Training & Education

CMMC Phase II Is Paused—But These 7 Compliance Mistakes Can Still Cost You Contracts

Training & Education

CMMC Phase II Is Paused—But These 7 Compliance Mistakes Can Still Cost You Contracts

by Josh Manuel on Aug 05 2026
The Department of War suspended the transition to CMMC Phase II, but it did not suspend the obligation to protect Controlled Unclassified Information. Phase I self-assessment requirements remain in place, and contractors must still address applicable DFARS, NIST SP 800-171, CUI handling, documentation and supply-chain obligations. Here are seven costly mistakes defense contractors should correct during the pause.
CMMC Phase I Requirements During the Phase II Pause: What Defense Contractors Must Still Do

Training & Education

CMMC Phase I Requirements During the Phase II Pause: What Defense Contractors Must Still Do

by Josh Manuel on Aug 05 2026
CMMC Phase II is paused, but CMMC Phase I requirements remain in place. Defense contractors may still need Level 1 or Level 2 self-assessments, current SPRS records, annual affirmations, accurate assessment scopes, and continued protection of FCI and CUI.
CMMC Phase II Pause Action Plan: What Defense Contractors Should Do in the Next 60 Days

Training & Education

CMMC Phase II Pause Action Plan: What Defense Contractors Should Do in the Next 60 Days

by Josh Manuel on Aug 05 2026
The CMMC Phase II pause action plan gives defense contractors a practical 60-day roadmap to confirm requirements, map CUI, correct scope, strengthen safeguards, build evidence, and prepare for what comes next.
CMMC Phase 2 Pause: Steps for Defense Contractors to Maintain CUI Compliance

Training & Education

CMMC Phase 2 Is Paused—CUI Compliance Is Not: What Defense Contractors Must Do Now

by Josh Manuel on Jul 23 2026
The Department of War has paused the rollout of CMMC Phase 2, but that does not mean CMMC Level 2, NIST SP 800-171, DFARS requirements, or CUI safeguarding obligations have been canceled or suspended. Contractors should use this review period to close security gaps, maintain accurate self-assessments, and continue protecting Controlled Unclassified Information—not put compliance efforts on hold.