The Department of Defense’s decision to pause CMMC Phase 2 implementation created immediate uncertainty across the Defense Industrial Base (DIB). Many contractors began asking the same questions:
- Is CMMC still moving forward?
- Should we pause our compliance efforts?
- Do NIST SP 800-171 requirements still apply?
- What should we do while the Department conducts its review?
The answer to the biggest question is clear: the implementation timeline has changed, but the responsibility to protect Controlled Unclassified Information (CUI) has not.
During a recent CyberSheath webinar, CEO Emil Sayegh, SVP of Compliance Casey Lang, and VP of Service Delivery Scott Whitehouse broke down what the CMMC Phase 2 pause means, what requirements remain in effect, and how defense contractors should approach the next 60 days.
What Actually Changed?
The Department of Defense paused Phase 2 of the CMMC rollout while a 60-day review is conducted. This pause affects the timeline for introducing mandatory third-party CMMC Level 2 certifications as a requirement for certain contract awards.
- It does not eliminate CMMC.
- It does not remove cybersecurity obligations.
- It does not eliminate the need to protect CUI.
As Casey explained, the pause is focused on how certification requirements are implemented—not whether contractors are required to maintain cybersecurity protections. The distinction is important: CMMC certification and cybersecurity compliance are related, but they are not the same thing.
What Did Not Change?
While the Department reviews implementation timelines, the underlying cybersecurity requirements remain in place. For organizations handling CUI:
- NIST SP 800-171 requirements still apply for organizations whose contracts include DFARS 252.204-7012 and who handle CUI.
- Applicable DFARS cybersecurity clauses in your contracts remain in effect.
- If required by your contract, Supplier Performance Risk System (SPRS) score posting and maintenance remains in effect.
- Contractors remain responsible for accurately representing their cybersecurity posture including ensuring any representations to the government or prime contractors are accurate and supportable.
- The pause does not change a contractor’s obligation to implement the necessary safeguards to protect sensitive information.
As Casey noted, “NIST 800-171 still exists. It is the requirements for protecting Controlled Unclassified Information.”
Contractors should not treat the pause as a reason to slow down. They should continue implementing and operating required controls, maintaining accurate documentation and evidence, and closing gaps to protect CUI and remain aligned with contractual requirements.
Should Contractors Stop Preparing for CMMC?
No. The recommendation from CyberSheath is to continue moving forward.
The reason is simple: implementing cybersecurity controls takes significantly more time than completing an assessment. Organizations must identify gaps, deploy technologies, establish processes, document practices, and build evidence before they are ready for verification.
Waiting could create unnecessary risk.
Organizations that continue strengthening their cybersecurity posture will be better positioned regardless of how the Department adjusts the timeline. As Scott summarized during the webinar: “Stay the course.”
Separating Fact from Speculation
The CMMC Phase 2 pause generated significant discussion and speculation throughout the industry. However, several common assumptions do not align with the facts.
Myth: CMMC is dead
Reality: The CMMC program has not been canceled.
The Department is reviewing implementation details, specifically around certification timing. Existing cybersecurity requirements and contractual obligations remain. CMMC has evolved over multiple years and across multiple administrations. While changes to implementation may occur, the need to protect CUI remains.
Myth: Contractors can pause cybersecurity efforts
Reality: Cybersecurity obligations remain.
Organizations handling CUI still need to implement the required protections outlined in NIST SP 800-171. The longest part of the process is typically not the assessment—it is preparing the environment, implementing controls, and creating sustainable processes.
Myth: NIST SP 800-171 will be replaced
Reality: No replacement framework has been announced as of today.
The Department’s review may result in changes to implementation, but there has been no indication that NIST SP 800-171 is being eliminated. Core cybersecurity practices—such as access control, vulnerability management, endpoint protection, and monitoring—remain foundational regardless of future policy changes.
Myth: Prime contractors will stop caring about cybersecurity
Reality: Supply chain expectations continue.
Prime contractors remain responsible for managing supplier risk. Many continue to evaluate cybersecurity maturity throughout their supply chains. Even if mandatory certification timing changes, demonstrating strong cybersecurity practices can remain a competitive advantage.
Why Cybersecurity Efforts Still Matter
The purpose of CMMC has always been larger than compliance. Protecting CUI helps protect the defense supply chain, safeguard sensitive information, and support the broader national defense mission.
A strong cybersecurity program helps organizations:
- Reduce risk.
- Protect sensitive data.
- Respond confidently to customer requirements.
- Prepare for future assessments.
- Strengthen relationships with prime contractors.
Third-party certification can also continue to provide value by independently validating that security controls have been implemented. As Casey explained, certification provides confidence that an organization has actually implemented the required protections—not simply documented an intention to do so.
What Contractors Should Do During the 60-Day Review
Rather than making decisions based on speculation, contractors should focus on actions they can control.
CyberSheath recommends organizations:
- Continue implementing and maintaining all applicable NIST SP 800-171 security controls.
- Address outstanding remediation items.
- Maintain accurate and up-to-date SPRS scores and reporting, where contractually required.
- Improve documentation and evidence collection to demonstrate consistent implementation of security controls.
- Continue preparing for future assessments.
- Monitor official DOD announcements.
The organizations best positioned for future requirements will be those that continue building mature cybersecurity programs today.
Cybersecurity Is More Than Passing an Assessment
One of the biggest lessons from the CMMC discussion is that compliance should not be treated as a one-time event. A sustainable cybersecurity program requires ongoing ownership, documentation, monitoring, and improvement.
As Emil explained, “We don’t want to help you pass an assessment once. We want to help you build a cybersecurity program and posture that protects your business every day.”
The goal is not simply achieving a certification milestone. The goal is creating security practices that reduce risk and protect critical information over time.
Final Takeaway: Stay the Course
The CMMC Phase 2 pause created uncertainty—but it did not change the mission. The Department may adjust timelines, processes, or implementation details. However, organizations handling CUI are still responsible for protecting that information.
The contractors that continue improving their cybersecurity posture today will be better prepared for whatever comes next. The timeline may have changed. The mission has not.
Want a deeper look at what the CMMC Phase 2 pause means for your organization?
Watch the full webinar, “The CMMC Pause: What Defense Contractors Need to Know,” featuring CyberSheath CEO Emil Sayegh, SVP of Compliance Casey Lang, and VP of Service Delivery Scott Whitehouse as they break down what changed, what remains in effect, and the steps contractors should take now to stay prepared.

