All Posts
ComplianceCybersecurity

CMMC Phase 2 Suspended: What Texas Defense Contractors Should Do Now

· Infonaligy

DoD suspended CMMC Phase 2 indefinitely. Texas defense contractors should keep building toward Level 2 rather than hitting pause.

CMMC Phase 2 Suspended: What Texas Defense Contractors Should Do Now

The Department of Defense has suspended CMMC Phase 2, which was set to begin requiring Level 2 third-party assessments in new contracts starting November 2026. The original four-phase rollout is now on hold while DoD reviews program costs, assessment capacity, and small business impact.

If you are a Texas defense contractor who has been preparing for the November deadline, this changes your timeline but not your trajectory. Here is what the suspension means and what you should do about it.

What Actually Changed

Phase 1, which requires Level 1 self-assessments in applicable contracts, remains in effect. Phase 2 was going to extend that to Level 2 third-party assessments conducted by C3PAOs (Certified Third-Party Assessment Organizations). That phase is now suspended with no replacement date announced.

The suspension does not change the underlying NIST SP 800-171 requirements. If your contracts include DFARS 252.204-7012, you are still contractually obligated to implement the 110 security controls in NIST 800-171 and maintain a current System Security Plan (SSP). CUI protection obligations have not changed. Prime contractors can still ask subcontractors to demonstrate compliance as a condition of teaming.

The assessment bottleneck was real. Fewer than 100 accredited C3PAOs existed to assess over 70,000 organizations. Suspension gives the ecosystem time to scale, but it also removes the forcing function that was driving urgency.

Why You Should Not Stop Preparing

Pausing your compliance program because of a timeline shift is a mistake for three reasons.

Contract competitiveness. Primes are already using CMMC readiness as a differentiator when bidding on contracts and selecting subcontractors. Several major defense primes issued supplier letters in 2026 requiring evidence of CMMC progress regardless of the Phase 2 timeline. If you cannot show a scored SSP and an active remediation plan, you are less competitive today.

Ramp time. Getting from a partial implementation to a passing Level 2 assessment takes most organizations 9 to 18 months. If Phase 2 resumes with a short runway, contractors who paused will be scrambling. Those who kept building will be ready.

The security gap is real. Nation-state actors targeting the defense industrial base are not waiting for CMMC timelines. The FBI and CISA have documented sustained campaigns against small defense suppliers, precisely because they tend to have weaker controls than primes. The 110 controls in NIST 800-171 exist because the threat warrants them.

Five Steps to Take During the Pause

Use this window to strengthen your position rather than coast.

1. Score your current state honestly. Calculate your SPRS score against all 110 NIST 800-171 controls. If you have not done a formal gap assessment, do one now while the pressure is lower and assessors have availability.

2. Close your highest-risk gaps. Focus on the controls that address the threats you actually face: multifactor authentication on all accounts accessing CUI, encryption of CUI at rest and in transit, endpoint detection and response across every endpoint, and network segmentation between CUI and general-purpose systems. These controls reduce your breach risk whether or not an assessor ever walks through your door.

3. Build your SSP and POA&M. A System Security Plan and Plan of Action and Milestones are required documentation under DFARS 7012 today. If yours are outdated or missing, that is a current contract compliance issue, not a future CMMC issue. Document every control implementation, every exception, and every remediation timeline.

4. Train your people. Security awareness training, CUI handling procedures, and incident response drills are among the most commonly failed assessment areas. They are also the cheapest to fix. Run a tabletop exercise simulating a phishing compromise that targets CUI. Make sure every employee who touches controlled information knows what it is and how to handle it.

5. Vet your IT provider’s CMMC experience. If your MSP cannot explain the difference between an SSP and a POA&M, they will not get you through an assessment. Ask about their experience with NIST 800-171 implementations, how they handle CUI boundary documentation, and whether they have helped other contractors through the C3PAO assessment process.

What Happens When Phase 2 Resumes

DoD has indicated it intends to resume the phased rollout after addressing cost and capacity concerns. When it does, expect a compressed timeline. The political pressure to protect CUI in the defense supply chain has not decreased. Congressional oversight committees have consistently pushed for faster implementation, not slower.

Organizations that used the pause to complete their compliance programs will be able to respond to contract requirements immediately. Those that waited will face the same 9-to-18-month ramp with a shorter deadline.

Where Infonaligy Fits

We work with defense contractors across Texas, from small machine shops to mid-size engineering firms, on CMMC compliance programs that cover gap assessments, control implementation, SSP documentation, and assessment preparation. We also provide the ongoing managed security and managed IT services that keep those controls operating after the assessment is done.

If you have been preparing for the November deadline and want to know how the suspension affects your specific situation, our team can help. If you have not started, this pause is your best opportunity to build a compliance program without the pressure of an imminent deadline.

Need Help With CMMC Compliance?

We help Texas defense contractors build and maintain NIST 800-171 compliance programs.

Get a Free Assessment

Serving Businesses Across Texas & Oklahoma