---
title: CMMC Phase II Is Suspended. Your CUI Obligations Are Not.
description: "CMMC Phase 2 suspension explained: what contracting officers must remove, what DFARS 7012 and SPRS still require, and why your CUI map matters."
image: https://teramis.us/hubfs/ChatGPT%20Image%20Sep%2030%2c%202026%2c%2001_33_42%20PM.png
---

[Skip to content](https://teramis.us/post/cmmc-phase-ii-issuspended-your-cui-obligations-are-not#main-content)

[![Teramis Logo](https://teramis.us/hs-fs/hubfs/Untitled%20design%20-%202026-07-20T135654.427.png?width=3000&height=2000&name=Untitled%20design%20-%202026-07-20T135654.427.png)Homepage](https://teramis.us)

- [Home](https://teramis.us)
- [Platform](https://teramis.us/platform)
  
    - [How Teramis Works](https://teramis.us/company/how-teramis-works)
    - [CUI Discovery](https://teramis.us/platform/cui-discovery)
    - [Evidence & Validation](https://teramis.us/platform/evidence-validation)
    - [Ongoing Monitoring](https://teramis.us/platform/ongoing-cui-monitoring)
    - [Remediation](https://teramis.us/platform/remediation)
    - [Deployment & Data Sources](https://teramis.us/platform/deployment-and-data-sources)
- [Who We Help](https://teramis.us/who-we-help)
- [Solutions](https://teramis.us/solutions)
  
    - By Decision
      
          - [CMMC Scoping](https://teramis.us/solutions/cmmc-scoping)
          - [CUI Boundary Validation](https://teramis.us/solutions/cui-boundary-validation)
          - [CUI Remediation & Spillage Monitoring](https://teramis.us/solutions/cui-remediation-spillage-monitoring)
          - [Migration Support](https://teramis.us/solutions/migration-support)
          - [Post-Incident CUI Scoping](https://teramis.us/solutions/post-incident-cui-scoping-and-discovery-teramis)
          - [Supply Chain and M&A](https://teramis.us/solutions/supply-chain-ma)
    - By Organization
      
          - [Small Business](https://teramis.us/solutions/by-organization/small-business)
          - [Enterprise](https://teramis.us/solutions/by-organization/enterprise)
          - [Government](https://teramis.us/solutions/government-agencies)
          - [CMMC Advisory](https://teramis.us/solutions/by-organization/cmmc-advisory)
- [Partners](https://teramis.us/partners)
  
    - [Partner Program](https://teramis.us/partners/partner-program)
    - [Partner Resources](https://teramis.us/partners/partner-resources)
    - [Who We Partner With](https://teramis.us/partners/who-we-partner-with)
      
          - [Partner MSPs & MSSPs](https://teramis.us/partners/who-we-partner-with#MSPs-MSSPs)
          - [CMMC Advisory and RPOs](https://teramis.us/partners/who-we-partner-with#CMMCAdvisoryandRPOs)
          - [GRC and Enclave Providers](https://teramis.us/partners/who-we-partner-with#GRC-EnclaveProviders)
          - [Technology Partners](https://teramis.us/partners/who-we-partner-with#TechnologyPartners)
    - [Become a Partner](https://teramis.us/partners/become-a-partner)
- [Resources](https://teramis.us/resources)
  
    - [FAQ](https://teramis.us/resources/faqs)
    - [Videos & Webinars](https://teramis.us/resources/videos-webinars)
    - [Resource Library & Downloads](https://teramis.us/resources/library)
    - [Blog](https://teramis.us/post)
- [Company](https://teramis.us/company)
  
    - [About Us](https://teramis.us/company/about)
      
          - [Use Cases](https://teramis.us/use-cases)
          - [FAQ](https://teramis.us/resources/faqs)
    - [Careers](https://teramis.us/company/careers)
    - [Contact](https://teramis.us/contact-us)

[Request Demo](https://teramis.us/request-a-demo)

- [Home](https://teramis.us)
- [Platform](https://teramis.us/platform)
  
