CMMC Phase II Is Paused—But These 7 Compliance Mistakes Can Still Cost You Contracts

Updated August 4, 2026

On July 13, 2026, the Department of War announced the immediate suspension of the transition to Cybersecurity Maturity Model Certification Phase II requirements, which had been scheduled to begin in November 2026.

That announcement created immediate confusion across the Defense Industrial Base.

Some companies interpreted the news as a delay in third-party certification. Others interpreted it as a suspension of the entire CMMC program. Still others assumed they could pause their cybersecurity and Controlled Unclassified Information initiatives until the Department finishes its review.

Those interpretations are not the same—and the distinction matters.

According to the Department’s official announcement, all Phase I self-assessment requirements remain in place. The Department also stated that contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012. During the interim period, the Department plans to enforce NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments.

The separate CMMC Phase II implementation suspension memorandum provides additional detail. During the suspension, program managers and requiring activities may designate CMMC Level 1 Self-Assessments or Level 2 Self-Assessments, but may not designate Level 2 C3PAO or Level 3 DIBCAC assessment requirements.

The CMMC Phase II pause changes how certain requirements are being implemented. It does not eliminate the underlying responsibility to protect FCI, CUI and covered defense information.

For defense contractors, the pause should not be treated as permission to stop. It should be treated as an opportunity to correct weaknesses before the Department announces what comes next.

The following seven mistakes can still create compliance, assessment and contract-performance risks.

Mistake #1: Assuming the CMMC Pause Means CMMC Was Cancelled

The most damaging mistake is also the simplest: assuming the Phase II pause means that CMMC—or federal cybersecurity enforcement more broadly—has disappeared.

The Department did not announce the cancellation of CMMC. It announced a comprehensive review intended to reduce unnecessary compliance burdens, improve scalability and create a more practical approach for small, medium-sized and nontraditional defense contractors.

The Department’s current position is clear:

  • The transition to Phase II is suspended.
  • Phase I self-assessment requirements remain in place.
  • Level 1 Self-assessment and Level 2 Self-assessment requirements may still appear in applicable procurements.
  • Contractors must continue protecting federal information.
  • NIST SP 800-171 Revision 2 will continue to be enforced during the interim period.
  • Applicable DFARS safeguarding requirements remain contractual obligations.

The updated CMMC Frequently Asked Questions also confirms that the Department began incorporating CMMC assessment requirements into applicable procurements when the revised DFARS clause became effective in November 2025 and has now suspended the transition to Phase II.

The practical lesson is that contractors should not rely on headlines alone. Review the clauses, requirements and information-security obligations contained in each solicitation, prime contract and subcontract.

Depending on the contract, those requirements may include:

A pause in one implementation phase does not automatically remove the other clauses already contained in a contractor’s agreements.

Mistake #2: Failing to Properly Identify CUI

CUI identification remains the foundation of every CMMC and safeguarding initiative.

A company cannot correctly protect, mark, store, transmit or destroy CUI until it understands what information qualifies as CUI and where that information originates.

Under 32 CFR 2002.4, CUI is information created or possessed by the Government—or created or possessed for or on behalf of the Government—that a law, regulation or government-wide policy requires or permits an agency to protect using safeguarding or dissemination controls.

That means information does not become CUI merely because:

  • A company considers it confidential.
  • It contains technical details.
  • It relates to a defense program.
  • An employee believes it looks sensitive.
  • A customer informally asks for it to be protected.

There must be an applicable legal, regulatory or government-wide authority behind the CUI designation.

Contractors should examine:

  • Contracts and subcontracts
  • Statements of work
  • Contract data requirements lists
  • Security classification guides
  • Distribution statements
  • Technical data packages
  • Government-provided documents
  • Prime-contractor flowdown instructions
  • The official CUI Registry

The CUI Registry is the government-wide repository for authorized CUI categories, markings, controls and applicable authorities. It should be used alongside the relevant agency’s implementing policies, including DoDI 5200.48 for Department of War information.

Misidentification creates risk in both directions.

Under-identification may leave protected information unmarked, exposed or processed outside the appropriate environment.

Over-identification can unnecessarily expand the compliance boundary, increase costs, restrict ordinary business information and create confusion among employees and subcontractors.

Before buying technology or scheduling an assessment, understand the information.

Mistake #3: Treating CMMC as an IT-Only Project

CMMC includes major technical cybersecurity requirements, but CUI protection is not confined to the IT department.

