CMMC Update: The Rollout has Paused – Your Compliance Obligations Have Not

By: Laura Fawcett, CGEIT, CISM, LCCA Director of Cybersecurity Assessments

July 14, 2026

The Pentagon is putting Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements on pause, immediately suspending third-party assessment mandates that were scheduled to begin on Nov. 10. Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements > U.S. Department of War > Release | U.S. Department of War

While the rollout timeline has shifted, the underlying cybersecurity requirements for contractors have not.

What Has Changed

The most significant change is that the Department of War has paused the planned transition to Phase 2 of the CMMC program. As a result, the November 10 date that would have required independent C3PAO assessments as a condition of award in more contracts is on hold while the program undergoes a 60-day review period.

This pause affects when third-party certification requirements may appear in contracts, but it does not eliminate the CMMC program or its cybersecurity expectations.

What Has Not Changed

Organizations handling Controlled Unclassified Information (CUI) are still expected to fully comply with NIST SP 800-171 requirements.

Current expectations remain in place, including:

  • Contractors must continue meeting NIST SP 800-171 requirements and attest to that compliance per the CMMC Level 2 Scoping and Assessment Guidance through the existing self-assessment (Phase 1) process.
  • Organizations submitting a self-assessment must achieve a score of 88 or higher, with Plans of Action and Milestones (POAMs) permitted only for the limited subset of requirements allowed by the CMMC program.
  • The Department of War continues to expect contractors to implement the full cybersecurity requirements—not simply say they are in place.
  • Government-led cybersecurity assessments continue to occur and have increased over the past six months. Many of these reviews are driven by enforcement efforts and heightened scrutiny following False Claims Act cases involving contractor cybersecurity representations.

Bottom Line

The timing of mandatory third-party C3PAO assessments may have shifted, but the cybersecurity obligations for defense contractors have not. Organizations should continue implementing and maintaining compliance with NIST SP 800-171, accurately reporting their scores, and preparing for eventual CMMC certification once the revised implementation schedule is announced. C3PAOs are still authorized to perform certification assessments, which demonstrate to the government, prime contractors, and partners that you have implemented NIST 800-171 and can demonstrate your compliance.

Guernsey Recommendation

The prudent course of action remains the same: continue building and maintaining compliance rather than waiting for the next rollout milestone.