    - [How Teramis Works](https://teramis.us/company/how-teramis-works)
    - [CUI Discovery](https://teramis.us/platform/cui-discovery)
    - [Evidence & Validation](https://teramis.us/platform/evidence-validation)
    - [Ongoing Monitoring](https://teramis.us/platform/ongoing-cui-monitoring)
    - [Remediation](https://teramis.us/platform/remediation)
    - [Deployment & Data Sources](https://teramis.us/platform/deployment-and-data-sources)
- [Who We Help](https://teramis.us/who-we-help)
- [Solutions](https://teramis.us/solutions)
  
    - By Decision
      
          - [CMMC Scoping](https://teramis.us/solutions/cmmc-scoping)
          - [CUI Boundary Validation](https://teramis.us/solutions/cui-boundary-validation)
          - [CUI Remediation & Spillage Monitoring](https://teramis.us/solutions/cui-remediation-spillage-monitoring)
          - [Migration Support](https://teramis.us/solutions/migration-support)
          - [Post-Incident CUI Scoping](https://teramis.us/solutions/post-incident-cui-scoping-and-discovery-teramis)
          - [Supply Chain and M&A](https://teramis.us/solutions/supply-chain-ma)
    - By Organization
      
          - [Small Business](https://teramis.us/solutions/by-organization/small-business)
          - [Enterprise](https://teramis.us/solutions/by-organization/enterprise)
          - [Government](https://teramis.us/solutions/government-agencies)
          - [CMMC Advisory](https://teramis.us/solutions/by-organization/cmmc-advisory)
- [Partners](https://teramis.us/partners)
  
    - [Partner Program](https://teramis.us/partners/partner-program)
    - [Partner Resources](https://teramis.us/partners/partner-resources)
    - [Who We Partner With](https://teramis.us/partners/who-we-partner-with)
      
          - [Partner MSPs & MSSPs](https://teramis.us/partners/who-we-partner-with#MSPs-MSSPs)
          - [CMMC Advisory and RPOs](https://teramis.us/partners/who-we-partner-with#CMMCAdvisoryandRPOs)
          - [GRC and Enclave Providers](https://teramis.us/partners/who-we-partner-with#GRC-EnclaveProviders)
          - [Technology Partners](https://teramis.us/partners/who-we-partner-with#TechnologyPartners)
    - [Become a Partner](https://teramis.us/partners/become-a-partner)
- [Resources](https://teramis.us/resources)
  
    - [FAQ](https://teramis.us/resources/faqs)
    - [Videos & Webinars](https://teramis.us/resources/videos-webinars)
    - [Resource Library & Downloads](https://teramis.us/resources/library)
    - [Blog](https://teramis.us/post)
- [Company](https://teramis.us/company)
  
    - [About Us](https://teramis.us/company/about)
      
          - [Use Cases](https://teramis.us/use-cases)
          - [FAQ](https://teramis.us/resources/faqs)
    - [Careers](https://teramis.us/company/careers)
    - [Contact](https://teramis.us/contact-us)

[Request Demo](https://teramis.us/request-a-demo)

![CMMC Phase II Suspension, CUI Obligations Remain](https://teramis.us/hs-fs/hubfs/ChatGPT%20Image%20Sep%2030%2c%202026%2c%2001_33_42%20PM.png?width=1774&height=887&name=ChatGPT%20Image%20Sep%2030%2c%202026%2c%2001_33_42%20PM.png)

CUI Discovery CUI Identification CUI management

# CMMC Phase II Is Suspended. Your CUI Obligations Are Not.

![Teramis](https://teramis.us/hs-fs/hubfs/2.png?width=48&height=48&name=2.png)

 Teramis

September 30, 2026

## What the CMMC Phase 2 suspension changed, and what it didn't.

On July 13, 2026, the Department of War paused the third-party audit portion of CMMC. On September 3, it made that pause binding on every contracting officer. Neither action touched the rules that require you to protect CUI, score yourself honestly in SPRS, and have a senior official affirm that score every year.

If anything, the pause puts more weight on your self-assessment. With no outside assessor reviewing your environment before award, the score you post and the affirmation behind it are what the government relies on. And the Justice Department showed twice this summer that it will test that reliance.

## July 13: the pause

CMMC was rolling out in phases. Phase I, already in effect, let contractors meet Level 1 and Level 2 requirements through self-assessment. Phase II, due November 10, 2026, would have made a Level 2 certification from a third-party assessor (a C3PAO) a condition of award for many contracts involving CUI.

