CMMC Phase II Pause Action Plan: What Defense Contractors Should Do in the Next 60 Days

Updated August 4, 2026

The CMMC Phase II pause gives defense contractors more time, but it does not eliminate the need to protect Federal Contract Information, Controlled Unclassified Information, or covered defense information.

This CMMC Phase II pause action plan gives contractors a practical 60-day roadmap for reviewing contracts, identifying CUI, correcting scope, strengthening physical safeguards, documenting evidence, and testing supply-chain readiness.

What should defense contractors do during the CMMC Phase II pause?

Defense contractors should continue meeting applicable Phase I self-assessment, FAR, DFARS, NIST SP 800-171, CUI safeguarding, and subcontract flowdown obligations. They should use the pause to verify contract requirements, map CUI, validate assessment scope, close security gaps, strengthen physical controls, document evidence, and prepare for future government or third-party verification.

This CMMC Phase II pause action plan organizes that work into manageable phases.

On July 13, 2026, the Department of War announced the immediate suspension of the transition to CMMC Phase II requirements and other pending CMMC implementation milestones. The Department also stated that Phase I self-assessment requirements remain in place.

According to the official CMMC Phase II suspension memorandum, program managers and requiring activities may use CMMC Level 1 Self or Level 2 Self requirements during the suspension, but may not designate Level 2 C3PAO or Level 3 DIBCAC assessments. The Department has also stated that it will continue enforcing NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments.

That distinction is critical.

The Department paused a portion of the CMMC rollout. It did not pause the underlying responsibility to safeguard federal information. CMMC Phase II and CMMC Level 2 are not the same things. Applicable requirements in FAR 52.204-21, DFARS 252.204-7012, DFARS 252.204-7019, DFARS 252.204-7020, existing contracts, and subcontract flowdowns may still apply. 

This CMMC Phase II pause action plan is not a replacement for legal, contractual, cybersecurity, or assessment advice. It is a practical framework for using the announced review period productively instead of waiting for another deadline.

Use the CMMC Phase II pause action plan as a working schedule, then adjust each phase to your company’s contracts, risks, size, and existing maturity.

Why contractors should use the pause instead of stopping

A delayed certification milestone can create a false sense of relief.

Companies may postpone remediation, stop collecting evidence, delay employee training, or assume that customers will no longer ask about cybersecurity readiness.

That approach creates avoidable risk.

The official CMMC program website states that all Phase I self-assessment requirements remain firmly in place. The Department’s CMMC reform announcement also states that contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012.

A strong CMMC Phase II pause action plan should therefore focus on work that remains valuable regardless of how the Department modifies the program:

  • Understanding what each contract requires
  • Identifying where FCI and CUI actually exist
  • Reducing unnecessary assessment scope
  • Fixing known NIST SP 800-171 weaknesses
  • Improving physical protection and CUI handling
  • Building evidence that controls are implemented
  • Reviewing subcontractors and external service providers
  • Training employees to follow documented procedures

The goal is not to spend blindly. The goal is to become more accurate, more defensible, and more prepared.

This CMMC Phase II pause action plan keeps the work centered on enduring compliance fundamentals rather than speculation.

CMMC Phase II Pause Action Plan, Days 1–10: Confirm what applies

The first step is not buying technology, canceling services you assume you no longer need, or scheduling an assessment. It is understanding the obligations already contained in the company’s contracts, subcontracts, solicitations, and customer instructions.

Create a contract-requirements inventory that identifies:

  • FAR 52.204-21 requirements involving Federal Contract Information
  • DFARS 252.204-7012 safeguarding and cyber-incident reporting requirements
  • DFARS 252.204-7019 requirements involving a current NIST SP 800-171 assessment
  • DFARS 252.204-7020 requirements involving DoD assessments and access
  • DFARS 252.204-7021 CMMC requirements
  • Prime-contractor cybersecurity clauses and flowdowns
  • Contract-specific security, marking, export-control, or data-handling instructions
  • Current SPRS submissions, scores, dates, and affirmations
  • Any stated CMMC Level 1 Self or Level 2 Self requirement

Do not assume every contract has the same requirement.

