If you’ve been following the news around the Cybersecurity Maturity Model Certification (CMMC) program, you may have heard that the Department of War (formerly the Department of Defense) has paused Phase II requirements. And if you’re a small or mid-sized defense contractor, you might be tempted to exhale, lean back, and table the whole compliance conversation for now.
I want to gently, but firmly, encourage you not to do that.
At CMIT Solutions of Greenville, we work alongside businesses navigating real challenges tight budgets, lean teams, and the ever-growing complexity of doing business with the federal government. We understand why a pause feels like breathing room. But in this case, standing still could cost you far more than pressing forward. Here’s what actually happened, why it happened, and what smart companies are doing about it right now.
What Actually Happened
On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect November 10, 2026. The suspension also placed later implementation milestones on hold across Department of War solicitations and contracts.
Officials pointed to two main concerns driving the decision. The first was cost. Internal estimates suggested that future CMMC phases could impose several billion dollars a year in compliance costs on small and mid-sized businesses as a group, with individual compliance bills for some companies approaching hundreds of thousands of dollars. The second was capacity. With roughly 100 authorized Certified Third-Party Assessment Organizations, or C3PAOs, available to serve more than 100,000 companies across the defense industrial base, there was no realistic way for that small pool of assessors to process that many companies on the original timeline. The math simply didn’t work.
In response, the Department stood up a CMMC Reform Task Force to conduct a top-to-bottom review of the program, with public input collected through a formal request for information. Recommendations are expected roughly 60 days after the suspension, putting the timeline at approximately mid-September 2026.
It’s worth pausing on the tone of the announcement itself, because it matters for how you should respond to it. Department officials were explicit that this is not a retreat from cybersecurity standards. The stated intent was to reduce the administrative burden of certification, not the substance of what’s required to protect sensitive information. That distinction is the entire point of this article.
This is meaningful news. It reflects real, sustained feedback from the defense industrial base, and it may well lead to a more practical and equitable framework once the review concludes. But here’s what did not change: your legal obligations.
The Audit Is Paused. The Liability Isn’t.
DFARS 252.204-7012, the federal clause requiring protection of Controlled Unclassified Information, is fully intact. All 110 security controls under NIST SP 800-171 still apply to any contractor handling CUI. The pause affects how the Department of War verifies compliance, not what you’re required to do to earn a contract or keep one.
During the suspension, contracting officers can still include CMMC Level 1 or Level 2 self-assessment requirements in contracts. Companies still need to complete annual self-assessments and submit accurate scores to the Supplier Performance Risk System, known as SPRS, which is the government’s central repository for contractor risk data. Contracting officers reference SPRS scores when awarding and administering contracts, so this isn’t an internal formality it’s a number the government actually relies on.
That’s where the real risk has shifted. With third-party audits suspended, enforcement has effectively moved to self-attestation, and SPRS entries are legally binding representations to the federal government. The Department of Justice’s Civil Cyber-Fraud Initiative has been actively pursuing False Claims Act cases built around exactly this kind of misrepresentation, and cybersecurity-related case activity has climbed sharply year over year. Affirming a compliant SPRS score when real gaps exist is not a theoretical risk. It carries treble damages and personal liability for whoever signs that entry, whether that’s an owner, a CFO, or an IT director.
As one legal expert summarized it, the worst response to the suspension is to freeze compliance work while continuing to affirm a compliant score, because that combination converts a compliance gap into personal legal exposure. In plain terms, doing nothing is not a neutral choice. If your systems have gaps and your SPRS score says otherwise, the pause doesn’t protect you. It simply removes the independent check that might have caught the discrepancy before it became a False Claims Act problem.
A Refresher: What CMMC Levels Actually Require
For contractors who’ve only half-followed CMMC news over the past couple of years, it helps to restate what the framework actually asks for, since none of it changed on July 13.
Level 1 applies to contractors handling Federal Contract Information, meaning information not intended for public release but not rising to the level of CUI. It requires 15 basic safeguarding practices under FAR 52.204-21, covering things like access control, basic system protection, and physical security of equipment. Level 1 requires an annual self-assessment and never required a third-party audit, even under the original Phase II rollout.
