CMMC Phase II is paused, but the underlying cybersecurity obligation is not. The Department has kept Phase I self-assessments in place, says it will continue enforcing NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments, and has reaffirmed contractors’ obligation to protect covered defense information. For defense companies, the durable requirement is increasingly clear: know where sensitive data lives, reduce unnecessary exposure, operate the controls, and be able to prove that security works.

Bottom line: the July 2026 suspension of CMMC Phase II changes the certification timeline. It does not remove the cybersecurity obligations already attached to defense contracting.

The Department has paused implementation in Phase I while a CMMC Reform Task Force reviews the program. Phase I self-assessment requirements remain in place, and the Department says it will continue enforcing NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments during the review.

For contractors, the practical distinction is:

certification mechanism paused ≠ security obligation paused.

What Actually Changed on July 13

On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II, which had been scheduled to begin November 10, 2026.

The Department also established a CMMC Reform Task Force for a comprehensive review of the program and tied that review to broader Acquisition Transformation System objectives:

  • speed to capability;
  • lower barriers for small, medium, and nontraditional businesses;
  • reduced administrative burden;
  • and cybersecurity requirements that are scalable and resilient.

The first phase of CMMC implementation began November 10, 2025.

Implementation is now paused in that first phase.

That distinction matters because Phase I did not disappear with Phase II.

What Did Not Change

The Department’s current CMMC guidance is explicit that Phase I self-assessment requirements remain in effect.

Its July announcement also states that defense contractors and subcontractors remain responsible for safeguarding covered defense information under existing contractual requirements, including DFARS 252.204-7012.

During the interim review period, the Department says it will enforce NIST SP 800-171 Revision 2 through:

  • contractor self-assessments;
  • and selected government-led assessments.

The core obligation therefore remains:

protect the government information your contract requires you to protect.

Phase I Is Still an Active Compliance Environment

The Department’s current CMMC site describes Phase I as supporting two self-assessment levels.

Level 1 addresses basic safeguarding of Federal Contract Information and requires annual self-assessment against the 15 requirements in FAR 52.204-21, followed by affirmation.

Level 2 self-assessment addresses Controlled Unclassified Information and applies the 110 requirements in NIST SP 800-171 Revision 2, with periodic self-assessment and annual affirmation requirements under the current framework.

Contractors therefore should not interpret the Phase II pause as meaning CMMC has become irrelevant to current solicitations or contract performance.

The operative requirement depends on the actual procurement, contract clauses, information being handled, and the contractor information system supporting the work.

This is where understanding federal contracting requirements and solicitation obligations matters before proposal submission—not after award.

The Pentagon Is Reconsidering Verification, Not the Need for Security

The Department’s public explanation for the pause focuses heavily on implementation burden.

Officials argue that the existing structure has imposed significant cost and administrative friction, particularly on smaller and nontraditional companies that the Pentagon is simultaneously trying to attract into the defense market.

But the Department’s Chief Information Officer was equally clear that robust cybersecurity remains a nonnegotiable priority.

The policy problem is therefore not:

security or competition.

It is:

how to increase real security while preserving a diverse, innovative, and economically viable supplier base.

That connects directly to the acquisition challenge examined in Diamondback’s analysis of whether the Pentagon can absorb innovation as quickly as it buys it.

Small Business Cannot Mean Small Cybersecurity

The tension is especially visible among small defense contractors.

A major prime may have:

  • dedicated security engineering;
  • cyber operations teams;
  • legal and compliance personnel;
  • enterprise identity systems;
  • security operations centers;
  • and mature information-governance processes.

A 30-person engineering, technology, manufacturing, or consulting company may not.

Yet the smaller company can still handle CUI, technical data, program information, software, manufacturing information, or other material valuable to an adversary.

The threat actor does not care how many employees the contractor has.

The information still matters.

Cybersecurity therefore has to scale down operationally without scaling down in purpose.

Compliance and Security Are Different Things

CMMC exists partly because written requirements alone did not always create confidence that controls were actually operating across the defense industrial base.

That distinction should remain central during reform.

A policy can say multifactor authentication is required.

Operational security asks whether MFA is actually enforced.

A procedure can describe access removal.

Operational security asks whether former employees still have credentials.

A system security plan can describe vulnerability management.

Operational security asks whether exposed systems are actually patched and monitored.

The same distinction applies to:

  • asset inventories;
  • privileged access;
  • logging;
  • incident response;
  • configuration management;
  • employee training;
  • backup protection;
  • and subcontractor access.

Documentation describes the control. Operations prove the control.

The Most Important Cybersecurity Question Is Often: Where Is the Data?

A contractor cannot protect CUI effectively if it cannot define where that information exists.

Useful questions include:

  • Which contracts generate or receive CUI?
  • Where is that data stored?
  • Which employees can access it?
  • Which devices can process it?
  • Which cloud services contain it?
  • Which subcontractors receive it?
  • Is it present in backups?
  • Can it be copied to unmanaged devices?
  • How does it leave the environment?
  • What happens when access is no longer required?

These questions define the actual security boundary.

This is where technology architecture, identity, data flows, and system boundaries become cybersecurity decisions rather than generic IT design choices.

Smaller Enclaves Can Reduce Security Complexity

One common contractor mistake is allowing sensitive government information to spread farther through the enterprise than the mission requires.

Every unnecessary system, user, device, application, and data path can increase security scope.

Thoughtful architecture can reduce that burden.

A contractor may be able to create a more controlled environment by:

  • segmenting CUI workloads;
  • limiting authorized users;
  • reducing local downloads;
  • using approved managed services;
  • centralizing identity;
  • controlling data movement;
  • and separating ordinary corporate operations from contract-sensitive workflows.

The objective is not simply easier assessment.

