Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
PHASE II SCENARIOS

If CMMC Phase II Comes Back Restructured Instead of Restored, What Changes for Small Contractors?

If Phase II returns in a new form, contract triggers, scope, timing, or burden could change; as of September 4, 2026 no specific redesign has been adopted.

Phase II is suspended, not erased. If the Department restores it in a restructured form, practical changes for small contractors could involve which contracts require third-party assessment, when requirements apply, how burden is reduced, or how assessment and evidence are structured—but none of those scenarios should be presented as adopted policy today.

Status note: reviewed September 4, 2026. Phase II is suspended, Phase I remains in force, and the Department of War's CMMC Reform Task Force review is still open. Re-check the official CMMC page before publication if this article is published after that date.

The rule in plain English

The July 13 announcement framed the review around cost, burden, small-business participation, and scalable security. Those are reasonable areas to watch, not safe outcomes to predict.

Anything that changes 32 CFR or DFARS implementation needs an authoritative implementing source before contractors should treat it as a new requirement.

How to implement it without overbuilding

Use scenario planning: maintain a base case for current Phase I/Rev. 2 obligations, a third-party-certification case, and a lighter/restructured case. Identify investments useful under all scenarios.

Prioritize controls, scoping accuracy, asset inventory, identity, logging, incident handling, and evidence discipline because those retain value even if certification mechanics change.

What evidence to keep

Keep the current source set, a decision log, budget scenarios, contract pipeline, and a list of projects that are regulation-dependent versus security-baseline-dependent.

Update the plan when the task-force report or implementing acquisition action appears.

Where teams get into trouble

The mistake is either freezing all security work or spending heavily on assumptions about a future assessment model. Both confuse durable safeguarding with uncertain certification mechanics.

Small-contractor walkthrough

Management asks for one forecast of what Phase II will look like after reform. The compliance lead instead builds multiple scenarios and identifies investments—asset inventory, identity, logging, incident response, evidence discipline—that remain useful no matter how certification timing is restructured.

A small contractor can manage reform uncertainty with a compact decision register: current rule or contract fact, official source, business action required now, reform-dependent assumption, owner, and next review trigger. That keeps the company responsive without building a large policy program around changes the Department has not yet adopted.

For the Phase II reform page, show the July 13, 2026 suspension date separately from the article's September 5 verification date. If a later task-force report, memo, deviation, or rule appears, add that action as a new dated event rather than silently replacing the historical reason the old November milestone stopped controlling.

Use scenario review to identify investments whose value does not depend on a future certification model: accurate scope, controlled identities, reliable logs, tested recovery, provider evidence, and disciplined CUI handling. Those dependencies deserve attention now because they remain relevant even if assessment timing or burden changes later.

Planning should rank work by durability: current Rev. 2 safeguarding and evidence work first, architecture changes with clear security value next, and spend tied solely to an unannounced future certification structure last. This lets a small contractor keep improving security without pretending the reform task force has already chosen a replacement Phase II model.

  • Maintain current obligations.
  • Track official reform output.
  • Model multiple scenarios.
  • Prioritize durable controls.

Current facts versus reform scenarios

As of September 5, 2026, Phase II remains suspended and Phase I self-assessment requirements remain in place. The Department has announced a comprehensive CMMC review intended to reduce barriers for small, medium, and non-traditional businesses, but no final replacement design for Phase II has been published. That means a small contractor should maintain two lists: what is true under today's posture and what could change only after an authoritative reform action.

Scenario variables may include which procurements can require third-party assessment, how risk affects assessment type, how evidence can be reused, how external providers are treated, and when a future phase takes effect. None of those possibilities should be written as adopted policy. A policy objective such as lowering burden does not equal a small-business exemption or a guaranteed relaxation of NIST safeguards.

No-regret work while the program is under review

Continue work that remains valuable under almost any credible reform: identify FCI/CUI, maintain an accurate asset inventory and SSP, control access, patch vulnerabilities, protect remote administration, validate backups, improve incident response, and retain evidence. Those activities support current DFARS/NIST obligations and reduce business risk even if future certification mechanics change.

Separate durable safeguarding spend from spend that exists only because of an obsolete rollout date. A contractor with no present third-party assessment driver should not pay a premium merely because November 10 used to be the Phase II milestone. Keep that assessment budget as a scenario while continuing technical remediation and self-assessment work that is still required.

  • Maintain Rev. 2/Phase I work that is currently active.
  • Keep scope, SSP, evidence, and provider records current.
  • Do not treat predicted reform details as adopted policy.
  • Use official program/acquisition changes as planning triggers.

Trigger-based reform monitoring

Define which events can change the company's plan: a Department CMMC publication, acquisition-rule or deviation change, formal implementation memo, solicitation language, or contract amendment. A vendor webinar, rumor, or consultant forecast should not change a contractual representation.

When a trigger occurs, update one central status record first and then audit sales claims, supplier questionnaires, budgets, project milestones, and published guidance that depend on the changed assumption. This avoids the common situation where one team uses post-reform language while another still follows the old phase chart.

WORKING CHECKLIST

A short working check

  • Maintain current obligations.
  • Track official reform output.
  • Model multiple scenarios.
  • Prioritize durable controls.
  • Avoid speculative deadlines.
  • Re-baseline when rules change.

Common questions

Will Phase II definitely return?

The Department has suspended it and is reviewing the program; the exact future structure is not settled as of September 4, 2026.

Could the old November 10 date still apply?

Do not treat it as active Phase II timing unless the Department formally restores or replaces it.

What work is safest to continue?

Work required by current contracts and durable Rev. 2 safeguarding implementation remains useful.

Should we cancel a voluntary C3PAO assessment?

That is a business decision. Reassess the customer/contract reason, cost, and expected value under the current pause.

Has DoD published the final replacement for Phase II?

Not as of September 5, 2026. Phase II remains suspended while the Department reviews the program; reform scenarios are not adopted policy.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.