CMMC After the Phase II Pause: What Manufacturers Still Need to Do
By Henry Decoo, Founder & Senior Technology Advisor, DTS IT Advisors. Based on an August 26, 2026 SAMA webinar discussion with Sean Burke of Ariento. Verified against official Department of War, NIST, and National Archives guidance as of August 29, 2026.
Quick answer: Did the Phase II pause cancel CMMC? No. The Department of War suspended the move to CMMC Phase II on July 13, 2026, along with other pending milestones, while it runs a 60-day program review. Phase I self-assessment requirements remain fully in effect: Level 1 for Federal Contract Information and Level 2 self-assessment for Controlled Unclassified Information. A paused deadline doesn’t erase a signed contract, so the practical work of clarifying contracts, CUI, scope, and evidence still needs to happen now.
What the Phase II pause actually changed
On July 13, 2026, the Department of War (the renamed Department of Defense) suspended the transition to CMMC Phase II and “pending and future CMMC implementation milestones” while it conducts a 60-day review of the program. The original Phase II implementation date had been set for November 10, 2026.
The Department was explicit that Phase I self-assessment requirements “remain firmly in place.” During the review period, it says it will continue enforcing cybersecurity compliance through self-assessments and select government-led assessments against NIST SP 800-171 Revision 2, the same standard already incorporated into the CMMC Program rule at 32 CFR Part 170.
The practical takeaway from the webinar was simple: a delayed deadline does not erase a signed contract. What your contracts require, what information you handle, and what your customers or prime contractors expect are unaffected by the pause.
What still applies under Phase I
LEVEL 1: 15 requirements
From FAR 52.204-21 · protects Federal Contract Information (FCI) · self-assessed annuallyLEVEL 2: 110 requirements
From NIST SP 800-171 Rev. 2 · protects Controlled Unclassified Information (CUI) · under the current Phase I pause, Level 2 uses a self-assessment every three years with annual affirmationAn authorized company official must affirm continued compliance in the Supplier Performance Risk System (SPRS): annually, and again after each new assessment. None of that changed on July 13. What paused is the enforcement of Phase II, the point at which CMMC requirements would have started appearing as a condition of contract award across more of the defense industrial base.
The broader CMMC framework includes Level 2 certification assessments performed by authorized C3PAOs for certain contracts. Those certification requirements are part of later CMMC implementation phases and are currently suspended. During the Phase I pause, the Department of War states that the CMMC Program may only require Level 1 and Level 2 self-assessments. If existing contract language appears inconsistent with current guidance, confirm the requirement with the appropriate contracting official before acting on it.
Start with the contract, not the acronym
CMMC conversations often start with labels: Level 1, Level 2, RPO, C3PAO, FedRAMP. Start one step earlier instead. Review the actual contract, solicitation, purchase order, and subcontract flow-down language.
A prime contractor can impose requirements through its subcontracting process, and it may weigh cybersecurity readiness when evaluating supplier risk. If the language is vague, ask the prime or contracting contact to clarify the required CMMC status, the applicable DFARS clauses, the expected handling of CUI, and the timing. Then document the answer rather than relying on an informal assumption.
This isn’t only a compliance exercise. A supplier that can’t accept protected information when a program needs it can create schedule and sourcing risk for the prime, which can affect competitiveness even while broader certification milestones are under review.
Determine whether you actually handle CUI
CUI is not simply “anything related to a government customer.” The National Archives defines it as information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy, but that isn’t classified. Contracts and agency guidance determine how that applies to your work.
For a manufacturer, likely examples include controlled technical information, certain engineering drawings, specifications, test data, or derivative files created while performing the work. A public specification, an ordinary shipping record, or a routine purchase order is not automatically CUI.
Don’t make this call from file names alone. Review markings, contract requirements, the CUI category involved, and guidance from the prime or contracting activity. If the status of information is unclear, get a written answer before deciding it’s inside or outside your protected environment.
Scope drives both risk and cost
Once CUI is identified, trace one realistic job from receipt to final disposition. Follow the drawing or data through email, customer portals, engineering workstations, file servers, cloud applications, backups, printers, CNC workflows, mobile devices, remote users, and downstream suppliers.
Every person, device, system, location, and service provider that touches that information can affect assessment scope. A missing asset creates risk. An unnecessarily broad boundary inflates licensing, remediation, monitoring, documentation, and assessment costs.
This is why buying software before mapping the workflow is so often wasteful. Document the current data flow first, define the intended protected boundary, identify dependencies, and record why each asset is in or out of scope.
An enclave is a scope strategy, not an automatic shortcut
An enclave is a separated environment designed to keep CUI inside a controlled boundary. It can make sense when a limited group performs a limited set of sensitive tasks and can work effectively inside that boundary. It can be a poor fit when CUI has to move continuously through engineering, shop-floor systems, printers, cloud applications, multiple locations, or outside suppliers.
The operational question isn’t simply whether an enclave is available. It’s whether employees can complete the required work without repeatedly moving information outside the boundary. Compare a self-managed enclave, a managed enclave, and a broader enterprise approach on workflow, responsibility, flexibility, ongoing cost, and assessment scope. Ask any enclave provider to document which controls it operates, which responsibilities stay with you, which endpoints and users remain in scope, and what activities are restricted.
Policies are not proof
A written policy describes what should happen. Readiness depends on whether the process is implemented, followed, monitored, and backed by evidence: configurations, access records, training records, incident procedures, risk reviews, inventories, logs, tickets, and other artifacts tied to the assessment objectives.
