The road to CMMC, and what the Phase 2 suspension changed
The certification timeline moved. The obligations did not. What defense contractors actually have to do right now, and why pausing your program would be the expensive reading of the news.
The Department of War suspended CMMC Phase 2 effective immediately, halting the 10 November 2026 move to third-party C3PAO assessments, and opened a review of the program. What did not change: DFARS 252.204-7012, all 110 NIST SP 800-171 controls, annual affirmations, SPRS scoring, incident reporting, and flow-down to subcontractors. Level 1 and Level 2 self-assessment obligations remain in force. Contractors who stop work now will face the same requirements later with less time, and misrepresenting a SPRS score carries False Claims Act exposure whether or not anyone is coming to assess it.
CMMC verifies something that has been contractually required since 2017. DFARS 252.204-7012 already obliges contractors handling covered defense information to implement all 110 controls in NIST SP 800-171. CMMC was the mechanism to check. The checking has been paused; the requirement has not.
Read this if
- You hold or bid on DoD contracts containing DFARS 252.204-7012
- A prime contractor has flowed CMMC requirements down to you
- You handle Federal Contract Information or Controlled Unclassified Information
- You paused your CMMC program after July 2026 and are wondering whether that was right
What the program actually looks like.
Durations assume a first attempt with a team that has other work to do. They are the numbers we would give you on a call, not the ones in a sales deck.
Determine what you actually hold
2 to 4 weeksFederal Contract Information and Controlled Unclassified Information are different things with different obligations. FCI means Level 1 and 15 basic safeguarding requirements from FAR 52.204-21. CUI means Level 2 and all 110 controls. Read your contracts rather than assuming.
Map where CUI lives and moves
3 to 6 weeksFollow it: email, file shares, engineering workstations, the ERP, the contract manager's laptop, the shop floor. This is the single highest-leverage activity in the whole program, because every system CUI touches falls in scope.
Design the boundary
4 to 8 weeksDecide whether to bring the whole company into scope or build an enclave that CUI lives inside. For most small and mid-sized suppliers the enclave is dramatically cheaper, and the decision to build one is usually worth more than the entire rest of the engagement.
Implement the 110 controls
3 to 9 monthsNIST SP 800-171 across access control, audit, configuration, identification and authentication, incident response, maintenance, media protection, personnel, physical, risk, security assessment, communications and system integrity. Some are technical, many are procedural, and the procedural ones are the ones that get skipped.
SSP, POA&M and SPRS
3 to 5 weeks, then continuousThe System Security Plan documents how each control is met. The POA&M covers what is not yet met, with dates. The score goes into the Supplier Performance Risk System. Note that not every control can sit on a POA&M, and the ones that cannot are the ones assessors look at first.
Self-assess and affirm
2 to 3 weeks, then annualPhase 1 requirements are active: self-assessment and an annual affirmation from a senior official. Level 2 self-assessments continue every three years with annual affirmation. The affirmation is a signed statement, and that signature is what creates personal exposure if the score is wrong.
Prepare for third-party assessment
When Phase 2 resumesC3PAO assessment is paused, not cancelled. Organizations that keep their evidence current will need a mock assessment and a short readiness pass. Organizations that stopped will be starting the implementation again against a shorter runway.
The five things that consume the calendar.
None of these are the parts people budget for, and all of them are the parts that slip.
- Finding CUI, which is always in more places than anyone expects, particularly email and personal drives.
- The procedural controls, which need written procedures and evidence people follow them, not just technology.
- Segmenting operational technology without stopping production, where change windows are measured in shifts.
- Getting a straight answer from an MSP about which controls they cover and which are yours.
- Documenting the SSP properly, which is a substantial writing exercise and cannot be delegated to a tool.
What moves the number.
Two organizations of the same size can differ several-fold on price. This is usually why.
- Whether you scope an enclave or bring the whole company in
- How much CUI has spread into email and unmanaged endpoints
- Whether operational technology touches the same network
- Existing maturity against NIST SP 800-171, which is usually lower than assumed
- Level 1 versus Level 2, which is 15 requirements versus 110
What you have to produce.
Every one of these will be asked for. Missing any of them is a finding.
| Artifact | What it has to contain |
|---|---|
| CUI and FCI determination | Which contracts, which clauses, which data |
| Data flow map | Where CUI enters, lives, moves and leaves |
| System Security Plan | How each of the 110 controls is met, in your environment |
| POA&M | What is not met, who owns it, when it closes |
| SPRS score and submission | Calculated honestly, with the working shown |
| Annual affirmation | Signed by a senior official who understands what they signed |
| Shared responsibility matrix | What your cloud and managed providers cover, in writing |
| Incident response plan | With the 72-hour DFARS reporting obligation built in |
Five failures we see repeatedly.
Each of these turns a manageable program into an expensive one. All five are avoidable at the start and very hard to fix in the middle.
Never defining the boundary
Without a deliberate CUI enclave, the entire company falls in scope: every laptop, every server, every user. The cost difference between a scoped enclave and a whole-company implementation is routinely five to one.
Assuming your cloud provider covers you
A FedRAMP authorized service is a component of your compliance, not a substitute for it. The controls that remain yours are numerous, and the shared responsibility split needs to be documented rather than assumed.
Using the POA&M as a parking lot
Not every control is eligible to be deferred, and a POA&M loaded with the ones that are not is the fastest way to fail. Dates that have already slipped once are read as an indicator of everything else.
An inflated SPRS score
Scoring generously feels harmless while nobody is checking. The affirmation is a signed representation to the government, and False Claims Act cases have already been brought on exactly this. The suspension of assessments does not suspend that exposure.
Treating the July 2026 suspension as a stand-down
The obligations survived intact. The organizations that keep going will be ready when Phase 2 resumes and can say so to primes in the meantime, which is itself becoming a discriminator in flow-down decisions.
What people ask us about CMMC.
Should we pause our CMMC program after the suspension?
What is the difference between Level 1 and Level 2?
How long does Level 2 take?
Can our MSP just handle this?
What happens when Phase 2 resumes?
Keep reading
The road to a SOC 2 report
What the year actually looks like, where the time really goes, and the five ways companies turn a four-month project into a fourteen-month one.
The road to ISO/IEC 27001:2022 certification
A management system, not a control checklist. What the standard actually requires, why Stage 1 audits fail, and the records auditors ask for that nobody thinks to keep.
Want this run for you?
We run these programs end to end: scoping, control design, evidence, auditor management, and the operating rhythm that keeps year two boring.