It is a smaller, more understandable attack surface.

Security architecture can reduce both risk and compliance complexity.

Cybersecurity Has to Begin Before the Proposal

Cybersecurity obligations should not be discovered after contract award.

Business-development and capture teams need to identify relevant clauses and information requirements while evaluating the opportunity.

Program leaders need to understand how the work changes the company’s technology environment.

Subcontract managers need to understand how sensitive information will flow down the supply chain.

The security lifecycle therefore begins earlier:

opportunity → requirements review → proposal → architecture → staffing → onboarding → operations → incident response → closeout.

This is a contract-execution and operational-governance discipline, not an IT afterthought.

The Supply Chain Extends the Security Boundary

Defense programs are distributed information ecosystems.

Technical information can move among:

  • government organizations;
  • prime contractors;
  • subcontractors;
  • engineering firms;
  • manufacturers;
  • software providers;
  • cloud platforms;
  • consultants;
  • and logistics partners.

Every legitimate connection can also become an attack path.

A sophisticated attacker does not have to compromise the largest company in the program if useful information is accessible through a weaker organization several tiers downstream.

This makes contractor cybersecurity a supply-chain resilience issue.

Diamondback’s analysis of why defense risk often begins below the prime-contractor level examines the same structural problem from the industrial side.

The Threat Environment Did Not Pause With Phase II

Defense contractors continue to hold information that can reveal:

  • technical specifications;
  • engineering data;
  • manufacturing processes;
  • software;
  • network architecture;
  • program schedules;
  • supplier relationships;
  • logistics information;
  • and operational dependencies.

Much of that information may not be classified.

It can still carry intelligence value when aggregated or combined with other sources.

The certification timeline therefore does not change the adversary’s incentive.

The policy framework is under review. The attack surface is not.

Cybersecurity Should Be Measured as an Operating Capability

If CMMC reform moves toward greater emphasis on scalable, resilient cybersecurity, contractors should expect outcome-focused questions to matter increasingly.

Can the organization identify every system handling CUI?

Can it show who has privileged access?

Can it detect unauthorized activity?

Can it contain an affected system?

Can it restore operations?

Can it demonstrate that configurations match policy?

Can leadership explain the current risk posture without waiting weeks for a consultant to reconstruct it?

Those are signs of operational maturity.

They also provide evidence useful under almost any future assessment structure.

Evidence Should Be Produced by Operations, Not Created for Assessment Day

The strongest security environments naturally generate evidence.

Identity platforms record access.

Endpoint systems record device state.

Vulnerability tools identify findings.

Ticket systems document remediation.

Configuration platforms record changes.

Security monitoring records events.

Training systems record participation.

When those operational systems are reliable, assessment evidence becomes a byproduct of daily security rather than a documentation exercise assembled shortly before an assessor arrives.

That is a more durable model regardless of how the CMMC reform review ultimately changes certification.

Security Should Follow Risk, Not Organizational Size

The challenge for CMMC reform is creating a model that is rigorous without becoming needlessly uniform.

A small supplier handling limited FCI does not present the same risk profile as a company operating a large environment containing significant CUI.

A contractor with a tightly segmented controlled enclave may have a different architecture from one processing CUI across hundreds of endpoints.

A scalable system should preserve minimum requirements while allowing assurance effort to reflect:

  • information sensitivity;
  • system scope;
  • mission impact;
  • architecture;
  • and demonstrated risk.

That is a risk-management and cybersecurity planning problem as much as a compliance-design problem.

Contractors Should Preserve Useful Preparation During the Pause

Companies that were already preparing for CMMC should separate durable security work from certification-specific work.

Durable investments include:

  • identifying CUI and FCI;
  • documenting system boundaries;
  • maintaining accurate asset inventories;
  • controlling access;
  • implementing multifactor authentication;
  • patching systems;
  • managing vulnerabilities;
  • segmenting controlled environments;
  • training personnel;
  • testing incident response;
  • understanding subcontractor dependencies;
  • and maintaining current system-security documentation.

Those practices remain valuable even if assessment methodology, certification frequency, or other CMMC mechanics change.

Cybersecurity Is Also a Market-Access Capability

Strong cybersecurity does more than reduce breach risk.

It can expand the missions a contractor is able to support.

A company that understands its data, architecture, controls, evidence, incident process, and supply-chain dependencies presents lower execution risk to government customers and prime contractors.

For small and nontraditional businesses, this can become competitive infrastructure.

The government increasingly wants access to commercial innovation.

Those companies still have to enter mission environments that require trust.

Speed, innovation, affordability, and security increasingly have to coexist.

The Best Preparation Is to Build a Security Program That Survives Policy Change

Contractors cannot know exactly what CMMC will look like after the reform review.

They can control whether their environments become more defensible.

The durable strategy is therefore not optimizing exclusively for one assessment date.

It is building repeatable security operations:

know the data → reduce the boundary → operate the controls → collect evidence → test response → improve continuously.

That approach remains useful if CMMC returns largely unchanged.

It remains useful if assessment requirements become more risk-based.

It remains useful if government-led validation increases.

And it remains useful because the underlying contractual and operational need to protect defense information continues.

The Certification Can Change. The Mission Requirement Remains.

The July Phase II suspension is significant.

It gives the Department an opportunity to reconsider how cybersecurity should be validated across a defense industrial base ranging from small commercial entrants to major primes.

But the central mission has not changed.

Defense information still needs protection.

Contractors still need to understand the information entrusted to them.

Controls still need to operate.

Incidents still need to be detected and managed.

Supply-chain exposure still matters.

And government customers still need confidence that contractors can be trusted with sensitive mission information.

CMMC Phase II is paused. Cybersecurity is not.

Primary Sources