CUI frequently passes through business processes that involve:

  • Estimating and sales
  • Contract administration
  • Engineering
  • Manufacturing
  • Quality assurance
  • Purchasing
  • Receiving
  • Shipping
  • Human resources
  • Facilities management
  • Printing and scanning
  • Visitor access
  • Records storage
  • Media disposal and destruction

A technical environment may be well protected while printed drawings sit unattended near a copier. A secure enclave may exist while visitors are allowed to enter a production area without escorts. A company may enforce multifactor authentication but fail to control removable media, physical access devices or CUI disposal.

Even the basic safeguarding requirements in FAR 52.204-21 include physical-access measures such as limiting access to authorized individuals, escorting visitors, monitoring visitor activity, maintaining physical-access logs and controlling access devices.

CMMC therefore requires cooperation between various business units, IT, security, operations and executive leadership.

A strong CUI program should answer questions such as:

  1. Where does CUI first enter the company?
  2. Who reviews and accepts it?
  3. Which employees need access?
  4. Where can it be printed?
  5. Where are physical copies stored?
  6. Which production areas use it?
  7. Can visitors see or overhear it?
  8. Which devices or removable media contain it?
  9. How is it shipped?
  10. How is it destroyed?

Physical tools such as CUI restricted-area signs, CUI media labels, cover sheets, visitor badges and destruction signage can help organizations operationalize documented policies and make handling expectations visible.

These products do not create compliance by themselves. They support a broader program that includes defined procedures, employee training, access controls and consistent execution.

Mistake #4: Over-Scoping or Under-Scoping the CMMC Environment

Scope is one of the largest drivers of CMMC complexity and cost.

An organization that places its entire corporate network within the CMMC assessment boundary may create unnecessary remediation, documentation and technology expenses.

An organization that defines its boundary too narrowly may exclude systems, people, facilities or service providers that actually process, store, transmit or protect CUI.

The official CMMC Level 2 Scoping Guide explains how organizations should identify assets within the Level 2 assessment scope. The related CMMC Level 2 Assessment Guide states that an organization may seek assessment for its entire enterprise network or for a specifically defined enclave, depending on how the assessment scope is established.

Scoping should follow the actual flow of CUI.

That includes evaluating:

  • CUI assets
  • Security-protection assets (SPAs)
  • Contractor-risk-managed assets (CRMAs)
  • Specialized assets
  • External service providers
  • Cloud environments
  • Managed service providers
  • Remote workers
  • Shared infrastructure
  • Printers, scanners and multifunction devices
  • Removable media
  • Physical workspaces

A useful starting point is to create a CUI data-flow map showing:

Origin → Receipt → Storage → Processing → Access → Transmission → Printing → Sharing → Archiving → Destruction

Business stakeholders are essential to this process. IT may know where data is stored electronically, but engineering, production, shipping and contract personnel often understand how information moves during actual contract performance.

Correct scoping is not simply about making the environment as small as possible. It is about creating a boundary that is accurate, defensible and aligned with how the company performs the work.

Mistake #5: Having Policies Without Evidence of Implementation

A written policy is not the same thing as an implemented security requirement.

The official CMMC Level 2 assessment methodology evaluates whether requirements are implemented correctly, operating as intended and producing the desired security outcome. Assessors may examine documentation, interview personnel and test systems or procedures.

This means a contractor may struggle to demonstrate compliance when:

  • The policy does not match actual operations.
  • Employees do not understand the procedure.
  • Logs or records are unavailable.
  • Controls were implemented only shortly before an assessment.
  • Documentation describes technology the company no longer uses.
  • Physical safeguards exist but are applied inconsistently.
  • The System Security Plan does not match the current environment.
  • POA&M items remain unresolved without proper management.

Examples of useful evidence may include:

  • System configuration records
  • Access-control lists
  • Authentication settings
  • Security logs
  • Visitor logs
  • Employee training records
  • Incident-response exercises
  • Media inventories
  • Destruction records
  • Photographs of controlled areas
  • Approved policies and revision histories
  • Screenshots demonstrating control implementation
  • Supplier flowdown records
  • Risk assessments
  • Updated network and data-flow diagrams

Contractors should also avoid treating a Plan of Action and Milestones as indefinite permission to remain noncompliant. Under the existing CMMC rule, POA&Ms are limited, and conditional CMMC statuses require successful closeout within 180 days.

The best time to collect evidence is while controls are being implemented—not days before an assessment or customer request.

