ClickCerts
Back to all posts

CMMC Phase 2 Is Suspended. Your Training Obligation Isn't.

CMMC Phase 2 is on hold, but DFARS 7012, your NIST 800-171 self-assessment, and the training controls behind your SPRS score aren't. Here's what still applies.

July 14, 2026ClickCerts Team
CMMC Phase 2 Is Suspended. Your Training Obligation Isn't.

On July 13, the Department of Defense suspended CMMC Phase 2 — the rule that would have required companies handling controlled unclassified information to pass a third-party (C3PAO) assessment before contract award, starting November 10, 2026. The suspension arrived in a memo from DoD Chief Information Officer Kirsten Davies, and it reaches further than the headline: Phase 3 and every other pending CMMC milestone are frozen too, while a new Reform Task Force spends 60 days working out what the program should become. Contractors get a say through a public Request for Information, with responses due August 14.

A lot of companies spent the past year budgeting, scoping enclaves, and getting in line for an assessment. If that's you, here's where things actually stand.

What actually changed

The November 10 deadline is off the calendar. Contracting officers have been directed to amend active solicitations and contracts that already carried Level 2 C3PAO or Level 3 assessment requirements, stripping those clauses out. And for the duration of the review, DoD says it will enforce NIST SP 800-171 Rev 2 the old way: self-assessments, plus select government-led assessments.

The department's stated reason is cost and capacity. Davies cited Small Business Administration findings that pushing into the later phases could run small and mid-sized businesses north of $7 billion a year — approaching $600,000 per company in some cases — with more than 100,000 companies needing assessments and only about 100 organizations authorized to perform them. Her verdict: “the math just simply doesn't math.”

So is CMMC dead?

Unknown and notably, the officials running the review declined to rule out ending the program outright. It could return on new dates, return in a modified form, or be replaced by a different verification model entirely. That's exactly what the task force and the RFI responses will decide. Which means the worst planning move available right now is betting your compliance posture on a prediction about a 60-day study.

What you're still on the hook for

Five things survived the announcement untouched:

  1. DFARS 252.204-7012. The contract clause requiring you to safeguard covered defense information predates CMMC and is unaffected by the pause.

  2. Phase 1. Level 1 and Level 2 self-assessments, with annual affirmations, have been required on applicable contracts since November 2025 — and still are.

  3. NIST SP 800-171 Rev 2. All 110 requirements remain the standard you're assessing yourself against.

  4. Government-led assessments. DoD kept the option to check your work directly during the pause.

  5. The False Claims Act. DOJ's Civil Cyber-Fraud Initiative has spent years pursuing contractors that overstate their cybersecurity, and none of that machinery paused.

Training didn't get a pause either

Within those 110 requirements is the Awareness and Training family — 3.2, and it's short enough to summarize. Your users, managers, and admins need to understand the security risks tied to their roles and the policies that apply to them. Anyone with specific security duties needs training to carry those duties out. And everyone needs to know how to spot and report the signs of an insider threat.

When you post a self-assessment score to SPRS, you're attesting that these controls are in place. For training, “in place” can't mean a session somebody ran once in 2024. It means training happens on a cadence, covers the right people, and leaves a record.

Your records are now the whole audit

Here's what is buried in this news. Under Phase 2, an accredited assessor would have examined your evidence and signed off before the government relied on your score. Under the pause, nothing sits between your attestation and the government except your own files.

If a government assessor, a prime contractor, or a DOJ attorney ever asks you to substantiate the training controls behind your score, the answer is whatever documentation exists that day. A training program you can't produce records for is — for compliance purposes — a training program that didn't happen.

And primes aren't waiting on the task force. Many pushed cybersecurity requirements down their supply chains long before Phase 2 had a date, and few will loosen them because of a study. The subcontractor who can hand over clean proof of an active training program has an edge over the one who promises to pull something together.

Where ClickCerts fits

ClickCerts won't configure your firewall or write your System Security Plan. It does one job: it makes your training program provable.

Assign training to every employee, and reminders go out automatically until it's done — completion stops depending on someone remembering to nag employees. Every completion is logged with a date, and every certificate carries a unique serial number with a public verification page, so a prime or an assessor can confirm it's genuine in seconds.

When your annual affirmation comes around, the evidence for the training controls is already sitting there. And if you're an MSP handling compliance for a portfolio of defense clients, you get the same visibility rolled up across every one of them.

CMMC has already been through one teardown — the 2021 review that produced CMMC 2.0 — and it's now in another. Requirements get rewritten. Records outlast rewrites.

The bottom line

The suspension removed a deadline. It didn't remove the obligation, and it didn't remove the risk of being unable to prove you met it. Keep your training running through the 60 days, keep the evidence, and let everyone else treat the pause as a vacation.

If your training records currently live in a spreadsheet — or nowhere — Contact us and we'll show you what provable looks like.

Subscribe

Updates that don’t suck.

A short note when we ship something worth knowing about. No spam, no drip campaigns.