On July 13, the Department of War [announced](https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/) that it was suspending Phase II immediately, along with all later implementation milestones. The same announcement said every Phase I self-assessment requirement stays in place. The stated reason was to cut compliance costs and barriers for small, medium, and non-traditional businesses.

The pause came through two memos rather than a rule change: a policy memo from the DoW Chief Information Officer and an implementation memo for contracting officers from the Under Secretary for Acquisition and Sustainment ([Holland & Knight](https://www.hklaw.com/en/insights/publications/2026/07/dow-suspends-cmmc-phase-ii-requirements)). The practical effect, per [Morgan Lewis](https://www.morganlewis.com/pubs/2026/07/department-of-war-suspends-cmmc-phase-ii-requirements-but-cybersecurity-obligations-remain): while the suspension lasts, contracting officers may include only CMMC Level 1 (Self) or Level 2 (Self) requirements in contracts.

The memo also created a CMMC Reform Task Force with 60 days to review the program. Its report was due to the CIO on September 11 and had not been made public as of late September ([Covington](https://www.insidegovernmentcontracts.com/2026/09/cmmc-reform-task-force-updates-september-2026/)).

## September 3: the pause becomes binding

A memo states policy. It does not rewrite the contract rules contracting officers work from, and another memo can reverse it. That gap closed on September 3.

That day, John Tenaglia, the Department's principal director for Defense Pricing, Contracting, and Acquisition Policy, signed a class deviation ([Washington Technology](https://www.washingtontechnology.com/contracts/2026/09/cmmcs-phase-2-suspension-locked-binding-regulation/415883/)). A class deviation is a formal, binding instruction to depart from the codified acquisition regulations. This one, Revision 3 of deviation 2026-O0025, is listed with the Department's other FAR overhaul deviations on the [Defense Acquisition Regulations System site](https://www.acq.osd.mil/dpap/dars/dfars_far_overhaul_class_deviations.html).

It does two things that matter here. It directs contracting officers to follow the Revolutionary FAR Overhaul requirements instead of the November 2025 CMMC final rule when writing contract clauses. And it orders them to remove every CMMC third-party assessment requirement from contracts ([Nextgov/FCW](https://www.nextgov.com/acquisition/2026/09/cmmcs-phase-2-suspension-locked-binding-regulation/415890/)).

Because the pause now lives in regulation rather than a memo, reversing it takes a more formal process. For planning purposes, self-assessment is the operating model until the Department takes affirmative action to change it.

What the deviation did not do is repeal CMMC. The CMMC program rule and the clause framework remain on the books; the change governs which requirements contracting officers put into contracts during the suspension.

## What contracting officers must strip out

The list is short. Everything removed is about who verifies your security, not what security you owe.

- **CMMC Level 2 (C3PAO) requirements.** The third-party certification that Phase II would have made a condition of award ([Nextgov/FCW](https://www.nextgov.com/acquisition/2026/09/cmmcs-phase-2-suspension-locked-binding-regulation/415890/)).
- **CMMC Level 3 (DIBCAC) requirements.** The government-led assessment tier, paused along with Phase II ([Morgan Lewis](https://www.morganlewis.com/pubs/2026/07/department-of-war-suspends-cmmc-phase-ii-requirements-but-cybersecurity-obligations-remain)).
- **Those requirements in existing awards, not just new ones.** The implementation memo tells contracting officers how to amend active solicitations and existing contracts ([Holland & Knight](https://www.hklaw.com/en/insights/publications/2026/07/dow-suspends-cmmc-phase-ii-requirements)).

Two cautions. First, nothing changes in your contract until the modification actually arrives. Existing CMMC clauses and prime contractor flowdowns remain enforceable until they are modified ([Government Contracts Law](https://www.governmentcontractslaw.com/2026/07/dod-suspends-cmmc-phase-2-what-happened-what-it-means-and-what-nobody-is-telling-you/)). Second, a prime managing its own supply chain risk may keep requiring a Level 2 certification from subcontractors (same source). Read your contracts and subcontracts, not the headlines.

