CMMC Phase II Is Paused: Five Things Defense Contractors Should Work on Now

CMMC Phase II Is Paused: Five Things Defense Contractors Should Work on Now

On July 13, 2026, the Department of War suspended the transition to CMMC Phase II. The third-party assessment requirement that was scheduled to take effect on November 10, 2026 is on hold while a CMMC Reform Task Force conducts a 60-day review, and recommendations are expected to surface around early October.

A lot of contractors read that headline and canceled their compliance projects. That is a mistake, and not a small one!

Here is what did not change: Level 1 and Level 2 self-assessments are still required where the clause is in your contract. DFARS 252.204-7012 is still in your contracts. NIST SP 800-171 is still the standard you attested to when you posted a score in SPRS. Primes are still flowing requirements down, and some of them were already asking for certification ahead of the deadline. The third-party audit got paused, but the obligation to meet the requirements did not.

The upside is that you now have time you did not expect to have. Spent well, it puts you in a better position than the contractors who stopped. Spent badly, it becomes the same scramble later with a different date on it. Here are five things worth doing during the pause:

1. Validate your SPRS score

Your SPRS score is an affirmation, submitted to the government, that your organization has implemented specific NIST SP 800-171 requirements. The False Claims Act does not care whether Phase II is paused, and the Department of Justice has been perfectly willing to pursue contractors whose scores did not match reality.

Most scores I encounter were built by someone reading the requirement text, deciding “yes, we do that,” and moving on. Go back through all 110 requirements with a different question: if an assessor asked me to prove this tomorrow, what would I show them?

For every requirement, one of three things is true. You can support each assessment objective with evidence, you cannot support it and need to change the score, or you cannot support it yet and need it on your POA&M with a real owner and a real date. Be honest about which bucket each one falls in. A lower score you can defend is worth more than a 110 you cannot. Re-submit if the number changes. The self-assessment is the enforcement mechanism right now, which means it is under more scrutiny during this pause, not less.

2. Strengthen the evidence, not just the policies

Policies say what you intend to do. Evidence shows that you did it. Assessors are not grading your intentions.

The organizations that struggle in assessments are rarely the ones with no policies. They are the ones with a beautiful policy binder and nothing behind it. When an assessor asks to see MFA enforced, a screenshot of the policy that requires MFA is not the answer. The conditional access policy in the identity provider is.

If you want to know where you stand, try collecting the following for your environment and see how long it takes:

  • Identity provider settings showing password, lockout, and session configuration as actually enforced
  • MFA enrollment and enforcement records for every account that touches CUI, including administrators and service accounts
  • Completed access reviews with dates, reviewer names, and evidence that flagged accounts were actually removed
  • Vulnerability scan reports from the last several cycles, plus the remediation tickets that followed them
  • Log samples that show what is being collected, from which systems, and that someone is reviewing them
  • Training records with completion dates, content, and role-based training for privileged users
  • Incident response tabletop or exercise records, with participants, scenario, findings, and follow-up actions
  • Configuration baselines for your workstations, servers, and network gear, and the mechanism that detects drift from them
  • Tickets showing recurring activities happening on schedule: account provisioning and deprovisioning, patch cycles, media sanitization, physical access reviews

If any of those took more than a few minutes to find, or could not be found at all, that is your gap. The evidence must exist as a byproduct of operating the control, not as something assembled in the two weeks before an assessment.

3. Reconfirm the CUI boundary

The most expensive mistake is treating the entire company as in scope because nobody ever mapped where CUI actually is.

Sit down and draw it. Where does CUI enter the organization: contract documents, prime portals, email, drawings from a customer’s engineering team? Where does it move: file shares, collaboration platforms, ticketing systems, someone’s laptop? Where is it stored, and where does it leave: subcontractors, shipping, a print shop, an offsite backup? A data-flow diagram that reflects reality, not the one from three years ago, is the foundation for everything else.

While you are at it, revisit the pieces people tend to skip:

  • Enclaves. If you built one, verify that CUI is actually staying inside it. An enclave that everyone works around is a diagram, not a boundary.
  • Cloud services. Anything that stores, processes, or transmits CUI needs to meet the FedRAMP Moderate requirement in DFARS 7012, and you need the shared responsibility documentation to show which controls the provider inherits and which you own.
  • MSPs and MSSPs. If an external provider administers in-scope systems, they are in your assessment. Their people, their tools, and their access all count. Confirm they know that, and confirm you have the contractual and technical evidence to back it up.
  • Subcontractors. If CUI flows to them, the requirement flows with it. Know which subs receive it and what they have attested to.
  • Security protection assets. The SIEM, the vulnerability scanner, the identity provider, and the endpoint tools that protect the CUI environment are in scope even if they never touch CUI themselves. Contractors regularly forget these and then discover them during scoping discussions.

Every asset you can legitimately keep out of scope is money saved. Every asset you wrongly kept out of scope is a finding.

4. Treat the SSP as a living document

The System Security Plan is the document assessors read first and the document most organizations write last. That is backwards. The SSP is supposed to describe how each requirement is met in your environment, specifically, in a way that someone could verify.

Three habits fix most SSP problems:

Match it to the environment that exists. If the SSP describes a firewall you replaced, a domain you migrated away from, or a process nobody follows, it is fiction. Walk the document against the current environment at least quarterly and after every significant change.

