The CMMC Phase II Pause Is Not a Cybersecurity Pause
EDITOR'S NOTE: This full report provides critical details of which all companies currently or anticipating future engagements with the Department of War or its prime contractors need to be aware.
by Justin Kreinbrink, VP of Assessments & Lead CCA @ DTC, LLC | SecureNM™ Founding Sponsor - Outreach & Education | August 2026
The contractual rollout has changed. Applicable cybersecurity obligations have not disappeared.
On July 13, 2026, the U.S. Department of War suspended the planned transition to Phase II of the Cybersecurity Maturity Model Certification program and established a CMMC Reform Task Force to conduct a 60-day review of the broader program. The announcement paused the expansion of Level 2 third-party certification requirements through DoW solicitations and contracts. It did not shut down CMMC, invalidate existing certificates, or eliminate the underlying responsibility to protect government information.
That distinction matters for New Mexico businesses supporting the Defense Industrial Base, whether they contract directly with DoW or work through prime contractors and other supply-chain partners.
What the Pause Changes
During the suspension, DoW is reconsidering the future structure, scope, and implementation of CMMC. The review could change which organizations require third-party certification, when certification must be obtained, or how compliance is validated.
The outcome is not yet known. DoW could revise or narrow the current third-party model, adopt a different assurance approach, or retain significant portions of the existing structure after delaying implementation.
What has changed immediately is the planned contractual rollout of Phase II. The CMMC program itself still exists.
The Cyber AB has publicly stated that only Phase II implementation requirements were suspended and that the broader CMMC ecosystem remains operational. Authorized C3PAOs continue to offer Level 2 certification assessments. At its July public town hall, the Cyber AB also stated that existing certificates remain valid and that, as of this writing, CMMC eMASS continues to process completed assessment results for reporting into SPRS.
Organizations may therefore continue pursuing certification based on anticipated contracting needs, prime-contractor expectations, supply-chain risk, or a desire for independent assurance beyond a self-assessment.
What has Not Changed
DoW has expressly stated that all Phase I self-assessment requirements remain in place. It has also said that, during the review, it will continue enforcing NIST SP 800-171 Revision 2 through contractor self-assessments and selected Government-led assessments.
DFARS 252.204-7012 also remains in effect where it is included in a contract. Contractors subject to that clause must continue providing adequate security for covered contractor information systems and implementing the applicable NIST SP 800-171 requirements.
Current DFARS policy also requires contractors subject to DFARS 252.204-7012 to have a current NIST SP 800-171 DoD Assessment for each covered contractor information system relevant to an award. Those assessment results must be available in the Supplier Performance Risk System.
In practical terms, the pause should not be interpreted as permission to stop implementing security requirements, disregard known deficiencies, or rely on an assessment score that cannot be supported by the organization’s actual environment.
DoW officials emphasized this point when announcing the suspension. Although the Department is reviewing the compliance model, it continues to describe cybersecurity as a critical priority and expects companies doing business with DoW to safeguard government information in accordance with applicable requirements.
Existing Certifications Still Carry Obligations
Organizations that have already achieved a CMMC Level 2 certification must continue maintaining the implementation represented by that status.
Under 32 CFR § 170.22, an Affirming Official must affirm continuing compliance after the assessment and annually following the Final CMMC Status date. The affirmation must attest that the organization has implemented and will maintain all applicable requirements for the systems within the relevant assessment scope. These affirmations are submitted through SPRS.
A Final Level 2 C3PAO status generally remains current for three years, provided there has been no change in compliance and the organization maintains a current annual affirmation.
Certification is therefore not a one-time event that allows an organization to stop monitoring its environment. It represents an assessed status that must be maintained.
Why Independent Assessment Still Matters
The current debate often treats compliance and cybersecurity as though they are competing objectives. A properly conducted CMMC assessment should not be a paperwork-counting exercise.
Under 32 CFR Part 170, an assessment evaluates whether security requirements are implemented correctly, operating as intended, and producing the required outcome. Policies, system plans, configurations, interviews, demonstrations, and technical records are evidence used to reach that determination; the documents themselves are not the ultimate objective.
A self-assessment can help an organization understand its posture, but an independent assessment provides a different level of assurance. It tests whether the organization’s interpretation, evidence, scope, and represented score can withstand external review.
That assurance may remain valuable even when a particular DoW solicitation does not presently require certification. Prime contractors may continue establishing supplier-security expectations based on program sensitivity, customer commitments, or supply-chain risk. A current certification can provide independently developed evidence supporting the cybersecurity posture an organization represents to its customers and the government. That can be particularly relevant where contractual eligibility, assessment scores, annual affirmations, or payment claims depend on the accuracy of those representations.
