CMMC Phase II Paused: What Defense Contractors Should Do Next

Posted July 14, 2026 by Philip Duplisey

The Department of War recently announced that it is suspending the implementation of CMMC Phase II requirements while it conducts a review of the program. The announcement has generated considerable discussion across the Defense Industrial Base (DIB), with many organizations asking a simple question: 

“Does this mean CMMC is over?” 

The short answer is no. 

While the requirement for third-party CMMC Level 2 assessments has been paused pending the review, cybersecurity obligations for defense contractors have not disappeared. Organizations that process, store, or transmit Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) must still safeguard that information and remain compliant with the contractual and regulatory requirements applicable to their contracts. 

Watch this video published by Kirsten Davies – DoW CIO.

The announcement changes the timeline, but it does not eliminate the need for sound cybersecurity practices. 

Looking Beyond Certification 

Over the past several years, much of the industry’s attention has focused on preparing for a CMMC assessment. While certification has become the visible milestone, it was never the ultimate objective. 

The real objective has always been to protect sensitive government information through well-designed security controls, documented processes, and repeatable operational practices. 

Whether an assessment occurs this year or next, organizations still need to answer fundamental questions: 

  • Do we understand where CUI resides? 
  • Have we implemented the required security controls? 
  • Are our policies current and actually followed? 
  • Can we demonstrate compliance with evidence rather than assumptions? 
  • Are we prepared to respond confidently to customer or government inquiries? 

Those questions remain just as important today as they were before the announcement. 

A Shift in Priorities 

Rather than creating less work, this pause may actually provide organizations with something many have been asking for: time to build compliance properly. 

Instead of rushing toward an assessment deadline, companies now have an opportunity to focus on creating a mature cybersecurity program that delivers lasting business value. 

In our experience, organizations are increasingly looking for practical assistance rather than simply another compliance checklist. 

They need partners who can help them implement solutions that work in the real world. 

What Business Leaders Should Be Working On 

The recent announcement presents business leaders with an opportunity to shift their focus from preparing for a certification event to strengthening the underlying cybersecurity capabilities of their organization. While assessment timelines may evolve, the need to protect sensitive government information and operate as a trusted defense contractor remains unchanged. 

Forward-thinking manufacturers should use this additional time to evaluate how cybersecurity requirements are being integrated into everyday business operations. Rather than asking how quickly they can prepare for an audit, leadership teams should be asking how to implement the security controls defined in NIST SP 800-171 in a way that supports the business without disrupting production, engineering, or customer delivery. 

This is also an ideal time to identify which security gaps represent the greatest operational and contractual risk, allowing limited resources to be directed where they will have the greatest impact. Instead of attempting to address every requirement at once, organizations can adopt a more deliberate, risk-based approach that builds a stronger and more sustainable security program. 

Documentation should also become a strategic priority. Well-organized System Security Plans, policies, procedures, asset inventories, and evidence repositories are not merely compliance artifacts—they demonstrate that cybersecurity practices are understood, repeatable, and embedded within the organization. Equally important is ensuring that policies are practical, clearly communicated, and realistic enough that employees will consistently follow them in their day-to-day work. 

Finally, organizations should use this period to establish reliable processes for collecting and maintaining evidence that demonstrates controls are operating as intended. Whether future requirements involve self-assessments or third-party certification, the ability to produce credible evidence of implementation will remain essential. 

For many organizations, the challenge is not understanding what needs to be done—it is determining how to accomplish it within the constraints of limited budgets, competing operational priorities, and leaninternal resources. These are fundamentally business decisions, requiring practical implementation strategies and thoughtful prioritization, not simply compliance checklists. 

The organizations that invest this time wisely will emerge with stronger cybersecurity programs, greater operational resilience, and a higher level of confidence—regardless of how the CMMC program evolves in the months ahead. 

Where Business Lens Adds Value 

At Business Lens, we believe the recent pause in CMMC assessments presents organizations with an opportunity to rethink what compliance should look like. For too long, many organizations have viewed compliance as a project with a finish line—preparing for an assessment, passing the assessment, and then moving on. In reality, cybersecurity doesn’t work that way. 

The organizations that consistently protect sensitive government information are those that make cybersecurity part of their everyday business operations. Compliance isn’t something they prepare for when an auditor is scheduled to arrive; it is embedded in the way they govern their systems, manage their people, document their processes, and make operational decisions. 

That is the philosophy behind every Business Lens engagement. 

Rather than focusing solely on preparing clients for a point-in-time assessment, we help organizations build an always-on compliance capability—one that enables them to continuously demonstrate that their cybersecurity program is functioning effectively. Whether the future involves self-assessments, third-party certification, customer audits, or an updated CMMC framework, organizations with mature operational processes will always be in a stronger position than those scrambling to prepare for the next compliance milestone. 

Building that capability requires far more than interpreting security controls. It requires experienced guidance to help leadership make informed decisions, prioritize investments, and develop a practical roadmap that aligns cybersecurity with business objectives and available resources. It means translating the requirements of NIST SP 800-171 into operational practices that employees can realistically follow without disrupting engineering, manufacturing, or customer delivery. 

It also requires disciplined documentation. System Security Plans, policies, asset inventories, CUI data flows, evidence repositories, and Plans of Action and Milestones are not simply documents produced to satisfy an auditor. They become the living record of how an organization protects Controlled Unclassified Information and demonstrates that its security controls are operating as intended. 

Equally important is establishing governance processes that keep compliance current as the business evolves. Systems change, employees join and leave, technologies are introduced, and threats continue to emerge. An effective cybersecurity program must evolve with them. By helping organizations establish repeatable processes for policy management, evidence collection, internal reviews, and continuous improvement, we enable compliance to become part of normal business operations rather than a periodic exercise. 

Every organization begins this journey from a different place. Some require strategic advice and executive guidance, while others need hands-on assistance implementing controls, developing documentation, organizing evidence, or preparing their internal teams. Business Lens adapts to each client’s needs, working as an extension of their organization to build capabilities that remain long after the engagement has concluded. 

The current pause in CMMC implementation should not be viewed as an opportunity to delay cybersecurity investments. It is an opportunity to build them correctly. Organizations that use this time to establishan always-on compliance capability will not only be prepared for whatever the Department decides next—they will also strengthen their resilience, improve customer confidence, and reduce operational risk. 

At Business Lens, we believe compliance is not the destination. It is the natural outcome of a well-managed cybersecurity program that operates effectively every day.