What actually happened
On 13 July 2026 the Department of Defense suspended CMMC Phase 2, which had been scheduled to take effect on 10 November 2026. Phase 2 was the step that would have made third-party assessment at CMMC Level 2 a condition of contract award for work involving controlled unclassified information.
The suspension came with a 60-day programme review, which puts updated guidance somewhere around mid-September 2026. What has not changed: Phase 1 remains in force. Since 10 November 2025, most new contracts have required at least Level 1 or Level 2 self-assessment at the time of award.
For European suppliers into the US defence chain, that combination - a live self-assessment requirement and an uncertain third-party assessment date - is a specific and manageable planning problem.
The mistake to avoid
The instinct after a regulatory pause is to reallocate the budget. It is the wrong instinct here for a structural reason: nothing in the suspension changes what CUI is, where it sits in your environment, or your obligation to protect it under existing contract terms. What was suspended is the assessment mechanism, not the underlying security requirement.
Suppliers who stand down entirely will restart from a colder position when the date returns, and the date is likely to return with less notice than the original timeline gave. Suppliers who continue at full assessment-preparation intensity will spend money on a certification cycle whose criteria may shift.
The middle path is to keep working on the parts of readiness that hold their value regardless of how the programme is restructured.
Work that pays off under any Phase 2 outcome
- CUI boundary definition: knowing exactly which systems, storage locations, and data flows are in scope is the input to every version of CMMC and to your existing contract obligations
- A defensible self-assessment record: your current Level 1 or Level 2 self-assessment is a representation to the government, and the evidence behind it should be able to withstand scrutiny even without a C3PAO
- Continuous evidence of the practices you claimed, rather than point-in-time screenshots gathered the week the score was submitted
- Supplier flow-down records: what you required of your own subcontractors, when, and what they confirmed
- Access and change history for CUI systems, retained for the full contract period rather than a rolling operational window
Why self-assessment evidence is the underrated asset
A self-assessment score submitted into the government's system is a claim about a state of the world on a given date. Nobody checks it at submission time. That does not make it low-risk - it makes it a claim that can be examined later, in a context you do not choose, potentially years after the person who made it has left.
The question that matters is not whether you scored honestly. It is whether you can demonstrate, at any later date, what the environment looked like when you scored it. Screenshots in a shared drive do not answer that. A dated, independently verifiable record of the configuration and control state does.
This is the same argument that applies to European regimes with self-declaration mechanics, which is why suppliers with dual EU and US obligations often find the evidence work consolidates neatly. Our earlier analysis of the programme, written before the suspension, is in CMMC 2.0 Phase 2 is coming: what European suppliers to US defense contracts need to know.
The consolidation opportunity
European suppliers in the US defence chain are almost always subject to NIS2 as well, and often to sector-specific requirements on top. Those regimes ask different questions but they draw on overlapping evidence: who accessed what, when did the configuration change, which suppliers were in the chain, what happened during an incident and how quickly.
Building that evidence base once and querying it three ways is meaningfully cheaper than running three programmes. We made the same case for financial entities facing both DORA and NIS2 in building one evidence layer for dual-regulated entities, and the structure transfers directly.
- Do not stand down the CUI scoping work - it is the input to everything
- Treat your existing self-assessment as evidence-backed, not just submitted
- Watch for the mid-September DoD guidance and re-plan against it rather than against the old November date
- Consolidate US and EU evidence collection now, while there is slack in the schedule
If you want to see what continuous, independently verifiable evidence looks like against your own CUI environment, you can start with one system boundary. The ROOTKey enterprise offering covers deployments where evidence has to satisfy more than one regulator at once.
在邮箱中获取网络韧性洞见
关于数据完整性、合规与连续性的实用、可审计指南--发布即送达。





