CMMC Phase II halt puts C3PAO assessments on hold but leaves NIST SP 800-171 obligations in force for contractors

Life Cycle Engineering August 26, 2026

Scott Palmer, lead CMMC certified assessor at Life Cycle Engineering, shared expert insight in a recent Industrial Cyber article examining the suspension of CMMC Phase II and what it means for defense contractors navigating ongoing cybersecurity requirements.

In the article, Scott explains that while the suspension pauses the planned third-party assessment requirement, it does not eliminate the underlying obligation to protect Controlled Unclassified Information (CUI). Contractors that have already invested in CMMC readiness can continue to benefit from the work completed, including implementing NIST SP 800-171 requirements and generating assessment evidence:

“Companies that have spent the time and money to implement NIST SP 800-171 security requirements should have also created accurate System Security Plans (SSPs), documented asset inventories, defined system boundaries, mapped data flows, and generated assessment evidence to adhere to these requirements,” Palmer said. “Those actions are crucial improvements to their cybersecurity programs that directly support government regulations, contractual obligations and sound security operations. Those are foundational requirements that I see as an assessor across multiple cybersecurity and industry frameworks.”

Scott Palmer, Life Cycle Engineering

The suspension raises important questions about the future of CMMC and the value of the cybersecurity investments contractors have already made. As the Department of War reviews the program, organizations can use this time to strengthen their security practices, documentation, and readiness for whatever comes next.

See Scott’s insights and the full discussion in Industrial Cyber.

Take the Next Step

Let’s drive your success together. Reach out today to see how our expertise can transform your operations.