CMMC Phase 2 was suspended on July 13, 2026, but Phase 1 self-assessments, DFARS 252.204-7012, and SPRS scoring stay in force for Texas defense contractors. The certification deadline moved. Your NIST 800-171 obligation did not.
The Department of War paused CMMC Phase 2 on July 13, 2026, pulling the November 10, 2026 third-party certification requirement off the calendar while a reform task force reviews the program. Everything underneath it survived. Texas contractors still owe a current SPRS score, an annual affirmation, and full NIST 800-171 Rev 2 implementation, and several primes are still enforcing their own supplier deadlines. If you were building toward CMMC and NIST 800-171 compliance in Texas, keep building.
What is the CMMC 2.0 timeline right now?
The CMMC 2.0 timeline is the phased schedule the Defense Department uses to write certification requirements into contracts. Phase 1 began November 10, 2025 and requires self-assessments. Phases 2 through 4, which add third-party and government-led assessments, are suspended as of July 13, 2026 pending a program review.
That is the short version. It is also where most contractors stop reading, which is a mistake, because the pause did something unusual. It removed the enforcement date without removing a single security requirement. Read the announcement as permission to stand down and you have misread it. The gap between those two interpretations is where contract eligibility and False Claims Act exposure now live.
What the Department of War actually paused on July 13, 2026

On July 13, 2026, DoD Chief Information Officer Kirsten Davies and Under Secretary for Acquisition and Sustainment Michael Duffey announced the immediate suspension of CMMC Phase 2, which had been set to begin November 10, 2026. A CMMC Reform Task Force was stood up the same day with a 60-day window to review the program and report back. DefenseScoop covered the announcement the day it happened.
The stated reason was arithmetic, not policy. Davies put it bluntly, saying “the math just simply doesn’t math for small to medium-sized businesses to even get compliant by the transition date.” She cited Small Business Administration data suggesting the later phases could cost small and midsize firms more than $7 billion a year. The capacity numbers were worse. More than 100,000 companies in the defense industrial base needed third-party assessments against roughly 100 authorized assessor organizations. That is not a backlog. It is a wall.
The Small Business Administration backed the decision the same day and published its own per-firm estimates, roughly $593,800 for a small business needing a third-party assessment and about $388,600 for one eligible to self-assess. Duffey framed the pause as market preservation, saying it keeps “more companies in the DIB who would otherwise be forced out of the market at a time when we need them most.”
Davies was also careful about what the pause was not. “We are not reducing cybersecurity through this measure,” she said. “We are reducing the red tape.” Read that twice if you supply the Defense Department. It is the whole story. The paperwork gate came down. The security floor did not move.
What Texas defense contractors still owe today
This is the part the headlines lost. The suspension touched the CMMC assessment layer and nothing beneath it. Every obligation below was in force on July 12. All of them are still in force today.
- DFARS 252.204-7012. Unchanged since 2017. You must implement NIST SP 800-171 Rev 2 and report cyber incidents to DoD within 72 hours. The pause did not touch this clause.
- DFARS 252.204-7019 and 7020. You must have a current NIST 800-171 self-assessment posted in the Supplier Performance Risk System, and DoD retains the right to run a higher-level assessment. Both clauses are still live at acquisition.gov.
- Your SPRS score. Scored out of 110, one point deducted per unimplemented control, with some controls weighted at 3 or 5 points. A stale score is a compliance finding on its own.
- The annual affirmation. A named Affirming Official attests each year that your implementation is accurate. That signature is a personal legal exposure, not a formality.
- Phase 1 self-assessment requirements. Contracts awarded under Phase 1 still carry Level 1 and Level 2 self-assessment conditions, and those contracts do not unwind because Phase 2 slipped.
There is a sharper edge here than most contractors appreciate. The Justice Department has been treating inflated SPRS scores as False Claims Act violations under its Civil Cyber-Fraud Initiative, and it is winning. In June 2026, a Huntsville contractor settled for $507,144 over unimplemented NIST 800-171 controls on two Navy contracts. Cybersecurity-specific FCA recoveries rose 233% year over year in fiscal 2025. None of that enforcement paused. Not one piece of it.
So the honest framing is this. Certification got easier to schedule. Misstating your security posture got no safer. If anything it got riskier, because with the third-party assessment gate down, your self-reported score now carries more weight than it did a month ago and the government has fewer chances to catch an inaccurate one before it hardens into a claim.