One business unit, program, or subcontract may handle only FCI, while another receives CUI and covered defense information. The requirement must be determined from the applicable solicitation, contract, subcontract, flowdown, and information involved.

Assign responsibility for each requirement:

  • Contract administration identifies clauses and flowdowns.
  • IT and security evaluate system impacts.
  • Operations identifies how contract information moves through the business.
  • Facilities reviews physical protection.
  • Executive leadership approves risk, budget, and remediation priorities.

Days 1–10 deliverables

By day 10, the CMMC Phase II pause action plan should produce:

  1. A list of active contracts and applicable cybersecurity clauses
  2. A list of customer and prime-contractor flowdowns
  3. A current SPRS and assessment-status summary
  4. A list of contracts involving FCI, CUI, or covered defense information
  5. A named owner for every unresolved requirement

Completing this first portion of the CMMC Phase II pause action plan prevents later remediation from being built on the wrong contractual assumptions.

CMMC Phase II Pause Action Plan, Days 11–20: Identify and map CUI

CUI identification is the foundation of CMMC readiness.

A contractor cannot accurately scope systems, facilities, employees, vendors, or controls until it knows what information must be protected.

The National Archives CUI Registry is the government-wide repository for approved CUI categories, markings, controls, and applicable authorities. DoD contractors should also review DoDI 5200.48 and contract-specific guidance rather than independently deciding that every sensitive document is CUI.

Start with the source of the information:

  • Government-furnished technical data
  • Drawings, specifications, and engineering files
  • Statements of work and contract deliverables
  • Controlled technical information
  • Quality records and inspection documents
  • Program schedules and performance information
  • Manufacturing work instructions
  • Export-controlled technical data
  • Information created for or on behalf of the Government
  • Prime-contractor files carrying CUI markings or handling instructions

Then map the full lifecycle:

Receipt → Review → Storage → Processing → Printing → Use → Sharing → Shipping → Archiving → Destruction

Include:

  • Employees and departments
  • Workstations and servers
  • Email and collaboration systems
  • Cloud platforms
  • Printers and scanners
  • Removable media
  • Manufacturing equipment
  • Remote users
  • Physical work areas
  • Shipping and receiving
  • Subcontractors
  • Managed service providers
  • Destruction locations

Do not automatically confuse company-confidential information with CUI.

Over-marking can unnecessarily expand scope, cost, and operational restrictions. Under-identification can leave protected information exposed or handled outside the appropriate environment.

Days 11–20 deliverables

By day 20, the CMMC Phase II pause action plan should include:

  • A CUI and FCI inventory
  • A CUI data-flow diagram
  • A list of employees and roles that access CUI
  • A list of systems and facilities that process, store, or transmit CUI
  • A list of external organizations that receive or protect CUI
  • A documented process for resolving unclear markings or contract instructions

This stage of the CMMC Phase II pause action plan should end with a shared understanding of what information requires protection and where it travels.

CMMC Phase II Pause Action Plan, Days 21–30: Correct the assessment scope

Scope determines which assets, people, facilities, and service providers must be addressed during an assessment.

Incorrect scope is one of the fastest ways to create unnecessary cost or hidden exposure.

The official CMMC Level 2 Scoping Guide identifies five asset categories used to define a Level 2 assessment environment:

  1. CUI assets
  2. Security protection assets
  3. Contractor risk-managed assets
  4. Specialized assets
  5. Out-of-scope assets

CUI assets process, store, or transmit CUI. Security protection assets provide security functions or capabilities to the assessment scope. Other asset categories have separate documentation and assessment considerations.

Use the CUI data-flow map to evaluate:

  • Corporate networks and CUI enclaves
  • Cloud environments
  • Managed service providers
  • Managed security service providers
  • External service providers
  • Remote employees
  • Shared identity and access systems
  • Printers, scanners, and multifunction devices
  • Manufacturing and operational technology
  • Removable media
  • Backup systems
  • Physical workspaces and storage areas

The objective is not to make the scope as small as possible. The objective is to make it accurate and defensible.

