AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

CMMC Watch: What the Return of Phase 2 Would Change, and Why None of the Readiness Work Is Wasted

CMMC Phase 2 return readiness: what changes when third-party assessment comes back, what conditional status at 88 means, and the work that counts either way.

Dr. Kashmala KhalidDr. Kashmala Khalid Dr. KashCo-Founder, healthcare and defense programsJanuary 18, 2027 · 6 min read

The question the front office asks in January

The quality manager at a 70-person precision machining company outside Wichita spent most of 2026 on work she did not train for. Scoping the systems that touch controlled unclassified information. Moving drawings out of a shared inbox. Writing a system security plan. Sitting with the shop supervisor to explain why the programming station could not keep the login everyone used.

In January her general manager forwards an email from a peer at another shop with one line above it: "So was all that for nothing?"

Below it is a note saying the third-party assessment mandate is still suspended and their company has stopped spending on it.

She does not answer straight away. She opens the folder instead. The plan of action has eleven open items, down from thirty-four. The SPRS score is 91, posted in October, affirmed by the president. The drawings arrive in a controlled folder now, and the shop floor prints them from one station that logs who printed what.

Then she opens the invitation that arrived the same morning: the prime's supplier day in March, agenda item four, "supply chain cybersecurity evidence expectations for the 2027 award cycle."

She replies to the general manager with one sentence. "Ask him what he will show them in March."

What a return would change, in plain words

CMMC is the Department of Defense's way of checking that contractors protect the information the government shares with them. Level 2 measures against NIST SP 800-171 Rev 2, a list of 110 security requirements that has been contractually required through DFARS 252.204-7012 since long before CMMC had a name.

Phase 1 is self-assessment. You score yourself against the 110, post the score in the Supplier Performance Risk System, and a senior official affirms it every year. The scoring scale runs from minus 203 to 110, because requirements carry different weights and a company that meets almost none of them lands well below zero.

Phase 2 would have added the outside examiner: a C3PAO conducting the assessment instead of you. The Department suspended Phase 2 on 13 July 2026, and no new date has been published.

What Phase 2 would change is who checks and how much evidence they want in front of them. What it would not change is the standard, the score, the affirmation, or the requirement to report a cyber incident within 72 hours.

The numbers that matter

Third parties were involved in 61 percent of manufacturing breaches in the Verizon 2026 Data Breach Investigations Report. Your prime knows that figure, which is why the March agenda has an item four.

The Verizon 2026 report found a median of 43 days to remediate a known exploited vulnerability. An assessor asks how you patch. An adversary asks how long you take.

The average cost of a data breach reached USD 4.99 million in the IBM Cost of a Data Breach Report 2026. A 70-person shop does not carry that, and no pause in a rule reduces it.

What to do this week

  1. Reconcile your SPRS score with the evidence behind it. Every point claimed should trace to something a stranger could look at: a screenshot, a policy with a date, a configuration export. A score you cannot show is a score you will be asked to explain. (CIS 8 Audit Log Management)
  2. Work the plan of action by weight, not by ease. The eleven open items are not equal, and a few requirements cannot be deferred under any conditional status, so closing three easy ones to feel progress is the wrong three. (CIS 3 Data Protection)
  3. Write the 72-hour incident procedure as a page anyone on second shift could follow: who declares, who calls, what gets preserved, and where the DIBNet reporting details are kept. DFARS 252.204-7012 did not pause, and 72 hours starts at discovery, not at the Monday meeting. (CIS 17 Incident Response Management)
  4. Turn on logging inside the boundary and store the logs where the people using those systems cannot alter them. The difference between a self-assessment and an assessed one is almost entirely evidence, and logs are the evidence you cannot recreate afterwards. (CIS 8 Audit Log Management)
  5. Map the flow-down. List every supplier, contract shop, plating house and IT provider that touches your controlled information, record what each one has told you in writing, and set the date you will ask again. (CIS 15 Service Provider Management)
  6. Prepare one page for the supplier day in March: current score, date posted, affirming official, open items with dates, and the boundary in two sentences. The shops that arrive with that page get treated differently from the shops that arrive with a promise. (CIS 15 Service Provider Management)

Where AccuSights fits

We scope first and treat second, the way any careful practice works. Our assessment finds the controlled information, draws the boundary, produces the system security plan and the plan of action, and gives you the evidence file behind every point of your SPRS score, the file a C3PAO would open first. Our team implements the controls at a reasonable rate, from data loss prevention and logging to scanning and protection of the assets inside the boundary, and we can stand up a partner enclave with encrypted email. Start with the CMMC accelerator, the three-minute Cyber Hygiene Test, or 15 minutes with an engineer.

Questions people ask

What does conditional CMMC Level 2 status mean? It is a pass with homework. Full status requires meeting all 110 requirements. A company that scores 88 or above may be granted a conditional status with a plan of action and milestones covering the remainder, and the conditional status is meant to be closed out, not lived in. Certain requirements cannot be deferred at all, so an 88 built by deferring the wrong three is not the same 88 as one built by deferring three minor items.

When will CMMC Phase 2 come back? No return date has been published. The Department of Defense suspended Phase 2 on 13 July 2026, and nothing since then has replaced the schedule. What did not pause is the part that governs you today: Phase 1 self-assessment against NIST SP 800-171 Rev 2, the score posted to SPRS with annual affirmation, and DFARS 252.204-7012 with its 72-hour reporting.

Is readiness work wasted if Phase 2 never returns in its current form? No, for three reasons. The 110 requirements come from NIST SP 800-171 Rev 2 and predate CMMC, so they stand on their own. Your SPRS score is calculated from the same assessment and is already a condition of award. And primes are asking their suppliers for evidence regardless of what the rule does, because their own eligibility depends on the chain beneath them.

A suspended exam date has never once made a patient healthier. The work you did in 2026 is the treatment, and it keeps working whether or not anyone comes to grade it.

Controls this post maps to

CIS 17 Incident Response ManagementCIS 8 Audit Log ManagementCIS 15 Service Provider Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the HIPAA and CMMC programs. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.