On July 13, 2026, the Department of Defense announced a significant change to the CMMC rollout. Phase II of CMMC, which would have required third-party assessments conducted by Certified Third-Party Assessment Organizations (C3PAOs), was suspended just months before its scheduled November 10, 2026 implementation date.
At the same time, DoD CIO Kirsten Davies established a CMMC Reform Task Force with a mandate to conduct a comprehensive review of the program and deliver recommendations within 60 days.
For many contractors, especially small and mid-sized businesses, the announcement raised immediate questions. Is CMMC being canceled? Should compliance projects be put on hold? Will certification still be required in the future?
The answer is more nuanced than a simple yes or no.
The pause was not driven by concerns about the importance of cybersecurity. Instead, it was driven by concerns about how the program was being implemented.
According to statements from the Department of Defense, Small Business Administration feedback, and internal program data, three recurring issues were creating challenges across the Defense Industrial Base (DIB):
- Rising compliance costs
- Limited C3PAO assessment capacity
- Complex implementation timelines
Collectively, these challenges were creating barriers for smaller contractors and non-traditional defense suppliers. In some cases, organizations that provide valuable products, services, and innovation to the defense supply chain were finding it difficult to navigate the certification process.
As quoted by DefenseScoop, the sentiment behind the decision was simple: “the math just simply doesn’t math.”
The pause is also being positioned as part of Secretary Hegseth’s broader Acquisition Transformation System initiative, which focuses on accelerating the delivery of capabilities to the warfighter while reducing unnecessary barriers to participation in the defense marketplace.
In other words, the Department of Defense is not questioning the need for cybersecurity. It is evaluating whether the current approach achieves that goal without creating unintended consequences for contractors.
What the Pause Actually Means
For organizations preparing for CMMC assessments, the 60-day pause creates uncertainty around timing, but it does not eliminate cybersecurity requirements.
The Department of Defense still expects contractors to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). Existing contractual obligations remain in place, and the underlying cybersecurity standards that support CMMC have not disappeared.
What has been paused is the implementation of Phase II assessment requirements while the task force reviews the program’s structure and effectiveness.
That distinction matters.
A temporary pause in certification requirements does not mean organizations can ignore security controls, stop compliance activities, or delay cybersecurity improvements.
What Has Not Changed
Despite the announcement, several key realities remain the same:
- Cyber threats continue to target defense contractors.
- NIST 800-171 remains the foundation for protecting CUI.
- Existing contractual cybersecurity obligations may still apply.
- Organizations handling sensitive defense information remain responsible for protecting it.
- Future validation requirements could still emerge from the task force’s recommendations.
The destination has not changed. The Department of Defense is simply reviewing the road map.
The Risk of Waiting
Whenever compliance timelines shift, there is a temptation to pause internal initiatives and wait for clarity.
That approach can create challenges later.
Cybersecurity maturity is built over time. Implementing controls, documenting processes, training users, and validating security measures cannot be accomplished overnight.
Organizations that stop their efforts now may find themselves rushing to address gaps once the task force completes its review and the Department provides updated guidance.
More importantly, cybercriminals are not pausing their activities while regulators review policy.
The risks remain:
- Ransomware attacks
- Supply chain compromises
- Credential theft
- Insider threats
- Business disruption
Strong cybersecurity practices continue to deliver value regardless of certification timelines.
What Organizations Should Focus on During the Pause
Rather than viewing the pause as a reason to stop, many organizations are treating it as an opportunity to strengthen their cybersecurity foundation.
Continue Closing Security Gaps
If you’ve already identified deficiencies against NIST 800-171 requirements, continue addressing them.
Priority areas often include:
- Multi-factor authentication
- Access control
- Vulnerability management
- Endpoint security
- Asset inventory
- Backup and recovery processes
These improvements reduce risk whether CMMC requirements change or not.
Strengthen Documentation
Documentation remains one of the most common challenges during assessments.
Use this time to refine:
- System Security Plans (SSPs)
- Policies and procedures
- Incident response plans
- Risk assessments
- Security awareness training records
A well-documented security program is easier to manage and easier to demonstrate during future reviews.
Validate Existing Controls
Many organizations assume that installed security tools automatically satisfy compliance requirements.
Take the opportunity to verify:
- Security configurations
- Log collection and retention
- Backup testing
- User access reviews
- Monitoring and alerting capabilities
The goal is confidence, not assumptions.
Invest in Security Awareness
Technology alone is not enough.
Employees should understand:
- How to recognize phishing attempts
- How to report suspicious activity
- Proper handling of sensitive information
- Their role in protecting company data
Organizations with strong security cultures are generally better positioned regardless of regulatory changes.
Looking Ahead
The outcome of the CMMC Reform Task Force review remains to be seen. Adjustments may be made to implementation timelines, assessment requirements, or compliance pathways.
What seems unlikely is a complete departure from cybersecurity accountability within the Defense Industrial Base.
The Department of Defense continues to emphasize the need to protect sensitive information across its supply chain. The current review is focused on making the program more practical and accessible, not eliminating the need for strong cybersecurity practices.
The Bottom Line
The CMMC 60-day pause is best viewed as a policy review, not a retreat from cybersecurity requirements.
While certification timelines may change, organizations that continue improving their security posture, strengthening documentation, and addressing compliance gaps will be in a stronger position when the Department of Defense announces its next steps.
For contractors across the DIB, the smartest move right now is simple: use the additional time to build a stronger cybersecurity program, regardless of what the final version of CMMC looks like.
Kyber Security helps Connecticut and Rhode Island defense contractors prepare for CMMC regardless of how the final timeline shakes out — see our CMMC compliance services for a current gap assessment.
CMMC Compliance Support for Fairfield County Contractors
Kyber Security is a CyberAB-certified Registered Practitioner Organization based in Trumbull, CT, helping defense contractors and subcontractors throughout Bridgeport, Stamford, Norwalk, and the rest of Fairfield County prepare for CMMC assessment. See our CMMC Compliance Services for the full breakdown.