## What still applies, unchanged

The obligations that actually govern how you protect CUI never depended on CMMC Phase II. As the Department put it on July 13, the action does not eliminate the requirement for companies to protect federal data ([WilmerHale](https://www.wilmerhale.com/en/insights/client-alerts/20260720-pentagon-suspends-cmmc-phase-2-requirements-and-launches-review-of-cybersecurity-certification-program)).

| Obligation | What it requires | Status after July 13 and September 3 |
| --- | --- | --- |
| DFARS 252.204-7012 | Implement the 110 security requirements of NIST SP 800-171 on systems that process, store, or transmit covered defense information; report cyber incidents within 72 hours | Unaffected ([Crowell & Moring](https://www.crowell.com/en/insights/client-alerts/department-of-war-immediately-suspends-cmmc-phase-ii-requirements-launches-60-day-reform-review)) |
| NIST SP 800-171 score in SPRS | Post a summary score of your implementation, from -203 to a perfect 110 ([Sidley](https://fcablog.sidley.com/2026/06/23/doj-reaches-507144-settlement-with-defense-contractor-signals-increased-fca-scrutiny-of-cybersecurity-self-assessments/)) | Still required |
| CMMC Level 1 and Level 2 (Self) | Self-assess against the required level and post results in SPRS | Still required where the contract carries it ([WilmerHale](https://www.wilmerhale.com/en/insights/client-alerts/20260720-pentagon-suspends-cmmc-phase-2-requirements-and-launches-review-of-cybersecurity-certification-program)) |
| Annual affirmation | A senior official affirms each year that the company continues to meet the requirements it self-assessed | Still required (same source) |

The enforcement backdrop has not paused either. In June, a Huntsville contractor paid $507,144 after posting a perfect 110 SPRS score while, according to DOJ, failing to implement required NIST SP 800-171 controls ([DefenseScoop](https://defensescoop.com/2026/06/18/defense-contractor-settles-cybersecurity-false-claims-act-allegations/)). On September 1, Honeywell Aerospace agreed to pay $2,042,518 over alleged NIST SP 800-171 noncompliance on one of its networks ([Justice Department](https://www.justice.gov/opa/pr/honeywell-aerospace-inc-agrees-pay-over-2m-settle-false-claims-act-allegations-failing)). Both cases rest on 252.204-7012 and the False Claims Act, not on CMMC certification.

## Why an outdated CUI map makes your self-assessment indefensible

A SPRS score is not a statement about your company in general. It is a statement about specific systems: the ones that process, store, or transmit CUI. Every control you score, and every point you claim, depends on where that boundary is drawn. And the boundary depends on knowing where the CUI actually is.

That is the weak point in most self-assessments. The boundary is usually drawn from a system security plan, an asset inventory, and interviews about where CUI is supposed to live. But CUI moves. Drawings get emailed, specs get saved to a personal OneDrive, old project shares keep copies nobody remembers. Each copy outside the documented boundary sits on a system your score never covered.

The result is a score that may be accurate for the environment you assessed and wrong for the environment you actually have. Consider what that means under each obligation:

- **Under 252.204-7012**, the controls must be in place wherever covered defense information lives. An unassessed file share holding CUI is an unprotected one.
- **In SPRS**, your score claims implementation across your CUI environment. If part of that environment was never in scope, the claim overstates your posture.
- **In the annual affirmation**, a senior official vouches for current compliance. A CUI inventory from last year supports a statement about last year.

Enforcement is already drawing these distinctions. The Honeywell allegations concerned noncompliance on one of the company's networks, not the whole enterprise ([Justice Department](https://www.justice.gov/opa/pr/honeywell-aerospace-inc-agrees-pay-over-2m-settle-false-claims-act-allegations-failing)). Compliance is judged system by system, and a system full of CUI that sat outside your boundary is exactly where that judgment lands.

A defensible self-assessment rests on three things you can show: current evidence of where CUI exists, a boundary that matches that evidence, and a record of checking again as the environment changes. The suspension removed the outside assessor. It did not remove the need to prove your score, and with less third-party review, that proof falls on you.

