Skip to content

CMMC Phase II Is Paused — Protecting CUI Is Not

August 24, 2026 · By admin

CMMC Phase II Is Paused – Now what?

The temporary pause of CMMC Phase II has understandably created uncertainty throughout the Defense Industrial Base (DIB). Organizations that have spent months preparing for CMMC Level 2 certification may be wondering whether they should slow down, reduce spending, or stop their readiness efforts entirely.

That would be a mistake.

The CMMC assessment process is only one component of a much larger responsibility: protecting Controlled Unclassified Information (CUI).

A pause in the rollout of third-party certification requirements does not eliminate the need for cybersecurity controls, sound information handling practices, or compliance with applicable contractual requirements.

CMMC Is More Than an Assessment

It is easy to view CMMC as a certification project:

Implement the controls. Prepare the documentation. Collect evidence. Pass the assessment.

But that approach misses the purpose of the program.

Organizations within the Defense Industrial Base may possess information related to military systems, engineering, logistics, technology, operations, manufacturing, maintenance, and other sensitive government activities.

That information has value to adversaries.

CMMC and NIST SP 800-171 provide a framework for reducing the likelihood that this information will be compromised.

The assessment verifies the security program.

The security program protects the information.

Those are not the same thing.

The CMMC Pause Does Not Mean Cybersecurity Requirements Disappear

The current pause affects the transition to CMMC Phase II requirements. It should not be interpreted as the cancellation of CMMC or as permission to stop protecting CUI.

Organizations should continue evaluating the cybersecurity requirements applicable to their contracts and environments, including their obligations surrounding NIST SP 800-171, DFARS requirements, CMMC self-assessments, and SPRS reporting where applicable.

More importantly, organizations currently handling CUI still have an operational responsibility to safeguard that information.

Threat actors are not waiting for the CMMC review process to finish.

Don’t Lose the Progress You’ve Already Made

Many organizations have already invested significant resources into CMMC Level 2 readiness.

They may have:

  • Identified systems that process, store, or transmit CUI
  • Developed a CUI data flow
  • Established their CMMC assessment boundary
  • Implemented technical security controls
  • Developed policies and procedures
  • Created or updated a System Security Plan (SSP)
  • Performed NIST SP 800-171 assessments
  • Developed Plans of Action and Milestones (POA&Ms)
  • Collected objective evidence
  • Improved identity and access management
  • Strengthened logging, monitoring, incident response, and vulnerability management
  • Evaluated external service providers and subcontractors

That work has value regardless of when a C3PAO assessment occurs.

Stopping now can allow documentation to become outdated, evidence to disappear, personnel to forget procedures, vulnerabilities to reappear, and temporary workarounds to become permanent problems.

Cybersecurity maturity is easier to maintain than it is to rebuild.

Use the Pause Strategically

Instead of treating the pause as downtime, organizations should treat it as additional preparation time.

Start with the CUI itself.

Where does CUI enter your organization?

Where is it stored?

Who can access it?

Which systems process it?

Where is it transmitted?

Which vendors, cloud services, MSPs, subcontractors, and external service providers can access it?

Then verify whether your documented CUI boundary actually reflects your technical environment.

Organizations should also use this period to validate controls rather than simply documenting them.

If your SSP says a security control is implemented, can your organization demonstrate it?

Can you produce the configuration?

Can you produce the logs?

Can employees explain the procedure?

Can you provide objective evidence showing that the control is operating as described?

Those questions matter whether an assessor arrives next month or next year.

CUI Protection Should Be Continuous

One of the biggest mistakes an organization can make is treating CMMC like an annual audit exercise.

Security controls must continue operating after an assessment.

Accounts still need to be reviewed.

Logs still need to be monitored.

Vulnerabilities still need to be remediated.

Incidents still need to be investigated.

Access still needs to be controlled.

CUI still needs to be protected.

The goal should not simply be to become CMMC ready.

The goal should be to establish a cybersecurity program in which protecting CUI becomes part of normal business operations.

Organizations That Continue Preparing Will Have an Advantage

The final structure and timeline of CMMC may continue to evolve.

But organizations that maintain their cybersecurity programs will be better positioned for whatever comes next.

They will understand their CUI environment.

They will have stronger documentation.

They will have more mature controls.

They will have better evidence.

And they will be able to respond more quickly when customers, prime contractors, contracting officers, or assessors ask questions about their cybersecurity posture.

The organizations that completely stop preparing may eventually discover that the pause did not save them money.

It simply postponed the work.

The Bottom Line

CMMC Phase II may be paused. Protecting CUI is not.

Organizations should continue improving their NIST SP 800-171 implementation, maintaining their documentation, validating their security controls, protecting CUI, and preparing for future CMMC requirements.

Do not prepare simply because an assessment is coming.

Prepare because your organization has been entrusted with information that needs to be protected.

At NTS Solutions, we help organizations understand their CUI environment, identify CMMC and NIST SP 800-171 gaps, develop remediation strategies, strengthen documentation, and prepare for assessment.

The assessment may be paused. Your security program shouldn’t be.

Ready to improve your environment?

Build a more secure, reliable technology foundation.

Start a Conversation