The Department of War paused CMMC Phase 2 on July 13, 2026, and opened a 60‑day review intended to lessen the compliance burden on small and non‑traditional businesses.
Pause mechanics: a timing change, not a surrender
The July 13 decision does not eliminate existing obligations. Phase 1 self‑assessment requirements, which took effect November 10, 2025 and introduced Level 1 and Level 2 self‑assessment language into applicable solicitations, remain in force. The pause affects the timing — and potentially the scope — of mandatory third‑party assessments originally scheduled to begin under Phase 2 on November 10, 2026, but it does not signal that federal expectations for protecting Controlled Unclassified Information (CUI) have diminished.
How certification activity is continuing despite the pause
Even with Phase 2 on hold, Certified Third Party Assessment Organization (C3PAO) assessments continue to be conducted, and organizations can still pursue certification. Many will need to do so either because a prime contractor requires certification now, or because they want to be well positioned once the Department of War or the Department of Defense (DoD) issues reformed requirements.
The shift envisioned under Phase 2 represents a fundamental move toward external validation: organizations must show not only that cybersecurity controls exist, but that those controls are documented, implemented, and ready for independent validation. Working with experienced C3PAOs, such as Schellman, or other trusted advisory partners can give organizations insight into assessment standards, evidence expectations, and remediation priorities.
Common gaps: mapping CUI, defining assessment boundaries
The decisive factor in a successful assessment is often preparation: a clear, demonstrable understanding of the environment, the paths CUI takes through it, and who or what interacts with that data. According to the source material, many contractors can describe their controls in abstract terms but struggle to fully map where CUI resides, how it moves across systems, and which users and third parties interact with it.
An assessor’s time is not well spent while a contractor defends architectural decisions that could have been documented in advance. Precise definition of assessment boundaries — which systems are in scope, how data flows among them, and where third‑party dependencies lie — materially reduces audit friction and the time needed to demonstrate compliance.
What this means for technologists and security teams, prime contractors, and small and non‑traditional businesses
- Technologists and security teams: Validate and document data flows, confirm where CUI resides, and ensure operational practices align with written policies, procedures, and technical controls so evidence is immediately available for review.
- Prime contractors and procurement leaders: Continue to set subcontractor expectations — commercial procurement requirements often run independently of the Department of War’s timeline, and primes may still demand third‑party validation or higher standards from their suppliers.
- Small and non‑traditional businesses: Treat the 60‑day review as a reprieve for preparation rather than a reason to delay; the pause was launched specifically to address compliance burden concerns, but obligations and commercial pressures remain.
Actionable steps during the Phase 2 pause
Organizations should use the review window to close practical gaps now rather than waiting for reissued rules. Recommended, evidence‑oriented steps drawn from the source are:
- Validate assessment scope: clearly document which systems, data sets, and vendors are in scope and why.
- Map CUI: identify where Controlled Unclassified Information resides and trace its movement through systems and third‑party services.
- Align operations with policy: verify that day‑to‑day practices match written policies, procedures, and implemented technical controls so evidence is coherent and demonstrable.
- Engage experienced assessors or advisors: consult C3PAOs (the source names Schellman) or other advisory partners to understand evidence requirements and likely remediation areas.
- Avoid deprioritization: commercial pressures from prime contractors frequently persist regardless of the Department of War’s timing, so reduced federal immediacy does not equal reduced commercial demand.
The 60‑day review launched July 13 is an operational pause, not a policy retreat. Organizations that use this interval to validate scope, collect and align evidence, and fix demonstrable gaps will reduce audit friction now and be better positioned when reformed Phase 2 requirements are announced — and better protected in the interim.
Original story: Preparing for CMMC: Finding and Filling Cyber Gaps During the Phase 2 Pause