Assign owners. Every requirement should have a named person who is responsible for keeping it implemented and for producing evidence on request. “IT” is not an owner. Neither is a vendor.

Document inheritance clearly. Where a cloud provider, MSP, or parent company delivers a control, the SSP should say so, name the provider, and reference the artifact that supports the claim. Inherited does not mean ignored. You still have to show it is working.

And then test the whole thing with the simplest exercise available: hand the SSP to the people named in it and ask them to explain what it says about their area. If the person responsible for account management cannot describe the process the SSP documents, either the document is wrong or the process is not real. An assessor will run this exercise anyway. Better to do it first.

5. Prepare for NIST SP 800-171 Revision 3

CMMC Level 2 is built on NIST SP 800-171 Revision 2. That is what the CMMC rule references, that is where SPRS scores come from, and that is what the DFARS clause currently requires. NIST published Revision 3 in May 2024, and it is the newer standard, but it is not yet the contractual baseline. Until DoW updates the rule, Rev. 2 is what you are held to.

That does not mean ignoring Rev. 3. It means preparing for it the right way. Conduct a gap analysis now so you know what will change when the baseline eventually moves, but do not rewrite your SSP to claim compliance with a standard against which you cannot yet be assessed. Rev. 3 reorganizes and consolidates requirements, introduces organization-defined parameters, and adds requirements in areas such as supply chain risk management and planning. Some changes will align with what you already do. Others will create new work.

NIST makes this easier than it sounds. The Rev. 2 to Rev. 3 change analysis published alongside the final revision lays out exactly what moved, merged, or was added. For smaller organizations, the NIST SP 1318 small-business primer is a readable starting point. Use both. Track the gaps. Do not change your score, your SSP, or your affirmations until the contractual baseline actually changes.

Consequences of the pause

Defense contractors have been required to implement NIST SP 800-171 since 2017. CMMC was created because self-attestation alone did not work. Too many organizations ignored the requirements until independent validation introduced real accountability.

Now, some companies are interpreting the pause in CMMC Phase II as permission to pause their compliance efforts altogether. Security initiatives have been put on hold. Resources have been reallocated. Unfinished remediation plans are gathering dust. Years of hard-won progress are beginning to unravel.

The effects extend across an entire ecosystem. Some contractors have shut down the secure enclaves they built to protect CUI. Assessors and consultants have left for other work. Organizations that invested in personnel, technology, training, and assessment capacity are waiting to learn whether the program will continue and what form it will take.

Everyone in this ecosystem was responding to what the government asked the defense industrial base to do: protect sensitive defense information. I hope the uncertainty does not last long.

That does not mean CMMC is beyond improvement. A thoughtful review could reduce unnecessary burdens, clarify expectations, and focus the program more directly on whether security controls work in practice. If that is truly the purpose of the pause, it could produce a stronger program that measures actual security rather than rewarding paperwork created merely to demonstrate compliance.

That review, however, must begin with an accurate understanding of cost. There are significant misconceptions about both the price of a CMMC assessment and the cost of implementing NIST SP 800-171. Implementation costs vary considerably based on an organization’s size, existing security posture, CUI footprint, architecture, and decision to isolate CUI within a properly scoped enclave. Those distinctions disappear when the cost of securing the entire defense industrial base is reduced to a single headline number.

The pause also does not mean assessments have stopped. CMMC Level 2 assessments are still taking place. I have personally led several assessments of organizations since the pause began. DIBCAC continues to conduct government-led assessments. Prime contractors still expect accurate, and often perfect, SPURS scores. Many also continue to prefer the assurance of an independent assessment.

Contractors should not base their security strategy on the hope that DIBCAC never calls. If an assessment begins, crossed fingers will not compensate for an inflated SPURS score, an outdated SSP, missing evidence, or controls that exist only on paper.

And the threat did not pause.

Congress invests billions of dollars in defense research and development, and contractor networks frequently become the custodians of the government’s most valuable defense research. A breach does more than expose information. It converts American investment into foreign military advantage.

This is not hypothetical. In 2013, a confidential Defense Science Board report obtained by The Washington Post identified more than two dozen major weapons programs whose designs had reportedly been compromised through Chinese intrusions into defense contractors. The affected programs included Patriot PAC-3, THAAD, Aegis, the F/A-18, the V-22, the Black Hawk, the Littoral Combat Ship, and the F-35.

One senior military official estimated that the theft provided billions of dollars in combat advantage and saved China approximately 25 years of research and development. Many affected contractors reportedly did not know they had been breached until the FBI notified them. That same year, an effort to require contractors to secure their networks or risk losing Pentagon business stalled.

That was thirteen years ago.

The government may be reconsidering how cybersecurity should be validated. It has not eliminated the need for security, and our adversaries are not waiting for the policy debate to end.

The choice is straightforward: protect the technological advantages we invest so heavily to create, or risk asking our service members to overcome on the battlefield what we failed to secure at home.

The objective cannot be compliance for compliance’s sake. It must be a defense industrial base that is demonstrably secure. Whatever CMMC becomes, that mission must not be allowed to pause.

Leave a Reply

Your email address will not be published.

Social Share Buttons and Icons powered by Ultimatelysocial