Practical Steps to Navigating the CMMC Phase II Pause

By: Leticia Lambourne

On July 13, 2026, the Department of Defense (DOD/DOW) announced an immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, pausing mandatory third-party assessments (performed by Certified Third-Party Assessor Organization (C3PAO) originally scheduled to begin in November 2026. While this announcement provides operational breathing room, it is a pause on mandatory third-party audits, not a reprieve from cybersecurity compliance.  

Phase I self-assessment requirements, mandatory NIST SP 800-171 compliance under DFARS 252.204-7012, and accurate submissions to the Supplier Performance Risk System (SPRS) remain fully active and enforceable. Defense Industrial Base (DIB) organizations should use this opportunity to fortify their security controls, clean up documentation, and ensure current self-certifications are defensible.  

What Is CMMC?

The CMMC is the DOD framework designed to protect sensitive government information across the defense supply chain. It verifies that defense contractors and subcontractors possess the cybersecurity controls necessary to safeguard two major classes of unclassified information:  

  • Federal Contract Information (FCI). Information that is provided by or generated for the government under a contract that is not intended for public release. 
  • Controlled Unclassified Information (CUI). Sensitive information that requires safeguarding or dissemination controls pursuant to law, regulation, or government-wide policy.

CMMC standardizes compliance by tying technical requirements to established cybersecurity benchmarks, primarily NIST SP 800-171 Rev. 2.  

Who Needs CMMC?

Any organizationprime contractor, or subcontractor that handles, stores, processes, or transmits FCI or CUI in the performance of a defense contract requires compliance. This group includes nontraditional defense suppliers, engineering entities, technology vendors, manufacturing partners, and specialized trades, such as construction organizations that work on military infrastructure. 

What Is the Impact of the ‘Phase II Pause’?

The DOD suspended CMMC Phase II via policy memorandum to address concerns about implementation costs and limited C3PAO audit capacity among small to midsize organizations.  

  • What IPaused. Solicitations and contracts will not mandate a formal C3PAO third-party audit as a prerequisite for contract award. Future rollout phases (Phases 3 and 4) are also frozen. 
  • What Remains Active. Phase I self-assessments are fully active. Organizations handling CUI must still comply with NIST SP 800-171, post accurate scores to SPRS, and submit annual executive affirmations. 
  • Task Force Review. A CMMC Reform Task Force is evaluating the program to streamline assessments and reduce burdens for small and medium-sized organizations. Recommended program updates are expected following this review.    

Why Is Security for CUI Still Mandatory?

The imperative to safeguard CUI exists independently of CMMC. Requirements stem from long-standing contractual rules, specifically DFARS clause 252.204-7012, which was established after significant cyber intrusions compromised defense weapon systems and military technologies through supply chain vulnerabilities. 

Furthermore, self-assessments submitted to SPRS carry substantial legal weight. Under the Department of Justice(DOJ’s) Civil Cyber-Fraud Initiative, knowingly misrepresenting cybersecurity compliance on government submissions can result in severe financial penalties under the False Claims Act.  

What Should Organizations Do Now?

Organizations should view this pause as a strategic window of opportunity to strengthen their cybersecurity posture without the immediate pressure of a formal C3PAO audit deadline. 

  1. Optimize and Bound Your Data Scope. Clearly identify where CUI enters, travels, and resides in your environment. Isolate CUI into dedicated enclaves to limit compliance costs, minimize operational footprint, and avoid whole-network retrofits.  
  2. Close Baseline Technical Gaps. Focus on implementing foundational, universal security controlssuch as Multi-Factor AuthenticationFIPS-validated encryption for data in transitaccess controls, and endpoint loggingthat protect against commercial cyber threats and fulfill mandatory Phase I requirements regardless of future rulemaking. 
  3. Formalize Documentation and Evidence. Ensure that mandatory operational governance documentation is complete and up-to-date. System Security Plans, Incident Response Plans, and Plans of Action and Milestones must be defensible and reflect operational reality. 
  4. Defend Your SPRS Score. Review and validate existing self-assessments submitted to the SPRS. Ensure your self-reported score and executive annual affirmation are backed by concrete evidence to mitigate legal exposure under the DOJ’s Civil Cyber-Fraud Initiative. 
  5. Prepare for Subcontractor Flow-Downs. Prime contractors will continue to hold subcontractors accountable for protecting CUI. Maintaining documented controls preserves eligibility for contract awards. 
Meet the Author
Security Consultant

Leticia Lambourne

Aldrich Solutions LLC

Leticia Lambourne joined Aldrich Solutions in 2026, bringing over 20 years of experience in information technology, security, and software development. Her background spans software development, system administration, and security and privacy consulting, giving her a broad perspective on the technology and security needs of organizations. Leticia works with clients to understand their information security needs… Read more Leticia Lambourne

Leticia's Specialization
  • Governance, risk, and compliance
  • Risk assessment and management
  • Incident response planning and testing
  • Business continuity and disaster recovery
  • Regulatory compliance
  • Security awareness and training
  • Information security policy development and program deployment
  • Security frameworks, including SOC 2 (SSAE 18), ISO 27001, CMMC v2.0, NIST SP 800-53, NIST SP 800-171, NIST CSF, and FedRAMP/StateRAMP
Connect with Leticia
Share
Related Articles
Man pointing at screen instructing his cybersecurity team in dimly lit room
Cybersecurity for Private Company Owners: Practical Steps to Protect Your Business in 2026
Why Cybersecurity Readiness Matters More Than Ever: Tips for Protecting Your Business and Data from BlueHammer

Looking for support or have a question?

Contact us to speak with one of our advisors.

Search

Sign up for our newsletter