*Can you show where your CUI lives today?* [*Talk to Teramis about a CUI discovery assessment*](https://teramis.us/cui-discovery-readiness-assessment-teramis?hsLang=en-us)*.*

## Sources

Government

- [Department of War: "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements" (July 13, 2026)](https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/)
- [Defense Acquisition Regulations System: FAR overhaul class deviations](https://www.acq.osd.mil/dpap/dars/dfars_far_overhaul_class_deviations.html)
- [U.S. Department of Justice: Honeywell Aerospace settlement (September 1, 2026)](https://www.justice.gov/opa/pr/honeywell-aerospace-inc-agrees-pay-over-2m-settle-false-claims-act-allegations-failing)

Law firms

- [Holland & Knight: DOW Suspends CMMC Phase II Requirements](https://www.hklaw.com/en/insights/publications/2026/07/dow-suspends-cmmc-phase-ii-requirements)
- [Morgan Lewis: Department of War Suspends CMMC Phase II Requirements, but Cybersecurity Obligations Remain](https://www.morganlewis.com/pubs/2026/07/department-of-war-suspends-cmmc-phase-ii-requirements-but-cybersecurity-obligations-remain)
- [Crowell & Moring: Department of War Immediately Suspends CMMC Phase II Requirements](https://www.crowell.com/en/insights/client-alerts/department-of-war-immediately-suspends-cmmc-phase-ii-requirements-launches-60-day-reform-review)
- [WilmerHale: Pentagon Suspends CMMC Phase 2 Requirements](https://www.wilmerhale.com/en/insights/client-alerts/20260720-pentagon-suspends-cmmc-phase-2-requirements-and-launches-review-of-cybersecurity-certification-program)
- [Covington (Inside Government Contracts): CMMC Reform Task Force Updates, September 2026](https://www.insidegovernmentcontracts.com/2026/09/cmmc-reform-task-force-updates-september-2026/)
- [Government Contracts Law: DoD Suspends CMMC Phase 2](https://www.governmentcontractslaw.com/2026/07/dod-suspends-cmmc-phase-2-what-happened-what-it-means-and-what-nobody-is-telling-you/)
- [Sidley (FCA Blog): DOJ Reaches $507,144 Settlement with Defense Contractor](https://fcablog.sidley.com/2026/06/23/doj-reaches-507144-settlement-with-defense-contractor-signals-increased-fca-scrutiny-of-cybersecurity-self-assessments/)

News

- [Washington Technology: CMMC's Phase 2 suspension locked in with binding regulation](https://www.washingtontechnology.com/contracts/2026/09/cmmcs-phase-2-suspension-locked-binding-regulation/415883/)
- [Nextgov/FCW: CMMC's Phase 2 suspension locked in with binding regulation](https://www.nextgov.com/acquisition/2026/09/cmmcs-phase-2-suspension-locked-binding-regulation/415890/)
- [DefenseScoop: Defense contractor settles cybersecurity False Claims Act allegations](https://defensescoop.com/2026/06/18/defense-contractor-settles-cybersecurity-false-claims-act-allegations/)

## Share this post

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fteramis.us%2Fpost%2Fcmmc-phase-ii-issuspended-your-cui-obligations-are-not><https://twitter.com/intent/tweet?url=https%3A%2F%2Fteramis.us%2Fpost%2Fcmmc-phase-ii-issuspended-your-cui-obligations-are-not><https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fteramis.us%2Fpost%2Fcmmc-phase-ii-issuspended-your-cui-obligations-are-not><https://pinterest.com/pin/create/button/?url=https%3A%2F%2Fteramis.us%2Fpost%2Fcmmc-phase-ii-issuspended-your-cui-obligations-are-not>[mailto:https%3A%2F%2Fteramis.us%2Fpost%2Fcmmc-phase-ii-issuspended-your-cui-obligations-are-not](mailto:https%3A%2F%2Fteramis.us%2Fpost%2Fcmmc-phase-ii-issuspended-your-cui-obligations-are-not)

## Keep reading

### [![Cybersecurity analyst reviewing CMMC compliance and CUI risk data](https://teramis.us/hs-fs/hubfs/ChatGPT%20Image%20Aug%203%2c%202026%2c%2001_58_55%20PM%20(2).png?width=1774&height=887&name=ChatGPT%20Image%20Aug%203%2c%202026%2c%2001_58_55%20PM%20(2).png) CMMC Compliance CUI Scoping CUI Discovery CMMC in 2026: What Defense Contractors Need to Know](https://teramis.us/post/post/cmmc-in-2026-what-defense-contractors-need-to-know)

