When the Department of Defense announced the temporary suspension of CMMC Phase II on July 13, 2026, a lot of contractors across the Defense Industrial Base exhaled. The announcement delayed the requirement for many companies to obtain a third-party CMMC Level 2 assessment, and after years of anticipating that deadline, a delay understandably feels like relief.
It shouldn't feel like permission to stand still. The pause changes a timeline. It does not change the threat landscape, the contractual obligations already in force, or the direction the program is heading. Contractors who treat this as an off-ramp are likely to be scrambling again when Phase II resumes. Contractors who treat it as a runway will be in a materially stronger position, with or without a certification deadline attached.
What was actually paused?
To use this window well, it helps to be precise about what has changed. The Department of Defense paused implementation of Phase II while it reviews the program with an eye toward reducing burden on contractors, particularly the small and mid-size businesses that make up the bulk of the Defense Industrial Base (DIB).
That review is focused on the mechanics of the certification requirement itself: how assessments are scheduled, who performs them, how the rule phases into contracts. It is not focused on whether contractors need to protect Controlled Unclassified Information (CUI). The pause is procedural. The underlying expectation is not going anywhere.
What has not changed
This is the point worth repeating to anyone in your organization who hears "CMMC paused" and assumes the whole subject is off the table. It isn't. Cybersecurity requirements protecting CUI remain fully in effect. Contractors are still expected to:
- Implement NIST SP 800-171 controls across every system, process, and vendor relationship that touches CUI.
- Maintain and update the SPRS score (the Supplier Performance Risk System rating that primes and contracting officers already check).
- Protect CUI in accordance with existing contractual and Defense Federal Acquisition Regulation Supplement (DFARS) clause obligations.
- Flow requirements down to subcontractors handling CUI on their behalf.
None of that was paused. The self-attestation and contractual mechanisms that were already requiring compliance before CMMC Phase II existed are still the law of the engagement.
False Claims Act risk still exists
This is where the pause can quietly become a liability if it's misread. Organizations that represent themselves as compliant with NIST SP 800-171 (in a SPRS score, a contract certification, or a proposal) while knowingly falling short of that standard can still face False Claims Act exposure. The Department of Justice's Civil Cyber-Fraud Initiative has already pursued cases on exactly this theory, and a paused certification program does nothing to change that risk.
If anything, a pause without a corresponding third-party check puts more weight on self-attestations being accurate, because there's no external assessment yet to catch a gap before a whistleblower, a customer, or an auditor does.
Why continuing your CMMC preparation makes business sense
Set the compliance mandate aside for a moment and look at this purely as a business decision. Contractors who continue building toward CMMC Level 2 readiness during the pause are:
- Reducing real operational and breach risk, not just paperwork risk.
- Strengthening the security posture that protects their own IP, financial data, and customer relationships, not only CUI.
- Positioning themselves to respond immediately and credibly whenever Phase II resumes, instead of restarting a multi-month preparation effort under deadline pressure.
- Building a defensible record of good-faith compliance effort, which matters both to primes evaluating subcontractors and to regulators evaluating attestations.
A pause in the certification requirement is not a pause in the value of the underlying work.
Prime contractors will still expect security
Primes are not waiting on the Department of Defense to decide how much cybersecurity maturity they want from their subcontractor base. Many have already built CMMC-aligned expectations into their own subcontract flow-downs, vendor risk assessments, and teaming decisions. That isn't likely to reverse just because a certification timeline moved. If your organization wants to be selected for defense subcontracts, demonstrating mature, documented cybersecurity practices remains a competitive differentiator, pause or no pause.
A pause in the deadline is a runway, not an off-ramp.
The threat landscape, the contractual obligations, and the direction of the program did not change. Only the certification timeline did.
Use the pause to get audit-ready, starting with NIST CSF
The most productive way to spend this window is to treat it as dedicated time to close the gap between where your security program is today and where a real assessment would expect it to be. A few specific, high-value moves:
Run a NIST Cybersecurity Framework (CSF) 2.0 assessment. CSF's functions (Govern, Identify, Protect, Detect, Respond, Recover) give you a structured, framework-agnostic way to evaluate program maturity. Because CSF maps cleanly to NIST SP 800-171 and to the control set underlying CMMC, a CSF assessment does double duty: it strengthens your overall security posture and directly informs your CMMC readiness.
Complete or refresh a gap assessment against NIST SP 800-171. Identify exactly which of the 110 controls are fully implemented, partially implemented, or not yet addressed. Be honest about it. This document is the foundation for everything else on this list.
Update your System Security Plan (SSP). Your SSP should describe your actual environment today, not the environment you had when the document was last touched. Outdated SSPs are among the most common findings in real assessments.
Review and remediate your Plan of Action and Milestones (POA&M). Every open item is a known gap with a clock on it. Use this pause to close as many as possible rather than letting them accumulate.
Conduct a security assessment with penetration testing. Understanding your actual exposure (unauthenticated and authenticated scanning, external footprint, and where appropriate, real-world exploitation testing) gives you evidence-based priorities instead of guesswork.
Extend attention to your Microsoft environment. Active Directory and Microsoft 365 / Entra ID configuration, privileged access, and password hygiene are frequent sources of findings and map directly to several NIST SP 800-171 control families.
Train your workforce. A meaningful share of control failures are people failures. Access hygiene, phishing susceptibility, and the handling of CUI are critical. Use the time for real training, not a once-a-year compliance video.
Build your evidence package now. Whatever assessment eventually applies (CMMC Level 2, a NIST CSF-based internal audit, or a customer-requested review), assessors want to see artifacts: policies, configurations, scan results, training records, access reviews. Assembling this while there's no deadline pressure produces a far better result than assembling it under one.
Framed this way, the pause is an unusually good opportunity: you get to do the highest-value security and compliance work without the compressed timeline. Organizations that use a NIST CSF assessment as their organizing framework during this window typically emerge with both stronger security and a much shorter path to CMMC certification whenever Phase II resumes, because the bulk of the underlying control work is already done and documented.
Final thoughts
The pause is not a cancellation, and it shouldn't be treated as one. The Department of Defense will finalize its revised approach to Phase II's implementation. Contractors who spend that time strengthening their actual security posture, closing control gaps, and building an audit-ready evidence base will be prepared whenever certification requirements resume, and better protected against breaches and False Claims Act exposure in the meantime. Contractors who spend it waiting will be right back where they started.
If you haven't yet run a NIST CSF assessment, now is the moment.
Digital Elevation helps mid-market defense contractors turn compliance frameworks into practical, audit-ready security programs.
Start the conversation arrow_forwardW. Scott Montgomery is Director of Security at Digital Elevation, where he leads the firm's security assessment and advisory practice. With more than 40 years of IT experience, Scott helps mid-market organizations, credit unions, and healthcare and defense-sector firms build practical, defensible security programs, from vulnerability management and examination readiness to compliance across frameworks including NIST CSF, FFIEC, GLBA, and HIPAA.