Management owns more than the budget. Leadership has to approve the scope, assign responsibility, support changes to business process, and make any required affirmation based on an accurate picture of the environment. Internal IT and outside providers can implement controls, but you can’t assume an MSP automatically owns every CMMC responsibility. A written, shared responsibility matrix (who implements, operates, documents, and provides evidence for each requirement) is a practical way to keep that from becoming a gap later.
Download the Manufacturer’s CMMC Readiness Checklist
Seven questions to answer before you spend more money: the same sequence used above, in a one-page format you can work through with your team.
Get the CMMC Readiness Checklist →
Spend money in the right sequence
The goal isn’t the cheapest path. It’s avoiding payment for the wrong solution before the problem is understood. A sensible sequence:
Verify contract requirements, information types, customer expectations, and internal ownership.
Map how FCI and CUI enter, move through, and leave the business.
Define and document the assessment scope and intended operating workflow.
Assess the controls and evidence actually in place.
Prioritize remediation by risk, contractual need, operational impact, and dependency.
Select technology and service providers only once the required outcomes are clear.
Common premature purchases include broad government-cloud licensing, duplicate hardware, evidence-gathering platforms, and enclave services that don’t fit the production workflow. Each can be valuable in the right design. None should substitute for scope and workflow analysis.
Match each provider to the job
Manufacturers often receive proposals that look similar but solve different problems. A managed service provider (MSP) may run day-to-day technology and implement controls. A managed security service provider (MSSP) focuses on monitoring, detection, and response. A CMMC consultant or Registered Practitioner Organization (RPO) can help interpret requirements, define scope, identify gaps, and prepare. A C3PAO (a CMMC Third-Party Assessment Organization certified by the Cyber AB) is the only kind of organization authorized to perform official Level 2 certification assessments.
The broader CMMC framework includes Level 2 certification assessments performed by authorized C3PAOs for certain contracts. Those certification requirements are part of later CMMC implementation phases and are currently suspended. During the Phase I pause, the Department of War states that the CMMC Program may only require Level 1 and Level 2 self-assessments. If existing contract language appears inconsistent with current guidance, confirm the requirement with the appropriate contracting official before acting on it.
Before signing anything, ask the provider to define the systems, users, locations, services, and subcontractors included in the engagement. Confirm assumptions, exclusions, work products, acceptance criteria, remediation support, licensing, implementation charges, recurring fees, travel, retesting, contract term, data ownership, and offboarding. Ask how assessment independence and conflicts of interest will be handled. Preparation and certification are different roles, and a proposal should clearly show who is advising, who is implementing, who may assess, and who remains responsible after the initial project ends. See our guide to evaluating technology vendors for a fuller version of this process.
A practical 30-60-90 day plan
First 30 days: collect contracts and flow-down clauses, identify likely FCI and CUI, name an executive owner, and map the current information flow.
By 60 days: validate the scope, complete or refresh the assessment, identify high-risk gaps, and document provider responsibilities.
By 90 days: remediate priority gaps, test whether employees actually follow the intended workflow, collect evidence, and confirm management can support any required submission or affirmation.
Companies already in progress shouldn’t automatically move to the next purchase. Confirm first that scope, assumptions, and evidence still match how the business actually operates.
Four decisions to make now
Confirm what your contracts and customers require.
Determine whether you receive or create CUI.
Validate the people, systems, locations, and providers inside the scope.
Choose the next investment only after the required outcome is defined.
Bottom line
The Phase II pause created more time to make good decisions. It did not remove the need to understand your contracts, protect sensitive information, or support what your company affirms. If you want an independent CMMC advisory conversation before your next move, that is a useful starting point.
Download the Manufacturer’s CMMC Readiness Checklist
Seven questions to answer before you spend more money.
Get the CMMC Readiness Checklist →
Frequently asked questions
Did the Phase II pause cancel CMMC?
No. It suspended the transition to Phase II and related implementation milestones for a 60-day review. Phase I self-assessment requirements were explicitly stated to remain in place.
Do I still need to follow NIST SP 800-171 right now?
If your contracts require Level 2 protections for CUI, yes. The Department has said it will keep enforcing compliance against NIST SP 800-171 Revision 2 during the review period.
What’s the difference between Level 1 and Level 2?
Level 1 covers 15 basic safeguarding requirements that protect Federal Contract Information and is self-assessed annually. Level 2 covers 110 requirements from NIST SP 800-171 that protect Controlled Unclassified Information, and is reassessed on a three-year cycle with annual affirmation in between.
Is DTS IT Advisors a C3PAO? Can DTS certify our company?
No. DTS IT Advisors is an independent technology advisory firm, not a Certified Third-Party Assessment Organization. Only a Cyber AB-authorized C3PAO can perform an official CMMC Level 2 certification assessment. Those certification requirements are part of later CMMC implementation phases and are currently suspended: during the Phase I pause, the Department of War states that the CMMC Program may only require Level 1 and Level 2 self-assessments. If existing contract language appears inconsistent with current guidance, confirm the requirement with the appropriate contracting official before acting on it. DTS helps manufacturers clarify scope, identify gaps, evaluate remediation options and providers, and sequence spending before or alongside that process.
Schedule an Independent CMMC Readiness Discussion
If you’re unsure whether you handle CUI, whether your scope is too broad, or whether two proposals are actually comparable, an independent second opinion before you commit is often the cheapest step in the whole process.
Sources and further reading
Electronic Code of Federal Regulations: 32 CFR Part 170, CMMC Program
National Archives: About Controlled Unclassified Information
Henry Decoo · Founder & Senior Technology Advisor, DTS IT Advisors · 941-559-8028 · hdecoo@dtsitadvisors.com