The CMMC timeline, phase by phase, with current status
Here is the full rollout as written into the 32 CFR program rule and the DFARS acquisition rule, next to where each phase actually stands after the July announcement.
| Phase | Original date | What it required | Status as of July 2026 |
|---|---|---|---|
| Program rule effective | December 16, 2024 | 32 CFR Part 170 establishes the CMMC program | In effect |
| Acquisition rule effective | November 10, 2025 | DFARS 252.204-7021 becomes insertable in solicitations | In effect |
| Phase 1 | November 10, 2025 | Level 1 and Level 2 self-assessments as a condition of award | Active and enforced |
| Phase 2 | November 10, 2026 | Level 2 C3PAO certification required for new awards | Suspended July 13, 2026 |
| Phase 3 | November 10, 2027 | Level 3 DIBCAC assessments, Level 2 on option exercises | Suspended pending review |
| Phase 4 | November 10, 2028 | Full implementation across all applicable contracts | Suspended pending review |
Notice what the right column never says. Cancelled. Every legal analysis of the announcement, including the WilmerHale client alert published a week later, lands on the same read. This is a suspension with a review attached, and the underlying rules are still on the books. Reform is likelier than repeal.
Why San Antonio contractors have the least room to relax

Texas carries more defense exposure than any other state, and San Antonio carries more cyber exposure than anywhere in Texas. Military installations generated an estimated $148.8 billion in economic output statewide in 2025 and supported nearly 629,000 jobs. Joint Base San Antonio is the largest joint base in the department. The 16th Air Force, which runs Air Forces Cyber, is headquartered at JBSA-Lackland, and the NSA Texas Cryptologic Center sits in the same city.
That concentration changes the risk math for local suppliers. The 16th Air Force has run joint threat-sharing efforts with San Antonio industry partners precisely because the contractor base around Port San Antonio and JBSA touches mission systems. When your customer is the organization that defends Air Force networks, “we were waiting on the rule” does not travel well. Nobody here is waiting.
The practical pressure is coming from primes, not from the Pentagon. Prime flow-down clauses did not pause when Phase 2 did, and several primes have kept their supplier deadlines exactly where they were. L3Harris Missile Solutions held its July 30, 2026 date for proof of Level 2 certification. Elbit Systems issued a supplier notice on July 16 telling vendors to confirm assessment requirements with their buyer rather than assume a cancellation, as Secureframe documented. Your contract with a prime is a private agreement. A federal pause does not rewrite it. Check yours.
If you supply into JBSA missions or sit anywhere in the Port San Antonio ecosystem, the safe operating assumption is that your buyer still expects evidence this year regardless of what the Federal Register currently says about Phase 2. We go deeper on the local picture in our guide to CMMC compliance IT services in San Antonio, including why a full GCC High migration is often the wrong first move.
What the reform task force could still change
The task force has a narrow mandate and a short clock. It issued a request for information asking industry about cost drivers, administrative burden, which specific controls produce real security outcomes, and where commercial solutions could substitute for custom compliance work. Responses were due by 12 p.m. Eastern on August 14, 2026. The final report to the CIO lands roughly 60 days from the July 13 announcement, which puts recommendations in mid-September.
Nobody outside the building knows what comes back. Based on the RFI questions and what Crowell and Moring flagged in its analysis, the plausible outcomes cluster into a few shapes.
- A longer runway. Phase 2 returns with a later start date once assessor capacity catches up. This is the least disruptive path and the most likely.
- A smaller scope. Fewer contracts trigger third-party assessment, or the Level 2 threshold moves so more suppliers stay in self-assessment territory.
- A trimmed control set. The RFI explicitly asked which controls deliver tangible outcomes, which reads like an opening for pruning the 110.
- More self-attestation, more enforcement. If the assessment gate stays down, expect the False Claims Act to do more of the work. That trade is already visible.
None of those outcomes change the floor. NIST 800-171 has been contractually required since 2017 through DFARS 7012, and no version of this review is going to tell defense suppliers they can stop protecting controlled unclassified information. Building to the 110 controls pays off under every scenario on that list. That is the whole point.
What to do in the next 90 days

The pause bought you time, not relief. Use it. The contractors who move now will walk into Phase 2 whenever it returns with their evidence already assembled, their scope already documented, and their score already defensible. The ones who treat this as a reprieve will land in the same assessor queue a year later, behind everyone who did the work. Here is the sequence we run with clients.
- Confirm your SPRS score is current and defensible. Pull the actual score, check the date, and make sure the number matches what your environment can prove. If it was optimistic, fix the environment before the next affirmation.
- Map where controlled unclassified information actually lives. Most contractors are wrong about this, usually because CUI has quietly spread into email, shared drives, and a couple of engineering workstations nobody scoped.
- Run a 110-control gap assessment against NIST 800-171 Rev 2. Document every gap with an owner and a date. This becomes your plan of action and milestones, and it is the artifact an assessor asks for first.
