3 assessment.

DFARS Clause Numbers

On February 1, 2026, the clause numbers behind CMMC changed for contracting officers, when Class Deviation 2026-O0025 directed them to a new DFARS part 240, Information Security and Supply Chain Security. A class deviation changes how contracting officers write solicitations without removing the older clause text from the regulations, so both sets of numbers stay in circulation.

  • Federal Acquisition Regulation (FAR) clause 52.204-21 was replaced by FAR 52.240-93, Basic Safeguarding of Covered Contractor Information Systems, which carries the same 15 requirements under the FAR Overhaul Part 40 text.
  • DFARS 252.240-7997, NIST SP 800-171 DoD Assessment Requirements, appears in the deviation and covers the same ground as DFARS 252.204-7020. Medium and High assessments remain, conducted by DIBCAC under NIST SP 800-171A.
  • DFARS 252.204-7019 has no counterpart in the deviation, though its clause text still appears in the codified DFARS.
  • DFARS 252.204-7012, 252.204-7021, and 252.204-7025 kept their numbers.

Contractors still post their CMMC status in SPRS, though that obligation now comes from the CMMC clauses and 32 CFR part 170.

Contractor Security Duties

Contractors must still protect two categories of information under clauses that exist independently of CMMC and are unaffected by the suspension:

  • FCI: The non-public information the government provides or generates under a contract, protected under FAR 52.204-21.
  • CUI: More sensitive information that requires safeguarding without being classified, protected under DFARS 252.204-7012.

DFARS 252.204-7012 also still requires contractors to:

  • Report cyber incidents
  • Preserve evidence from those incidents
  • Meet security standards when they use cloud services
  • Pass the applicable requirements down to their subcontractors

Exactly which obligations apply depends on the contract, the information a contractor handles, and the required CMMC level. See the CMMC requirements guide for who must comply and which safeguards, assessments, affirmations, and documentation are required at each level.

How the CMMC Rule-making Timeline Set the Dates

The CMMC program rests on two federal rules — the one that created it and the one that enforces it through defense contracts.

  • 32 CFR Part 170: The CMMC Program rule, published on October 15, 2024, defines the CMMC levels, assessment types, phased rollout, and affirmation requirements. It took effect on December 16, 2024.
  • 48 CFR and DFARS: The CMMC Acquisition rule, published on September 10, 2025, authorizes the DoD to include CMMC requirements in solicitations and contracts. It took effect on November 10, 2025, launching Phase 1 and setting the original yearly dates for Phases 2–4.

For more about how the program rule and acquisition rule work together, see the CMMC 2.0 rule and timeline guide.

The Original Four-Phase CMMC Rollout

Originally, the CMMC rules added assessment requirements in four phases, starting on November 10, 2025. Since the July 2026 suspension, however, every phase after Phase 1 is on hold.

Phase Original start date Original requirement Status in October 2026
Phase 1 November 10, 2025 Level 1 and eligible Level 2 self-assessments at DoD discretion Active
Phase 2 November 10, 2026 Level 2 C3PAO assessments for applicable acquisitions Suspended July 13, 2026
Phase 3 November 10, 2027 Broader Level 2 C3PAO use and selected Level 3 DIBCAC assessments Original planning baseline
Phase 4 November 10, 2028 CMMC requirements in all applicable contracts and option periods, with a commercially available off-the-shelf (COTS) exception Original planning baseline

Under the original schedule, each phase was scheduled to begin one year after the previous one, with full implementation planned for November 10, 2028. The only exception covered acquisitions made up entirely of COTS items.

Because the DoD has not announced a new Phase 2 date, Phase 2 will not start on November 10, 2026 as originally planned.

Until the DoD publishes a replacement schedule, November 2027 and November 2028 are reference points from the original plan, not deadlines.

How to Prepare for CMMC While Phase 2 Is Suspended

CMMC readiness depends on knowing which CMMC level each contract requires, maintaining the required safeguards, and keeping evidence up to date. The same work supports self-assessments today and prepares contractors for third-party assessments once Phase 2 resumes.

Five steps keep that work current while the phase schedule is on hold.

Step 1 — Confirm which CMMC level is required.

Check whether each contract involves FCI, which requires Level 1, or CUI under NIST SP 800-171 Rev. 2, which requires Level 2. Use the CUI and FCI scoping guide to identify which information a contract covers.

Step 2 — Run or re-run a self-assessment.

Review every required practice and keep evidence of how the organization carries each one out. Use the NIST SP 800-171 guide for details on the 110 Rev. 2 requirements behind CMMC Level 2.

Step 3 — Keep your SPRS records current.

Submit the NIST SP 800-171 DoD Basic Assessment score to SPRS, along with CMMC status, unique identifier, and affirmations. Renew Level 1 status every year, and affirm Level 2 and Level 3 status annually to keep it current across its three-year term.

Step 4 — Use POA&Ms only where permitted.

Do not use them at Level 1. At Levels 2 and 3, document only eligible unmet requirements and remediation deadlines, then close every POA&M item within 180 days of receiving conditional CMMC status.

Step 5 — Watch for official CMMC updates.

Follow the DoD CMMC page and the CMMC news and status guide for a replacement schedule.

Build a CMMC readiness plan before the next deadline.