Level 2 applies to contractors handling CUI and aligns closely with the 110 controls in NIST SP 800-171. This is the level most affected by the pause, since Phase II would have required many Level 2 contracts to undergo third-party C3PAO assessments rather than self-assessment. For now, Level 2 contracts can still specify self-assessment only.
Level 3 applies to a smaller group of contractors handling the most sensitive information and involves government-led assessments. Level 3 was largely unaffected by the Phase II pause, since it was never structured around the C3PAO marketplace in the same way.
Most small and mid-sized defense contractors fall into Level 1 or Level 2, which means most of you are currently operating exactly as you were before the suspension. You’re still self-assessing, still scoring yourselves in SPRS, and still held to the underlying NIST 800-171 controls whether or not a third party ever checks your work.
Your Prime Contractors Haven’t Paused
The Department of War’s memo binds Department of War personnel and contracting officers. It does not rewrite the terms of agreements already in place between primes and subcontractors. Many prime contractors have CMMC Level 2 requirements written directly into subcontract agreements, complete with their own timelines, audit rights, and remedies for non-compliance, and those terms remain fully enforceable regardless of what happened in Washington.
Before you slow down your compliance efforts, pull up your current subcontract language and any flow-down clauses tied to cybersecurity or CMMC, and ask your prime, in writing, whether anything has actually changed for your specific agreement. Get that answer documented before adjusting your own compliance posture in any way. Don’t assume ask. Primes are, in many cases, under just as much pressure as you are to demonstrate a secure supply chain, and some are choosing to hold subcontractors to CMMC-aligned standards regardless of what the federal timeline says, simply because it reduces their own risk.
The Window of Opportunity Is Open Right Now
Here’s the part I genuinely want you to hear: this pause is an opportunity for companies willing to stay the course.
The defense market is bifurcating in real time. On one side are companies pressing forward, implementing controls, documenting evidence, and positioning themselves to be ready the moment Phase II resumes or a revised framework takes its place. On the other side are companies standing down entirely and hoping the issue quietly resolves itself. When requirements are reinstated, and the underlying statutory basis for protecting CUI makes that very likely, those two groups will be in dramatically different positions.
With only about 100 authorized C3PAOs serving more than 100,000 defense industrial base companies, the backlog for third-party assessments was already a structural bottleneck before the pause, and there’s no reason to expect it to resolve itself during a 60-day review. Companies that are already assessment-ready when the marketplace reopens will move to the front of that line. Companies starting from zero will be waiting behind everyone else who used this window productively.
There’s also a competitive dimension worth naming plainly. Contractors with documented, CMMC-aligned practices are already seeing higher win rates, stronger pricing power in negotiations, and preferred supplier status with primes who are actively streamlining and de-risking their supply chains. That dynamic doesn’t pause just because an audit requirement does.
It Protects Your Business in More Ways Than One
Beyond contracts and compliance, pursuing CMMC readiness strengthens your entire cybersecurity posture, and that has ripple effects reaching well past your defense work. Insurers increasingly reward documented, certified security practices with lower premiums and stronger coverage terms, so a mature security posture often pays for itself in reduced cyber insurance costs alone. It also tends to raise the value of the business itself: if you ever consider a sale, an outside investment, or a capital raise, a well-documented security posture reduces friction for buyers and supports stronger valuations, since it removes one of the biggest sources of uncertainty in due diligence.
There’s a quieter benefit too. Firms with mature practices tend to catch gaps during routine internal reviews rather than discovering them during a high-stakes external assessment, when the stakes and the pressure are both much higher. And companies with current documentation respond to bid requirements faster than companies scrambling to gather evidence under deadline pressure, which becomes a real competitive advantage over time. Underneath all of that is something simpler: knowing you’ve done right by your clients, your team, and your business is worth something in its own right.
What We Recommend Right Now
Don’t stop working. Keep implementing your NIST 800-171 controls and documenting your progress as if the third-party assessment were still six months away. A managed cybersecurity program makes this ongoing effort far easier to sustain than trying to track it manually across spreadsheets and email threads.
Keep your SPRS score accurate. Only affirm what you can genuinely support with evidence, since inaccurate scores carry serious legal risk rather than just a slap on the wrist. Regular reviews through managed IT services help ensure your self-assessment actually reflects the current state of your systems rather than a snapshot from a year ago.
Review your subcontracts and confirm in writing whether your prime contractors have modified flow-down requirements before making any compliance decisions of your own.
