Five Takeaways from This Week’s CyberAB Town Hall
Over the past few weeks, much of the conversation surrounding CMMC has been driven by headlines following the Department of War’s decision to suspend Phase II implementation while the program is reviewed. Predictably, social media has been filled with speculation ranging from “CMMC is dead” to “everything has changed.”
This week’s CyberAB Town Hall painted a much more measured picture.
Rather than suggesting cybersecurity requirements are being abandoned, the discussion reinforced something many of us working with defense contractors have believed for some time: while the mechanics of CMMC may evolve, the expectation that organizations protect sensitive government information has not changed.
Several themes emerged that are worth sharing.
The Reform Review is about more than CMMC Mechanics.
One of the more interesting observations was that the current review extends well beyond CMMC itself. The Pentagon appears to be examining how cybersecurity requirements fit into a broader effort to improve agility across the Defense Industrial Base while reducing unnecessary cost and administrative burden, particularly for small and medium-sized businesses. That is an important distinction. The discussion is not simply about changing an assessment model; it is about finding a better balance between strong cybersecurity, operational resilience, and the realities of running a business.
Fraudulent Level 2 Claims are a Concern.
Another topic that generated considerable discussion was the growing concern around fraudulent Level 2 certifications. As third-party verification requirements are temporarily paused, the potential for organizations to make unsupported claims about their compliance naturally increases. Fortunately, there is already a practical way for prime contractors to verify a supplier’s status. Rather than relying on marketing material or verbal assurances, they can request a PDF export of the supplier’s SPRS record. It is a straightforward step that provides an additional level of confidence during supplier due diligence, expect them to start doing this.
The obligation didn’t change.
Perhaps the most important clarification from the Town Hall was that the underlying contractual obligations have not changed. DFARS 252.204-7012 remains in effect, and organizations handling Controlled Unclassified Information are still expected to implement the safeguards required by NIST SP 800-171. What has been suspended is the requirement for third-party verification—not the responsibility to protect sensitive information. That distinction is easy to lose in the current news cycle, but it is fundamental to understanding where defense contractors stand today.
There is no such thing as “CMMC implementation.”
There was also a point made that strongly resonated with us at Business Lens. We often hear organizations talk about “implementing CMMC,” but that phrase misses the mark. CMMC is not something that is implemented. Organizations implement NIST SP 800-171. CMMC is simply one method of verifying that those security requirements have been implemented effectively. Security is the operational discipline; certification is only a point-in-time assessment of that discipline.
This distinction has always influenced the way we work with our clients. Our objective has never been to help organizations prepare for a single assessment. We help them establish what we describe as an always-on compliance capability—one where security controls, documentation, policies, evidence collection, and governance become part of normal business operations. Whether an assessment occurs this year, next year, or under a revised framework, organizations with mature operational processes will always be better prepared than those treating compliance as a project with a deadline.
Stop absorbing CUI-marking ambiguity.
The Town Hall also addressed a topic that has frustrated many subcontractors for years: inconsistent or unclear CUI markings. The guidance was refreshingly practical. Organizations should not automatically assume responsibility for interpreting ambiguous markings. When there is uncertainty, the appropriate course of action is to seek clarification from the contracting authority or information owner. Resolving classification questions upstream helps reduce unnecessary compliance effort while ensuring that organizations apply the appropriate level of protection to the information they receive.
Taken together, these discussions reinforce a broader message. The current review should not be interpreted as a signal to pause cybersecurity initiatives. If anything, it offers organizations the opportunity to strengthen their programs without the pressure of an immediate certification deadline. Businesses that continue investing in sound governance, practical implementation, accurate documentation, and ongoing operational discipline will be well positioned regardless of how the CMMC program ultimately evolves.
At Business Lens, we believe the future of compliance is not defined by a single assessment. It is defined by an organization’s ability to demonstrate, every day, that its cybersecurity program is operating effectively. Compliance should not be something you prepare for—it should be the natural outcome of a cybersecurity program that is always on.
Continue Reading
July 14, 2026
CMMC Phase II Paused: What Defense Contractors Should Do Next
June 23, 2026
