The Pentagon Just Hit Pause on CMMC Phase II. That's Not the Good News You Think It Is.
On July 13, the Department of War suspended CMMC Phase II — the third-party cybersecurity assessment requirement that was supposed to kick in for defense contractors on November 10. The Small Business Administration applauded the move. Trade groups exhaled. And somewhere in a conference room, a defense subcontractor's CFO is already asking whether they can shelve that $400,000 compliance project.
That CFO is about to make an expensive mistake.
What Actually Got Suspended
Let me be specific about what changed and what didn't, because the headlines are doing real damage here.
What's paused: the requirement for Certified Third-Party Assessment Organizations (C3PAOs) to independently verify a contractor's cybersecurity posture before they can bid on contracts handling Controlled Unclassified Information. The DoW is launching a 60-day Reform Task Force to figure out whether the program can work without crushing the small businesses it's supposed to protect.
What's not paused: everything else. DFARS clause 252.204-7012 remains fully in effect. That means every defense contractor and subcontractor handling covered defense information is still contractually obligated to implement all 110 security controls from NIST SP 800-171. Phase I self-assessments and attestations — where you certify under penalty of the False Claims Act that your security controls are in place — remain mandatory.
Read that last part again. You are still attesting, under penalty of law, that your controls are in place. The only thing that changed is nobody's coming to check your homework for a while.
The Compliance Trap
In Cyber Risk Is Business Risk, I write about the gap between compliance and security — how organizations chase the checkbox and mistake the certificate for the capability. The CMMC suspension is about to create a textbook example.
The SBA's own analysis pegged compliance costs at approximately $593,800 per certification for small firms requiring third-party assessments, and about $388,600 for those eligible for self-assessment. Across the defense industrial base, future CMMC phases could have cost small and mid-sized businesses more than $7 billion annually. Those numbers are real, and they were pushing innovative firms out of defense work entirely.
But here's where the trap closes: the threat environment doesn't care about your compliance timeline. In the same month the DoW announced the suspension, the Anubis ransomware group hit Coca-Cola's Fairlife subsidiary hard enough to halt U.S. production — disclosed in a Form 8-K SEC filing on July 16. Abbott Laboratories confirmed it was investigating unauthorized access after ShinyHunters gained entry through a voice phishing campaign targeting employees. AssuranceAmerica disclosed that a single compromised employee account led to the exposure of 6.9 million individuals' records.
Adversaries are not waiting for the Reform Task Force to file its report.
Three Questions for the Board
If you're on the board of a company in the defense supply chain — or frankly, any organization that was using CMMC as its cybersecurity North Star — this is the moment to apply what I call the Three Questions framework:
1. What are we actually protecting, and does our leadership understand the risk?
CMMC was always a proxy for something more fundamental: can you protect sensitive information from sophisticated adversaries? If your security program was built around passing an audit rather than defending systems, the suspension just removed the audit without changing the threat. Ask your CISO: "If we stripped away every compliance requirement tomorrow, what would we still do because it's the right thing to protect the business?"
2. Are we spending the right money in the right places?
The compliance cost numbers are eye-watering, but they mask a deeper budget question. Many contractors were spending on assessment preparation — documentation, gap analysis, remediation of audit findings — rather than on the security controls themselves. If the assessment is paused, redirect that assessment-prep budget toward the actual controls. Implement the NIST 800-171 requirements because they make you harder to breach, not because someone's checking.
3. What happens when the music starts again?
The Reform Task Force reports to the DoW CIO within 60 days of the July 13 announcement — putting the deadline around mid-September 2026. Whatever replaces Phase II will still require demonstrated cybersecurity maturity — the government isn't going to stop caring about protecting defense information. Companies that used the suspension as a vacation will face a scramble when the new requirements land. Companies that kept investing will be positioned to comply on day one.
The Capacity Problem Nobody's Talking About
There's another dimension to this that boards should understand. Before the suspension, roughly 100 authorized C3PAOs existed to assess an estimated 80,000 to 120,000 defense contractors needing Level 2 certification. That math never worked. Even if Phase II had launched on schedule, the bottleneck would have created a years-long queue that rewarded early movers and punished procrastinators.
The Reform Task Force may change the assessment model, but it won't change the fundamental reality: demonstrating cybersecurity maturity takes time, money, and organizational commitment. You can't cram for it the night before the test.
What to Ask Your CISO This Week
If you're a board member or executive at a company affected by CMMC, here's what I'd put on next week's agenda:
- Are we still implementing NIST 800-171 controls on the original timeline? The suspension doesn't change the contractual obligation. Slowing down creates legal exposure under the False Claims Act.
- What's our Plan of Action and Milestones (POA&M) status? If there are known gaps in your security controls, are they being closed? The fact that nobody's auditing doesn't mean nobody's attacking.
- Are our prime contractors still flowing down CMMC requirements? Primes can — and many will — continue requiring Level 2 compliance from their subcontractors regardless of the DoW suspension. Check your contracts.
- What's our exposure if a breach happens during the suspension? If you attested to controls you haven't implemented and then suffer a breach, the legal consequences just got worse, not better. The suspension removed the safety net of a third-party assessment catching your gaps before an adversary does.
The Bottom Line
The CMMC Phase II suspension is a regulatory pause, not a security holiday. The threats haven't paused. The contractual obligations haven't paused. And the False Claims Act liability for attesting to controls you haven't implemented definitely hasn't paused.
In my experience, the organizations that get burned worst by regulatory shifts are the ones that confuse the absence of enforcement with the absence of risk. Don't be that organization. Use this window to get your house in order — not because an auditor is coming, but because an adversary already has.