Stay engaged with the Reform Task Force timeline. The report is due around mid-September 2026, and knowing what’s coming allows you to respond quickly instead of scrambling after the fact. Our IT guidance resources track developments like this so you don’t have to monitor federal announcements yourself.
Use this window to shore up the fundamentals. This is a good moment to tighten up network management, confirm your data backup and disaster recovery plans are genuinely solid rather than assumed solid, and make sure your cloud services environment is configured with CMMC-aligned access controls from the start. If your team is still procuring hardware and software on an ad hoc basis, standardizing through consistent IT procurement also makes future assessments, self or third-party, far less painful when they come. And if staff rely on shared drives, email, or collaboration tools that were never configured with CUI handling in mind, it’s worth reviewing your productivity applications and unified communications setup as well.
Finally, partner with people who know this space. You don’t have to figure out DFARS clauses, SPRS scoring nuances, and C3PAO logistics alone, and trying to do so entirely in-house often costs more in wasted hours than bringing in help would have.
Where Things Stand and Where They’re Headed
It’s worth stepping back and putting the last two years in context. The CMMC final rule established the phased implementation schedule back in November 2024. Phase I self-assessment requirements went into effect in November 2025 and remain fully in force today. Then, on July 13, 2026, the Department of War suspended the Phase II third-party assessment requirements that were originally set to begin November 10, 2026. That suspension is expected to run until the Reform Task Force delivers its recommendations, likely around mid-September 2026, at which point the Department will decide how to move forward, whether that means resuming the original Phase II plan, adopting a revised version of it, or something else entirely.
What’s notable is what stayed constant through all of this: the requirement to protect CUI, the 110 controls under NIST 800-171, and the obligation to self-assess and report accurately to SPRS. The only variable that moves is who checks your work, not whether the work needs to be done.
Common Questions We’re Hearing
A number of contractors have asked us whether the pause means they can stop working on compliance altogether. The answer is no. Level 1 and Level 2 self-assessment obligations, DFARS 252.204-7012, and the underlying NIST SP 800-171 controls remain fully in effect. Only the rollout of mandatory third-party assessments is paused, and the substance of what you’re required to protect hasn’t moved at all.
Others have asked whether CMMC could be cancelled entirely once the review wraps up. Officials have said publicly that the goal is reducing certification-related administrative burden, not lowering the underlying cybersecurity baseline. Some restructuring of how assessments happen is likely, but outright cancellation is considered unlikely given the statutory basis for protecting CUI and the years of policy work already invested in the framework.
We’ve also fielded questions about what to do with an open Plan of Action and Milestones right now. The short answer is to keep working at it. A POA&M that shows real, ongoing progress toward closing identified gaps is far safer, and far more credible to a prime contractor or a future assessor, than one that sits untouched during the pause. An untouched POA&M paired with an unqualified SPRS affirmation is precisely the combination that creates legal exposure.
Some have asked whether now is a bad time to invest in compliance-related IT upgrades, given the uncertainty. It’s arguably the best time. Vendors, IT partners, and internal teams have breathing room to implement changes properly instead of racing a deadline, and firms that use this window well will be genuinely ready, not just paper-ready, well ahead of competitors when Phase II resumes or a revised framework takes effect.
And finally, several contractors have asked how they’re supposed to know if their prime contractor’s requirements have changed. The honest answer is that you won’t know until you ask. The federal pause doesn’t automatically flow down into private subcontract terms, so reach out to your prime’s contracts or compliance team directly and get their answer in writing.
The Bottom Line
The CMMC pause is not a stop sign. It’s a speed bump, one that may ultimately lead to a better, more workable framework for small and mid-sized businesses. But the underlying obligation to protect sensitive defense information hasn’t wavered, and the companies that keep moving during this window will be the ones who thrive when requirements are reinstated in whatever form they take.
We care deeply about the businesses we serve. That’s why we’re sharing this now, rather than waiting until the pressure is back on. If you have questions about where your business stands or what your next steps should be, we’d love to have that conversation.
You’ve put too much into your business to let a pause become a setback. Let’s keep moving together.
CMIT Solutions of Greenville serves small and mid-sized businesses across the Upstate with managed IT services, cybersecurity, and compliance support. Explore our service packages to see what fits your business, or contact us to schedule a conversation.


