Blog
CMMC Phase 2 Is on Hold: What Contractors Need to Know
Christopher Souza | CEO
The Department of War has issued another significant update to the Cybersecurity Maturity Model Certification (CMMC) program. Class Deviation 2026-O0025, Revision 3. The most important takeaway is that the planned November 2026 rollout of mandatory CMMC Level 2 C3PAO certification assessments has been suspended. For now, applicable contracts may continue using CMMC Level 1 or Level 2 self-assessment requirements while the Phase 2 transition remains suspended.
For defense contractors, however, the change should not be viewed as a suspension of cybersecurity compliance. Organizations handling Controlled Unclassified Information (CUI) remain responsible for meeting applicable NIST SP 800-171 requirements and supporting the cybersecurity posture they report to the government.
In practical terms, a delayed C3PAO requirement does not change the security controls organizations should already have in place.
Government Assessments Are Still in Play
Organizations should remember that self-assessment does not necessarily mean self-verification will be the only form of oversight they encounter.
The government maintains mechanisms for independently evaluating contractor compliance with NIST SP 800-171, including assessments conducted through the Defense Contract Management Agency and Defense Industrial Base Cybersecurity Assessment Center (DCMA/DIBCAC).
Organizations should therefore be prepared to support their reported cybersecurity posture with documentation, technical evidence, policies, procedures, and working security controls. An SPRS score should reflect what can actually be demonstrated within the environment, not simply what an organization believes it has implemented.
What Defense Contractors Should Be Doing Now
The additional time created by the Phase 2 suspension should be used to strengthen readiness rather than postpone it. Defense contractors should focus on several areas:
- Prepare for Government Verification—not just C3PAO Certification
- The independent certification timeline may have changed, but your technical environment remains critical. Organizations should use this additional time to ensure their NIST SP 800-171 controls can withstand a government-led assessment, including documentation review, technical validation, and live demonstrations.
- Prepare for the 180-Day Remediation Requirement
- Under the CMMC framework, organizations that eventually receive a Conditional CMMC Status must close permitted POA&M items and achieve Final status within the applicable 180-day remediation period. Contractors should identify and address weaknesses now rather than waiting until that remediation clock begins.
- Review Your Subcontractor and Supplier Compliance
- CMMC compliance is also a supply-chain responsibility. Prime contractors must flow applicable CMMC requirements to subcontractors handling FCI or CUI and, where required, ensure subcontractors have the appropriate current CMMC status before awarding the subcontract. This makes vendor and subcontractor cybersecurity due diligence increasingly important. To help prime contractors manage this responsibility, TSI offers Vendor and Subcontractor Vetting Services designed to evaluate downstream suppliers against applicable NIST SP 800-171 and CMMC requirements. TSI can help primes identify compliance risks, assess supplier readiness, review supporting documentation, and establish a repeatable process for validating subcontractor cybersecurity posture before sensitive information or contract work is shared.
Addressing these issues now gives organizations time to correct weaknesses methodically instead of trying to resolve them after an assessment, solicitation, or contract requirement creates an immediate deadline.
Do Not Forget About Your Supply Chain
CMMC is also a supply chain issue. Prime contractors must understand which requirements apply to subcontractors handling Federal Contract Information (FCI) or CUI and make sure applicable cybersecurity requirements are properly flowed down.
That means cybersecurity due diligence should extend beyond an organization’s internal network. Primes should understand how subcontractors protect sensitive information, whether their cybersecurity representations can be supported, and whether weaknesses within the supply chain could create additional contract risk.
TSI’s Vendor and Subcontractor Vetting Services can help prime contractors review supplier readiness, identify NIST SP 800-171 and CMMC compliance concerns, evaluate supporting documentation, and establish a more consistent process for assessing downstream cybersecurity risk.
The Case for Continuing Toward Certification
CMMC Level 2 certification has not been eliminated. The current deviation suspends the Phase 2 transition, but organizations that are already well into their CMMC preparation should carefully consider whether stopping that work makes business sense.
For organizations competing for defense work, demonstrating a mature and independently validated cybersecurity program may also help distinguish them from competitors that have chosen to rely solely on self-assessment. Prime contractors and government customers are increasingly paying attention to whether suppliers can substantiate their cybersecurity claims, regardless of when mandatory C3PAO certification ultimately becomes a contract requirement.
The timeline may have changed, but preparing early still puts organizations in a stronger position when certification requirements return.
Contact TSI Today!
The CMMC Phase 2 suspension gives defense contractors additional time, but it does not remove their responsibility to protect CUI or maintain an accurate and defensible cybersecurity posture. As a CMMC Registered Provider Organization (RPO), TSI can help assess your NIST SP 800-171 and CMMC readiness, address technical and documentation gaps, prepare for potential government assessments, evaluate subcontractor compliance, and build a practical path toward eventual certification. Contact TSI today to discuss how the latest CMMC changes affect your organization and make sure your business is prepared for government scrutiny and future certification requirements.
About Technical Support International
TSI is 37-year old cybersecurity (MSSP) and IT support (MSP) company specializing in helping DIB organizations address their NIST 800-171 and CMMC compliance obligations. As a CMMC-AB Registered Provider Organization (RPO), TSI offers a complete NIST 800-171 and CMMC support solution to help guide our clients toward a successful certification audit and provide the assurance that they’re adhering to these expansive compliance requirements.
Categories
- Backup & Disaster Recovery
- Business Operations
- Case Studies
- Cloud Services
- Cyber Security
- Employee Spotlight
- Finance & Budgeting
- Glossary Term
- Governance & IT Compliance
- Managed Services
- Mobile Device Management
- Network Infrastructure
- NIST 800-171 & CMMC 2.0
- PCI
- Podcast
- Project Management
- TSI
- Uncategorized
- vCIO
Cyber Security Policy Starter Kit:
10 Critical Policies That Every Company Should Have in Place
