CMMC phase 2 is paused. The email problem isn’t.
CMMC Phase 2 is paused, but CUI still moves through email, chat, and collaboration tools. Here’s what contractors should focus on now.
Seven months ago, a machining subcontractor in a piece on this site passed its self-assessment, then watched a CUI drawing package land in two mailboxes outside its assessment boundary within three weeks. The point of that story was that a clean CMMC assessment and a controlled data flow are not the same thing. On July 13, 2026, the Department of War supplied a second piece of evidence for that argument, and it did it by removing the one mechanism that was supposed to make the gap someone else's problem to catch.

Source: Dow Chief Information Officer, CMMC Program (July 13, 2026)
What got paused, and what didn't
That mechanism was Phase 2: a requirement, set to start November 10, 2026, that Level 2 contractors be certified by a third-party assessor, a C3PAO, before award. DoD suspended it, citing a mismatch between roughly 100 approved assessment organizations and more than 100,000 companies that would need review, plus compliance costs estimated at over $7 billion a year for small and mid-sized businesses. A Reform Task Force is now reviewing the program, with findings due around mid-September, and Phase 3 and Phase 4, the later milestones that would have extended certification further, are frozen alongside it.
What DoD paused, in other words, was the check. It did not pause the thing being checked: Phase 1 self-assessments, SPRS score submissions, and the annual affirmation a senior official signs remain fully enforceable under DFARS 252.204-7012 and 252.204-7019, and a current SPRS score still conditions award. Nobody has said when third-party verification comes back, or in what form, which leaves that affirmation carrying weight it was not originally designed to carry alone.
The check disappeared, the exposure didn't
That distinction, check versus obligation, is why this reads as a reprieve and isn't one. A third-party assessor was going to stand between a contractor's claim and the government's reliance on it, a second set of eyes with the job of catching a false "we control our CUI" before it became evidence. With that layer paused, the affirming official's signature is the entire record, and a signature is a much smaller thing to be wrong about in front of the Department of Justice than a C3PAO's field work would have been. It was already enough on its own. In December 2025, before Phase 2 was even suspended, DOJ settled with Swiss Automation, an Illinois precision machining supplier, for $421,234 over allegations it failed to protect technical drawings supplied to DoD primes. No C3PAO was involved in surfacing that case; what DOJ needed was a gap between what the company represented and what its systems actually did, which is exactly the gap a self-assessment now stands alone in front of.
The gap was never about who's checking
That gap, notably, is not a new one, and it is not something a certified assessor would have closed either. The original piece walked through why a defined enclave was never the whole job: Control 3.1.3 requires controlling the flow of CUI under approved authorizations, 3.13.8 requires cryptographic protection in transmission, 3.13.11 requires that cryptography be FIPS-validated. Those controls apply whether the entity reading the affirmation is a company's own compliance lead or an outside assessor, because a drawing forwarded to settle a quick question or a file dropped into chat because it beats the portal creates the same ungoverned copy either way. Third-party certification was never going to catch that on its own; it tests the same self-reported boundary a self-assessment does, just with an outside signature attached. So the suspension does not reopen a question about whether the flow-tracing work matters. It just removes, for now, the backstop that might have caught a contractor who skipped it.
What the next few months are for
Which is what makes the next several months worth using rather than waiting out. If the affirmation is the whole record, it has to be true before it is signed, not defensible after an inquiry starts, which means the mapping, containment, and expiration work the original piece described, seeing where CUI actually travels, routing it through a controlled channel instead of a general inbox, applying retention rules so copies stop piling up, is no longer optional groundwork for a future audit. It is what the signature is currently resting on. It is also worth building now precisely because a company that already has identity-verified access and a log of who touched what will not be starting from zero when Phase 2 resumes in whatever form the Task Force recommends, and the assessor coverage that made the original timeline tight, a year or longer from gap assessment to audit-ready, has not gotten any less tight while frozen. A paused deadline is not a canceled one.
What to actually do
1. See it
Map where CUI actually moves through email, ticketing, shared drives, and chat, then follow it out to partners and vendors. Control 3.1.3 cannot be satisfied on paths nobody has traced, and the map usually surprises people. A drawing that policy says lives in one enclave often exists in a dozen places, several outside the company. Once the paths are visible, close them.
2. Contain it
Pull CUI out of general inboxes and chat and route it through a dedicated, controlled channel. An inbox retains by default, so every attachment becomes a standing copy. A controlled channel turns each exchange into a governed event with a defined path, which is what an approved authorization looks like in practice. Containment fixes the path, but existing copies keep accumulating.
3. Shrink it
That is what expiration and retention rules do. Apply them so copies stop piling up. A copy that no longer exists cannot leak, and an expiring exchange caps what a compromised account can reach. An attacker in a mailbox holding years of attachments takes years of CUI. An attacker in a channel where exchanges expire takes very little.
The certification framework around CMMC is genuinely in flux right now. The definition of controlled unclassified information moving through an uncontrolled inbox is not. That is still the half of the job that fails quietly, task force or no task force.
Prevent social engineering attacks
Start with one integration, validate quickly, and expand across your environment.