Over-scoping can force the company to remediate systems that never touch or protect CUI. Under-scoping can omit assets that support, secure, process, store, transmit, or expose CUI.

Days 21–30 deliverables

By day 30, the CMMC Phase II pause action plan should produce:

  • A documented assessment boundary
  • A categorized asset inventory
  • An updated network diagram
  • A list of external service providers and their responsibilities
  • A list of assumptions requiring validation
  • A summary of opportunities to reduce unnecessary CUI exposure

The scoping portion of the CMMC Phase II pause action plan should be reviewed jointly by business, contracts, security, operations, and IT personnel.

CMMC Phase II Pause Action Plan, Days 31–40: Strengthen physical CUI protection

Cybersecurity controls are only part of CUI protection.

Printed drawings, production travelers, visitor access, shipping documents, storage areas, and destruction processes can create exposure even when the network is secure.

Review how employees handle physical CUI in:

  • Engineering offices
  • Manufacturing work cells
  • Quality and inspection areas
  • Receiving and shipping
  • Conference rooms
  • Printer and scanner stations
  • Records-storage rooms
  • IT closets and server areas
  • Remote-work locations
  • Destruction and disposal points

Test whether the company consistently:

  • Limits physical access to authorized individuals
  • Escorts and monitors visitors when required
  • Maintains appropriate physical-access records
  • Controls keys, badges, and other access devices
  • Uses correct CUI markings and cover sheets
  • Prevents unattended exposure at printers and workstations
  • Stores physical CUI appropriately
  • Protects CUI during internal movement and external shipment
  • Uses an approved destruction method
  • Trains personnel on what to do when markings are missing or unclear

FAR 52.204-21 includes basic physical-protection measures involving authorized access, visitor escorting, visitor monitoring, access logs, and management of physical-access devices for covered contractor information systems. DoDI 5200.48 provides additional DoD CUI handling, marking, safeguarding, and destruction procedures.

Physical products support these procedures but do not create compliance by themselves.

CUI Restricted Area Signs, SF 901 Cover Sheets, CUI labels, visitor badges, floor tape, storage identifiers, and destruction signs should reinforce documented access, marking, handling, and training practices.

Contractors reviewing facility controls can also explore the complete CUI Signs collection and CUI Compliance Packs.

Days 31–40 deliverables

By day 40, the CMMC Phase II pause action plan should include:

  • A facility walk-through report
  • A list of physical-access and visitor-control gaps
  • A documented marking and cover-sheet procedure
  • A printer, scanner, storage, and destruction review
  • Photographic evidence of implemented physical safeguards
  • A purchasing list tied to documented requirements rather than assumptions

The physical-security portion of the CMMC Phase II pause action plan should make daily CUI-handling expectations easier for employees and visitors to recognize.

CMMC Phase II Pause Action Plan, Days 41–50: Build evidence and close gaps

CMMC readiness is not demonstrated by policies alone.

The official CMMC Level 2 Assessment Guide describes assessment methods that include examining documentation, interviewing personnel, and testing systems or procedures.

Evidence should show that controls are implemented correctly, operating as intended, and producing the required security outcome.

Review the System Security Plan and confirm that it matches the current environment.

Remove outdated systems, vendors, diagrams, and procedures. Add missing assets, responsibilities, and information flows.

Organize evidence by security requirement. Depending on the requirement, evidence may include:

  • Policies and procedures
  • System configurations
  • Screenshots
  • Access-control lists
  • Audit logs
  • Training records
  • Visitor logs
  • Incident-response exercises
  • Network and data-flow diagrams
  • Asset inventories
  • Risk assessments
  • Photographs of physical controls
  • Media and destruction records
  • Supplier agreements and flowdowns
  • Management reviews and affirmations

Review every POA&M item.

Determine:

  • Whether the issue is still open
  • Whether the planned remediation is realistic
  • Who owns the remediation
  • What evidence will prove closure
  • Whether the item is eligible for a POA&M
  • Whether the required closeout timeline applies

Conditional CMMC statuses and POA&M closeouts remain subject to 32 CFR Part 170. When a conditional status is permitted, applicable POA&M closeout assessments must be completed within 180 days.

