CMMC ComplianceCyber Grants Alliance Blog

CMMC Rule Status Update: Phase 1 Self-Assessment Still Holds, C3PAO Certification Begins November 10, 2026

July 10, 2026 Cyber Grants Alliance 5 min read
CMMC compliance timeline showing Phase 1 self-assessment now leading to mandatory Level 2 C3PAO certification on November 10, 2026

Here is this week’s CMMC status in one line: nothing moved, and that is exactly the point. There were no new 32 CFR Part 170 or 48 CFR (DFARS) rule changes this week. The Cybersecurity Maturity Model Certification program remains in Phase 1, self-assessment still satisfies many Department of Defense contracts, and mandatory Level 2 certification by a C3PAO still begins on November 10, 2026.

For small manufacturers and suppliers in the Defense Industrial Base, a quiet week can feel like permission to wait. It is not. The rule is settled, the timeline is fixed, and every quiet week is a week off the clock you have to reach Phase 2.

Have questions about where you stand?

Book a call and get a straight answer about whether Phase 1 self-assessment covers you or whether you need to start on C3PAO certification now.

Book a Call with Us →

Where Does the CMMC Rule Stand Right Now?

Two federal rules make up the CMMC framework. The first, 32 CFR Part 170, is the CMMC Program rule itself. The second is the DFARS acquisition rule (48 CFR) that places CMMC requirements into actual DoD contracts through clause 252.204-7021. Both are final and in force. Neither changed this week.

That leaves the program where it has been since Phase 1 began: DoD solicitations may require a CMMC Level 1 or Level 2 self-assessment, and contractors post their scores in the Supplier Performance Risk System (SPRS) with a senior official affirmation. No emergency notice, no reopened comment period, no new delay. When you see no headline, the correct reading is that the machine is running on schedule.

What Does Phase 1 Self-Assessment Actually Require?

During Phase 1, a Level 2 self-assessment means you evaluate your own environment against all 110 NIST SP 800-171 Revision 2 controls, calculate your SPRS score out of a possible 110, document how each control is implemented in a System Security Plan, and record any gaps in a Plan of Action and Milestones. A senior company official then affirms the result.

Self-assessment is lighter than a third-party audit, but it is not a lower bar on the controls themselves. The same 110 controls apply. The honest question during Phase 1 is not whether you can self-attest, it is whether your self-attestation would survive a C3PAO looking at the same evidence. If you are still deciding which level you fall under, our guide on CMMC Level 1 vs Level 2 is the place to start.

A self-assessment is a starting line, not a finish line. Phase 2 is the day the government stops taking your word for it.

What Changes on November 10, 2026?

Phase 2 begins. From that date, DoD solicitations may require a verified CMMC Level 2 certification issued by an accredited C3PAO as a condition of award for any contract that involves Controlled Unclassified Information. A self-assessment alone will no longer satisfy those contracts. You can review the official phase structure through the DoD CIO CMMC program and the acquisition clause at DFARS 252.204-7021.

If your contracts already carry DFARS clause 252.204-7012, you handle CUI and Level 2 is your target. Certification is not something you can order the week before you need it. The path from gap assessment to a passing C3PAO audit typically runs 12 to 18 months, and there are only about 80 accredited C3PAOs serving tens of thousands of Level 2 companies. Assessment slots are already booking months out.

Why "No News" Is the Worst Reason to Wait

Every time a week passes without a rule change, some contractors quietly conclude that the deadline might slip. Read the signal the other way. The rule is final, both the program rule and the acquisition rule are enacted, and the phased schedule is written into regulation. A stable rule is not a soft rule. It is the opposite.

The companies that wait until the second half of 2026 will collide with three problems at once: assessor backlogs, rushed remediation, and higher costs for compressed timelines. The contractors who use these quiet months to complete a gap assessment and start remediation will be the ones holding a certificate when a Phase 2 solicitation lands.

What Should You Do During Phase 1?

Step 1: Run a Gap Assessment Now

You cannot remediate what you have not measured. A CMMC gap assessment maps your current posture against the 110 controls and hands you a prioritized remediation plan. This is the single highest-value move available to you during Phase 1, and Cyber Grants Alliance can fund it.

Get a Funded CMMC Gap Assessment

The CGA CMMC Gap Assessment Grant provides a fully funded gap assessment covering all 110 NIST 800-171 controls for qualifying Defense Industrial Base contractors. Grants are awarded first come, first served.

Apply for the Grant →

Step 2: Confirm Whether You Handle CUI

Check your contracts for DFARS 252.204-7012. If it is present, you handle CUI and Phase 2 certification applies to you. If you are unsure, ask your prime contractor; they are required to flow CMMC requirements down to subcontractors.

Step 3: Get on a C3PAO Schedule Early

Even before remediation is finished, reach out to accredited assessors listed in the Cyber AB Marketplace and get on a calendar. You can move a booked slot. You cannot recover months you spent waiting for a delay that is not coming.

Step 4: Fund the Work Before You Pay Out of Pocket

Remediation and certification cost real money. Before spending from your own budget, explore the grant programs available through Cyber Grants Alliance, which cover gap assessments, penetration testing, and employee cybersecurity training.

Frequently Asked Questions

Common questions about the current CMMC Phase 1 status.

Did the CMMC rule change in July 2026?

No. There were no new 32 CFR Part 170 or 48 CFR CMMC rule moves this week. The program remains in Phase 1, and Phase 2 mandatory Level 2 C3PAO certification still begins November 10, 2026.

Is a self-assessment still enough right now?

During Phase 1, many DoD contracts accept a Level 2 self-assessment with an SPRS score and a senior official affirmation. That window narrows as Phase 2 phases in third-party certification starting November 10, 2026.

Is a delay to the timeline coming?

There is no indication of one. Both the CMMC Program rule and the DFARS acquisition rule are finalized and enforceable. Planning around a hoped-for delay is a gamble against a fixed legal timeline and a limited pool of assessors.

Join the CMMC Grant Summit 2026

Cyber Grants Alliance is hosting a free virtual summit built for Defense Industrial Base manufacturers navigating CMMC. Reserve your seat.

Reserve Your Seat →
Share this article: LinkedIn X Email