CMMC Ready Now
Compliance Alert

CMMC Phase 2 Prep: 5 Moves That Still Matter During the Pause

On July 13, 2026, the Department of War suspended CMMC Phase II, pending review, so the November 10 certification gate is on hold. The obligations underneath it are not, and the five moves below still protect your contracts.

Update: CMMC Phase II is suspended

On July 13, 2026, the Department of War suspended CMMC Phase II, effective immediately, pending review, and the Small Business Administration backed the decision the same day. The third party certification gate that November 10, 2026 pointed at is paused. The obligations underneath it were not repealed, so the moves below still matter. For the full picture, read what the July 2026 pause means for defense contractors.

Before the pause, November 10, 2026 was the date contracting officers would gain authority to require a third party CMMC Level 2 certification as a condition of award for work involving Controlled Unclassified Information (CUI). That certification gate is now on hold pending the Department’s review. What did not change is DFARS 252.204-7012 and the NIST SP 800-171 obligations it carries, or the self assessment and SPRS reporting requirements in DFARS 7019 and 7020. The difference between winning and losing DoD work still comes down to preparation.

Here are the five moves every contractor should still make, in priority order.

What Changes When CMMC Phase 2 Begins

Under the phased rollout defined in 32 CFR Part 170, Phase 1 (which began November 10, 2025) required self-assessments and affirmations in SPRS. Phase 2 was set to raise the bar so that contracts involving CUI could require a CMMC Level 2 certification performed by an authorized C3PAO before award. The July 13, 2026 suspension put that third party certification requirement on hold pending review, while leaving the SPRS self assessment and affirmation obligations in place.

When the certification gate is in force, that word “before” matters: certification is a prerequisite for award, not a promise you can fulfill after signing. With Phase II paused, that gate is not being applied in new solicitations right now, but the self assessment and SPRS obligations that screen your bid still are. We covered the mechanics of the rule in our earlier post on CMMC Phase 2 requirements.

The scale of the change is worth pausing on. The Department of Defense estimates that tens of thousands of companies in the defense industrial base handle CUI and will eventually need Level 2 certification. As of this spring, only about 1,000 organizations held one. The contractors who close that gap early will spend late 2026 winning work; the rest will spend it explaining to primes why their certificate is still pending.

Move 1: Confirm Your CMMC Level and Assessment Scope

Start with the data. Do you create, receive, or store CUI? Which contracts carry DFARS 252.204-7012 or the new 7021 clause? Your answers determine whether you need Level 1 self-assessment or Level 2 certification, and they define your assessment boundary.

Scoping errors are among the most expensive mistakes in a CMMC program. A boundary drawn too wide inflates cost; drawn too narrow, it can invalidate your assessment. If you are unsure where to draw the line, our guide on what activates CMMC is the place to start.

Move 2: Update Your SPRS Self-Assessment and Affirmation

Primes and contracting officers are checking SPRS scores before they shortlist bidders. An outdated or missing score is a silent disqualifier. Refresh your NIST SP 800-171 self-assessment, submit the current score, and make sure a senior official has filed the required affirmation.

This step costs nothing and takes days, not months. There is no reason it should not be done this week.

Move 3: Close Your Remaining Gaps Now

Most contractors need 12 to 18 months to remediate a typical gap list — a reality we documented in why 18 months is not enough. With four months left, the honest question is no longer “can we close everything” but “what must be closed before assessment, and what can legitimately ride on a POA&M.”

Prioritize the high-weight controls first. Multi-factor authentication, access control, audit logging, and incident response procedures cannot be deferred — they are evaluated at assessment and must be fully implemented. POA&M accommodations exist for lower-weight gaps, but assessors and contracting officers are increasingly skeptical of programs that rely heavily on them.

Controls That Cannot Ride a POA&M

Access control (AC), multi-factor authentication (IA.3.083), audit logging (AU), and incident response (IR) are among the practices assessors require fully implemented before issuing a passing assessment. If any of these are on your gap list, they move to the front of your remediation queue.

Move 4: Get on a C3PAO Schedule Before the Queue Grows

Roughly 103 authorized C3PAOs are serving a defense industrial base of about 80,000 companies, and wait times are stretching past a year. Booking an assessment slot now — even a provisional one — is one of the cheapest insurance policies available. The Cyber AB Marketplace lists every authorized assessor.

A scheduled slot also creates a forcing function for your remediation plan. Teams that are accountable to an assessment date move faster than teams working against a general sense of urgency. The calendar pressure is real and it is useful — use it.

Move 5: Build Your Evidence Package Early

Assessors do not grade intentions — they grade evidence. Screenshots, configurations, policies, training records, and system security plan (SSP) detail should be organized against each of the 110 controls before the assessment team arrives. Contractors who assemble evidence during remediation, rather than after, consistently move through assessments faster.

A practical structure: one folder per control family, one evidence index that maps each artifact to the specific NIST SP 800-171A assessment objective it satisfies, and a named owner for keeping each artifact current. When an assessor asks how you enforce session lock, the answer should take ninety seconds, not a scavenger hunt.

The Bottom Line on CMMC Phase 2

The November 10, 2026 certification gate is paused, not cancelled, and the obligations underneath it never paused at all. Contractors who treat the suspension as a reason to stand down will restart from behind; contractors who keep their SPRS score, scope and remediation current stay ready for whatever the review produces. Every move above holds its value regardless of what the Department does next with Phase II.

Get a Straight Answer About Your Phase 2 Readiness

Not sure where you stand with four months to go? Book a free 30-minute call with Rick and get an honest read on your CMMC Phase 2 position, with no sales pitch. We never touch your CUI — your data stays exactly where it belongs.

Book a Free Call with Rick