Certification does not guarantee that an organization will avoid a DIBCAC assessment, government inquiry, whistleblower allegation, or enforcement action. It does, however, provide an independently assessed record of the organization’s implementation at a defined point in time.
Cybersecurity Representations can Carry False Claims Act Risk
The Phase II pause does not remove the risk associated with knowingly inaccurate cybersecurity representations.
The U.S. Department of Justice’s Civil Cyber-Fraud Initiative uses the False Claims Act to pursue government contractors and grant recipients that knowingly misrepresent their cybersecurity practices, knowingly fail to comply with applicable cybersecurity requirements, or knowingly fail to satisfy required incident-reporting obligations. The False Claims Act also allows private whistleblowers to bring actions on behalf of the government.
DOJ has continued bringing cybersecurity-related False Claims Act cases involving alleged failures to implement required controls, unsupported representations of compliance, and noncompliance with contractual cybersecurity requirements. Recent matters have involved defense contractors and requirements associated with NIST SP 800-171, DFARS, cloud-service protections, and other federal cybersecurity obligations.
A certification does not provide immunity from a DIBCAC assessment, whistleblower complaint, DOJ investigation, or False Claims Act action. It can, however, provide independent evidence that an organization’s implementation was evaluated against defined requirements at a particular point in time. That evidence may help an organization support the reasonableness and accuracy of the cybersecurity posture it represented, provided the organization continues maintaining the certified environment and discloses material changes appropriately.
The practical lesson is not that every deficiency creates False Claims Act liability. The relevant concern is knowingly making or supporting a material false representation, knowingly disregarding contractual cybersecurity obligations, or failing to report when reporting is required. Organizations should therefore ensure that assessment scores, affirmations, proposals, invoices, and other statements made to the government or prime contractors are accurate and supported by the actual operating environment.
Why This Matters in New Mexico
New Mexico’s economy includes national laboratories, military installations, aerospace and space companies, manufacturers, engineering firms, research institutions, and small businesses supporting federal missions through multiple tiers of the supply chain.
A company does not need to hold a prime DoW contract to encounter cybersecurity requirements. Applicable DFARS obligations may flow to subcontractors that process, store, or transmit covered defense information. Prime contractors may also establish additional supplier-assurance requirements based on their own contractual responsibilities and risk-management decisions.
The uncertainty surrounding the Phase II rollout may make these supply-chain decisions more important, not less. Where the government, a prime contractor, or a supplier cannot confidently determine whether CUI will enter a system or contract, organizations may take a more conservative approach to scope and assurance.
That does not mean every company automatically needs a CMMC Level 2 certification. It means each organization should make that decision based on its actual information flows, contracts, customers, systems, and anticipated business opportunities.
Questions Business Leaders Should be Asking
The review period gives organizations time to confirm several foundational points:
- Which current contracts and subcontracts contain FAR, DFARS, or CMMC clauses?
- What FCI or CUI does the organization receive, create, process, store, or transmit?
- Which systems, facilities, personnel, and external service providers support that information?
- Is the system security plan current and consistent with the actual operating environment?
- Is the organization’s SPRS score accurate, current, and supported by objective evidence?
- Which requirements remain unimplemented, and are they documented in an appropriate plan of action?
- Have prime-contractor and customer expectations been confirmed?
- Has the organization evaluated whether independent certification supports its future contracting strategy?
- Has the organization considered submitting comments to DoW's public Request for Information on CMMC reform, due August 14, 2026?
These are useful questions regardless of what the CMMC Reform Task Force ultimately recommends.
Use the Review Period Deliberately
The Phase II pause creates ambiguity. It does not provide certainty that third-party assessments will disappear, that the requirements will become easier, or that organizations preparing today are wasting their effort.
The review could reduce the number of organizations required to obtain certification. It could also reaffirm the current model, establish a more targeted third-party approach, or introduce additional expectations related to operational resilience, manufacturing, and other risks that NIST SP 800-171 was not originally designed to address.
Until DoW completes that process, organizations should avoid making long-term cybersecurity decisions based solely on headlines or public speculation.
For New Mexico’s defense suppliers, the prudent course is to understand current contractual obligations, maintain an accurate and supportable security posture, communicate with prime contractors and customers, and make assessment decisions based on actual business and program needs.
The path to certification may change. The responsibility to protect sensitive government information remains.
Sources
