Current development

CMMC Phase II was suspended on July 13, 2026.

The suspension changes the near-term implementation schedule for Phase II requirements, but Phase I self-assessment requirements remain active. It does not remove existing safeguarding, incident-reporting, contract, NISP, classified-system, or customer-specific obligations.

What remains true

Contracts and information continue to drive the requirement.

  1. Read the solicitation and contract. Program headlines do not replace the clauses in the procurement.
  2. Know the information. FCI, CUI, classified information, export-controlled information, and customer data create different obligations.
  3. Know the system. Boundaries, providers, facilities, users, and connections determine implementation and evidence.
  4. Make accurate representations. Leadership should understand what the company is certifying, affirming, submitting, or promising.
  5. Maintain the program. Readiness is an operating condition, not a document-delivery event.

Leadership decisions

Five decisions prevent most expensive false starts.

01

Which opportunities matter?

Prioritize the contracts and customers that justify the investment.

02

What information will we handle?

Confirm the actual data and classification requirements.

03

Where will the work occur?

Define systems, locations, providers, users, and connectivity.

04

What must exist before award?

Separate pre-award status from post-award implementation work.

05

Who owns the risk?

Assign authority for investment, acceptance, affirmation, and remediation.

Choose a pathway

Start with the guide that matches the work.