Dev48
Language
  • About
  • Services
  • Industries
  • Technologies
  • Articles
  • Contacts
Book a call
    Home/Articles/Suspending cmmc phase ii what this means for your compliance and zero trust stra
Dev48

© 2026 · All rights reserved.

Suspending CMMC Phase II: What This Means for Your Compliance and Zero Trust Strategy

Фото: Sergio-sq (Pixabay) — https://pixabay.com/photos/moon-moon-phases-sky-8006703/

Suspending CMMC Phase II: What This Means for Your Compliance and Zero Trust Strategy

The DoD has paused the CMMC Phase II timeline, but not the risks. Learn what is required right now and how a Zero Trust approach will help you prepare for the future.

September 24, 2026•Updated: September 27, 2026
  • Reducing program lag, not cybersecurity standards
  • Maintaining compliance: 4 critical factors for your CMMC strategy
  • Interim measures plan
  • Preventing unauthorized data disclosure
  • Bottom line

Key takeaways

The U.S. Department of Defense (DoD) has adjusted its Cybersecurity Maturity Model Certification (CMMC) implementation timeline, pausing the deadline for Phase II requirements (accreditation via mandatory third-party assessment organizations, C3PAOs), which was originally set for November 10, 2026.

As the newly formed CMMC reform task force focuses on streamlining the CMMC 2.0 program, the need to raise cybersecurity standards remains unchanged.

The reality is that in today's threat landscape, risks are only increasing, especially as AI enables attackers to orchestrate multi-vector, hyper-volumetric, and application-level attacks.

As a result, it is critical to maintain a focus on extending Zero Trust security to the application, API, and workload levels.

Reducing program lag, not cybersecurity standards

While CMMC II requirements are paused while the task force streamlines the program, this does not mean your compliance strategy should stop. Any organization in the defense industrial base that handles Controlled Unclassified Information (CUI)—including commercial contractors, research centers, and government facilities—must still follow current CMMC assessment mandates, as well as applicable contract terms.

Maintaining compliance: 4 critical factors for your CMMC strategy

Here are four important points to keep in mind:

  • All Phase I CMMC self-assessment requirements remain in effect and are mandatory. Maintain active compliance with current baseline security protocols.

All Phase I CMMC self-assessment requirements remain in effect and are mandatory. Maintain active compliance with current baseline security protocols.

  • Compliance remains strictly tied to the NIST SP 800-171 Rev. 2 framework. Continue to demonstrate adherence to baseline cybersecurity requirements. The responsibility for compliance with DFARS clause 252.204-7012, which requires ongoing adherence to the 110 security controls of NIST SP 800-171, remains in place.

Compliance remains strictly tied to the NIST SP 800-171 Rev. 2 framework. Continue to demonstrate adherence to baseline cybersecurity requirements. The responsibility for compliance with DFARS clause 252.204-7012, which requires ongoing adherence to the 110 security controls of NIST SP 800-171, remains in place.

  • At its core, CMMC relies on Zero Trust principles. Refine your approach to Zero Trust architecture to help you meet DoD interim requirements and long-term security architecture goals.

At its core, CMMC relies on Zero Trust principles. Refine your approach to Zero Trust architecture to help you meet DoD interim requirements and long-term security architecture goals.

  • CMMC certification levels depend on government-conducted assessments. Expect proper oversight from the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), which continues to conduct many of these assessments, and other experts during this pause.

CMMC certification levels depend on government-conducted assessments. Expect proper oversight from the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), which continues to conduct many of these assessments, and other experts during this pause.

Interim measures plan

To help your team stay on track, ensure you are meeting immediate Phase I self-assessment requirements and National Institute of Standards and Technology (NIST) standards.

The table provides good ways to align the five main stages of compliance with approaches and solutions that meet core Zero Trust requirements.

1. Enforce identity and access perimeters

  • Restrict access exclusively to verified, authorized users

Restrict access exclusively to verified, authorized users

  • Create granular authentication protocols in environments containing Federal Contract Information (FCI) or CUI

Create granular authentication protocols in environments containing Federal Contract Information (FCI) or CUI

Access Control and Zero Trust: Follow the principle of 'Least Privilege' to ensure identity-based access for every request using ZTNA both inside the enterprise and at the tactical edge (which aligns with the NIST SP 800-171 identification, authentication, and access control families). This should also include DNS security to block known malicious domains (e.g., botnets, phishing links, and malware injection sites).

The National Security Agency provides the Akamai GovShield solution for secure DNS free of charge to small and medium-sized Defense Industrial Base (DIB) contractors to help them meet these security standards.

2. Secure enclaves and data transmission

  • Create secure enclaves to isolate CUI from standard commercial corporate traffic

Create secure enclaves to isolate CUI from standard commercial corporate traffic

  • Implement robust cryptographic controls for data moving within or outside your perimeter

Implement robust cryptographic controls for data moving within or outside your perimeter

Network Segmentation and Data Protection: Prevent lateral movement within the network using micro-segmentation and protect CUI in transit.

