Summary
CMMC Phase II may be paused, but defense contractors should not pause their data security work. NIST SP 800-171 obligations, DFARS requirements, and the need to protect CUI remain in effect, making this review period an opportunity to strengthen visibility, access controls, and evidence-gathering before the next version of CMMC takes shape.
CMMC Phase II Is Paused
The Department of War’s July 13 announcement suspending CMMC Phase II requirements has sent a ripple through the Defense Industrial Base (DIB). Organizations that were preparing for third-party assessments by November 10, 2026, are now facing a different reality: the certification timeline is uncertain, but data security obligations remain unchanged.
At first glance, some organizations may view the suspension as a reprieve. The Department cited prohibitive compliance costs, bureaucratic burdens, and concerns that smaller and non-traditional businesses were being pushed out of the DIB. To address those concerns, officials have launched a 60-day review of the program and paused future CMMC implementation milestones while maintaining existing Phase I self-assessment requirements.
But businesses should resist the temptation to interpret this as a reason to slow down data security initiatives.
The reality is that the government has paused a certification requirement and not the need to protect sensitive defense information.
What Changed — and What Didn’t
Under the announcement, CMMC Phase II requirements, including planned third-party certification assessments, are suspended pending a comprehensive review. The Department will continue enforcing NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments. Defense contractors also remain contractually obligated to protect covered defense information under DFARS 252.204-7012.
In other words, the audit schedule may have changed, but the security expectations have not.
This distinction is critical. CMMC was never intended to create data security requirements out of thin air. Rather, it was designed to verify that contractors had implemented the safeguards needed to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). Those underlying obligations remain in force.
Organizations that treat the pause as permission to delay security improvements may find themselves scrambling once the Department completes its review and announces the next iteration of the program.
The Bigger Issue: Compliance vs. Security
The Department’s announcement highlights a debate that has existed since CMMC’s inception: Are organizations spending too much time on compliance paperwork and not enough time on meaningful security outcomes?
That question is worth asking.

Fortra has long advocated for a practical, risk-based approach to data security. Compliance frameworks are valuable because they establish standards and accountability. However, compliance alone does not stop data loss, prevent insider threats, or reduce the impact of a breach.
Organizations can pass an audit and still struggle to answer fundamental questions:
- Where is our CUI?
- Who can access it?
- How is it being shared?
- Can we prove it is protected?
- What evidence can we provide during an assessment?
Those are security questions first and compliance questions second.
The most successful organizations view CMMC as a byproduct of good security practices rather than the sole objective.
Why This Is Still a Business Decision
One of the most important lessons from recent CMMC discussions is that data security readiness is not just an IT problem. It is a business issue that affects revenue, contracts, supply chain relationships, and future growth opportunities.
As Skip Chapman, CISSP, C|CISO, Director of Government Programs at Fortra, has emphasized in previous guidance, organizations handling FCI or CUI still face significant business risks if they fail to meet government security requirements.
Even with CMMC Phase II on hold, defense contractors should continue asking:
- Which contracts require protection of CUI?
- What security requirements already exist in our agreements?
- What are our prime contractors expecting from us?
- How quickly could we demonstrate compliance if requirements are reinstated in a revised form?
The answers to these questions influence business eligibility regardless of how the certification framework ultimately evolves.
The Data-First Opportunity
For organizations wondering what to do during the review period, the answer is surprisingly simple: focus on the data.
One of the biggest challenges in CMMC readiness has always been scoping. Companies often struggle because they do not fully understand where CUI exists, how it moves throughout the organization, or which systems must be protected.
A data-first approach helps organizations establish a stronger foundation by:
- Discovering sensitive information across the environment
- Classifying and labeling CUI consistently
- Limiting unnecessary CUI sprawl
- Controlling access and sharing
- Generating evidence needed for future assessments
These activities deliver value whether a company faces a formal CMMC assessment next year, three years from now, or under an entirely redesigned framework.
More importantly, they reduce actual risk today.
CMMC Phase II Suspension: What Defense Contractors Should Do Next
The Department’s 60-day review may result in significant changes to CMMC. We could see streamlined assessments, expanded use of self-attestations, new approaches for small businesses, or entirely different verification mechanisms. At this point, the future framework remains unclear.
What is clear is that data security is not going away.
Threat actors are not pausing their efforts because certification timelines have changed. Sensitive defense information remains a target. Supply chain security remains a national security concern. And contractors remain responsible for protecting the data entrusted to them.
For defense contractors, the smartest response to the CMMC Phase II suspension is not to stop preparing. It is to shift focus from audit deadlines to operational resilience.
The companies that emerge strongest from this transition will be those that use the pause as an opportunity to improve visibility into their data, strengthen controls around CUI, and build sustainable security programs. Whether the next version of CMMC arrives in months or years, those organizations will be ready—not because they chased a compliance checkbox, but because they invested in protecting what matters most.
This blog was originally published on Fortra’s blogsite, view the post here.
Carahsoft Technology Corp. is The Trusted Government IT Solutions Provider, supporting Public Sector organizations across Federal, State and Local Government agencies and Education and Healthcare markets. As the Master Government Aggregator for our vendor partners, including Fortra, we deliver solutions for Geospatial, Cybersecurity, MultiCloud, DevSecOps, Artificial Intelligence, Customer Experience and Engagement, Open Source and more. Working with resellers, systems integrators and consultants, our sales and marketing teams provide industry leading IT products, services and training through hundreds of contract vehicles. Explore the Carahsoft Blog to learn more about the latest trends in Government technology markets and solutions, as well as Carahsoft’s ecosystem of partner thought-leaders.