The Pentagon’s pause of CMMC Phase 2 rocked the defense industrial base (DIB). Some contractors interpreted “pause” as permission to stop. At CMMC CON 2026, speakers from across the DIB, the Pentagon, and the legal community made clear that interpretation is wrong and potentially dangerous.
The State of the DIB: Progress with a Confidence Gap
CyberSheath CEO Emil Sayegh opened the conference by presenting findings from the 2026 State of the DIB report, featuring a Merrill Research survey of 302 U.S. defense contractors. There is some progress: 83% of contractors now have a documented system security plan, and 76% have documented plans of action and milestones, both the highest levels our annual report has measured to date. Five core security technologies, including multi-factor authentication (63%) and secure IT backups (48%), reached at least 40% adoption for the first time.
But confidence in self-reported Supplier Performance Risk System (SPRS) scores dropped from 94% in 2024 to 65% this year, and only 1% of contractors said they were fully prepared for certification. Companies are doing more, and they’re realizing how much more there is to do.
The Pentagon: A CMMC Pause is Not a Compliance Pause
James Mismash, the Pentagon’s Deputy Assistant Secretary for Industrial Base Growth, delivered the keynote and addressed the suspension. Phase 1 self-assessments remain required. DFARS 252.204-7012 obligations remain in force. And the False Claims Act still applies to inaccurate SPRS submissions.
“Suspending one part of the implementation model is not the same as relaxing the cybersecurity mission,” Mismash said.
He described the review as an effort to reduce unnecessary friction and build a framework that works for smaller firms without weakening security standards. He also outlined broader initiatives, including the Smaller War Plants Commission and the Secure Space Network, a program to deploy approximately 50 mobile sensitive compartmented information facilities to give more companies access to classified work.
CMMC Enforcement and the Risk of Getting Compliance Wrong
Michael Gruden, a partner at Steptoe who leads the firm’s cybersecurity and incident response practice, reinforced the enforcement angle in his cybersecurity masterclass. He walked contractors through the full regulatory timeline and the legally binding nature of CMMC affirmation requirements.
“Even well-intended companies are misinterpreting controls,” Gruden said, “or their documentation is missing some of the specificity, where it could be interpreted that it’s misrepresented to a regulator.”
What Defense Contractors Should Prioritize Now
Other sessions addressed what contractors need to do now from multiple angles. Fernando Machado of Cybersec Investments walked through the assessment process and the documentation assessors expect. Kevin Thomas, Microsoft’s Chief Security Advisor for the U.S. Defense Industrial Base and Federal, covered how AI is changing the threat environment for defense contractors. CyberSheath CFO Rick Moore and VP of Solutions Engineering Michael Bailie examined the real costs of NIST SP 800-171 and DFARS compliance using data from the State of the DIB report.
Prime Contractors Aren’t Waiting on CMMC
Supply chain readiness came up in nearly every session. Sayegh emphasized that primes are already imposing their own CMMC requirements on subcontractors regardless of what the government mandates. A dedicated panel featuring Doug Cherry of Monterey Technologies and Megan Downie of Spirit Electronics covered what cybersecurity requirements have become non-negotiable for primes and the most common compliance gaps among small and mid-sized suppliers.
What Comes Next After CMMC CON 2026
The message across two days of CMMC CON 2026 was consistent: A pause in one phase of CMMC implementation does not mean contractors can pause their cybersecurity and compliance efforts. Existing requirements remain, enforcement risk remains, and primes are continuing to raise expectations across their supply chains.
Thank you to everyone who joined us for CMMC CON 2026 and to our sponsors, A-LIGN, Keeper Security and AvePoint for helping make this year’s event possible.
Missed a session or want to watch one again? We’ll be releasing CMMC CON 2026 sessions on the CyberSheath YouTube channel. Subscribe to be notified as new sessions are released.
