The July 2026 announcement suspending Phase 2 of CMMC gave many government contractors a reason to pay attention. It also gave them a reason to ask questions.
Does this mean CMMC has been delayed again? Does Level 2 still matter? Should a company continue spending time and money preparing? What happens to organizations that were expecting to need a third-party CMMC assessment?
There is, however, one important distinction that needs to be understood before answering any of them: CMMC Phase 2 and CMMC Level 2 are not the same thing.
Those are reasonable questions, especially for smaller defense contractors trying to run a business while keeping up with changing cybersecurity requirements. There is, however, one important distinction that needs to be understood before answering any of them: CMMC Phase 2 and CMMC Level 2 are not the same thing.
The Department of War (DoW) suspended the move into the second phase of CMMC implementation. It did not eliminate CMMC Level 2 or the underlying responsibility to protect Controlled Unclassified Information (CUI). For contractors currently subject to CMMC Level 2 self-assessment requirements, the fundamentals still matter. In fact, this may be a good time to concentrate on them.
Phase Versus Level: Understanding the Difference
The terminology can be confusing because CMMC uses numbers to describe two different things. A phase describes where the government is in its rollout of CMMC, while a level describes the cybersecurity requirements that apply to an organization.
Phase 1 of CMMC implementation began November 10, 2025. During Phase 1, applicable contracts can require either a Level 1 self-assessment or a Level 2 self-assessment. Phase 2 was scheduled to begin November 10, 2026, and would have expanded the use of Level 2 certification assessments performed by Certified Third-Party Assessment Organizations, or C3PAOs.
In July 2026, the Department suspended the transition into Phase 2 while it reviews the program. Phase 1 self-assessment requirements, however, remain in place.
The CMMC levels answer a different question. CMMC Level 1 focuses on safeguarding Federal Contract Information (FCI) and is based on the 15 basic safeguarding requirements in FAR 52.204-21. CMMC Level 2 is associated with protecting CUI and is based on the 110 security requirements of NIST SP 800-171 Revision 2.
The simplest way to remember the distinction is that phase tells you where the government is in the CMMC rollout; level tells you what cybersecurity requirements apply to the contractor. A contractor should not hear that Phase 2 has been suspended and conclude that Level 2 no longer matters. Those statements mean two very different things.
CMMC Is About More Than Preparing for an Assessment
The continuing confusion between phases and levels points to a larger issue. For some organizations, CMMC preparation has gradually become synonymous with preparing for an assessment.
Questions such as When will the C3PAO arrive? What documents will the assessor want? What score do we need? What policies are missing? have started to dominate the conversation.
Those questions certainly have a place in CMMC preparation, but they should not be the starting point. The more important question is much simpler: Are the security requirements actually being met?
For an organization protecting CUI, CMMC Level 2 is grounded in the 110 requirements of NIST SP 800-171 Revision 2. Those requirements address everyday security practices including access control, configuration management, identification and authentication, incident response, risk assessment, security awareness and system protection.
Those activities matter whether an assessor is scheduled to arrive next month, next year or sometime later. The objective is not simply to look compliant on assessment day. The objective is to protect CUI.
The Phase 2 suspension therefore provides contractors with an opportunity to return to the fundamentals. Start with the requirements themselves, take them one at a time and determine what is actually happening inside the organization.
Moving From Policy to Actual Practice
Access control provides a useful example. A company may have a policy stating that only authorized employees can access CUI. That is appropriate, but it is only the beginning.
The organization also needs to understand who has access, who determines whether an employee should have access, how that approval is communicated to IT, which systems contain CUI and how privileges are assigned. It should know what happens when someone changes jobs or leaves the company and, just as importantly, how the organization confirms that access was actually removed.
Those questions move the conversation away from what a policy says and toward what the organization actually does.
For CMMC readiness, four elements should align: the policy describes what should happen, the procedure explains how it happens, the technology may help enforce it, and the evidence demonstrates that it actually happened.
When those elements tell different stories, there is a gap worth investigating.
The “Tell Me. Show Me.” Approach
A practical way to review Level 2 requirements is to adopt a simple mentality: Tell me. Then show me.
In many cases, plain language is more useful because it demonstrates that the people responsible for the process actually understand it.
“Tell me” means that someone responsible for a requirement should be able to explain how the organization satisfies it. The explanation does not need to sound as though it came from a cybersecurity textbook. In many cases, plain language is more useful because it demonstrates that the people responsible for the process actually understand it.
Consider employee termination. If the organization says system access is removed when employees leave, someone should be able to explain who initiates the process, who disables the accounts, which systems are checked and how the organization confirms the work is complete.
Then comes “show me.” Select a recent employee termination and follow the trail. Look for the termination notification, determine when the account was disabled, verify whether cloud applications and remote access were addressed, and locate the ticket or other record documenting the work. Most importantly, determine whether what actually happened matches the organization’s written procedure.
The same approach can be used throughout the security program. If employees receive security awareness training, review the training records. If vulnerability scans are performed, look at a recent scan and determine what happened to the findings. If multifactor authentication is required, verify where and how it is configured. If the company has an incident response process, understand what happens when an incident occurs and look for evidence that the process has been exercised.
