08/25/2026
CMMC Phase 2 is suspended but your security shouldn’t be 🔒
DoD has suspended CMMC Phase 2 third-party assessments and paused subsequent rollout milestones until further notice, with a 60-day CMMC Reform Task Force review now underway as DoD reconsiders how the program is implemented.
CMMC Level 1 and Level 2 self-assessments and the annual affirmation in SPRS (Phase 1) remain in effect. While the rollout details may change, the baseline requirements — the 110 controls of NIST SP 800-171 Rev. 2 under DFARS 252.204-7012 — remain the same.
At ACS, we don't just focus on compliance checklists—we focus on your business. Whether you're a full-time DoD contractor or an organization with only a portion of your work supporting the government, your cybersecurity strategy should be built around your business processes, not just an audit.
Don't wait for the review to conclude. Use this time to move beyond temporary fixes and build a security program that will last.
Talk to an ACS CMMC expert before your next RFP deadline — book a 30-minute consult: https://www.agilecyberseal.com/contact/ ⬅️