CMMC Phase 2 Paused; Contractors Must Maintain Readiness

DoD delayed Phase 2, but NIST, DFARS, and Phase 1 compliance requirements remain in effect.

Contractors across the field have spent a significant amount of time preparing for CMMC. Their early efforts focused on understanding the framework, such as identifying controlled unclassified information (CUI), mapping out systems, and implementing base-level controls, but that phase is largely complete. Now we’re seeing that the focus for many organizations has shifted to validating whether what has been built will hold up under assessment, where many are realizing there is more to CMMC compliance than they thought.

What we’re seeing more often now are organizations that thought they were close to readiness, only to find out late in the process that they don’t meet the required controls in NIST Special Publication 800-171 Revision 2. The issue is in proving, with evidence, that the controls are working as intended. When they don’t, timelines start to slip, and in some cases, delay access to contracts.

These preventable delays could impact organizations' bottom lines. The Department of Defense continues to distribute hundreds of billions of dollars annually through its contractor network, creating a landscape in which the ability to demonstrate cybersecurity readiness can determine who may participate. Much of that government spending is spread among a small group of large contractors, which means there is even more pressure on small-to-mid-sized firms to meet requirements quickly to stay competitive.

Why Documentation and Evidence Are Critical

What’s important to remember is that CMMC requires organizations to demonstrate how they protect CUI within their systems and applications used to process Department of Defense contractual work. During the Phase 2 suspension, organizations must demonstrate those protections through applicable self-assessments and may also be subject to select government-led assessments. This still demands a level of rigor that many organizations’ existing internal reviews are not equipped to provide.

At first glance, many of these environments would look complete if this were any other situation. Controls have been implemented, policies are documented, and teams have a clear understanding of what’s required. But organizations are now realizing that assessments operate differently under CMMC. Documentation needs to align directly with each control, and evidence must show how those controls function effectively over time to address each security practice and subsequent assessment objectives. The closer organizations seemingly get to completing an assessment, the more those details will determine outcomes.

In practice, this means organizations and, where applicable, government assessors evaluate how a control is designed, configured, and enforced, and whether there is clear evidence supporting the effectiveness of each control. This can include reviewing logs, examining system configurations, and tracing how specific requirements are met across different parts of the environment. Organizations that haven’t prepared for such detailed scrutiny often find that their documentation and evidence do not fully align with how controls are implemented in practice.

Assessment Scrutiny Is Exposing Operational Gaps

The assessment also introduces a different kind of pressure test. Controls that work in isolation may not hold up when evaluated within a broader system or ecosystem, and documentation that seems complete may not align with how the evidence must be structured. In some cases, teams can explain how a control works but cannot demonstrate it consistently across environments.

Part of the challenge is structural. Most organizations are not building environments specifically for CMMC. They are adapting systems that evolved over time, often shaped by earlier contract requirements that pointed toward cybersecurity best practices without requiring formal validation. Those environments now need to support a higher level of accountability and scrutiny.

Scope Definition Continues to Slow Certification Efforts

What we’re seeing is that all of this often leads to more work for organizations. System boundaries need to be redefined, data flows clearly understood, and processes that were previously documented informally need to be formalized for review and validation.

In some cases, organizations will discover late in the process that more of their environment falls within scope than they expected, which expands both effort and timeline. Conversely, many organizations have discovered that they have over-scoped their environment, adding additional time, effort, and cost to their CMMC process to “right size” their assessment boundary.

Scope definition remains one of the more consistent pressure points. Understanding where CUI resides and how it moves through an organization is foundational to success. When that picture is incomplete, organizations either over-scope — bringing in systems that don’t need to be included — or under-scope, missing elements that later surface during assessment. Both scenarios introduce delays that are difficult to absorb late in the process.

Late-Stage Rework Is Increasing Costs and Delays

Another pattern we’re seeing is the amount of rework happening near the end of readiness efforts. Organizations that have already invested significant time and resources are being forced to revisit earlier decisions to meet assessment expectations, which means refining documentation, adjusting architectures, or rebuilding evidence.

This can include revisiting earlier work that was not designed with formal certification in mind. The additional work is often about tightening what already exists rather than starting over, but it still adds time and complexity at a stage when organizations expect to be moving forward.

CMMC Requires a Business-Wide Commitment

How CMMC is framed internally also shapes its outcomes. In some organizations, it’s treated as a technical compliance exercise with responsibility sitting mostly within IT or security teams. While that approach can move implementation forward, it often leaves gaps in how controls are then maintained and demonstrated over time.

The best way to think about CMMC is that it’s an ongoing requirement for the organization. Controls must be consistently monitored, documented, and enforced. Evidence must be available and aligned to specific requirements on an ongoing basis. That tends to require broader ownership across security, compliance, and business leadership, rather than treating CMMC as a point-in-time compliance exercise.

Organizations that treat CMMC as a business-wide program, rather than a one-off IT checklist or security task, tend to move through assessment with ultimately lower costs. These organizations will align their technical controls with governance, documentation, contractual requirements, and ongoing monitoring much earlier in the process, thereby reducing the need for late-stage adjustments.

Supply Chain Pressure Is Raising the Stakes

The Phase 2 suspension eases the immediate pressure of the deadline, but it should not be used as a reason to stop preparing. Existing self-assessment and safeguarding requirements remain in effect while the department reviews the program. Organizations can use this window to validate their environments before gaps surface and require additional rounds of work.

The impact is beginning to extend outside individual contractors, too. As prime contractors continue evaluating CMMC readiness, they are paying closer attention to the readiness of their suppliers and partners. Requirements are moving through the supply chain, and cybersecurity readiness can influence who can participate in certain opportunities. For organizations further down the chain, readiness is becoming a prerequisite rather than a differentiator. Especially if those organizations wish to avoid penalties under the Fair Claims Act.

External Validation Will Determine Future Defense Opportunities

In practice, the organizations making the most progress are those that treat CMMC as a coordinated, end-to-end program: aligning technical controls, documentation, and ongoing monitoring early, rather than reconciling them at the point of assessment.

In my work at CDW with organizations navigating CMMC readiness, I’m seeing that teams who bring that level of coordination early, and with experienced guidance, are far more likely to move through assessment without disruption.

Ultimately, the purpose of CMMC is to establish a more formal framework for cybersecurity evaluation in defense contracting to protect CUI. For many organizations, the work to implement these controls is already well underway. But the real test is whether those controls can be demonstrated consistently. The Phase 2 pause gives contractors more time to strengthen their evidence and address gaps before the department determines what comes next.

About the Author

Aaron McCray

Aaron McCray

Field CISO at CDW

Aaron McCray is a Field CISO at CDW and a cybersecurity executive with more than 27 years of experience in information security, cyber risk management, governance, compliance, privacy, and operational resilience. His expertise spans enterprise cybersecurity strategy, AI governance, data protection, and risk management across commercial, federal government, and Department of Defense environments.

McCray is also a retired U.S. Navy Commander (CDR) with extensive experience in intelligence, information warfare, and operational security gained through active duty and reserve service.

At CDW, he advises organizations on cybersecurity strategy, AI-enabled security operations, governance frameworks, resilience planning, and enterprise risk management. He is a frequent contributor and speaker on topics including AI in cybersecurity, cyber resiliency, CISO leadership evolution, and data governance.

His certifications and credentials include CISSP, HCISPP, CISA, CRISC, and AWS Cloud Practitioner, along with a master’s degree in business administration.

 

Sign up for our eNewsletters
Get the latest news and updates