The Phase II suspension should not be interpreted as unlimited permission to leave known weaknesses unresolved.

Days 41–50 deliverables

By day 50, the CMMC Phase II pause action plan should produce:

  • An updated System Security Plan
  • An evidence index mapped to applicable requirements
  • A prioritized remediation register
  • A reviewed and updated POA&M
  • Named control and evidence owners
  • A list of missing evidence that must be generated through normal operations

The evidence portion of the CMMC Phase II pause action plan should demonstrate normal, repeatable operations rather than a last-minute assessment exercise.

CMMC Phase II Pause Action Plan, Days 51–60: Test the program and supply chain

The final phase should test whether the program works outside the policy document.

Select a representative piece of CUI and trace it through the organization.

Confirm:

  • Who receives it
  • Where it is stored
  • How it is marked
  • Who can access it
  • Whether it is printed
  • Which suppliers receive it
  • How it is shipped
  • How it is archived
  • How it is destroyed

Conduct employee interviews using practical questions:

  • How do you recognize CUI?
  • What do you do if a document is unmarked?
  • Where may CUI be stored?
  • Can CUI be emailed to a personal account?
  • What happens when a visitor enters a controlled area?
  • How is printed CUI transported?
  • Which destruction method is approved?
  • Who should receive a cyber-incident report?
  • Which subcontractors are authorized to receive this information?

Review subcontractors and external providers.

DFARS 252.204-7012 includes flowdown obligations for applicable subcontracts involving covered defense information or operationally critical support. FAR 52.204-21 also includes a flowdown requirement for applicable subcontracts involving Federal Contract Information.

Confirm:

  • What information each supplier receives
  • Why the supplier needs it
  • Which clauses and instructions were flowed down
  • Whether lower-tier subcontractors receive the information
  • How the supplier protects the information
  • How information will be returned, retained, or destroyed
  • How cyber incidents will be communicated
  • What evidence the supplier can provide
  • Whether cloud and managed-service responsibilities are documented

Finish with a tabletop readiness review.

Have leadership, contracts, operations, IT, security, and facility personnel walk through:

  • An assessment request
  • A customer cybersecurity inquiry
  • A visitor entering a controlled area
  • A suspected cyber incident
  • An incorrectly marked document
  • A supplier requesting additional technical information
  • A lost device or removable-media event
  • A physical CUI-handling failure

Days 51–60 deliverables

By day 60, the CMMC Phase II pause action plan should include:

  • A completed internal readiness review
  • Employee interview results
  • A tested CUI lifecycle trace
  • A supplier and external-provider risk summary
  • Corrective actions with owners and due dates
  • An executive readiness report

The final stage of the CMMC Phase II pause action plan converts findings into assigned corrective actions instead of leaving them as informal observations.

60-day CMMC pause checklist

Use this condensed CMMC Phase II pause action plan as a leadership checklist:

  • Review contracts, clauses, and flowdowns
  • Confirm current SPRS and self-assessment status
  • Identify FCI, CUI, and covered defense information
  • Map the complete CUI lifecycle
  • Validate the CMMC assessment boundary
  • Categorize assets and external providers
  • Review physical access and visitor controls
  • Correct marking, printing, storage, shipping, and destruction gaps
  • Update the System Security Plan
  • Build an organized evidence library
  • Review POA&M eligibility and closeout plans
  • Test employee knowledge
  • Validate subcontractor flowdowns
  • Conduct an internal readiness review
  • Report risks and priorities to leadership

Leadership should revisit this CMMC Phase II pause action plan whenever official guidance, contract requirements, customer expectations, or the company’s CUI environment changes.

What defense contractors should not do during the pause

A useful CMMC Phase II pause action plan also defines what to avoid.