Review all 149 CMMC Level 1–3 requirements and 457 assessment objectives, and map them to related framework controls.

Access the NIST 800-53 Multi-Framework Crosswalk →

How to Simplify CMMC Readiness

CMMC readiness depends on continuously reviewing requirements, collecting evidence, documenting findings, and tracking remediation. With no replacement deadline announced, security and compliance teams have to keep assessment responses, evidence, and remediation records current for an unknown stretch of time.

Spreadsheets and shared documents make that harder, since records spread across files and quickly fall out of date. A governance, risk, and compliance (GRC) platform solves that problem by keeping every step of the assessment process in one place.

Isora GRC links CMMC assessments with systems, evidence, risks, POA&Ms, and reporting so teams can run Level 1 and Level 2 self-assessments and maintain one review-ready record for annual affirmations and future assessments.

See the GRC Assessment Platform™ in action →

Assessment Management

Run CMMC assessments across departments without losing track of contributors, deadlines, or responses. In Isora, teams can group assessments by compliance goal, monitor status and participation, send reminders, enforce deadlines, and review responses in one dashboard, so completed work and outstanding items stay visible.

Learn more about Assessment Management with Isora GRC →

Inventory Management

Define CMMC scope by cataloging the assets, vendors, and applications that handle FCI or CUI. In Isora, teams can add data classifications and custom metadata, link inventory items to assessments and documents, track vendor product deployments, and search or filter records, so every in-scope item carries the context needed for review.

Learn more about Inventory Management with Isora GRC →

Risk Management

Move CMMC assessment findings into remediation without separating them from the controls and systems that produced them. In Isora, teams can publish findings directly to the risk register, assign owners, score and prioritize risks, track remediation plans and milestones, and preserve an audit log, so accountability remains clear through closure.

Learn more about Risk Management with Isora GRC →

Reports & Scorecards

Show CMMC readiness with scorecards and reports generated directly from live assessment data. In Isora, teams can compare results, review risk matrices and statistical insights, drill into responses with evidence and comments, and export PDF or CSV reports, so reviewers can trace each summary back to the underlying work.

Learn more about Reports & Scorecards with Isora GRC →

Key Takeaways

Phase 1 remains active, so contractors must maintain the required self-assessments and safeguards for FCI and CUI.

Under the September 3, 2026 class deviation, Phase 2 and all later implementation milestones remain suspended. As of October 2026, the DoD has not announced a replacement Phase 2 date or revised schedule. The original November 2027 and November 2028 dates are historical planning baselines, not current deadlines.

Contractors should confirm the CMMC level required by each contract, refresh self-assessments, maintain accurate SPRS records, use POA&Ms only where permitted, and keep evidence current.

Maintaining CMMC readiness becomes harder when assessments, evidence, inventories, and remediation records sit across disconnected files. Isora GRC connects this work in one GRC Assessment Platform™ so teams can sustain readiness as the timeline changes.

See how Isora GRC supports CMMC compliance →

CMMC Deadline FAQs

When is CMMC compliance required?

CMMC compliance is required once a DoD solicitation or contract includes the CMMC requirements. During the Phase 2 suspension, contracts can only require Level 1 or Level 2 self-assessments, but contractors must still meet their existing DFARS security obligations.

Is there a CMMC deadline in 2026?

No, not for Level 2 third-party assessments. The DoD suspended the Phase 2 start date of November 10, 2026, when Level 2 C3PAO assessments would have become mandatory, and hasn’t published a new date. The DoD’s instructions do not address voluntary C3PAO assessments, including ones already in progress.

What happened to the November 10, 2026 CMMC deadline?

The DoD suspended CMMC Phase 2 on July 13, 2026, before its planned November 10 start. As a result, contracting officers must update active solicitations to remove any Level 2 C3PAO or Level 3 DIBCAC assessment requirements. Existing contracts with those requirements must drop them before the next option period or during the next scheduled administrative modification.

When does CMMC go into effect?

CMMC went into effect in defense contracts on November 10, 2025, when Phase 1 began, and that phase remains active today. It followed two rules. The CMMC Program rule took effect on December 16, 2024, and the CMMC acquisition rule took effect on November 10, 2025, making CMMC enforceable through contracts.

What are the CMMC phases?

CMMC originally had four phases, each starting a year apart. Phase 1 introduced self-assessments, Phase 2 added Level 2 C3PAO assessments, Phase 3 added selected Level 3 DIBCAC assessments, and Phase 4 brought full implementation. Phase 1 remains active, but the DoD has suspended Phase 2 and every phase after it.

Is CMMC still happening after the suspension?

Yes, CMMC is still active. Phase 1 self-assessments continue, and contractors must still protect FCI and CUI under their existing contract clauses. Only the later phases are on hold, and the DoD’s September 3, 2026 class deviation keeps them paused until the DoD cancels it or adds it to the acquisition regulations.

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

Learn More
Our GRC Resources

Dive into our research-backed resources–from product one pagers and whitepapers, to webinars and more–and unlock the transformative potential of powerfully simple GRC.

Learn More
Get the InfoSec GRC Brief
Join 1,000+ CISOs, compliance officers, and risk managers reading the information security GRC news worth sharing.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo