Cyberuptive

Updated August 21, 2026

CMMC Phase 2 pause: what Pacific subcontractors still owe.

November 10, 2026 is no longer the date. The safeguarding duty did not leave with it. If you handle CUI for a prime at JBPHH, Schofield, or INDOPACOM, treat this as a pause in third-party certification timing, not a holiday from 32 CFR 170 or DFARS 7012.

Originally published May 5, 2026 · Updated August 21, 2026 · Cyberuptive Team · Honolulu

The direct answer

On July 13, 2026 the Department of War suspended CMMC Phase II, which had been scheduled for November 10, 2026. Phase I self-assessment requirements remain in force. The 32 CFR Part 170 program rule was not repealed. DFARS 252.204-7012 is still the contract clause that makes CUI handling a security problem, not a slide deck.

This page originally treated Q3 2026 as a six-month sprint to a C3PAO assessment. That calendar is wrong now. The work inside it is not. A 30-person engineering firm in Honolulu, a logistics shop in Aiea, or a software team in Kakaako still has to know where CUI lives, who can touch it, and what evidence would survive a self-assessment or a prime’s flow-down review.

What changed on July 13, 2026

The Department of War announced an immediate suspension of Phase II requirements that were set to begin November 10, 2026. The CMMC policy page is explicit: Phase I self-assessments stay. The Department also posted an implementation memo and opened a review of the program.

Read that as a change in acquisition timing, not a change in the underlying duty:

  • Still in force: 32 CFR Part 170, effective December 16, 2024.
  • Still in force: Phase I Level 1 (Self) and Level 2 (Self) where the contract already calls for them.
  • Still in force: DFARS 252.204-7012 safeguarding and cyber-incident reporting, including flow-down to subcontractors that process, store, or transmit covered defense information.
  • Paused: the November 10, 2026 Phase II transition that would have made third-party C3PAO assessments the default for new CUI work.

If a current contract already requires a C3PAO or DIBCAC assessment, follow the contract. The pause is a program-level acquisition decision. It does not rewrite a clause you already signed.

The clause that still drives this

CMMC is how DoW verifies a posture. DFARS 7012 is how that posture got into the subcontract in the first place. Most Pacific firms we see did not wake up wanting a maturity model. They woke up because a prime flowed down 7012, then asked for an SPRS score, a System Security Plan, and a date.

That sequence did not stop in July. Primes still have to protect CUI on their own systems and on yours. A pause in Phase II does not give a Honolulu sub a clean story if the next incident lands on a shared SharePoint site that was never in the CUI boundary.

The companion timeline piece, The CMMC 2.0 Timeline for Pacific Contractors, still describes how the program was built. Use this page for what to do after the pause. Use Hawaii MDR and 24/7 SOC if the actual gap is who can contain an identity attack at 03:00 HST.

What Level 2 still means without a Phase II clock

Level 2 is still NIST SP 800-171 on the CUI environment, 110 controls, a scoped boundary, a System Security Plan, and a Plan of Action and Milestones you can defend. The self-assessment is a score plus a narrative. It is not a certificate you buy in October.

Pacific shops get this wrong in the same three places they did before the pause:

  • The boundary is a wish. CUI in personal OneDrive, a bookkeeper’s laptop, and an unmanaged file share is still CUI. If it is out of scope on paper and in use on Tuesday, the self-assessment is fiction.
  • The SSP is a brochure. Assessors and primes read it against tickets, configs, and backup jobs. A 40-page PDF that no one has opened since the last proposal is not a control.
  • Shared IT is treated as shared responsibility. A local MSP that patches Windows but cannot produce AU, IA, IR, or MP evidence is not covering 7012. You still own the score.

What to do this quarter instead of racing November

Drop the month-by-month C3PAO countdown. Keep a shorter, honest sequence:

  1. 1. Re-read the clauses you already signed. FAR 52.204-21, DFARS 252.204-7012, and any CMMC Level 1 (Self) or Level 2 (Self) language added since November 2025. Write down what the prime can already ask for.
  2. 2. Freeze the CUI inventory for 30 days, then keep it current. Systems, SaaS, backups, and the people with access. If you cannot list it, you cannot scope it.
  3. 3. Score the 110 honestly. A gap list with owners beats a 95 that collapses in a tabletop. Put dates on the POA&M items that are actually funded.
  4. 4. Make the SSP match production. MFA, logging, encryption at rest, media handling, and incident contacts should be copy-pasteable from the environment, not from a template.
  5. 5. Decide whether you need a C3PAO at all this year. Book one if a current contract or a specific RFP requires it. Do not book one because a blog post from May said November 10 was coming.

Where an MSSP still fits

An MSSP does not “get you certified.” It operates the controls you will later claim: 24/7 detection, containment authority, evidence packs for AU/SI/IR/IA, and a personnel-handling story you can put in the SSP. That work is useful whether Phase II returns in six months or eighteen.

For CUI-handling work, insist on documented U.S.-person analyst access and U.S. soil for the SOC function. Follow-the-sun is not an answer if the sun is in a non-U.S. SOC. The Hawaii-specific version of that argument is in Why Honolulu defense contractors need a Pacific MSSP.

What to do this week

Pull the clauses. Pull last quarter’s SPRS affirmation if you have one. Write down who can isolate an endpoint tonight without calling you. If the CUI list is a spreadsheet from 2024, start there. The pause bought calendar. It did not buy a clean incident.

If you want a second pair of eyes on that inventory, scoped, not a six-month RFP, start with a 30-minute call. Bring the clause list and the current EDR / identity stack. We will tell you whether the self-assessment is the gap, whether you need CMMC compliance support, or whether the current setup already covers the duty.

References

Aloha, let's talk

Want this applied to your Pacific subcontract?

Bring the clauses and the CUI list. We will tell you what the pause changed: and what it did not.