Preparing for CMMC: Finding and Filling Cyber Gaps During the Phase 2 Pause
Published: Jul 31, 2026
For the past year, Cybersecurity Maturity Model Certification (CMMC) compliance has mainly focused on self-assessments. Organizations handling Controlled Unclassified Information (CUI) have spent time evaluating their environments, documenting controls, and identifying gaps against required cybersecurity standards. CMMC Phase 2, originally scheduled for November 10, 2026, was set to mandate independent assessments conducted by Certified Third Party Assessment Organizations (C3PAOs) for new DoD solicitations and contracts involving CUI. However, the Department of War (DoW) paused CMMC Phase 2 on July 13, 2026, and launched a 60-day review to lessen the burden of compliance for small and non-traditional businesses.
Phase 1 self-assessment requirements are still in place, meaning the recent pause is simply a change in timing (and potentially scope) of enforcement, rather than a signal that the underlying obligation to protect federal data is any less important moving forward.
Phase 1, which took effect November 10, 2025, introduced Level 1 and Level 2 self-assessment requirements into applicable solicitations.
What To Expect in The CMMC Certification Process
Even with the recent pause, C3PAO assessments are still being conducted. Organizations can still pursue certification, and many will need to, either because a prime contractor requires it or because they want to be well positioned once reformed requirements are developed. This shift represents a fundamental transition to external validation, requiring organizations to demonstrate that not only cybersecurity controls exist, but they are documented, implemented, and ready for independent validation.
The organizations most likely to succeed and thrive are those that have a clear understanding of the environment, data flows, and cybersecurity responsibilities before an assessor arrives. While many contractors are able to describe their cybersecurity controls, they struggle to fully map where CUI resides, its movement through the environment, and the systems, users, and third parties that interact with it. An organization’s ability to effectively demonstrate compliance, rather than spend valuable time defending architectural decisions during an audit, is often determined by their understanding of data flows and precise definition of assessment boundaries.
How to Prepare for CMMC During the Phase 2 Pause
Some organizations might be tempted to deprioritize CMMC preparation now that Phase 2 is on hold. However, that would be a mistake because prime contractors frequently set their own subcontractor cybersecurity expectations independent of DoW’s timeline and obligations haven’t changed, meaning less federal pressure doesn’t mean reduced commercial pressure.
Organizations should use this remaining time to validate assessment scope, identify cybersecurity gaps, and ensure they can provide the evidence required to support compliance claims. This includes confirming where CUI resides, understanding how it moves through the environment, and verifying that operational practices are aligned with policies, procedures, and technical controls.
Early preparation can also help organizations avoid common assessment challenges. Working with experienced C3PAOs, such as Schellman, or other trusted advisory partners, can provide valuable insights on assessment standards, evidence requirements, and areas that may require remediation before certification.
Organizations that treat this period as an opportunity to strengthen their cybersecurity posture, rather than just getting ready for an audit, will be better positioned for successful assessments and long-term compliance.
About Douglas Barbin
As President and National Managing Principal, Doug Barbin is responsible for the strategy, development, growth, and delivery of Schellman’s global services portfolio. Since joining in 2009, his primary focus has been to expand the strong foundation in IT audit and assurance to make Schellman a market leading diversified cybersecurity and compliance services provider. He has developed many of Schellman's service offerings, served global clients, and now focuses on leading and supporting the service delivery professionals, practice leaders, and the business development teams. Doug brings more than 25 years’ experience in technology focused services having served as technology product management executive, mortgage firm CTO/COO, and fraud and computer forensic investigations leader. Doug holds dual-bachelor's degrees in Accounting and Administration of Justice from Penn State as well as an MBA from Pepperdine. He has also taken post graduate courses on Artificial Intelligence from MIT and maintains multiple CPA licenses and in addition to most of the major industry certifications including several he helped create.