By Travis Goldbach, VP of CMMC
Since the Department of War announced the suspension of the CMMC Phase II rollout, there has been no shortage of opinions across the Defense Industrial Base. Some have declared the program dead. Others have suggested organizations should stop pursuing certification altogether. Neither conclusion is supported by the facts.
This announcement is not the end of CMMC. It is a pause in one portion of the implementation timeline while the Department reviews the program. Organizations that understand what actually changed, and more importantly what did not change, will be in the strongest position moving forward.
One of the biggest misconceptions is that the CMMC program has been suspended. It has not.
Every major component of the CMMC ecosystem remains operational and available.
The Department of War has not directed The Cyber AB to suspend or modify any of the program elements that fall under its responsibility. Likewise, the Supplier Performance Risk System (SPRS) and the CMMC Enterprise Mission Assurance Support Service (eMASS) remain operational and continue accepting C3PAO certification assessment submissions.
Organizations can still complete a CMMC Level 2 Certification Assessment today and receive a valid certification.
The Department suspended the beginning of the CMMC Phase II rollout that was scheduled to begin on November 10.
Specifically, the Department delayed implementation of the requirement that applicable Department solicitations and contracts require a CMMC Level 2 Certification Assessment performed by an authorized C3PAO as a condition of contract award.
As a result, implementation of DFARS Clause 252.204-7021 relating to mandatory C3PAO Level 2 certifications and DIBCAC Level 3 assessments for new Phase II contract awards has also been delayed.
That is an important distinction.
The Department did not suspend cybersecurity requirements.
The Department did not suspend CMMC assessments.
The Department did not suspend The Cyber AB.
The Department did not suspend C3PAOs.
The Department suspended one milestone in the contractual implementation schedule.
The overwhelming majority of contractual cybersecurity obligations remain exactly as they were before the announcement.
The following DFARS clauses continue to apply to awarded contracts and continue flowing throughout the defense supply chain.
Organizations supporting Department programs continue to have cybersecurity obligations regardless of the temporary delay in Phase II implementation.
Organizations will also continue submitting self affirmations where required for both CMMC Level 1 protecting Federal Contract Information (FCI) and CMMC Level 2 protecting Controlled Unclassified Information (CUI).
Another important point that has received very little attention is the scope of the suspension.
The Department’s announcement applies only to contracts awarded between the Department of War and the awarded contractor.
It does not invalidate contractual requirements established by prime contractors throughout their supply chains.
Many prime contractors have spent years preparing for CMMC implementation. They have invested heavily in supplier readiness programs, supply chain risk management, and cybersecurity validation. Those business decisions remain theirs to make.
If a prime contractor requires suppliers to obtain CMMC Level 2 Certification as part of its supplier qualification process, this announcement does not eliminate that requirement.
For many organizations, certification will continue to be driven by customer expectations rather than federal contract language.
Organizations that complete a CMMC Level 2 Certification Assessment today continue to differentiate themselves from competitors.
Independent certification demonstrates that an accredited C3PAO validated an organization’s implementation of NIST SP 800-171 rather than relying solely on self attestation.
That independent validation provides confidence to customers, prime contractors, investors, and acquisition teams.
Certification also provides stronger evidence that an organization exercised due diligence regarding its cybersecurity representations, helping reduce exposure to False Claims Act enforcement should cybersecurity claims ever be challenged.
As supply chain cybersecurity becomes an increasingly important discriminator, organizations with certification will likely continue to enjoy a competitive advantage over peers that delayed preparation.
Another practical implication of the announcement is timing.
The suspension of Phase II will likely delay mandatory migration to NIST SP 800-171 Revision 3 until future Federal Acquisition Regulation updates governing Controlled Unclassified Information begin appearing in contracts.
Organizations should certainly begin understanding Revision 3 and planning for its implementation, but there is no indication that immediate migration is necessary.
Organizations should avoid interpreting this announcement as a reduction in federal cybersecurity oversight.
With DIBCAC no longer preparing to initiate CMMC Level 3 assessments in the near term, the Department may have additional capacity to conduct non voluntary DFARS 252.204-7012 audits and other oversight activities across the Defense Industrial Base.
Organizations should expect scrutiny of cybersecurity implementation to continue and potentially increase while the broader CMMC program is reviewed.
Another source of confusion has been the use of the term “Phase II.”
The suspension announced by the Department relates to the CMMC Program rollout timeline.
It does not suspend Phase 2 of the CMMC Assessment Process (CAP) Version 2.0, which is the assessment methodology used by authorized C3PAOs during certification assessments.
These are two entirely different concepts.
Certification assessments continue using the established CMMC Assessment Process.
The organizations that will emerge strongest from this period of uncertainty will not be those that stop investing in cybersecurity.
The implementation schedule may have shifted, but the underlying cybersecurity expectations have not.
Every major shift in the CMMC program has created uncertainty. Organizations that reacted emotionally often found themselves scrambling when requirements returned. Organizations that stayed focused on building mature cybersecurity programs consistently found themselves ahead of their competitors.
The current pause presents another opportunity.
Organizations can use this time to strengthen cybersecurity, improve documentation, complete independent certification assessments, and position themselves ahead of competitors who choose to wait.
The Department has paused one contractual milestone.
It has not paused the need to protect Controlled Unclassified Information.
It has not paused the responsibility to safeguard the Defense Industrial Base.
It has not paused the expectation that contractors demonstrate cybersecurity maturity.
Those organizations that continue investing now will be best positioned when the next phase of CMMC implementation begins.
Still have questions? Explore our CMMC Phase II Suspension FAQ for answers to the most common questions and practical guidance for navigating the suspension.
Travis Goldbach is a cybersecurity and compliance leader with 20 years of experience driving growth and go-to-market strategy for federally regulated industries. He currently leads Coalfire Federal’s unified GTM strategy and previously guided AWS toward CMMC certification while helping customers advance secure, scalable compliance in the cloud.