military laptops like these could be subject to CMMC media sanitization. DoD-contracted providers would eventually need to erase all FCI and CUI data, but will need to be CMMC certified to get the contract in the first place.

Home » Resources » CMMC Level 2 and the 2026 Review: What Changed for Contractors, and What Stays Enforceable Righ…

CMMC Level 2 and the 2026 Review: What Changed for Contractors, and What Stays Enforceable Right Now

On July 13, 2026, the U.S. Department of War suspended the transition to Phase II of Cybersecurity Maturity Model Certification (CMMC), originally scheduled for November 10, 2026, and held pending and future CMMC implementation milestones in abeyance while a CMMC Reform Task Force conducts a 60-day review of the program. That headline moved fast, and most of the versions that reached contractors dropped the qualifier that matters. CMMC’s expansion is on hold. Phase 1 self-assessment requirements aren’t, and neither are the data security obligations underneath them.


It would be easy—and expensive—to read this as “compliance can wait.” It can’t, and for media sanitization it never could. Here’s what’s actually paused, what’s still a condition of award today, and why sanitization would survive even if the Task Force rewrote CMMC from scratch.

Stephanie Larochelle Stephanie Larochelle, a tech enthusiast and writer based in Florida, is dedicated to simplifying the intricacies of the digital world. As Blancco's senior content writer, her goal is to make data erasure easily understandable and approachable so everyone can navigate this crucial aspect of data security.

What the CMMC pause changes for Level 2 requirements

CMMC became enforceable in two steps. The 32 CFR Part 170 program rule, effective December 16, 2024, established the CMMC 2.0 framework: three levels, defined assessment types, and the practices required at each level. The 48 CFR acquisition rule, published September 10, 2025 and effective November 10, 2025, made CMMC a contract gate: from that date, DoD contracting officers began writing CMMC status requirements into new solicitations, with an eligible status in SPRS required at the time of award.

November 10, 2025 also started Phase 1 of a planned multi-year rollout. Phase 1 puts Level 1 and Level 2 self-assessment requirements into applicable contracts, with DoD discretion to require third-party (C3PAO) Level 2 certification for select acquisitions, a discretion the July 2026 memos withdrew for the duration of the review. Later phases were designed to expand third-party certification requirements across the defense industrial base over the years that followed.

The July 2026 suspension applies to those later phases. Phase 1 remains in effect: self-assessment requirements continue to appear in new solicitations, annual affirmations are still due, and a contractor without the required CMMC status in SPRS is still ineligible for award on contracts that carry the clause. What the Task Force review pauses is the expansion of certification requirements (the timeline for when C3PAO assessments become widespread), not the program’s presence in contracts today.

The implementing guidance is more specific than “later phases are paused.” During the suspension, program managers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self) in procurement requests and requirement documents; they may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). Where an active solicitation already carries a C3PAO or DIBCAC requirement, requiring activities must amend it out and contracting officers must issue the corresponding amendment as soon as practicable; existing contracts are to be modified before the next option period or at the next scheduled administrative modification. No waivers will be granted during the review.

For CMMC Level 2 specifically, that leaves a single path. CMMC L2 is aligned with NIST SP 800-171 Rev 2, and Level 2 (Self) is the only CMMC Level 2 assessment type a requiring activity may designate while the review runs. The CMMC Level 2 requirements themselves have not moved. The controls, the practices, and the evidence expected of a CMMC Level 2 compliant contractor are the same today as they were before July 13. What changed is who checks them: your own team, and in selected cases the government, instead of a C3PAO.

Sanitization rules under FAR, DFARS, and NIST SP 800-171

Media sanitization gets described as a CMMC requirement. It isn’t, not quite. CMMC verifies a requirement that already existed in your contracts, and that still exists whether or not CMMC does.

The obligation to sanitize or destroy media containing Federal Contract Information before disposal or release for reuse comes from FAR 52.204-21, the basic safeguarding clause that applies to essentially every federal contractor handling FCI. The obligation to protect Controlled Unclassified Information (including sanitizing media that held it and sanitizing equipment sent for off-site maintenance) comes from NIST SP 800-171 as flowed down through DFARS 252.204-7012, which has been in defense contracts since well before CMMC existed.

CMMC changed the enforcement model, replacing pure self-attestation with structured assessment and affirmation. The Task Force can adjust that model. It cannot remove the underlying clauses from your contracts, and the CIO memo says so directly: all other contractual cybersecurity clauses remain intact, and DFARS 252.204-7012 stays in effect throughout the suspension. If you deprioritize sanitization during the pause, you’re not avoiding an obligation, you’re deferring one you already owe. And rebuilding an evidence trail after the fact costs a lot more than keeping one as you go.

CMMC Level 2 controls and practices for media sanitization

Under the current CMMC three-level model, sanitization appears at every level a contractor is likely to hold, and it sits squarely inside the CMMC Level 2 controls that most CUI-handling contractors are assessed against:

LevelData CoveredAssessmentSanitization practices
Level 1Federal Contract Information (FCI)Annual self-assessmentMP.L1-b.1.vii: sanitize or destroy media containing FCI before disposal or release for reuse
Level 2Controlled Unclassified Information (CUI)Self-assessment or C3PAO certification, depending on the contract (C3PAO designations suspended during the review)MP.L2-3.8.3: sanitize media containing CUI before disposal or reuse; MA.L2-3.7.3: sanitize equipment of CUI before off-site maintenance
Level 3CUI on highest-priority programsGovernment-led (DIBCAC) assessment (not designatable during the review)Builds on all Level 2 practices

The CMMC Level 2 practices above come from the Media Protection and Maintenance domains, and the CMMC Level 2 Self-Assessment Guide is the reference an assessor works from in deciding whether you meet them. Sanitization under these practices means the data is unrecoverable even with advanced forensic tools. Reformatting and standard “wiping” do not meet that bar. NIST SP 800-88, the federal reference standard for media sanitization, defines three methods (Clear, Purge, and Destroy), and the appropriate method depends on the media type and the sensitivity of the data it held. Purge-level erasure allows drives and devices to be verified as sanitized and then reused or resold; destruction is reserved for a small number of media  where sanitization and verification is not considered suitable.

CMMC Level 2 self-assessment steps to take during the review

Use the review window. Contractors who spend it tightening their evidence will be ready for whatever the Task Force recommends, and defensible in the meantime under the rules already sitting in their contracts. Four things worth doing now:

Blancco data erasure for CMMC Level 2 sanitization requirements

Blancco data erasure solutions perform software-based sanitization aligned to NIST SP 800-88 R2 Clear and Purge methods across the full range of enterprise media (PCs, Macs, servers, loose drives, virtual machines, and mobile devices) and produce a digitally signed, audit-ready erasure report for every asset processed.

Centralized reporting through the Blancco Management Portal gives contractors the per-device evidence trail that a CMMC Level 2 assessment, your annual affirmation, and any future third-party review all depend on. Blancco is itself certified to ISO 27001 for information security management and ISO 27701 for privacy information management, and for contractors who can’t route asset or erasure data through a cloud service, Blancco Management Portal is also available as an on-premise deployment inside your own environment.

To see how Blancco supports CMMC media protection and maintenance requirements, reach out to our team