CMMC Deadlines Just Shifted: What North Carolina Defense Contractors Should Do in 2026

Tego > Blog > Blog > CMMC Deadlines Just Shifted: What North Carolina Defense Contractors Should Do in 2026
Computer hand typing

CMMC Deadlines Just Shifted: What North Carolina Defense Contractors Should Do in 2026

CMMC 2.0 is the federal certification that demonstrates a defense contractor can protect Controlled Unclassified Information (CUI). In 2026, the rollout changed twice. First, in July, the government paused third-party certification. Then, on September 3, it codified that pause into the contract rules that contracting officers actually follow. Here is the trap: the pause removed the assessor, not the requirement. Every NIST SP 800-171 control still applies, and the penalties for getting it wrong have become sharper. North Carolina defense contractors should read this as a reason to act, not to relax.

What changed with CMMC in 2026

The timeline moved quickly, and it shifted twice. In July, the Department paused the transition to Phase 2, which would have required third-party (C3PAO) certification. Many treated that as a policy memo they could ignore. Then, on September 3, 2026, the Department of War (the renamed Department of Defense) signed a class deviation, DFARS 2026-O0025 Revision 3, that incorporated the pause into the contracting rulebook.

That second step is the one that matters. A policy memo provides guidance. A class deviation tells every contracting officer exactly what to do. The table below shows how the program reached this point.

Milestone Date What it means
32 CFR Part 170 effective December 16, 2024 The CMMC program rule became official
48 CFR (DFARS) clause effective November 10, 2025 Phase 1 began; contracts can require CMMC
Phase 2 transition paused July 13, 2026 The government suspended the move to third-party certification
Class deviation signed September 3, 2026 The pause became a rule contracting officers must follow
Full-implementation date November 10, 2028 The rule’s long-standing final phase date, unchanged since 2025

Clearing up the 2028 myth

You may see vendor content claiming CMMC is off the table until November 2028. That is wrong and dangerous to believe. November 10, 2028, has been the full-implementation date written into the rule since 2025. The pause didn’t create a new runway. More to the point, it says nothing about what a prime contractor will require from you next quarter. Treat the 2028 date as the far end of a process you are already in, not as permission to stop.

What North Carolina defense contractors should do now

The smart move is not to relax. It is to have your contracts reviewed before others modify them around you. Contractors who understand exactly what their agreements require will navigate the next two quarters smoothly, while others are surprised by an amendment they did not see coming.

Start with your live agreements. If you have a solicitation or bid with a C3PAO requirement, or an option exercise due in the next two quarters, that paperwork needs a review now. Then keep building your security baseline. Map your CUI, score yourself honestly against all 110 controls, and post an SPRS number you can defend under oath. Write your System Security Plan (SSP) and Plan of Action and Milestones (POA&M), then close the riskiest gaps first. The affirmation you sign should reflect reality, because reality is now the only thing standing between you and a False Claims Act headline.

How Tego helps North Carolina contractors with CMMC

Tego is an engineering-led IT firm in Raleigh, North Carolina, that designs and manages the NIST SP 800-171 controls DoD contractors depend on. The team runs CMMC 2.0 gap assessments, handles remediation, builds defensible System Security Plans, and helps you understand what your contracts actually require as they change. Day to day, those controls run through Tego’s enterprise managed services, so a baseline built during prep doesn’t quietly drift out of compliance later.

Credibility counts when a signature carries legal weight. Tego is a prime contractor on the North Carolina Statewide IT Contract and a repeat Inc. 5000 honoree, so contractors get a partner who speaks both engineering and compliance without a translator. You can see the full scope of that work on Tego’s security, audit, and compliance services.

Key takeaways

  • A September 3, 2026 class deviation turned the CMMC Phase 2 pause into a rule contracting officers must follow.
  • Contracting officers are removing Level 2 (C3PAO) and Level 3 requirements from new, posted, and existing contracts.
  • Nothing about the obligations changed: all 110 NIST SP 800-171 controls, DFARS 7012, the SPRS score, and the annual affirmation still apply.
  • With no third-party assessor, your affirmation is the only check, and DOJ is enforcing false claims (Honeywell paid over $2M, settled in North Carolina).
  • CMMC is not off the table until 2028, so review any contract with a C3PAO requirement or a near-term option exercise now.

Frequently asked questions

Did the September 2026 class deviation cancel CMMC? No

No. It directs contracting officers to remove third-party (C3PAO) and Level 3 requirements from contracts for now. The underlying security obligations, including all 110 NIST SP 800-171 controls and DFARS 7012, remain fully in force.

Can I stop working on compliance because of the pause?

No, and doing so is risky. Self-assessment, SPRS scoring, and the annual affirmation still apply, and the government can still assess your systems. Primes can also still require certification from their subcontractors.

Can I really be sued over a self-assessment?

Yes. Your affirming official’s signature is now the only verification in the system, and the False Claims Act applies to false attestations. In 2026, LOGZONE paid $507,144, and Honeywell Aerospace paid more than $2 million to settle cybersecurity claims.

Is CMMC off the table until November 2028?

No. November 10, 2028 has been the rule’s full-implementation date since 2025. It is not a new runway, and it does not change what a prime contractor may require from you next quarter.

What should I do if my contract has a C3PAO requirement?

Have it reviewed now. Contracting officers are amending existing contracts before the next option exercise, so you want to understand exactly what your agreement requires before it changes around you.

Does CMMC apply to subcontractors?

Yes. Prime flow-down is untouched by the class deviation. If a subcontractor handles FCI or CUI, it must meet the level tied to the data it handles, and a prime can still require proof.

Is your contract about to be modified while your 800-171 gaps stay open? Tego reads what your agreements actually require and builds the controls behind your affirmation. Start a contract-and-compliance review with Tego before the next option exercise.