That is a much different exercise than simply asking whether the company has a policy for every requirement.
Your SSP Should Describe the Environment You Actually Have
The System Security Plan, or SSP, is an important part of an organization’s security program, but it should describe the environment that exists today. It should not describe the environment everyone hopes will exist before an assessment. That distinction matters because a carefully written paragraph does not implement a security requirement. Neither does purchasing a security product.
A company can invest in an impressive collection of cybersecurity tools and still have significant gaps if those tools are not configured correctly, incorporated into operating procedures and monitored.
For each Level 2 requirement, the organization should be able to determine what is required, how it is implemented, who owns it, what technology supports it, where the process is documented and what evidence supports the answer. It should also be willing to identify what is not yet complete.
If those questions cannot be answered, the organization has identified an area that deserves attention. That is not a reason to hide the problem. Finding those gaps is the purpose of readiness work.
Evidence Should Be Part of Normal Operations
Evidence should not be something a company begins collecting a few weeks before an assessment. Ideally, it should be a natural result of performing the work correctly. That begins with understanding the CUI environment. Contractors should know where CUI enters the organization, where it is stored, where it travels, who can access it and which service providers or cloud systems touch it.
Responsibility for applicable requirements also needs to be clear. An IT provider may manage the firewall. Human resources may play a role in employee onboarding and termination. Management may approve access, while a security provider may perform vulnerability scanning.
The organization needs to understand how those responsibilities fit together, particularly when technology or security functions are outsourced. This is especially important for smaller government contractors that depend heavily on managed service providers and other outside resources. Outsourcing the work does not mean outsourcing the need to understand it.
If a contractor is asked how a security requirement is satisfied, saying “the IT company handles that” is not a particularly useful answer. Someone within the organization should understand what the provider does, how those activities support the requirement and where the supporting evidence can be found.
Be Careful About What the Company Attests To
There is another reason to take the “tell me, show me” approach seriously. A self-assessment involves making representations about the organization’s cybersecurity posture, and those representations deserve care.
The federal government has used the False Claims Act in cybersecurity-related enforcement matters involving allegations that contractors failed to meet required cybersecurity obligations or made inaccurate representations concerning their cybersecurity practices.
That does not mean every missed security requirement or compliance mistake automatically becomes a False Claims Act case. The facts, contractual requirements, knowledge and applicable law matter, and contractors concerned about potential legal exposure should seek advice from qualified counsel.
From an operational standpoint, however, the lesson is straightforward. Before making an attestation, leadership should understand what is fully implemented, what is not, what the evidence actually supports and whether the organization’s documentation matches its real-world environment.
An organization should not attest to something simply because it intends to fix it later. An assessment should reflect the organization’s actual security posture, not the score it would prefer to have.
Use the Phase 2 Pause Productively
The Phase 2 suspension should not be viewed as permission to put CMMC work on hold. Instead, contractors can use this period to build repeatable security and compliance habits.
That can include reviewing requirements throughout the year rather than waiting for an assessment, keeping the SSP current as the environment changes, and reviewing the CUI boundary whenever a new system, application or vendor is introduced. Organizations should also periodically test employee onboarding and termination procedures, review vulnerability findings, exercise incident response and confirm that technical controls continue to operate as intended.
A simple internal review can be surprisingly effective. Periodically select a requirement and ask the person responsible, “Tell me how we do this.” Then follow it with, “Show me how we do this.”
If the explanation, documentation, technology and evidence all match, move on. If they do not, there is work to do. That is useful information to discover now rather than during an assessment.
Phase 2 May Be Suspended. Level 2 Readiness Is Not.
The suspension of CMMC Phase 2 changes the government’s implementation schedule. It does not make the underlying cybersecurity requirements disappear.
That is why the terminology matters. Phase 2 is not Level 2. Phases describe the CMMC rollout, while levels describe the cybersecurity requirements that apply to contractors.
For organizations handling CUI and subject to Level 2 self-assessment requirements, the practical work remains familiar: understand the 110 NIST SP 800-171 Revision 2 requirements, determine how they apply to the environment, document what is actually being done and maintain evidence supporting those conclusions.
Where something does not match, fix it.
The current pause offers something valuable: time to concentrate on the substance instead of an assessment date. Contractors can use that time to check the CUI boundary, compare the SSP with the actual environment, talk with the people responsible for the controls, examine technical settings and review the evidence. Where something does not match, fix it.
Before an assessment or affirmation is submitted, leadership should be able to ask one final question: If someone asked us to prove this tomorrow, could we explain how we do it and show them the evidence?
Contractors handling CUI should use the Phase 2 suspension as an opportunity to conduct a practical Level 2 readiness review rather than putting their CMMC efforts on hold. Start with the 110 NIST SP 800-171 Revision 2 requirements and compare each one with what is actually happening in the environment. Make sure the SSP, policies, procedures, technical configurations and evidence tell the same story.
Where they do not, identify the gap and address it. Organizations that do not have the internal resources to conduct that review can consider working with qualified CMMC and cybersecurity professionals to help interpret the requirements, validate implementation, organize evidence and prepare for what comes next. Phase 2 may be suspended. Level 2 readiness is not. ![]()
Jacqui Magnes
Leave a Comment