By Travis Goldbach, VP of CMMC
The Department of War’s decision to pause the rollout of CMMC Phase II has understandably created uncertainty across the Defense Industrial Base (DIB). Many organizations immediately asked the same question:
“Should we stop preparing for CMMC?”
The answer is simple.
No.
In fact, organizations that use this pause to strengthen their cybersecurity posture will likely emerge with a significant competitive advantage when the program resumes.
The recent announcement suspended the implementation of Phase II, delaying the contractual requirement for certain contractors to obtain a CMMC Level 2 certification before award. It did not eliminate the CMMC program, invalidate existing cybersecurity requirements, or stop C3PAOs from performing certification assessments. Certification assessments, training, examinations, and the supporting CMMC ecosystem all remain operational.
Perhaps more importantly, the underlying cybersecurity obligations for contractors have not disappeared.
DFARS 252.204-7012 remains in effect. NIST SP 800-171 requirements remain in effect. Existing contractual obligations remain in effect. Prime contractors remain responsible for managing cyber risk throughout their supply chains.
The destination has not changed.
Only the timing has.
One of the unintended consequences of CMMC over the past several years was that many organizations began viewing certification as the finish line.
It never was.
The purpose of CMMC has always been to improve the cybersecurity resilience of the Defense Industrial Base, not simply to generate assessment reports.
The Department’s announcement reinforces this point. While officials cited concerns regarding compliance burden and acquisition speed, they did not argue that cybersecurity is less important. Instead, they indicated that the implementation model deserves another review.
That distinction matters.
Organizations should expect the government to simplify implementation, not abandon cybersecurity expectations.
Every market disruption creates two groups.
The first group waits. The second group prepares.
History consistently shows which group gains market share.
Companies that continue improving their NIST SP 800-171 implementation, validating evidence, documenting their System Security Plans, and obtaining independent assessments will be positioned to respond immediately when contractual requirements return.
Those organizations will also provide greater confidence to prime contractors looking to reduce supplier risk.
The pause has created additional time. It has not created permission to delay cybersecurity.
Perhaps the most overlooked aspect of the announcement is that prime contractors continue to bear responsibility for protecting Controlled Unclassified Information throughout their supply chains.
Whether driven by contract requirements, customer expectations, or enterprise risk management, many primes have already invested heavily in supplier cybersecurity initiatives.
That investment does not disappear because one implementation milestone moved.
In fact, many prime contractors are expected to continue requesting CMMC certifications or equivalent assurance from critical suppliers to reduce operational and contractual risk.
The government’s pause applies to its contractual rollout. It does not dictate how prime contractors manage supplier risk within their own programs.
Some organizations now question whether pursuing certification is worth the investment.
That question should be reframed.
Instead of asking: “Do I have to certify today?”
Organizations should ask: “What business risks am I reducing by certifying?”
Independent certification demonstrates that cybersecurity controls have been validated, not simply self-attested.
It provides greater confidence to customers. It differentiates suppliers during source selection. It strengthens executive governance.
It reduces the likelihood of overrepresenting cybersecurity capabilities, an area that has increasingly intersected with False Claims Act enforcement. Organizations that achieve CMMC Level 2 certification also demonstrate documented due diligence that can strengthen their overall risk posture.
Certification should be viewed as a business investment, not merely a compliance expense.
Rather than pausing cybersecurity initiatives, executive leadership should focus on five priorities:
The Department’s review presents an opportunity to improve how CMMC is implemented across the Defense Industrial Base. Simplification, reduced administrative burden, and better alignment with acquisition objectives are all worthwhile goals.
But none of those objectives eliminate the need to protect Controlled Unclassified Information.
Cyber threats have not paused. Nation-state adversaries have not paused. The Defense Industrial Base cannot afford to pause either.
Organizations that continue investing in cybersecurity during this period will be the ones best positioned regardless of how the final CMMC framework evolves.
The organizations that stay the course today will not simply be ready for tomorrow’s requirements. They will be better businesses because of it.
Still have questions? Explore our CMMC Phase II Suspension FAQ for answers to the most common questions and practical guidance for navigating the suspension.
Travis Goldbach is a cybersecurity and compliance leader with 20 years of experience driving growth and go-to-market strategy for federally regulated industries. He currently leads Coalfire Federal’s unified GTM strategy and previously guided AWS toward CMMC certification while helping customers advance secure, scalable compliance in the cloud.