Table of Contents

CMMC Is Paused. Here’s What Defense Suppliers Should Do Right Now.

Picture of CyberDuo
CyberDuo

On July 13, 2026, the Department of War hit pause on the CMMC rollout. Phase 2, which was set to make third-party certification mandatory for most contracts involving Controlled Unclassified Information starting November 10, 2026, is suspended along with the later phases, pending a 60-day review whose guidance is expected around mid-September. The stated reason was blunt: the third-party assessment requirement was proving too expensive and slow for small and midsize businesses, and the Small Business Administration reported that compliance costs were pushing companies out of the defense supply chain.

For a machine shop in Anaheim or a components supplier in Irvine, this feels like a reprieve. Here is why it is not one, what actually changed, what did not, and the smartest way to use the next few months.

What changed

Three things, and they are narrower than the headlines suggest. New solicitations can now designate only CMMC Level 1 (Self) or Level 2 (Self). Level 2 (C3PAO) requirements are being removed from active solicitations and existing contracts. And CMMC waiver procedures are paused while the review runs. The review itself is being handled by a CMMC Reform Task Force, which is due to report back within the 60-day window.

What did not change (this is the important part)

Your underlying cybersecurity obligations are exactly what they were on July 12.

Phase 1, which took effect November 10, 2025, is still in force. Most new contracts still require at least CMMC Level 1 or Level 2 self-assessment compliance at the time of award. If you handle CUI, you are still required to implement the 110 security controls of NIST SP 800-171, to maintain a System Security Plan, to post your self-assessment score in the Supplier Performance Risk System, and to rapidly report cyber incidents under the existing DFARS clauses. A contract can still require a posted SPRS score before award, which means your real deadline is set by when your specific opportunities go out, not by the rollout calendar.

Prime contractors did not pause either. Many are doing more supplier due diligence, not less, and increasingly prefer suppliers who can show independently validated security. Flow-down obligations from primes remain in force regardless of what the Department does with its phases.

And the legal risk has, if anything, sharpened. False Claims Act enforcement actions have already been brought against contractors whose SPRS scores were found to be inaccurate, including the first action against a subcontractor, and a December 2025 indictment made clear that individuals can be held personally liable. An inflated self-assessment score during a pause is not a safe harbor. It is a documented misrepresentation with a longer shelf life.

The trap: treating a pause as a cancellation

Here is how the next year plays out for two kinds of suppliers.

The first shop hears “paused” and stops. The 800-171 gap-remediation project goes back on the shelf, the evidence stops accumulating, and the SPRS score stays where it is, or stays inflated. Then the review concludes, Phase 2 restarts with a new date, and every CUI-handling supplier in the country needs a C3PAO assessment at once. Assessment capacity is already limited. Auditors typically want four to six months of operating evidence: logs, access reviews, incident response tests, vulnerability scans, policy enforcement records. None of that can be manufactured after the fact. The first shop is now at the back of a very long line with a very thin evidence file, while primes quietly route work to suppliers who are ready.

The second shop treats the pause as free time. It uses the months without a hard certification date to actually close its 800-171 gaps at a sane pace, fix its SPRS score so it reflects reality, and start generating the evidence trail that a future assessor will demand. When Phase 2 restarts, it books an assessor early, passes on the first attempt, and becomes the supplier primes prefer during the scramble.

Same pause. Opposite outcomes. The difference is what you do in the next 90 days.

What to do right now

Get honest about your SPRS score. Re-run your NIST 800-171 self-assessment against reality, not aspiration. If your posted score does not match your systems, fix the systems or fix the score, because the mismatch is the legal exposure.

Close the gaps that take the longest. Multifactor authentication everywhere, encryption of CUI at rest and in transit, logging and monitoring, access control and privilege management, and a tested incident response process are the controls most shops are missing and the ones that take months to operationalize. Start those first.

Start the evidence engine. Turn on the logging, schedule the access reviews and vulnerability scans, run the incident response tabletop, and keep the records. Evidence is where most CMMC efforts break down, and it only accumulates with time.

Document flow-down and CUI boundaries. Know exactly which contracts and which systems touch CUI. Subcontractors who were never formally notified of CUI flow-down are the most common surprise in this space.

Watch for the review guidance, but do not wait on it. Whatever the task force recommends in September, it will not remove the obligation to protect CUI. It may change how you prove it. Build the program that satisfies both.

Where we fit

We align defense suppliers’ environments to NIST 800-171 and CMMC on the technical side: the identity architecture, encryption, endpoint protection, logging and 24/7 monitoring through our in-house SOC, and the evidence trail that makes an SSP defensible and an assessment passable. We are not a C3PAO and we do not perform your certification assessment; independence is the point. What we do is make sure that when the assessor arrives, they find a working program.

This is home-turf work for us in Orange County, where the aerospace and defense supply chain runs deep, and across Los Angeles and San Diego as well. Our cybersecurity services and managed IT services pages show the full model, and our Orange County market deep dive covers why this county’s defense cluster makes CMMC readiness so consequential locally.

If you are a supplier who just exhaled at the word “paused,” reach out. We will help you use the pause instead of losing it.

Talk to our team