CMMC Is Paused. The Cybersecurity Obligation Is Not.
August 13, 2026
CMMC Is Paused. The Cybersecurity Obligation Is Not.
CMMC Phase II is paused, but the underlying cybersecurity obligation is not. The Department has kept Phase I self-assessments in place, says it will continue enforcing NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments, and has reaffirmed contractors’ obligation to protect covered defense information. For defense companies, the durable requirement is increasingly clear: know where sensitive data…



