Blog
CMMC Phase II Delayed: Why Preparation Still Matters
Christopher Souza | CEO
On July 13, 2026, the Department of Defense (DoD) announced the temporary suspension of CMMC Phase II, which had been scheduled to begin on November 10, 2026. As part of the announcement, the DoD established a task force to conduct a 60-day review of the program while continuing to enforce existing cybersecurity requirements. Phase I remains in effect, and organizations must still comply with applicable self-assessment requirements.
This announcement raises an important question: Should organizations pause their CMMC efforts? The answer is no. While the rollout of mandatory C3PAO assessments for many Level 2 organizations has been delayed, the contractual and cybersecurity requirements that protect federal information have not changed. Companies that handle Covered Defense Information (CDI), Controlled Unclassified Information (CUI), or Federal Contract Information (FCI) must continue meeting their obligations under DFARS 252.204-7012 and NIST SP 800-171 Rev. 3.
What Actually Changed?
The suspension primarily affects the planned expansion of mandatory third-party CMMC assessments for certain Level 2 contractors and Level 3 government assessments. It does not eliminate the underlying cybersecurity requirements that defense contractors have been previously responsible for.
According to the DoD, organizations should expect the following during the review period:
- Phase I CMMC requirements remain in effect.
- NIST SP 800-171 Rev. 2 will continue to be enforced through self-assessments and selected government-led assessments.
- DFARS 252.204-7012 requirements for protecting Covered Defense Information and reporting cyber incidents remain unchanged.
- Contractors and subcontractors must continue safeguarding FCI and CUI throughout their environments.
The certification timeline may have shifted, but the responsibility to secure federal data has not.
Why This is Time to Prepare, Not Pause
Some organizations may view this announcement as additional time before pursuing compliance- this would be a costly mistake. Certification takes 6-18 months of planning and waiting until new guidance is released will only negatively contribute to an already challenging timeline.
Instead, defense contractors should use this 60-day review period to strengthen their cybersecurity programs while addressing the contractual requirements that exist today. Even if portions of CMMC evolve following the DoD’s review, the work invested in implementing NIST SP 800-171 security controls, documenting processes, and improving operational maturity will continue providing long-term value.
Fail to prepare, prepare to fail!
How Defense Contractors Should Use This Time
Rather than putting projects on hold, organizations should continue working toward a mature cybersecurity program by focusing on practical implementation activities such as:
- Validating CMMC scope and identifying systems that store, process, or transmit CUI.
- Remediating outstanding NIST SP 800-171 security gaps.
- Implementing required technical safeguards and strengthening existing controls.
- Updating System Security Plans (SSPs), policies, procedures, and supporting documentation.
- Collecting objective evidence needed to support future assessments.
- Preparing for applicable self-assessment requirements while monitoring future CMMC guidance.
None of these activities become wasted effort because they directly support existing DFARS and NIST requirements that remain enforceable today.
What TSI Recommends
As an authorized CMMC Registered Provider Organization (RPO), Managed Service (MSP), and Managed Security Service Provider (MSSP), TSI recommends organizations stay focused on their cybersecurity and compliance implementations rather than waiting for the outcome of the DoD’s review. Organizations should:
- Continue all planned CMMC and NIST SP 800-171 implementation efforts.
- Not postpone technical, documentation, policy, or evidence collection activities.
- Use the review period to resolve outstanding compliance gaps.
- Reevaluate third-party assessment timing once the Department releases updated guidance.
The organizations that continue improving their cybersecurity posture today will likely face fewer challenges when future CMMC requirements are announced.
Contact TSI Today!
Changes to the CMMC program can create uncertainty, but they should not stop your organization’s progress toward stronger cybersecurity and contractual compliance. The current pause provides an opportunity to strengthen your environment, improve documentation, and address security gaps before additional guidance is released.
TSI has helped organizations across the DIB implement NIST SP 800-171, prepare for CMMC, and build cybersecurity programs that support both compliance and day-to-day operations. If you have questions about how the Phase II suspension impacts your organization, or would like assistance evaluating your current readiness, contact our team of experts today. We will continue monitoring the DoD’s developments and help ensure your organization remains prepared for whatever comes next.
About Technical Support International
TSI is 37-year old cybersecurity (MSSP) and IT support (MSP) company specializing in helping DIB organizations address their NIST 800-171 and CMMC compliance obligations. As a CMMC-AB Registered Provider Organization (RPO), TSI offers a complete NIST 800-171 and CMMC support solution to help guide our clients toward a successful certification audit and provide the assurance that they’re adhering to these expansive compliance requirements.
Categories
- Backup & Disaster Recovery
- Business Operations
- Case Studies
- Cloud Services
- Cyber Security
- Employee Spotlight
- Finance & Budgeting
- Glossary Term
- Governance & IT Compliance
- Managed Services
- Mobile Device Management
- Network Infrastructure
- NIST 800-171 & CMMC 2.0
- PCI
- Podcast
- Project Management
- TSI
- Uncategorized
- vCIO
Cyber Security Policy Starter Kit:
10 Critical Policies That Every Company Should Have in Place