### [![](https://teramis.us/hs-fs/hubfs/1e2ccccf-dcd7-465b-91a8-7403b2c42a40.png?width=1585&height=992&name=1e2ccccf-dcd7-465b-91a8-7403b2c42a40.png) CUI Identification Closing the Gaps: Accurate CUI Identification and Continuous Monitoring](https://teramis.us/post/closing-the-gaps-why-accurate-cui-identification-and-continuous-monitoring-are-essential-for-cmmc-compliance)

[![Teramis\_logo\_horiz\_white (1)](https://teramis.us/hubfs/Teramis_logo_horiz_white%20(1).avif "Teramis_logo_horiz_white (1)")](https://246523533.hs-sites-na2.com/home)

###### Teramis provides precision CUI discovery, validation, and ongoing monitoring so Defense Industrial Base organizations can build CMMC scope on evidence. Teramis identifies, validates, reports, and monitors Controlled Unclassified Information. Teramis does not move, tag, remediate, delete, or alter discovered data.

<https://www.linkedin.com/company/teramis/>

- [Platform](https://teramis.us/platform)
  
    - [How Teramis Works](https://teramis.us/company/how-teramis-works)
    - [CUI Discovery](https://teramis.us/platform/cui-discovery)
    - [Remediation](https://teramis.us/platform/remediation)
    - [Evidence & Validation](https://teramis.us/platform/evidence-validation)
    - [Ongoing Monitoring](https://teramis.us/platform/ongoing-cui-monitoring)
    - [Deployment & Data Sources](https://teramis.us/platform/deployment-and-data-sources)
- [Who We Help](https://teramis.us/who-we-help)
  
    - [Enterprise](https://teramis.us/solutions/by-organization/enterprise)
    - [Government](https://teramis.us/solutions/government-agencies)
    - [CMMC Advisory](https://teramis.us/solutions/by-organization/cmmc-advisory)
    - [Small Business](https://teramis.us/solutions/by-organization/small-business)
- [CUI Solutions](https://teramis.us/solutions)
  
    - [Boundary Validation](https://teramis.us/solutions/cui-boundary-validation)
    - [Spillage Monitoring](https://teramis.us/solutions/cui-remediation-spillage-monitoring)
    - [CMMC Scoping](https://teramis.us/solutions/cmmc-scoping)
- [Partners](https://teramis.us/partners)
  
    - [Partner Resources](https://teramis.us/partners/partner-resources)
    - [Our Partners](https://teramis.us/partners/who-we-partner-with)
    - [Become a Partner](https://teramis.us/partners/become-a-partner)
- [Resources](https://teramis.us/resources)
  
    - [FAQ](https://teramis.us/resources/faqs)
    - [Video Media](https://teramis.us/resources/videos-webinars)
    - [Blog](https://teramis.us/post)
- [Company](https://teramis.us/company)
  
    - [About Us](https://teramis.us/company/about)
    - [Careers](https://teramis.us/company/careers)
    - [Contact](https://teramis.us/contact-us)

![teramis footer image](https://teramis.us/hs-fs/hubfs/teramis%20footer%20image.png?width=800&height=320&name=teramis%20footer%20image.png "teramis footer image")

Ready to find your CUI? See how Teramis helps your organization identify CUI, validate the CMMC boundary, and monitor what changes over time. 

[Talk to Us About CUI](https://teramis.us/talk-to-us-about-cui)

---

[Privacy Policy](https://teramis.us/privacy-policy) · [EULA](https://teramis.us/eula) · © 2026. All rights reserved.

 Cookie Settings

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Teramis",
    "url" : "https://teramis.us/post/author/teramis"
  },
  "dateModified" : "2026-09-30T17:37:15.126Z",
  "datePublished" : "2026-09-30T17:37:15.000Z",
  "headline" : "CMMC Phase II Is Suspended. Your CUI Obligations Are Not.",
  "image" : [ "https://teramis.us/hubfs/ChatGPT%20Image%20Sep%2030%2c%202026%2c%2001_33_42%20PM.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://teramis.us/post/cmmc-phase-ii-issuspended-your-cui-obligations-are-not",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://teramis.us/hubfs/Untitled%20design%20-%202026-07-20T135654.427.png"
    }
  }
}
```