CMMC Phase II Is Paused - Your CMMC Strategy Shouldn’t Be
- chickey1
- 2 days ago
- 4 min read
By Chetrice Romero, Senior Cybersecurity Advisor at Ice Miller, LLP

The verification process may be changing — but the responsibility to protect sensitive government information is not.
The Department of Defense's decision to suspend Phase II of the Cybersecurity Maturity Model Certification (CMMC) program has created understandable confusion across the Defense Industrial Base. Phase II, originally scheduled to begin November 10, has been suspended while the Department reviews the program. Importantly, Phase I remains in effect, including applicable self-assessment requirements.
For manufacturers, the takeaway is simple: The process for verifying compliance may be changing, but the responsibility to protect sensitive government information is not.
Organizations should not interpret the Phase II suspension as a reason to stop preparing. Instead, this is an opportunity to step away from the race toward a deadline and build a thoughtful CMMC strategy.
What Is Still Required During the CMMC Phase II Pause?
CMMC did not create the government's expectation that contractors protect sensitive information. The program builds on cybersecurity requirements that already existed for organizations entrusted with federal contract information and controlled unclassified information. During the current Phase I implementation, the department continues to require applicable Level 1 and Level 2 self-assessments and to enforce NIST SP 800-171 Revision 2 requirements through self-assessments and selected government-led assessments. Level 1 organizations are assessed against the 15 safeguarding requirements associated with protecting FCI and generally include contractors or subcontractors that handle FCI but do not process, store, or transmit CUI. Level 2 focuses on protecting CUI and, during Phase I, applicable self-assessments address the 110 security requirements in NIST SP 800-171 Revision 2.
For executives, however, becoming fluent in every acronym should not be the first objective. Leadership needs to understand what government information the organization receives or creates, what contractual requirements apply to it, and whether the organization can demonstrate that those requirements are actually being met.
Selling a product to the department or to a defense prime does not automatically mean every piece of information within the company is CUI. Likewise, selling commercially available off-the-shelf products does not automatically exempt an entire company from CMMC. Applicability depends on the particular work, information, systems, and contractual requirements involved.
Before spending significant money on compliance, understand what you actually have to protect.
Don't Start with 110 Requirements. Start with Your Business.
For an organization that may require Level 2, looking immediately at 110 cybersecurity requirements can make CMMC feel like 110 separate projects. But it shouldn't be approached that way. Start with the business:
What government information do you receive or create?
Where does it enter the organization?
Where is it stored or transmitted?
Who has access?
Which systems touch it?
Which subcontractors, service providers, or cloud environments are involved?
Then determine what actually belongs within your CMMC scope.
The department maintains specific Level 1 and Level 2 scoping guidance because the assessment environment must reflect the systems and assets involved in processing, storing, transmitting, or protecting applicable information. Understanding those information flows before making major technology investments can significantly affect the complexity and cost of the CMMC journey.
Only then should the organization assess its current state, identify gaps, and determine what needs to happen next.
Who Owns Your CMMC Roadmap?
Another mistake is treating CMMC solely as an IT department project.
Technology is important, but CMMC can cross contracts, legal, procurement, operations, human resources, physical security, policies, training, third-party providers, incident response, disaster recovery, documentation, and executive accountability.
Your managed service provider may own technical remediation. Legal may address contractual requirements. Procurement may manage suppliers. Human resources may support workforce requirements. Other specialists may develop governance, conduct exercises, address cloud environments, or prepare the organization for assessment.
But who owns the overall CMMC strategy? Someone needs to understand where the organization is today, where it needs to be, and how all of those workstreams connect. That means establishing priorities; identifying dependencies; assigning ownership; coordinating specialists; tracking remediation and evidence; and giving leadership visibility into progress, risk, cost, and key decisions.
Organizations also should not assume one provider must perform every part of CMMC. In a program that crosses so many disciplines, a provider willing to identify its strengths and recommend qualified specialists for other areas can be a positive sign.
CMMC requires specialists. CMMC readiness requires a strategy that brings those specialists together.
Use the Pause to Build the Roadmap
Instead of asking only when Phase II will begin, leadership should be asking: "What should we be doing now?"
Understand what information you have and what requirements apply.
Define your scope.
Assess where you are today.
Identify the gaps between your current and required state.
Prioritize those gaps based on risk and dependencies.
Establish program ownership.
Bring in the right expertise.
Build a realistic roadmap for implementation, documentation, testing, and ongoing maintenance.
And don't build solely for an assessment. Policies should reflect how the organization actually operates. Employees should understand their responsibilities. Vendors and subcontractors should be appropriately managed. Incident response plans should be exercised. Recovery plans should work when technology is unavailable. Documentation should demonstrate what the organization actually does, not simply what it intends to do.
The details of CMMC may continue to evolve, but those investments strengthen the organization, regardless of how the verification model ultimately changes.
The verification process may change. The threats will change. But organizations that understand their environment, establish a strategy, and continuously strengthen their cybersecurity program will be better positioned for both. Compliance may be the requirement. Resilience should still be the goal.
Chetrice Romero is a senior cybersecurity advisor at Ice Miller focused on CMMC program strategy, cybersecurity governance, compliance, and organizational resilience. She can be reached at chetrice.romero@icemiller.com.




Comments