Do not:

  • Assume CMMC has been cancelled
  • Stop protecting CUI
  • Delay every security improvement until the review ends
  • Buy tools without confirming scope and responsibility
  • Treat an MSP’s marketing statement as sufficient evidence
  • Mark every sensitive document as CUI
  • Ignore physical protection because the IT environment is secure
  • Leave policies disconnected from daily operations
  • Send suppliers more CUI than they need
  • Allow old SPRS, SSP, POA&M, or asset information to remain uncorrected

The most valuable improvements are usually the ones that remain necessary under multiple possible outcomes:

  • Accurate information identification
  • Limited access
  • Reliable security controls
  • Documented evidence
  • Trained personnel
  • Controlled information flow
  • Accountable suppliers
  • Current system documentation

That is why the CMMC Phase II pause action plan prioritizes foundational controls over deadline-driven activity.

The pause is a preparation window, not a finish line

No contractor can know exactly what the Department’s CMMC review will produce.

Requirements, schedules, assessment models, or implementation guidance may change.

However, the official announcement already provides enough direction for companies to act responsibly. Phase I self-assessments remain, NIST SP 800-171 Revision 2 enforcement continues during the interim period, and applicable contractual safeguarding obligations remain relevant.

A disciplined CMMC Phase II pause action plan lets contractors improve readiness without making speculative investments.

It focuses first on:

  • Contract requirements
  • CUI identification
  • Accurate scope
  • Physical protection
  • Technical safeguards
  • Evidence
  • Employee readiness
  • Supply-chain accountability

Companies that use the pause to become more accurate and operationally consistent should be better prepared for customer scrutiny, government-led assessments, future CMMC changes, and the daily responsibility of protecting CUI.

The CMMC Phase II pause action plan should leave the organization with a clearer scope, stronger evidence, and fewer unresolved assumptions.

Make physical CUI controls easier to follow

Employees are more likely to follow a process when expectations are visible, consistent, and available where work happens.

CUI Supply provides marking and handling products for defense contractors, manufacturers, engineering firms, research organizations, and other entities working with Controlled Unclassified Information.

Explore:

These products support a compliance program but do not independently establish compliance, satisfy every contract requirement, or guarantee certification.

Product selection should follow the needs identified through the CMMC Phase II pause action plan.

Frequently Asked Questions

Is CMMC Phase II cancelled?

No. The Department announced a suspension of the transition to Phase II requirements and initiated a review of the CMMC program. Phase I self-assessment requirements remain in place.

What is the best way to use the CMMC Phase II pause?

The best approach is to follow a structured CMMC Phase II pause action plan: confirm contract requirements, identify and map CUI, validate scope, strengthen physical and technical controls, build evidence, review suppliers, and test employee readiness.

A documented CMMC Phase II pause action plan also gives leadership a measurable way to track progress.

Do contractors still need to protect CUI during the pause?

Yes. Applicable contractual and regulatory safeguarding requirements continue. Contractors should review their specific FAR, DFARS, contract, subcontract, and customer obligations.

Can a solicitation still require a CMMC assessment during the suspension?

The implementing memorandum states that program managers and requiring activities may include CMMC Level 1 Self or Level 2 Self requirements during the suspension. They may not designate Level 2 C3PAO or Level 3 DIBCAC assessments during the suspension period.

Should contractors stop preparing for a C3PAO assessment?

Contractors should reassess timing and spending based on their contracts, customers, risks, and business goals.

They should not stop foundational work such as:

  • CUI identification
  • CMMC scoping
  • NIST SP 800-171 remediation
  • Evidence collection
  • Employee training
  • Supplier reviews
  • Physical CUI protection

Does buying CUI signage or labels make a company compliant?

No.

Signs, labels, cover sheets, badges, and other products can support documented controls, but compliance depends on the organization’s applicable requirements, policies, procedures, training, technical safeguards, physical safeguards, and consistent implementation.

How long should this action plan take?

This article uses 60 days because the Department announced a 60-day CMMC review period.

Contractors can compress or extend the steps based on their size, existing maturity, contract requirements, available resources, and risk.

Primary sources

This article is provided for general educational purposes and is not legal, contractual, cybersecurity, or certification advice.

Share information about your brand with your customers. Describe a product, make announcements, or welcome customers to your store.