Mistake #6: Assuming an MSP or Cloud Provider Makes the Company Compliant

Many contractors and Organizations Seeking Certifiction (OSC) rely on managed service providers, managed security service providers, cloud platforms, external IT companies and specialized software vendors.

Those providers can be essential to a company’s cybersecurity program. They can also become a major source of scope, documentation and contractual risk.

Hiring an outside provider does not transfer the contractor’s or OSC's safeguarding responsibility to that provider. The organization itself remains responsible for meeting requirements regardless of what provider they hire.

Before relying on an external service, contractors should understand:

  • Whether the provider processes, stores or transmits CUI
  • Whether the provider’s systems fall within the CMMC assessment scope
  • Which security requirements are the contractor’s responsibility
  • Which requirements are the provider’s responsibility
  • Whether responsibility is shared
  • What evidence the provider will make available
  • Whether required contractual terms are included
  • Where the information is physically and logically stored
  • Whether subcontractors or additional cloud services are involved
  • How incidents will be reported and investigated
  • What happens to CUI when the relationship ends

The CMMC Level 2 Scoping Guide specifically addresses external service providers and the role they may have within an organization’s assessment environment.

A provider’s marketing claim, certification or compliance statement should not be accepted without understanding exactly what services, systems and responsibilities are covered.

Document the relationship in contracts, responsibility matrices, system-security documentation and the CUI data-flow map.

Mistake #7: Ignoring Subcontractors and the Wider Supply Chain

CUI protection does not end when information leaves the prime contractor’s network.

When subcontract performance requires access to covered defense information, the information and applicable obligations flow down to the subcontractor.

DFARS 252.204-7012 requires the clause to be included in applicable subcontracts involving operationally critical support or covered defense information. The prime contractor must determine whether information required for subcontract performance retains its identity as covered defense information and requires protection.

Similarly, FAR 52.204-21 contains a flowdown requirement for applicable subcontracts where Federal Contract Information may reside in or transit through the subcontractor’s system.

Contractors should know:

  • Which suppliers receive FCI or CUI
  • Why each supplier needs the information
  • What information is actually necessary
  • Which clauses were flowed down
  • Whether the supplier understands its responsibilities
  • How information is transmitted
  • Where the supplier stores it
  • Whether additional lower-tier subcontractors receive it
  • How cyber incidents will be communicated
  • How CUI will be returned, retained or destroyed

Sending a supplier the entire technical package when it needs only one drawing can unnecessarily expand risk.

The more accurately a contractor can control the flow of CUI, the easier it becomes to manage scope, access, accountability and supply-chain exposure.

How Defense Contractors Should Use the CMMC Phase II Pause

The pause should be used to improve readiness—not to wait for the next announcement.

Contractors can use this period to:

  1. Review active contracts, subcontracts and new solicitations for applicable cybersecurity clauses.
  2. Confirm current NIST SP 800-171 assessment and SPRS information where required.
  3. Identify the FCI and CUI used during contract performance.
  4. Build or update the organization’s CUI data-flow map.
  5. Reevaluate the CMMC assessment scope.
  6. Compare the System Security Plan with the current operating environment.
  7. Review open POA&M items and remediation timelines.
  8. Validate managed-service and cloud-provider responsibilities.
  9. Review physical access, visitor management, printing, marking, storage and destruction procedures.
  10. Confirm appropriate requirements are flowed down to subcontractors.
  11. Train employees on the procedures that apply to their actual roles.
  12. Organize evidence before it is requested by a customer, prime contractor or government assessor.

The final form of CMMC may change following the Department’s review. Contractors should expect additional guidance regarding assessments, implementation schedules, small-business support and the future structure of the program.

But the Department has already made one point clear:

The obligation to protect federal data remains.

The companies that use this period to simplify scope, improve documentation, train employees and strengthen CUI handling will be better positioned for whatever requirements follow the review.

Make CUI Handling Clear and Repeatable

Policies are most effective when employees can see and follow them during daily operations.

CUI Supply provides practical marking and handling tools for defense contractors, manufacturers, engineering firms and other organizations working with Controlled Unclassified Information.

Explore:

CUI marking products should be selected and used according to the organization’s contracts, policies, information ownership and applicable government guidance. Products support the execution of a compliance program but do not independently establish compliance or certification.

Primary Sources

This article is provided for general educational purposes and is not legal, contractual or certification advice.

Share information about your brand with your customers. Describe a product, make announcements, or welcome customers to your store.