This isn't a hypothetical for construction. The Associated General Contractors of America has told its members that most will fall under CMMC Level 1 or Level 2 and should expect the clause in their contracts. It's already showing up on real jobs. One recent Army Corps of Engineers solicitation, to replace transformer stations and a pump station at a fuel depot in Japan, designated a CMMC Level 2 self-assessment and stated that the government would check each offeror's status in SPRS before award.
Not long ago, a construction firm reached out to us for exactly this reason. Their prime contractor had started pushing them on CMMC, and they wanted to understand what they were being asked to commit to before it became a problem. That's the right instinct. Most firms don't ask until after the ink is dry.
In this article:
Partly, yes, and that's where a lot of the confusion comes from.
On July 13, 2026, the Department of War (formerly the Department of Defense) suspended Phase 2 of CMMC. Phase 2 was the stage, scheduled for November 10, 2026, when third-party certification assessments would have become a condition of award for contracts involving Controlled Unclassified Information. Phases 3 and 4 were put on hold too, and a CMMC Reform Task Force was created to review the program. The Department then reissued a class deviation on September 3. It tells contracting officers to remove third-party CMMC requirements from solicitations, allows Level 1 and Level 2 self-assessments, and keeps NIST SP 800-171 as the baseline. The Task Force's recommendations went to the Department's CIO in September but haven't been made public as of this writing.
My colleague Jim Ambrosini covered the suspension in detail in CMMC Update: The Certification Is Suspended. The Standard Is Not. His title says it well.
What was paused is the independent audit. What wasn't paused is the following:
A government memo can suspend a government program. It can't rewrite the agreement you signed with a private company. Primes still have to manage risk in their supply chains, and most of them aren't loosening their flowdown language while a review plays out.
A government memo can suspend a government program. It can't rewrite the agreement you signed with a private company.
So the question isn't whether CMMC still matters. The question is what your clause actually requires today.
It's about the data you touch, not the work you do. CMMC levels follow the information you receive, store, or send.
Federal Contract Information (FCI) is non-public information generated or provided under a government contract. For a construction firm, that could be project schedules, pricing, or correspondence about a federal job. FCI generally maps to Level 1, which is a set of basic safeguarding requirements from FAR 52.204-21. It requires an annual self-assessment and an affirmation by a senior official.
Controlled Unclassified Information (CUI) is more sensitive. In construction, it's often the drawings and specifications for DoD facilities, security plans, and site access details for military installations. If your team is pulling marked drawings into a plan room, emailing them to a detailer, or opening them on a tablet in the field, that data is living on your systems. CUI generally maps to Level 2 and all 110 controls in NIST SP 800-171.
If you're unsure which applies to you, our article on CMMC Level 1 vs. Level 2 walks through the decision.
Your level isn't automatically your prime's level. A prime might need Level 2 overall while your scope only involves FCI, or the reverse. The clause should say which level applies to you, and it should match the data you'll actually handle.
Timing matters. CMMC status is generally required before award and must be maintained for the life of the contract. It's not something to finish "sometime during the project."
Pull the agreement out and look for the following:
Related article: Where you store your CUI data matters more than you think
Take a breath. Signing the clause doesn't mean you're out of compliance today. It means you've committed to getting there, and you should know where you stand. Here's where I'd start.
The pause bought everyone some breathing room on third-party audits. It didn't change the clause in your subcontract or the security expectations behind it. Firms that use this window to understand their data and close real gaps will be in a strong position whatever the Task Force recommends. Firms that treat the pause as a reason to wait will be starting from scratch when the timeline returns.
If your prime is asking about CMMC and you're not sure what you've committed to, we're happy to help you sort it out. We work with construction and engineering firms on exactly these questions. Our CMMC Readiness services can help you read your flowdown language, figure out which level applies, and build a plan you can stand behind.