Skip to main content
CMMC Phase 2 Pause Exposes Gap Between Policy and PreparationCMMC & DIB Assessment
4 min readFor DIB Contractors

CMMC Phase 2 Pause Exposes Gap Between Policy and Preparation

What Happened

On July 13, 2026, the Department of War paused CMMC Phase 2 for a 60-day review to ease compliance burdens on small and non-traditional defense contractors. Originally, Phase 2 was set to take effect on November 10, 2026, requiring independent assessments by Certified Third Party Assessment Organizations (C3PAOs) for new DoD solicitations involving Controlled Unclassified Information (CUI). Phase 1 self-assessment requirements, effective since November 10, 2025, remain active and enforceable.

This isn't a breach or compromise. No technical controls failed. Instead, it highlights a widespread organizational failure to recognize that regulatory timelines and operational readiness don't always align.

Timeline

November 10, 2025: Phase 1 self-assessment requirements take effect under 32 CFR Part 170. Organizations handling CUI must document compliance with NIST SP 800-171 Rev 2 controls.

July 13, 2026: Department of War pauses Phase 2 implementation, delaying mandatory C3PAO assessments originally set for November 10, 2026.

Present: Phase 1 obligations remain in force. C3PAO assessments continue for organizations pursuing voluntary certification or meeting prime contractor demands.

Which Controls Failed or Were Missing

The pause didn't expose failed technical controls but revealed gaps in compliance program management and third-party risk oversight.

Program Management (PM) Family: Organizations treating CMMC as a future issue rather than a current requirement failed PM-9 (Risk Management Strategy). You can't manage compliance risk if your strategy assumes regulatory timelines won't change.

System and Services Acquisition (SA) Family: Prime contractors imposing cybersecurity requirements on subcontractors, independent of federal timelines, demonstrate SA-9 (External Information System Services). The supply chain doesn't wait for policy reviews to conclude.

Planning (PL) Family: Organizations lacking clear assessment boundaries and data flow maps failed PL-2 (System Security Plan). If you can't describe where CUI resides, how it moves, and who accesses it, you have documentation debt, not a plan.

The most critical missing control isn't in NIST SP 800-171. It's the discipline to separate "what we're required to do" from "when the government will check." These are different questions.

What the Relevant Standard Requires

NIST SP 800-171 Rev 2 requires 110 security controls across 14 families. CMMC Level 2 maps directly to these requirements, adding assessment rigor but not changing the underlying obligations.

3.12.1 (Media Protection): "Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital." You must know where CUI exists to protect it.

3.13.1 (System and Communications Protection): "Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems." This requires documented data flows and defined assessment boundaries.

3.1.1 (Access Control): "Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)." You can't limit access to systems you haven't scoped.

DFARS 252.204-7012 doesn't pause when DoW reviews policy. It requires adequate security on covered contractor information systems and cyber incident reporting within 72 hours. Your prime contractor's flow-down requirements don't pause either.

32 CFR Part 170 establishes the CMMC program structure but doesn't create new technical requirements. It mandates assessment and certification processes. The pause affects when you'll face a C3PAO, not whether your controls must exist.

Lessons and Action Items for Your Team

Stop conflating regulatory enforcement with operational requirements. Phase 1 self-assessments remain active. NIST SP 800-171 controls remain mandatory under existing DFARS clauses. The pause changes assessment timelines, not your obligation to protect CUI.

Map your data flows now. Document where CUI enters your environment, which systems process it, where it's stored, and how it exits. Include third-party integrations, backup systems, and development environments. If you discover CUI in unexpected systems, you've defined your remediation scope.

Define your assessment boundary with precision. The boundary isn't "our network." It's the specific systems, applications, and infrastructure components that process, store, or transmit CUI. Document what's in scope and what's explicitly excluded. Your C3PAO will challenge vague boundaries.

Validate that operational practices match documented controls. Your System Security Plan describes what you do. Your assessment evidence proves you do it. If your incident response plan says you review logs daily but your SIEM shows weekly reviews, that's a gap. Close it before an assessor finds it.

Engage your prime contractors directly. Ask what cybersecurity requirements they'll impose regardless of federal timelines. Many primes won't wait for Phase 2 to resume before demanding C3PAO certification from critical subcontractors. Commercial pressure often exceeds regulatory pressure in the DIB.

Use this period for remediation, not relaxation. Organizations that treat the pause as preparation time will enter assessments with documented controls, validated evidence, and clear boundaries. Organizations that deprioritize CMMC work will scramble when enforcement resumes.

Consider pursuing voluntary certification. C3PAO assessments continue despite the pause. If you're confident in your controls, voluntary certification demonstrates readiness and may satisfy prime contractor requirements before they become contractual mandates.

The pause in Phase 2 didn't create a compliance holiday. It created a window to fix what you've been deferring. Your next contract vehicle won't care whether DoW was reviewing policy when you failed to protect CUI. Use the time you've been given.

You Might Also Like