The Current CMMC Change
CMMC Phase I began November 10, 2025, and its self-assessment requirements remain in place for acquisitions that include them. On July 13, 2026, the Department announced the immediate suspension of the CMMC Phase II requirements that had been scheduled for November 10, 2026. The Department is reviewing the program, so contractors should not plan from the superseded rollout calendar. The change does not replace the solicitation and contract. A business still needs to identify the information it will handle, read the applicable clauses, maintain required safeguards, and confirm its assessment and Supplier Performance Risk System posture.
CMMC Status After the July 13 Phase II Suspension
The current source of truth is the Department CIO CMMC page. On July 13, 2026, the Department announced that Phase II requirements were suspended immediately and that implementation remains in Phase I while the program is reviewed. The prior November 10, 2026 Phase II date is no longer an active deadline. Phase I self-assessment requirements remain in place. A small business should read the solicitation and contract clauses it is actually targeting, identify whether it will handle Federal Contract Information or Controlled Unclassified Information, and confirm the required assessment and SPRS posture. The suspension does not erase underlying cybersecurity duties in an existing contract, and it does not justify buying a certification package that no current notice requires. Keep required safeguards and documentation current, but do not let a consultant's old rollout chart substitute for the official status or acquisition language. The Department says its review will focus on speed to capability, lower barriers for small and nontraditional businesses, and scalable cybersecurity measures. Until new official guidance is published, any claim about a replacement Phase II date, universal third-party-certification deadline, or number of contractors that must certify is speculative.
🔍 Search related opportunities now
Read the Current Clause, Not a Headline Summary
Acquisition law, the FAR, DFARS, class deviations, and the solicitation work together. A new statute may require implementation before a contractor experiences the change in a particular acquisition. Broad claims that every small business is exempt from cost principles, certified cost data, business systems, or subcontract flowdowns are not a safe basis for pricing or compliance. A nontraditional defense contractor is not simply another name for every small business. The current DFARS definition and provision use a prior full Cost Accounting Standards coverage test and allow an acquisition official to treat certain supplies and services as commercial. That treatment is permissive and acquisition-specific. For each pursuit, list the representations, cost or pricing requirement, cybersecurity clauses, data rights, accounting obligations, and subcontract flowdowns actually present. Ask an APEX Accelerator or qualified contracts adviser about an unclear clause rather than applying an article's summary to the bid. SBIR/STTR was reauthorized separately. The Small Business Innovation and Economic Security Act was signed April 13, 2026 and extended both programs through September 30, 2031. Current DoD topics appear through the Defense SBIR/STTR Innovation Portal and SBIR.gov. See the current reauthorization guide before relying on an older topic calendar.
What the Live DoD Inventory Contains
Funding Landscape currently tracks 13,517 open DoD opportunities under the article-refresh instrument. That number is rendered from the current database rather than frozen in this article. The inventory includes active solicitations, notices, research announcements, sources sought, and other procurement records. Those are not interchangeable. A solicitation asks for a bid or proposal. A sources-sought notice or RFI is market research and does not itself award a contract, but a strong response can affect the acquisition strategy and set-aside decision. A broad agency announcement seeks research ideas, often through white papers or abstracts. A grant or SBIR topic uses different eligibility and submission rules. Start with live DoD results, then open the official notice and every amendment. Filter for the product, service, research area, place of performance, and set-aside that actually match the business. A large raw count is useful for measuring coverage, not for claiming that thousands of bids fit one company.
How to Find Current DoD Opportunities Without a Stale List
A fixed list of closing-soon notices becomes misleading within days. Use three saved searches instead. 1. Exact capability: the product, service, platform, material, or research outcome you can deliver. Add relevant NAICS and PSC codes, but do not rely on codes alone. 2. Market entry: search sources sought, RFIs, industry days, and subcontracting notices. These are often the best places for a new vendor to influence a set-aside or meet a prime before the team is fixed. 3. Research: search BAA, CSO, SBIR, and the specific DoD technical office. Confirm whether the first response is a white paper, abstract, proposal, or topic submission. The live results panel on this guide is allowed to render only when the engine finds at least three strong current defense-contract matches. If inventory falls below that floor, it disappears and the guide remains. Always use SAM.gov, the Defense SBIR/STTR portal, or the issuing component as the deadline and amendment source of truth.
A Realistic Market-Entry Sequence
A first DoD contract rarely follows a universal month-by-month schedule. Registration, cybersecurity, relationships, and proposal development can overlap, and the current acquisition controls what is required. Start with SAM.gov, UEI and CAGE information, accurate NAICS codes, and a capability statement tied to work the business can perform. For cybersecurity, identify the information the target contract would expose and follow the current solicitation, contract clauses, NIST requirements, and Phase I assessment rules. The July 2026 Phase II suspension means an old certification calendar should not drive the plan. Use industry days, APEX Accelerators, small-business offices, sources-sought notices, and award history to learn how the agency buys the capability. Subcontracting can build relevant performance and contract-administration experience, but the prime's requirements still need to be read carefully. Search SAM.gov award history in the relevant NAICS and product/service codes, identify current buyers and primes, and invest in a proposal only after confirming notice type, set-aside, deadline, place of performance, cybersecurity, and deliverables.
Set-Asides and Market Entry
Set-asides limit competition to qualified small businesses or a named socioeconomic program. The acquisition's NAICS code, size standard, certification requirement, and representation control eligibility. Use the current FAR Part 19 guidance and SBA certification systems rather than relying on old award-limit tables. Certifications include 8(a), HUBZone, women-owned and economically disadvantaged women-owned small business, and service-disabled veteran-owned small business. A certification creates eligibility for certain competitions. It does not prove capability, pricing, responsibility, or fit. Sources-sought responses are important because contracting officers use market research to assess whether enough capable small businesses exist for a set-aside. Respond with the exact capability, relevant performance, capacity, codes, contract vehicles, and constraints requested. Do not send a generic capability statement in place of the requested answers. The DoD Mentor-Protégé Program can provide structured developmental assistance to eligible firms. Read the current program requirements and approved agreement process before presenting it as an automatic route to a subcontract.
What You Should Do This Week
1. Check the current CMMC status and target clause. Phase II is suspended. Keep Phase I self-assessment and any contract-specific cybersecurity duties current, but do not plan from the obsolete November 2026 deadline. 2. Verify SPRS requirements. Confirm what assessment record the acquisition requires and whether the business's current record is accurate. 3. Verify SAM.gov registration. Registrations expire annually. Check before a proposal deadline. 4. Find your APEX Accelerator. The former PTAC network provides government-contracting counseling. Use the official APEX Accelerators directory. 5. Identify your NAICS and PSC range. Use the codes that describe the actual capability, then confirm each notice's scope. See the NAICS and PSC guide. 6. Search for set-asides. Start with live small-business, 8(a), HUBZone, WOSB, and SDVOSB filters that match certifications the business actually holds.
Summary: Key Changes
CMMC remains in Phase I. The Department suspended Phase II on July 13, 2026. Confirm the assessment and safeguarding requirements in the acquisition you target and monitor the official CIO page for replacement guidance. Contract clauses control the pursuit. Do not assume a statutory or consultant summary removes a pricing, accounting, cybersecurity, or subcontract requirement from a particular acquisition. SBIR/STTR is active through 2031. It was reauthorized in a separate law signed April 13, 2026. Verify current component topics on the official portal. We track 13,517 open DoD opportunities. The live number includes multiple notice types, so qualify the acquisition stage and set-aside before investing in a response.