

On July 13, 2026, the Department of Defense (DoD) suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) while a reform task force reviews the program. Third-party assessment requirements and implementation milestones are currently paused (DoW, 2026).
The standard behind the schedule did not change. The underlying security requirements and the obligation to demonstrate compliance with them remain in effect.
During the suspension, program offices may not designate a CMMC Level 2 (C3PAO) or Level 3 assessment, but self-assessment scores still post to the Supplier Performance Risk System (SPRS), affirmations still come due, and a Government-led assessment can still arrive.
| In This Article: A practical breakdown of CMMC audit preparation, covering scope decisions, documentation review, control validation, assessor interviews, internal readiness reviews, and the obligations that continue after certification. |
What a CMMC Audit Is Designed To Accomplish
A CMMC assessment measures implementation of the 110 security requirements in NIST SP 800-171 Rev 2, which are grouped into 14 families. Assessors do not grade the requirement as a unit. They grade the assessment objectives underneath it by examining artifacts, interviewing people, and testing systems.
DFARS 252.204-7012 requires contractors to safeguard covered defense information and report cyber incidents whether or not a third-party assessment is on the calendar. During the Phase 2 suspension, the Department enforces baseline compliance through CMMC Level 1 and Level 2 self-assessments and select Government-led assessments (DoW, 2026).
Scoping comes first and drives everything after it. The assessment covers assets that process, store, or transmit Controlled Unclassified Information (CUI), plus the security protection assets that defend them. Over-scoped environments drag file shares, engineering workstations, backup systems, and laptops inside a boundary that never needed them, and every asset inside that boundary has to be documented and evidenced.
A Final Level 2 certification is good for three years. A designated Affirming Official owes an affirmation of continuing compliance every year. An organization that scores at least 88 of 110 with open gaps receives Conditional status and a Plan of Action and Milestones (POA&M) that has to close within 180 days of the Conditional Status Date, confirmed by a closeout assessment.
Reviewing Your Security Documentation
The System Security Plan (SSP) is the first thing an assessor opens. Each of the 110 requirements needs a description of how it works in your environment, naming the systems, tools, and people involved. Generic control language lifted from a template tends to get flagged.
Each requirement needs supporting policies, procedures describing who does what and how often, and evidence that both are being followed. Evidence is usually where programs are thin. Access-review records, dated configuration exports, training rosters, incident tickets, and change approvals are what an assessor uses to close the distance between the written program and the operating one.
An SSP written 18 months ago may describe a network that has since added a collaboration platform, moved a workload to a new tenant, or onboarded a subcontractor. If an external cloud service stores, processes, or transmits covered defense information, DFARS 252.204-7012 requires that service to meet security requirements equivalent to the FedRAMP Moderate baseline, and the shared responsibility matrix should say plainly which requirements the provider covers and which stay with you.
Validating Technical Security Controls

Multifactor authentication trips up a lot of organizations. Coverage has to reach all network access to CUI, not just remote access through the VPN. Local administrative accounts, cloud consoles, and privileged accounts on engineering systems all sit inside that line.
Cryptography draws the same kind of finding. NIST SP 800-171 Rev 2 calls for FIPS-validated cryptography to protect the confidentiality of CUI, which means a module with a Cryptographic Module Validation Program certificate number, not a product datasheet that mentions AES-256 (NIST, 2020). Assessors score audit logging on retention, on content, and on whether anyone reads the logs on a stated cadence.
Vulnerability scanning and Penetration Testing show whether the boundary behaves the way the network diagram says it does. When a finding maps to a requirement carrying a five-point deduction under the DoD Assessment Methodology, it should move ahead of lower-weighted items in the queue.
Preparing Your Team for the CMMC Audit
Assessors interview the people who hold specific roles, often without the compliance lead. A system administrator may be asked how account provisioning gets approved, a shipping clerk may be asked what happens to media that leaves the facility, and an engineer may be asked how they report a suspected incident and to whom.
An answer that contradicts the written procedure creates a finding even when the technical control is working.
Prepare people to describe what they do rather than to recite policy language. If the procedure says a suspected incident goes to a specific mailbox within an hour, the person who does it should be able to both say that plainly and point to where it is written. Training records should show role-based training reaching the people whose duties touch CUI.
Conducting a Pre-CMMC Audit Readiness Review
An internal readiness review works only if you scope it the way an assessor will, which is often narrower and stricter than an internal team expects. Score yourself against the 320 assessment objectives in NIST SP 800-171A rather than the 110 requirements in NIST SP 800-171 Rev 2. Record met, not met, or not applicable for each one, and attach the evidence that supports the call.
Scoring weight decides what gets fixed first. The DoD Assessment Methodology deducts 5, 3, or 1 point depending on the requirement (DoD, 2020), and under 32 CFR 170.21 only 1-point requirements can go on a POA&M, with a narrow exception for CUI encryption where a module is in use but not FIPS-validated.
Six more requirements, covering external connections, public information, the system security plan, and three physical access controls, are barred from a POA&M no matter what they score. Anything in those categories has to be met on assessment day, so it belongs at the front of the remediation list, tracked to closure with a named owner, a target date, and the artifact that will prove it is done.
Managing the CMMC Audit Process
The assessment runs in phases under the CMMC Assessment Process, from planning and preparation through conducting the assessment, reporting, and POA&M close-out. Assessments slip when an organization cannot produce evidence on request, which is more often a problem with filing than security.
Designate one point of contact to field every request and track what has gone out. Organize the evidence repository by requirement number so an artifact takes minutes to retrieve instead of hours to reconstruct.
Answer the question asked. Volunteering systems or processes outside the assessment scope invites questions that expand the work without improving the result.
Expect an in-brief that confirms scope and schedule, checkpoints while the team works, and an out-brief on preliminary results. If you disagree with a call on an objective, raise it during the assessment while the team can still look at more evidence.
Maintaining Compliance After a CMMC Audit

Continuous Monitoring keeps controls under observation between assessments, and the annual affirmation puts the Affirming Official’s name behind a statement that the applicable requirements are implemented and will stay implemented.
A new subcontract, a new software platform, or a new physical location can move the boundary. Each of those should trigger an SSP update, a reassessment of the affected requirements, and a revised SPRS score.
Vaultes is a Veteran-owned firm accredited as a FedRAMP Third Party Assessment Organization (3PAO) and as a CMMC Third Party Assessment Organization (C3PAO). We work with Government agencies and Defense Industrial Base contractors on readiness reviews, control validation, Penetration Testing, and Continuous Monitoring.
Contact us online to request a consultation. We can discuss where your program stands and what preparation makes sense while the CMMC schedule is under review.
About Vaultes
Vaultes is a leading provider of cybersecurity solutions, dedicated to protecting organizations from evolving cyber threats. Our team of experts delivers tailored strategies and advanced technologies to ensure robust and resilient security postures.
More Info

