Skip to main content
The state of ai impact assessment
DoD Halts CMMC Phase II: Your 60-Day Action PlanRegulatory Frameworks
4 min readFor Compliance and Regulatory Affairs Teams

DoD Halts CMMC Phase II: Your 60-Day Action Plan

The Pentagon's suspension of CMMC Phase II requirements on July 13 doesn't mean your cybersecurity efforts should pause. Instead, you have 60 days to strengthen your security posture before the CMMC Reform Task Force presents its recommendations. Here's what your team needs to do now.

The Problem: Compliance Theater vs. Real Security

The DoD paused CMMC Phase II due to "prohibitive compliance costs and bureaucratic burdens" that didn't enhance security. A CyberSheath report revealed only 1% of defense contractors felt ready for Phase II audits, despite around 80,000 companies needing certification by November 10, 2026.

This suspension shifts focus from mere compliance to genuine cyber hygiene. During this period, you must still meet NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments. The 110 security controls remain, but mandatory C3PAO audits are on hold until the task force completes its review.

What You Need Before Starting

Documentation baseline:

  • Your current NIST SP 800-171 self-assessment (SPRS score in SPRS)
  • System Security Plan (SSP) detailing implementation of each control
  • Plan of Action and Milestones (POA&M) for any gaps
  • Contract clauses referencing DFARS 252.204-7012 and 252.204-7019

Technical inventory:

  • Systems processing, storing, or transmitting CUI
  • Network diagrams showing CUI flow and segmentation
  • Access control matrices
  • Incident response runbooks for CUI breaches

Team alignment:

  • Executive sponsor for remediation spending
  • IT/security lead for control implementation
  • Contracts lead for DoD solicitation changes
  • Finance lead for compliance scenario modeling

If you're a subcontractor, confirm your prime's expectations. Some primes may still require C3PAO assessments in flow-down clauses.

Step-by-Step Implementation

Step 1: Conduct a Control-by-Control Gap Analysis (Week 1)

Don't wait for new guidance. Compare your current state against NIST SP 800-171 Rev 2.

For each control:

  • Document status (implemented, partially implemented, not implemented)
  • Identify evidence (config files, logs, policy docs, training records)
  • Calculate remediation effort (hours, cost, dependencies)

Focus on the 14 families, such as Access Control, Awareness and Training, and Incident Response.

Common gaps in defense contractors:

  • AC-2(7): Missing documented approval workflows for privileged user accounts
  • AU-3: Incomplete audit record content
  • IR-6: Lack of formal incident reporting process to notify DoD within 72 hours
  • SC-7: Inadequate segmentation of CUI systems from corporate networks

Step 2: Prioritize Remediation by Contract Risk (Week 2)

Not all controls are equal. Prioritize based on:

Contract dependency:

  • Active contracts requiring CUI handling
  • Dollar value at risk if unable to bid on future CUI work
  • Competitive landscape

Audit likelihood:

  • Assume you're a candidate for government-led assessments if holding contracts above $7.5M or handling sensitive CUI.
  • Primes may conduct supplier assessments independently.

Quick wins:

  • Controls implementable in under 40 hours with existing tools
  • Policy/procedure gaps easily closed with documentation

Step 3: Build Your Evidence Repository (Weeks 3-4)

Even without C3PAO audits, proof of compliance is essential. Create a central repository (SharePoint, GRC platform, or structured file share) containing:

For each control:

  • Implementation statement
  • Evidence artifacts (screenshots, config exports, policy PDFs)
  • Responsible party and last review date
  • Residual risk statement if partially implemented

Automation where possible:

  • Use CIS-CAT Pro or OpenSCAP for configuration validation
  • Export SIEM correlation rules for audit review
  • Pull vulnerability scan reports

Step 4: Implement Technical Controls for CUI Segmentation (Weeks 5-8)

Network segmentation is often costly. If CUI systems share infrastructure with non-CUI systems, you need:

Network layer:

  • Dedicated VLAN or subnet for CUI processing
  • Firewall rules restricting access to authorized users/systems
  • Network access control enforcing device compliance

Endpoint layer:

  • Full-disk encryption on all CUI endpoints
  • Mobile device management enforcing passcode and remote wipe
  • Endpoint detection and response with 90-day log retention

Identity layer:

  • Multi-factor authentication for all CUI access
  • Privileged access management for admin accounts
  • Session timeout after 15 minutes of inactivity

Consider moving CUI workloads to FedRAMP Moderate cloud environments like AWS GovCloud or Azure Government if budget is tight.

Validation: How to Verify It Works

Self-Assessment Verification

Update your SPRS score in the Supplier Performance Risk System:

  1. Log into SPRS
  2. Navigate to your company profile
  3. Submit updated assessment reflecting closed gaps
  4. Your score will appear in DoD source selection evaluations

Aim for a score of 110. Anything below 88 may raise questions in source selection.

Third-Party Validation (Optional)

Consider:

  • Gap assessment by a C3PAO: Costs $15K-$50K; provides a dry run before government-led assessments
  • Penetration testing: Validates technical controls under realistic conditions
  • Tabletop exercises: Tests incident response procedures with your team

Contract Language Review

Check solicitations for updated CMMC language. The suspension means:

  • DFARS 252.204-7021 may be removed or modified in new contracts
  • DFARS 252.204-7012 remains in effect
  • Primes may still require subcontractor assessments via flow-down clauses

Maintenance: Ongoing Tasks

Monthly:

  • Review POA&M progress
  • Update evidence repository
  • Check DoD acquisition websites for updates

Quarterly:

  • Rerun vulnerability scans
  • Conduct IR tabletop exercise
  • Review access control matrices

Annually:

  • Full NIST SP 800-171 self-assessment refresh
  • Security awareness training for CUI-handling personnel
  • Update System Security Plan

Monitor these sources:

The task force has 60 days to deliver recommendations. Use this time to close gaps, document evidence, and prepare for any framework changes. The controls will remain, but the audit process might shift. Get compliant now to be ready for any outcome.

Promotional banner for the Penetration Report Template Kit

You Might Also Like