3. Automate oversight and tracking

  • Move away from manual logging

Move away from manual logging

  • Establish continuous monitoring of network architectures, automate compliance mapping, and track unauthorized configuration drift

Establish continuous monitoring of network architectures, automate compliance mapping, and track unauthorized configuration drift

Audit and Accountability: Use DNS Posture Management to automate compliance with security standards and monitor system configuration.

4. Conduct a self-assessment against NIST SP 800-171

  • Assess your system for compliance with the 110 controls of NIST SP 800-171 Rev. 2

Assess your system for compliance with the 110 controls of NIST SP 800-171 Rev. 2

  • Assess your level of compliance honestly, identify technical gaps, and create a Plan of Action and Milestones (POA&M)

Assess your level of compliance honestly, identify technical gaps, and create a Plan of Action and Milestones (POA&M)

Basic requirements for Phase I self-assessment: meet the mandatory basic hygiene checks required by the DoD during the Phase II suspension. For additional recommendations, see the NIST Risk Management Framework.

5. Upload results to SPRS

  • Ensure that your self-assessment results and corporate compliance status are officially uploaded and updated in the Supplier Performance Risk System (SPRS).

Ensure that your self-assessment results and corporate compliance status are officially uploaded and updated in the Supplier Performance Risk System (SPRS).

Stay informed: maintain active status for any pending Requests for Information (RFI) and future contracts with the DoD.

Preventing unauthorized data disclosure

As defense contractors begin using AI assistants and automated agents to process complex proposals and engineering data, access paths to CUI and FCI are becoming dynamic and machine-driven. Traditional perimeter controls cannot verify how large language model pipelines extract local data. Extending the Zero Trust concept to the edge device level ensures that automated AI workflows, inter-service APIs, and non-human identities strictly adhere to NIST SP 800-171 least-privilege policies, preventing unauthorized data disclosure before compliance audits are conducted.

Key takeaway

Although the second phase of CMMC is suspended, it is critical to remain committed to maximum protection. By prioritizing automated auditing, strict network segmentation, and Zero Trust-based access control, you can meet Phase I self-assessment requirements while remaining prepared for any future recommendations from the CMMC reform working group, including any future government-led assessments for organizations seeking higher CMMC levels.

At Akamai, we can help you navigate CMMC requirements and this latest change. We partner with defense organizations around the world, helping them strengthen their overall Zero Trust-based protection across all environments—from corporate networks to the tactical edge. To learn more about our Zero Trust protection solutions and how to achieve your compliance and security goals, contact one of our experts today.

About the author(s)

Erin Verna

Erin Verna is a Principal Product Marketing Manager at Akamai. She has spent the last six years working on Zero Trust architectures and has over a decade of experience in application security.

Tags

← All articles

More in Cloud & Infrastructure

All →
A new skill finds AI agent risks, fixes them, and proves the fix worked
Microsoft

A new skill finds AI agent risks, fixes them, and proves the fix worked

Amazon data center communities: Here’s what’s happening near data centers across the US
Amazon

Amazon data center communities: Here’s what’s happening near data centers across the US

Microsoft packages business AI in single app as it tries to compete with Anthropic
Пресса
Microsoft

Microsoft packages business AI in single app as it tries to compete with Anthropic

An update on Angular’s TypeScript 7-powered Compiler
Microsoft

An update on Angular’s TypeScript 7-powered Compiler

From Opus 5 to Opus 5.5: better fixes at 58% less cost in the SonarQube Remediation Agent
SonarSource

From Opus 5 to Opus 5.5: better fixes at 58% less cost in the SonarQube Remediation Agent

Dropbox and SpaceXAI turn project context into durable work in the Cursor Marketplace and Grok Bot
Dropbox

Dropbox and SpaceXAI turn project context into durable work in the Cursor Marketplace and Grok Bot

More from Akamai

What Would RAG Look Like If Miranda Priestly Were the User?
Akamai

What Would RAG Look Like If Miranda Priestly Were the User?

The CMMC Phase II Suspension: What It Means for Your Compliance and Zero Trust Strategy
Akamai

The CMMC Phase II Suspension: What It Means for Your Compliance and Zero Trust Strategy

Unifying Client-Side Protection in Akamai Application Protection Platform
Akamai

Unifying Client-Side Protection in Akamai Application Protection Platform

What to Do When Your Competitors Are Scraping Your Prices
Akamai

What to Do When Your Competitors Are Scraping Your Prices

What AI Can, Cannot, and Should Not Do
Akamai

What AI Can, Cannot, and Should Not Do

Beyond Identity: Governing the Agentic Enterprise
Akamai

Beyond Identity: Governing the Agentic Enterprise