
If you own any part of your company's Cybersecurity Maturity Model Certification (CMMC) program, you've had a long couple of weeks.
The Department of War suspended Phase II on July 13. The November assessment deadline is gone, a task force has 60 days to recommend what comes next, and officials have not ruled out ending the program in its current form.
The reaction across the defense industrial base moved fast and mostly in one direction. Budgets frozen. Projects shelved. Readiness calls pushed to next year.
If that's the conversation happening at your company right now, it's worth slowing down. What got suspended is narrower than the coverage suggests, and your position got riskier in the process.
CMMC was built to verify something that already existed.
DFARS 7012 has been standard in defense contracts since 2016. It obligates you to protect covered information using NIST 800-171. Your company agreed to that years ago, probably before anyone started talking about certification.
CMMC arrived in 2020 to check whether contractors were actually doing it. In July, the government paused the checking. The obligation stayed exactly where it was.
That distinction matters most when you look at the budget. When people quote six-figure CMMC costs, the assessment itself is a small slice, generally tens of thousands every three years. The rest went into implementation, which 7012 already required. Cancel the program now and most of what you cancel was never the certification.
Katie Arrington, who built CMMC, has leaned on the same analogy for years. We accept rules of the road, licenses, seat belts, insurance that tracks whether we follow them, because we share the road and one careless driver can hurt someone besides himself. The information superhighway is no different. That's why the requirements exist in the first place.
Here's what the pause did to that picture.
Picture the state pulling its patrol cars off the road (e.g. removing the audit requirement under CMMC). The limit holds at 55, and you could drive 85 tomorrow with nobody there to stop you. But the patrol car was never the reason for the number. The ticket was always the cheapest thing that could happen to you at 85. The expensive ones are the guardrail you crash into, your car, the other driver you injure, their car, your insurance rates, your license.
Here's what stayed on the road when the patrol car left:
Now the part that gets lost.
Your affirming official signs a statement that your security posture is what you claim. Contracts get awarded on the strength of that signature. Until July, a C3PAO was going to review the claim before it counted.
That reviewer is gone for at least a year. The signature still happens.
And False Claims Act exposure never ran through CMMC to begin with. It attaches to the representation itself, which is why DOJ has been bringing these cases since well before certification existed. CMMC was the patrol car. The FCA is the guardrail, and nobody moved it.
So the paperwork got lighter and the exposure got heavier, at the same time.
The task force reports in September. Three things are worth your attention until then.
Keep going. Whatever you were building was required before July and is required now. Stopping means restarting later, usually under a deadline you don't control.
Check your score honestly. If you suspect it's generous, correcting it now through a documented corrective action puts you in a far stronger position than having someone else find it later.
Get your evidence in order. With scheduled assessments off the table, what protects you is being able to demonstrate what you're actually doing on short notice, without rebuilding it from scratch each time. (Hint: this is exactly what Diligent is built to do for CMMC and every other framework or regulation you're on the hook for)
Over the coming weeks we'll cover:
Alongside the suspension, the Department published a request for information. It asks contractors directly what compliance costs, which controls deliver real security, and which ones fall short. Responses are due at noon Eastern on Friday, August 14.
If you've done this work, respond. Opportunities like this are rare. The people rewriting the rules are asking the people living under them what actually works.
One thing worth keeping straight. Burdensome and useless belong in separate categories. Some requirements cost real money and earn it. Others are cheap and hollow. Treating them as one bucket is how a review meant to reduce cost ends up producing a weaker baseline that helps nobody.
Tell them what the paperwork cost you. Tell them what the security bought you. They're asking both questions.
The next 60 days matter.
Whether the task force keeps CMMC largely intact, reshapes it, or replaces parts of it entirely, the same challenge remains: demonstrating that your security program is real, repeatable and defensible. The organizations that come out of this period strongest won't be the ones that paused everything. They'll be the ones that used the uncertainty to tighten their controls, improve their evidence and understand where their real exposure sits.
That's exactly what we're watching right now.
We're hosting a live webinar on August 12 2026 with our partners at 38North and A-LIGN to discuss what the pause means in practice, what we're hearing from contractors across the defense industrial base and the decisions security, compliance and operations leaders should be making before the task force reports in September.
We'll bring together the advisor's perspective, the assessor's perspective and the platform perspective, with plenty of time for questions and discussion.