CMMC’s pause isn’t a cancellation

Gettyimages.com/Evgeny Ostroushko
Contractors still have obligations, self-assessments and False Claims Act exposure aren't going anywhere, writes Perry E. Keating, president of Protiviti Government Services.
For defense contractors, the Defense Department’s 60-day suspension of CMMC Phase II requirements should not be read as a stop-work order on cybersecurity.
It is a pause in the rollout of certain certification requirements, but it does not pause contractors’ responsibility to protect government information.
The distinction matters. On July 13, the department announced the immediate suspension of Cybersecurity Maturity Model Certification Phase II requirements, which were scheduled to take effect on Nov. 10. The department also said it would begin a comprehensive review of the CMMC program, focused on reducing barriers for small, medium and non-traditional businesses while emphasizing scalable, resilient cybersecurity measures.
At the same time, the announcement made clear that Phase I self-assessment requirements remain in place and that contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012.
That is the key message government contractors should take from this moment: the certification timeline may be changing, but the obligation to protect federal information is not.
Why the Pause Matters
CMMC has long been one of the most closely watched cybersecurity compliance programs in the defense market. For many contractors, particularly small and mid-sized businesses, the anticipated movement into Phase II raised difficult questions about cost, timing, assessment capacity and competitive access to defense work.
The department’s announcement acknowledges those concerns. It specifically cites the need to align the program with acquisition transformation priorities, reduce unnecessary barriers and maintain a strict security baseline while keeping innovators and competition in the defense supply chain.
This represents a significant policy signal. It suggests the government is not walking away from cybersecurity expectations, but it is reconsidering how those expectations are verified, implemented and scaled across a diverse Defense Industrial Base.
For contractors, the announcement brings both relief and uncertainty.
The immediate pressure around Phase II implementation may be reduced. Some solicitations and contracts may be modified as the department suspends pending and future CMMC implementation milestones. But uncertainty about the future model does not eliminate present obligations.
What Has Not Changed
The most important point is that CMMC was never the only driver of cybersecurity obligation. Defense contractors handling federal contract information or controlled unclassified information have long been subject to contractual and regulatory requirements tied to protecting government data.
Those obligations include maintaining appropriate safeguards, understanding where sensitive government information resides, documenting cybersecurity practices, performing self-assessments where required, and supporting representations made to the government or prime contractors.
The department’s announcement states that during the interim period, cybersecurity compliance with NIST SP 800-171 Rev. 2 will be enforced through self-assessments and select government-led assessments, with emphasis on tangible cyber hygiene rather than administrative overhead. It also states that the action does not eliminate the requirement for companies to protect federal data.
That should shape contractor behavior over the next 60 days. Organizations should not dismantle project teams, shelve remediation plans or allow documentation to grow stale. Instead, they should use the review period to strengthen the fundamentals.
The Risk of Overreacting
The greatest risk for contractors is misreading the suspension as cancellation.
Some organizations may be tempted to pause assessments, delay remediation, defer evidence collection or tell business units that CMMC no longer matters. That would be a mistake.
Prime contractors will still need confidence that their subcontractors can protect sensitive information. Customers will still ask about cybersecurity posture. Contracting officers may still require self-assessments. And organizations will still need to support the accuracy of cybersecurity representations made in proposals, certifications, contract performance communications and supplier questionnaires.
There is also a False Claims Act dimension. Even if the third-party certification pathway changes, unsupported or inaccurate cybersecurity claims can still create enforcement risk. A contractor that tells the government it has implemented required controls should be able to demonstrate the basis for that statement.
In short, the compliance mechanism may be under review. The accountability remains.
What Contractors Should Do Now
Defense contractors should use the 60-day review period to focus on practical, defensible cybersecurity governance.
1) Confirm your scope. Identify which contracts, systems and data environments involve federal contract information or controlled unclassified information.
2) Review current self-assessments. Ensure that scores, affirmations and supporting documentation are accurate.
3) Continue remediation. Address known gaps against NIST SP 800-171 requirements. A pause in certification timing should not become a pause in risk reduction.
4) Maintain documentation. Keep system security plans, plans of action and milestones, policies, procedures and technical evidence. Documentation remains central to defensible compliance.
5) Monitor contract requirements. Review active solicitations and contracts for any changes related to CMMC clauses, customer expectations or flow-down requirements.
6) Keep Leadership engaged. Elevate the issue to executive leadership. This is not merely an IT compliance question. It affects contract eligibility, customer trust, supply chain participation and enterprise risk.
The Bottom Line
The Defense Department’s 60-day review may produce meaningful changes to CMMC implementation. It may reduce burden, reshape assessment timing or create a more scalable model for the Defense Industrial Base.
But contractors should not confuse regulatory recalibration with regulatory retreat.
Cybersecurity remains a condition of doing business in the federal market. The companies best positioned after the review will be those that continue protecting government information, strengthening evidence, validating representations and treating cybersecurity as a business risk, not just a certification exercise.
CMMC implementation may be paused, but contractors' cybersecurity responsibilities remain in effect.
Perry E. Keating is the leader of Protiviti’s CMMC practice and President of Protiviti Government Services. He advises government contractors and commercial organizations on cybersecurity, CMMC readiness, government data protection, regulatory compliance and cyber governance.