CMMC Phase 2 is still the date to be ready for.
CMMC Phase 2 remains the plan of record for 10 November 2026. On 13 July 2026 the Department of War paused enforcement pending a 60-day Reform Task Force review (RFI closed 14 August 2026); no replacement date has been issued and Phase 2 has not been cancelled. Nothing underneath it moved: DFARS 252.204-7012 still applies, all 110 NIST SP 800-171 Rev 2 controls must still be implemented, and the annual SPRS self-assessment score is still mandatory — a score DOJ prosecutes under the False Claims Act. Preparing to November is the only assumption that is safe whether enforcement resumes on schedule, slips, or returns in a different shape.
Where the programme actually stands
Enforcement was paused on 13 July 2026 pending the Department of War's Reform Task Force review; the RFI closed 14 August 2026. Phase 2 was not cancelled, and no replacement date has been issued. We tell you this rather than leaving you to find it — and it changes nothing about what you should be doing, because the pause applied to the certificate, never to the obligation underneath it.
What is binding on you today
Three things the 13 July memo did not touch. Each is in force right now, with or without a third-party assessment.
DFARS 252.204-7012
The safeguarding clause is in your contract today. It was never part of the phase-in schedule and the pause did not touch it. Breach of it is breach of contract, now.
All 110 NIST SP 800-171 Rev 2 controls
The control set is unchanged. What Phase 2 would have added is a third-party checking your work — not the work itself.
Your annual SPRS self-assessment
Still mandatory, still submitted under your own name. With no assessor in the loop, that score is your representation to the government.
A paused certificate is not a paused prosecutor
Self-attestation is the gate right now, and DOJ prosecutes it. Under the Civil Cyber-Fraud Initiative it has settled fifteen False Claims Act cases — MORSECORP paid $4.6M over an inflated SPRS score, LOGZONE $507,144 for certifying a perfect 110 with controls unimplemented.
MORSECORP — $4.6M
Self-reported an SPRS score of 104. A third-party gap analysis found 22% of controls implemented and a true score of −142. Settled March 2025.
Raytheon / Nightwing — $8.5M
System Security Plan failures under NIST 800-171. Settled May 2025. The largest cyber-FCA settlement of the year.
Your own attestation
With no assessor in the loop, the score you submitted is your representation to the government. The question an investigator asks is whether you can evidence it.
The gap nobody has closed yet
Most contractors have policies, an SSP and a POA&M. Almost none can say what their staff pasted into ChatGPT last quarter — which is the newest way CUI leaves a boundary and the least logged.
Know what your people are actually sending
AI prompt traffic is the newest way CUI leaves a boundary and the least logged. Point one URL at the gateway and every prompt is inspected on your own hardware before it goes anywhere.
Turn that into evidence, not a feeling
A SHA-256 hash-chained audit log of every prompt event, mapped to the NIST 800-171 controls it touches. This is the artifact an assessor asks for and the one nobody has.
Score it before someone else does
The AI Risk Assessment Report runs 14 days in your environment and hands you a signed PDF risk-scoring every AI prompt event against NIST 800-171 Rev 2. $499 one-time, one time, no subscription.
FAQ
CMMC Phase 2 — straight answers
Still have questions? Talk to a compliance engineer — we respond within 4 business hours.
Can you evidence your SPRS score before November?
Fourteen days on your own hardware, one signed PDF, $499 one-time one time. No subscription, no MSA, no data leaving your network.
Get the readiness report