CorpInfoTech Blog | Resources and education regarding the latest in cybersecurity and compliance!

CMMC Phase 2 Is Paused. Here's Why Defense Contractors Should Stay the Course

Written by Waits Sharpe | Jul 22, 2026 5:22:39 PM

On July 13, 2026, the U.S. Department of War released a statement announcing the "immediate suspension of the CMMC Phase 2 requirements, which were originally scheduled to come into effect on November 10, 2026."  This announcement has understandably raised questions across the Defense Industrial Base about what the pause means for CMMC and how organizations should move forward. 

Based on the information available today and our ongoing evaluation through credible government and industry sources, our recommendation is simple: stay the course.

What Was Actually Announced?

The DoW's statement explains that they are suspending the CMMC Phase 2 requirements alongside pending and future CMMC implementation milestones to initiate a 60-day review of the CMMC program. The stated goal of this review is "prioritizing speed to capability, lowering barriers to small, medium, and non-traditional businesses, and replacing bureaucratic compliance with scalable, resilient cybersecurity measures." The Department's CIO, Kristin Davies, is establishing a CMMC Reform Task Force to "conduct a comprehensive top-to-bottom review of the certification program". 

During this time, the task force will collect industry feedback from their public Request for Information (RFI) regarding compliance challenges. Using this feedback, the DoW intends to "recommend realistic, scalable security measures that prioritize speed to capability and lower barriers for small and non-traditional businesses".

It is important to specify that Phase 2 is temporarily paused, NOT canceled. Phase 1 requirements remain active and the DoW will enforce compliance with NIST 800-171 Rev 2 through self-assessments and select government-led assessments. This pause does not negate an organization's obligation to protect CUI and adhere to the 110 practices outlined in NIST 800-171 Rev 2. 

Separating Facts from Speculation

As with any major change in legislation, there is no shortage of speculation and social media rumors surrounding the future of the CMMC program. Some of the information being disseminated online comes from anonymous sources whose credentials, access, and supporting evidence cannot be verified.

CorpInfoTech is not basing customer guidance on speculation. We are gathering information through credible sources whose roles, qualifications, and connection to the CMMC program are known. This includes C3PAOs, the MSP Collective, government leaders, congressional contacts, Department of War representatives, and recognized CMMC professionals with direct knowledge of the program.

What Hasn't Changed

It is important to distinguish between CMMC as a verification mechanism and the underlying requirement to safeguard covered defense information under DFARS 252.204-7012.

The CMMC program is designed to verify that defense contractors have implemented the applicable security requirements in NIST SP 800-171 Revision 2. Depending on the CMMC level and contract requirements, verification may occur through a self-assessment or a certified third-party assessment.

Those underlying security obligations have not changed. Contractors must still protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI), maintain accurate and current System Security Plans (SSPs), collect evidence showing that policies and procedures are being followed, and submit required assessment scores to the Supplier Performance Risk System (SPRS).

The pause has not eliminated the work contractors must perform. The controls and security requirements that CMMC was designed to assess remain in place. What has been paused is the broader expansion of Phase 2 requirements—not the obligation to protect sensitive information or maintain compliance with existing contractual requirements.

Whether an organization ultimately completes:

  • a C3PAO assessment,
  • a self-assessment, or
  • a future Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) review,

it will still need accurate documentation, properly implemented controls, current evidence, and a security program that can withstand review.


Why Waiting Could Create More Risk Than Moving Forward

This pause is not an excuse to neglect compliance readiness, rather, doing so may create more risk for organizations in the future. Choosing the "wait and see" approach means that an organization's documentation falls out of date, evidence is not collected on time, SSPs become stale, and security improvements are delayed. The Department's statement makes this abundantly clear when it states that "It is critical to note that this action does not eliminate the requirement for companies to protect federal data. All defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012." The consequences for failing to safeguard CUI remain the same as they were prior to the recent pause.

Additionally, many contract opportunities may still require certification from prime contractors. Many primes continue to require suppliers to demonstrate CMMC readiness regardless of regulatory timing. An example of this is when, on July 16, Elbit Systems encouraged suppliers to stay the course and continue to implement NIST 800-171 and be prepared to complete a CMMC Level 2 (self) assessment when required.

CorpInfoTech's Perspective

For more than 25 years, CorpInfoTech has helped organizations in regulated industries strengthen cybersecurity, implement secure IT solutions, and navigate evolving compliance requirements. We believe that a program like the CMMC is necessary and good for protecting our nation's security posture and safeguarding our country's intellectual property. It's why we pursued our own CMMC level 2 certification and went through the same third-party audit many of our clients will have to go through. It's why we participate in JCDC initiatives and partner with organizations like the MSP Collective. It's also why our recommendation is clear, once again: stay the course.

We want to make it clear that regardless of the pause, the underlying work remains necessary. Regardless of the final assessment pathway, a defensible CMMC Level 2 program requires:

  • Clearly defined CUI scope and data flows
  • Fully implemented security requirements
  • An accurate and current System Security Plan
  • Organized, objective evidence
  • Documented policies and procedures
  • Controls that operate effectively over time 

A self-assessment would not eliminate these expectations. Organizations would still need to support their assertions with complete documentation, credible evidence, and operationally effective controls. For customers currently engaged with CorpInfoTech on CMMC Level 2, we recommend continuing the agreed readiness plan, including technical implementation, documentation, evidence development, control validation, and assessment preparation. 

The pause may provide additional time. The best use of that time is to close remaining gaps, strengthen your evidence, and prepare to meet whichever assessment pathway ultimately applies.

"The Department's action pauses the transition to CMMC Phase II while it conducts a 60-day review. It is not a cancellation of CMMC. Phase I remains active, current DFARS obligations remain enforceable, and organizations should continue their readiness work toward NIST 800-171 Revision 2 compliance. This action has already caused significant confusion, and considerable FUD is circulating. When someone makes a sweeping or alarming claim, ask a simple question: where is that written down? Read the Department's announcement and rely on authoritative sources. Give CIO Davies and the Department the opportunity to evaluate what is working, identify unnecessary friction, and determine how Phase II proceeds. The DIB now has an opportunity to inform that evaluation. If your organization is materially involved in the CMMC process, whether pursuing certification or already certified, respond to the Request for Information when it is issued. Tell the Department about your experience, costs, operational burdens, and implementation difficulties."

Lawrence Cruciana - President, CorpInfoTech, Lead CCA

Stay Focused on Readiness

Regulatory reviews and changes are not unusual following changes in leadership. While this review may impact timelines and assessment pathways, it does not change the need for a mature cybersecurity and compliance program. Organizations that continue strengthening their security, maintaining documentation, and building evidence today will be better positioned regardless of how the final phase 2 implementation unfolds.

Regardless, CorpInfoTech is still your one partner from CMMC readiness to continuous compliance.

Don't Let the Pause Delay Your Progress

Whether you're preparing for your first CMMC Level 2 assessment or maintaining an existing compliance program, CorpInfoTech helps defense contractors implement the required controls, maintain operational readiness, and prepare for long-term compliance.

Schedule a CMMC Readiness Consultation

  CorpInfoTech, a Managed Service Provider (MSP) with over 25 years in the SMB space, is a trusted partner for business pursuing compliance and cybersecurity. We are a CMMC Level 2 (C3PAO) certified MSP and a Cyber AB Registered Provider Organization (RPO). Also, as the first CIS accredited organization, we help organizations implement the CIS controls as it pertains to CMMC and your overall cybersecurity posture. CorpInfoTech is your trusted partner for secure, compliant growth in every changing digital landscape.