Skip to main content
Should You Wait or Certify Now?Certification & Accreditation
6 min readFor Compliance Managers

Should You Wait or Certify Now?

The Department of War paused CMMC Phase 2 on July 13, 2026, for a 60-day review. Phase 1 self-assessment requirements remain in place. You're facing a choice: continue toward independent certification through a C3PAO, maintain your current self-assessment posture, or pause all preparation until the review concludes.

This isn't just about timing. Your decision affects budget allocation, team workload, and contract positioning for the next 12-18 months.

The Decision You're Facing

Should you pursue independent CMMC certification now, during the Phase 2 pause, or wait for the review to conclude?

This decision hinges on three factors: your contract pipeline, your prime contractor relationships, and your current readiness state. The pause doesn't eliminate the obligation to protect CUI. It changes the enforcement timeline, not the technical requirements.

Key Factors That Affect Your Choice

Contract Requirements vs. Timeline Uncertainty

Phase 1 self-assessments are still mandatory for applicable solicitations. The pause affects only the transition to mandatory C3PAO assessments. If your current contracts require self-assessment, that obligation hasn't changed.

Your prime contractors may impose their own certification timelines regardless of the Department of War's schedule. Many primes use CMMC Level 2 certification as a subcontractor screening criterion independent of federal mandates. Ask your contracting officers directly if they require C3PAO certification for bid eligibility.

Your Assessment Boundary Definition

Can you draw a precise line around where CUI resides in your environment? This is the best predictor of assessment readiness.

If you can't map CUI data flows with specificity, you're not ready for a C3PAO assessment regardless of the Phase 2 timeline. Organizations that struggle during assessments typically can't answer: which systems process CUI, which users access it, which third parties touch it, and where it moves between environments.

If you've completed this mapping exercise and documented your boundaries, you're positioned to pursue certification. If you haven't, use the pause to complete it.

Evidence Collection Maturity

Do you have documented evidence for each NIST SP 800-171 control you claim to implement? Not just policies and procedures, but operational evidence: access review logs, vulnerability scan reports, incident response records, training completion data, configuration baselines.

C3PAO assessments require you to demonstrate implementation, not just describe it. If your evidence collection process is manual, inconsistent, or incomplete, the pause gives you time to systematize it before an assessor arrives.

Path A: Pursue Certification Now

Choose this path if:

  • A prime contractor requires C3PAO certification for your next bid cycle.
  • You've completed assessment boundary mapping and can articulate exactly which systems, users, and data flows are in scope.
  • You have documented evidence for each NIST SP 800-171 control across people, process, and technology domains.
  • Your leadership views certification as a competitive differentiator, not just a compliance obligation.
  • You've conducted an internal gap assessment and remediated major findings.

What this path requires:

Select a C3PAO and schedule your assessment. Budget 8-12 weeks for the assessment process itself, plus remediation time for any findings. C3PAO assessments are still being conducted during the pause.

Prepare a System Security Plan that documents your assessment boundary, CUI data flows, control implementation details, and compensating controls for any NIST SP 800-171 requirements you don't fully meet. Your SSP is the primary artifact assessors will validate against your actual environment.

Assign an internal point of contact who understands your architecture, can locate evidence quickly, and can explain implementation decisions. Assessors will ask detailed questions about network segmentation, access control logic, and incident response procedures. Generic answers waste time and raise concerns.

Risk consideration:

The 60-day review may result in modified requirements that affect your certification scope. If you certify now under current standards and the Department of War narrows requirements, you've over-invested. If they expand requirements, you may need supplemental assessment activities. Weigh this regulatory uncertainty against your contract timeline pressure.

Path B: Strengthen Readiness During the Pause

Choose this path if:

  • Your next CUI-related contract isn't scheduled for 6+ months.
  • You've identified gaps in your NIST SP 800-171 implementation through self-assessment.
  • Your assessment boundary is unclear or you can't map CUI data flows with precision.
  • Your evidence collection is inconsistent or you lack operational proof of control effectiveness.
  • You want to use the pause to reduce assessment findings rather than rush to certification.

What this path requires:

Conduct a structured gap assessment against NIST SP 800-171 Rev 2 requirements. Don't just check whether controls exist; validate that they function as documented and produce evidence an assessor can verify.

Map your CUI data flows systematically. Document: which contracts introduce CUI into your environment, which systems store or process it, which users have access, which third parties interact with it, and where it moves between networks or cloud environments. This mapping exercise reveals your actual assessment boundary, which is often larger than organizations initially estimate.

Build your evidence collection process before you need it. Identify which controls require continuous evidence (access reviews, vulnerability scanning, log monitoring) versus point-in-time evidence (policy approval, training completion, disaster recovery tests). Automate collection where possible; manual evidence gathering doesn't scale during an assessment.

Address major gaps now. If you lack multi-factor authentication, network segmentation, or FIPS-validated cryptography for CUI at rest, remediate these before scheduling a C3PAO assessment. These are objective requirements with no compensating control options.

Risk consideration:

Prime contractors may require certification sooner than you expect. If you delay and a major contract opportunity requires C3PAO certification on short notice, you'll be forced to rush preparation. Monitor your pipeline actively.

Path C: Minimal Maintenance Until Review Concludes

Choose this path if:

  • You have no active CUI contracts and no imminent bids requiring CMMC.
  • You're a small business and the Department of War review explicitly aims to reduce burden on your organization size.
  • Your prime contractors have confirmed they won't require certification until Phase 2 formally resumes.
  • You've completed Phase 1 self-assessment requirements and documented your current state.

What this path requires:

Maintain your existing self-assessment documentation. Update it when your environment changes: new systems, new users, new third-party relationships, new contracts introducing CUI.

Monitor the Department of War review outcomes. The 60-day review concludes in September 2026. Revised requirements may narrow scope, adjust maturity levels, or modify assessment processes. Don't assume current standards will remain unchanged.

Preserve institutional knowledge. If the staff who completed your self-assessment leave or change roles, document their work thoroughly. When Phase 2 resumes, you'll need to rebuild context quickly.

Risk consideration:

You're betting that the review will substantively reduce requirements or extend timelines. If the Department of War reaffirms current standards and accelerates Phase 2, you'll be behind competitors who used the pause to certify. This path works only if you have genuine pipeline visibility and flexible timelines.

Summary Matrix

Factor Certify Now Strengthen Readiness Minimal Maintenance
Contract pressure Prime requires certification Next bid in 6+ months No active CUI contracts
Boundary definition Clearly mapped Partially mapped Unknown or undocumented
Evidence maturity Documented and accessible Gaps identified Self-assessment complete
Gap status Minor findings only Major gaps remain Not assessed in detail
Timeline flexibility Immediate need Moderate urgency Can wait for review outcome
Budget availability C3PAO fees approved Internal remediation funded Minimal spend authorized

The pause isn't permission to stop preparing. It's a chance to move from reactive compliance to deliberate readiness. Organizations that use this time to map their CUI environment, systematize evidence collection, and remediate gaps will spend less time defending architectural decisions during assessment and more time demonstrating control effectiveness.

If you can't answer where your CUI lives and how it moves, that's your priority regardless of which path you choose.

You Might Also Like