- Decide your enclave strategy before you spend money on it. Scoping CUI into a segmented, encrypted environment on Microsoft 365 Commercial is cheaper and faster than a full GCC High migration for most suppliers, and it shrinks your assessment boundary.
- Write the System Security Plan properly. Not a template with your name swapped in. A real SSP that describes how each control is implemented in your environment, because that document is what gets audited.
- Ask every prime you supply what their current expectation is, in writing. Their deadline governs your business regardless of what the Federal Register says.
- Rehearse the affirmation. Sit your Affirming Official down with the evidence and see whether they would still sign. If they hesitate, you have found your real gap.
One honest caveat on that list. Step 4 is where we see the most expensive mistakes, in both directions. Some suppliers over-buy and migrate their entire tenant to GCC High when only a handful of people ever touch CUI. Others under-scope and quietly leave controlled data in a general-purpose environment that will never pass. The right answer depends on your contract mix and your data flow, and it is worth getting a second opinion before you commit a budget to it.
Where Uprite fits, and where we do not

Straight answer first. Uprite is not a C3PAO. We do not conduct CMMC assessments and we will not pretend otherwise, because any provider claiming they can both build your environment and certify it is describing a conflict of interest rather than a service. What we do is build and run the IT environment that passes the assessment when someone independent conducts it.
That work is concrete. A 110-control gap assessment against NIST 800-171 Rev 2, remediation with owners and dates, an encrypted CUI enclave on Microsoft 365 Commercial where a full GCC High migration is not warranted, a System Security Plan and evidence library that survives review, and ongoing managed security after the assessment so the score does not drift. We have offices in Houston, San Antonio, and Dallas-Fort Worth, we triage issues in under 10 minutes, and we back the relationship with a 120-day satisfaction guarantee. We have also been named to the MSP 501 list 7 years running, most recently at No. 264 in 2026.
For defense suppliers who also carry state-level obligations, the same control work tends to satisfy more than one requirement at once. Our breakdown of the Texas SB 2610 safe harbor explains how a recognized framework can reduce breach liability under state law, and our San Antonio cybersecurity services team handles the monitoring layer that both CMMC and cyber insurance underwriters expect to see.
Not sure where your SPRS score actually stands?
We will run a 110-control gap assessment against NIST 800-171 Rev 2, show you exactly which controls are costing you points, and tell you honestly whether an enclave or a GCC High migration is the right call. Call (866) 570-3065 or request a consultation.
Questions Texas defense contractors are asking right now
Is CMMC cancelled?
No. CMMC Phase 2 is suspended, not cancelled, and Phase 1 remains active. The 32 CFR program rule and the DFARS acquisition rule are both still on the books. A reform task force is reviewing the program and recommendations were due to the DoD CIO in mid-September 2026. Expect changes to scope or timing rather than repeal.
Do I still need a SPRS score during the pause?
Yes, and this catches people out. DFARS 252.204-7019 and 7020 were untouched by the July 13 announcement, so a current NIST 800-171 self-assessment posted in SPRS is still a condition of doing business with the Defense Department. Your annual affirmation obligation is also unchanged.
My prime still wants CMMC Level 2 certification. Can I tell them the deadline moved?
Not really. Prime flow-down requirements are contractual agreements between you and the prime, and a federal pause does not amend them. L3Harris Missile Solutions kept its July 30, 2026 supplier deadline. Elbit Systems told suppliers to confirm requirements with their buyer rather than assume cancellation. Ask your prime directly and get the answer in writing.
What happens to a Level 2 assessment I already scheduled with a C3PAO?
You can generally proceed, and many contractors are choosing to. An assessment completed now still demonstrates your posture to primes, and it puts you ahead of the queue whenever Phase 2 resumes. Confirm with the C3PAO and with any prime that required it, since some buyers have paused their own requests while others have not.
Does the pause affect defense contractors in San Antonio differently?
It affects them less, in practice. San Antonio suppliers work around Joint Base San Antonio, the 16th Air Force, and the NSA Texas Cryptologic Center, where prime and program-office expectations tend to run ahead of the regulatory floor. Local buyers were asking for evidence before the rule required it and most are still asking now.
If Phase 2 is paused, what is the actual risk of doing nothing?
False Claims Act exposure, and it is not theoretical. The Justice Department settled a NIST 800-171 case for $507,144 in June 2026, and cybersecurity FCA recoveries rose 233% year over year in fiscal 2025. With the third-party assessment gate down, your self-reported score carries more weight, and a signed affirmation that does not match reality is the exposure.










