CMMC Intel Report

The CMMC Reset: A Closer Look

What the CMMC Phase 2 suspension means for defense contractors—and what to do next

The Department of War suspended CMMC Phase 2 on July 13, 2026, pausing the third-party C3PAO certification requirement that was scheduled to appear in new contracts starting November 10, 2026.

But the pause does not mean cybersecurity requirements have gone away.

Phase 1 remains in effect, the November 10, 2026 SPRS self-attestation deadline is unchanged, and existing DFARS cybersecurity requirements continue to apply.

Get the CMMC Intel Report

Fill in your details to access the report and understand what the CMMC reset means for your organization.

What’s Inside the Report

The CMMC landscape has changed, but the compliance work has not disappeared.

Download the report to understand:

What changed: Why CMMC Phase 2 was suspended and what the decision means for defense contractors.

What remains mandatory: Why Phase 1 self-attestation and the November 10, 2026 SPRS deadline remain unchanged.

What happens to DFARS 7012: Why NIST SP 800-171 Revision 2 remains the contractual baseline during the pause.

What the pause means for certification: How third-party C3PAO certification may evolve when the program returns.

What contractors should do now: Practical considerations for organizations that are already certified, undergoing assessment, self-attesting, or working with a compliance partner.

What comes next: Key signals around certification narrowing, timeline changes, and potential assessor-market consolidation.

How to stay prepared: Why monitoring, evidence, documentation, remediation, and accurate SPRS attestation remain important during the pause.

CMMC Is Paused. Your Compliance Work Isn't.

The report explains why organizations should not treat the Phase 2 suspension as a reason to stop preparing.

For organizations that are self-attesting, the November 10 deadline remains in place. For organizations already certified or undergoing assessment, the report outlines considerations for maintaining readiness while the program is under review.

Where Netsmartz Can Help

Netsmartz can support organizations across the CMMC readiness journey—from assessment and remediation to continuous monitoring and future certification readiness.

Assess

Review and score all 110 NIST SP 800-171 Revision 2 practices using the DoD methodology.

Remediate

Address gaps across identity, endpoint, network, and Microsoft 365 while establishing the monitoring needed to support those controls.

Certify

When third-party certification resumes, support readiness reviews, evidence preparation, and coordination with an independent C3PAO.

A Practical Path to CMMC Readiness

Netsmartz’s engagement can include:

  • Gap Assessment
  • System Security Plan (SSP) and POA&M
  • CUI Scope and Enclave Design
  • Remediation Engineering
  • Managed Detection & Response
  • Assessment Support

This approach helps organizations strengthen the controls that remain important regardless of how the CMMC program evolves.

Beyond CMMC

The same security and compliance foundation can support additional requirements such as SOC 2, HITRUST, PCI DSS, ISO 27001, and accredited penetration testing—allowing evidence and controls developed for one requirement to support broader compliance needs.

Start With a CMMC Scoping Call

Not sure what the current CMMC changes mean for your organization?

Schedule a 30-minute scoping call with the Netsmartz team to review what your contracts require, where your CUI resides, and where your SPRS score stands today.

You leave with a written scope, a scored gap view, and a prioritized plan toward November 10; whether or not you ultimately pursue certification.

Talk to a CMMC Expert