Updated August 21, 2026
CMMC timeline for Pacific contractors after the Phase 2 pause.
November 10, 2026 is no longer the date. Phase I self-assessments and DFARS 252.204-7012 never left. This is the Pacific contractor timeline after July 13, 2026.
Published April 22, 2026 · Updated August 21, 2026 · Cyberuptive Team · Honolulu
The direct answer
The CMMC Program rule at 32 CFR Part 170 took effect on December 16, 2024. Phase I of the acquisition rollout began November 10, 2025. Phase II, the point at which a C3PAO assessment was slated to become the default for new CUI work, was scheduled for November 10, 2026.
On July 13, 2026 the Department of War announced the immediate suspension of Phase II. The official policy page is explicit: “All Phase I self-assessment requirements remain firmly in place.” The companion press release and implementation memo are the source documents. This is a pause, not a repeal.
If you handle Federal Contract Information or Controlled Unclassified Information for a prime at Joint Base Pearl Harbor-Hickam, Schofield Barracks, Marine Corps Base Hawaii, or a mainland program that flows work into the Pacific, the duty that remains is the same one we covered in the Phase 2 pause brief: implement the controls, score them honestly, and keep the System Security Plan matched to production.
The dates that still matter
| Date | What it did | Status now |
|---|---|---|
| Dec 16, 2024 | 32 CFR Part 170 took effect. CMMC stopped being a proposed rule. | Still in force. |
| Nov 10, 2025 | Phase I. Self-assessment requirements appear in new DoW solicitations for Level 1 and self-Level 2. | Still in force. |
| Nov 10, 2026 | Original Phase II start. Third-party C3PAO assessments were slated to become the default for new CUI work. | Suspended July 13, 2026. Not a live deadline. |
| July 13, 2026 | DoW suspended Phase II and later milestones and opened a program review. | Current policy. Watch the CIO policy page for the next date, if one is published. |
What Phase I still requires
Phase I is not a courtesy period. If a new solicitation calls for CMMC Level 1 (Self) or Level 2 (Self), you still have to produce the self-assessment, the senior-official affirmation, and a Supplier Performance Risk System score that you can defend. DFARS 252.204-7012 still requires adequate security on covered systems and incident reporting, and it still flows to subcontractors that process, store, or transmit covered defense information.
Level 1 is the FAR 52.204-21 basic safeguarding set for Federal Contract Information. Level 2 is NIST SP 800-171 on the CUI boundary. Level 3 is a higher-priority subset assessed by DIBCAC. Most Pacific subcontractors should assume Level 2 until a contracting officer writes something narrower. That assumption did not change on July 13.
What the pause does not do
- It does not cancel a C3PAO requirement already written into a current contract.
- It does not waive SPRS scoring or the annual affirmation.
- It does not make commercial Microsoft 365 a safe place for CUI. The CMMC rule does not name GCC High; 7012 still requires a FedRAMP Moderate baseline or equivalent for cloud that stores, processes, or transmits CUI.
- It does not pause incident reporting, logging, or the personnel-handling rules for CUI.
What Pacific contractors should do now
The Hawaii defense surface is not theoretical. Joint Base Pearl Harbor-Hickam, Schofield Barracks, Marine Corps Base Hawaii, Fort Shafter, and the INDOPACOM staff functions those installations support sit on a dense subcontractor layer. A 20-person engineering firm on a prime’s flow-down is in the same clause set as the prime. Use the pause as calendar, not as a holiday.
- Confirm the level from the clauses, not from a blog post. Pull every current DoW subcontract and the last three RFPs you answered. Write down whether the language is Level 1 (Self), Level 2 (Self), or an existing third-party requirement.
- Bound the CUI environment. One defined user list and one defined set of systems is cheaper to defend than a flat network where CUI could be anywhere. If the CUI list is a 2024 spreadsheet, start there.
- Pick a cloud tenant that meets 7012, then document it. Commercial Microsoft 365 is not a safe assumption for CUI. Name the actual tenant in the SSP.
- Stand up the controls you cannot fake in an interview. Continuous monitoring, audit logging with retention, incident response, and vulnerability management are the usual collapse points. They are also the controls a managed SOC is built to run.
- Author the SSP. Live with the POA&M. Both are living documents. Treating them as one-time PDFs is how self-assessments fail even when nobody is coming with a C3PAO badge.
- Do not book a C3PAO because November used to be the date. Book one if a current contract or a live solicitation requires it. The official marketplace is at cyberab.org/Marketplace.
Why a Pacific MSSP still matters
Time zone, U.S.-person handling, and INDOPACOM-AOR threat context are not marketing. They are the substance of a useful CMMC engagement. When a prime calls about a CUI handling question at 09:00 HST, an East Coast provider is already five or six hours into its day and often gone. For CUI-handling work, insist on documented U.S.-person analyst access and U.S. soil for the SOC function. Follow-the-sun is not an answer if the sun is in a non-U.S. SOC.
An MSSP does not “get you certified.” It operates the controls you will later claim. That work is useful whether Phase II returns in six months or eighteen. The Hawaii-specific version of that argument is in Why Honolulu defense contractors need a Pacific MSSP and Hawaii MDR and 24/7 SOC.
What to do this week
Pull the clauses. Pull last quarter’s SPRS affirmation if you have one. Write down who can isolate an endpoint tonight without calling you. If you want a second pair of eyes on that inventory, scoped, not a six-month RFP, start with a 30-minute call. Bring the clause list and the current EDR / identity stack. We will tell you whether the self-assessment is the gap, whether you need CMMC compliance support, or whether the current setup already covers the duty.
References
- 89 FR 83092, CMMC Program final rule, 32 CFR Part 170, effective December 16, 2024
- DoW CIO, CMMC Policy: Phase II suspended July 13, 2026; Phase I self-assessments remain
- Department of War, suspension of CMMC Phase II requirements, July 13, 2026
- DoW implementation memo, Implementing Suspension of CMMC Phase II
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting