Business

Understanding the CMMC Pause: Key Changes and Action Steps

On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements. The move was memorialized in a memo dated July 10, 2026, signed by DoW Chief Information Officer Kirsten Davies. Those requirements had been scheduled to take effect on November 10, 2026, and would have pushed many contracts handling Controlled Unclassified Information (CUI) into mandatory third-party C3PAO assessments.

The stated goal is straightforward: reduce compliance barriers for small, medium, and non-traditional businesses so the Defense Industrial Base can expand faster under the Department’s current acquisition priorities.
A 60-day CMMC Reform Task Force review is now underway, including a public Request for Information seeking industry input on cost drivers and administrative burden. Phase I self-assessment requirements remain firmly in place.

This is not a free pass.
It’s a pause on one layer of bureaucracy — not a suspension of the underlying security obligations.

What Actually Changed (and What Didn’t)

Suspended

  • The November 2026 transition to Phase II — third-party Level 2 assessments as a condition of award in many cases.
  • Pending and future CMMC implementation milestones (including Phase III and IV) that would have required C3PAO or DIBCAC assessments.
  • During the review period, contracting officers are limited to requiring only Level 1 (Self) or Level 2 (Self) assessments in new procurements.
  • Existing contracts that already contain Phase II language will have that language removed by modification, either before the next option period or at the next scheduled administrative update.

Still fully in force

  • Phase I self-assessments and annual affirmations in SPRS.
  • DFARS 252.204-7012 obligations to protect covered defense information and implement NIST SP 800-171 controls.
  • Contractual cybersecurity requirements that primes flow down to subcontractors.
  • The Department of Justice’s Civil Cyber-Fraud Initiative, which continues to treat inaccurate self-assessments and false claims seriously.

The official release is worth reading in full: Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements. The SBA has also publicly backed the move, arguing the prior framework was pushing small firms out of the defense supply chain.

In short: the certification theater got paused. The requirement to actually protect the data did not.

What Contractors and Subcontractors Should Do This Month

  1. Don’t stop your security work.
    Use the breathing room. Many teams were racing toward a November deadline that no longer exists in its previous form. That race produced a lot of checkbox activity. Now’s the time to swap checkboxes for durable controls.
  2. Re-run a realistic readiness assessment.
    Update your SPRS score and your internal gap analysis against NIST SP 800-171. If you used a simple calculator earlier this year — I published one that turns a short questionnaire into a readiness score, estimated SPRS, missing controls, and a three-year cost projection — pull it back up and refresh the inputs. See: Building a CMMC Readiness Calculator That People Can Actually Finish.
  3. Treat continuous compliance as the real requirement.
    Annual self-assessments and point-in-time evidence dumps are fragile. The reform language itself points toward “scalable, resilient cybersecurity measures” — which reads as continuous monitoring and automated evidence collection, not another round of spreadsheets and screenshot marathons.
  4. Watch your primes.
    A Phase II pause at the Department level doesn’t automatically relax every subcontract. Large primes often impose flow-down requirements stricter than the current minimum, and many won’t move as fast as the Department did.
  5. Document the affirming official and the continuous compliance process.
    Phase I still requires a named senior official to affirm ongoing compliance in SPRS. Make sure that process is real, not aspirational — and that it’s written down somewhere your next audit (or your next enterprise customer’s security questionnaire) can find it.

Why This Matters Even If You’re Not a Defense Contractor

The same pattern is playing out across enterprise sales and cyber insurance. Buyers and underwriters increasingly expect SOC 2 Type II, continuous control monitoring, and proof that security isn’t a once-a-year project. The CMMC pause is a signal that purely bureaucratic compliance regimes are being questioned across the board. The companies that win are the ones that treat security and compliance as an operating system, not an annual fire drill.

A few related pieces if you want to go deeper:

The Opportunity Hidden Inside the Pause

The Department’s own language talks about lowering certification-related burdens while preserving the underlying cybersecurity baseline. That’s exactly the gap continuous, AI-assisted compliance platforms are built to fill.

Instead of treating the next 60–90 days as a chance to relax, treat them as a chance to:

  • Close your highest-risk control gaps.
  • Automate evidence collection so the next self-assessment — or the eventual reformed assessment, whatever shape it takes — isn’t a scramble.
  • Move from “we can pass an audit” to “we can demonstrate continuous control effectiveness.”

Small and mid-sized teams will never match the headcount of a Fortune 500 security organization.
The realistic path is better tooling and tighter integration between IT operations, threat detection, and compliance evidence — not more headcount you can’t hire.
Pstt… that is why we built EspressoLabs’ CMMC service.

Practical Next Steps This Week

  • Pull your latest SPRS entry and your last self-assessment.
  • Identify the three controls that would most improve your actual security posture — not just your score.
  • Confirm who your Affirming Official is, and that the continuous compliance process behind them is documented, not assumed.
  • If you sell into enterprise or government, map which customers or primes still require third-party assessments regardless of the Department’s pause.
  • Revisit any readiness calculator or gap analysis you already have and update the numbers.

The suspension is real.
So is the underlying requirement to protect sensitive information. The companies that use this window to build durable, automated controls will be in a stronger position no matter what the reform produces — a lighter CMMC, a different framework, or just a longer Phase I period.

The ones that treat it as a reason to relax will still be scrambling when the next contract, or the next customer security questionnaire, shows up.

If you want a quick, no-sales readiness snapshot, the calculator I published earlier is still up and takes only a few minutes.
Use the pause productively.


Discover more from Ido Green

Subscribe to get the latest posts sent to your email.

Standard

Leave a comment