KEY TAKEAWAYS
- The Department of War has paused the planned rollout of CMMC Phase II, delaying mandatory third-party cybersecurity assessments while it conducts a 60-day review of the program.
- The pause does not eliminate existing cybersecurity obligations. Organizations that work with the Department of War or are part of the Defense Industrial Base (DIB) must still meet applicable contractual security requirements.
- Businesses should use this additional time to strengthen their cybersecurity practices, improve documentation, and address any security gaps rather than delaying their efforts.
If your business works with the Department of War, supports the defense supply chain, or plans to pursue federal contracts, you’ve likely seen headlines about the recent pause to the Cybersecurity Maturity Model Certification (CMMC) program.
For many organizations, the announcement has raised an obvious question: What does this mean for my business?
On July 13, 2026, the Department of War announced it is suspending the planned implementation of CMMC Phase II, which had been scheduled to take effect on November 10, 2026. The Department is conducting a comprehensive 60-day review aimed at reducing unnecessary costs and administrative burden while maintaining strong cybersecurity across the Defense Industrial Base. Phase I self-assessment requirements remain in place.
While this is a significant update, it should not be interpreted as a pause on cybersecurity. Organizations that work with the Department of War may still have contractual cybersecurity obligations and should continue strengthening their security programs while the Department reviews Phase II.
In this blog, we’ll explain what changed with the CMMC Phase II rollout, what hasn’t changed for organizations that work with the Department of War, and the steps your business should consider taking next.
What Is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is the Department of War’s cybersecurity framework for organizations that do business with the federal government, particularly those that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
Rather than relying solely on organizations to attest that they meet cybersecurity requirements, CMMC was designed to verify that contractors have implemented appropriate safeguards to protect sensitive government information.
Depending on the type of work being performed, organizations may be required to:
- Complete annual self-assessments.
- Undergo independent third-party assessments.
- Demonstrate compliance with security controls based on NIST SP 800-171.
The overall goal is straightforward: reduce cyber risk across the defense supply chain by ensuring contractors maintain an appropriate level of cybersecurity.
What Changed?
The recent announcement specifically affects Phase II of the CMMC rollout.
Phase II would have required many contractors handling Controlled Unclassified Information (CUI) to complete third-party assessments conducted by authorized CMMC Third-Party Assessment Organizations (C3PAOs) before becoming eligible for certain contract awards.
The planned implementation of those Phase II requirements has now been paused while the Department reviews the program.
According to the Department, the review is intended to:
- Lower barriers for small and medium-sized businesses.
- Reduce unnecessary administrative burden.
- Improve the scalability of the program.
- Maintain strong cybersecurity while modernizing how compliance is demonstrated.
For organizations already working toward CMMC readiness, the pause provides additional time to strengthen security controls, improve documentation, and address any remaining gaps while the Department completes its review.
However, the announcement should not be interpreted as the end of CMMC or as a signal that cybersecurity requirements are going away.
What Didn’t Change?
The pause applies to the implementation of Phase II, not to the underlying cybersecurity expectations for organizations that work with the Department of War.
Depending on their contracts, organizations may still be required to:
- Protect Controlled Unclassified Information (CUI).
- Meet applicable DFARS cybersecurity requirements.
- Complete required self-assessments where applicable.
- Maintain security controls that protect government information.
The pause does not eliminate existing contractual or security obligations. Organizations that work with the Department of War should continue following applicable requirements while monitoring for future guidance on CMMC.
Who Does This Affect?
The CMMC Phase II pause primarily affects organizations that work with the Department of War or are part of the Defense Industrial Base. That includes many small and medium-sized businesses, not just large defense contractors.
Examples include organizations that provide:
- Manufacturing services
- Engineering and design
- Technology and software
- Logistics
- Professional services
- Specialized components or equipment
If your business supplies products or services to companies that do business with the Department of War, there’s a good chance cybersecurity expectations are already part of your customer requirements or may become part of future contracts.
Even organizations that don’t currently work directly with the federal government may encounter similar cybersecurity expectations from customers seeking greater confidence in their supply chain.
Why the Pause Happened
The review is focused on improving how organizations demonstrate cybersecurity compliance.
According to the Department, the existing rollout created challenges for many small and medium-sized businesses. Officials also cited concerns about the limited availability of authorized third-party assessors, which could make implementation difficult as the program expanded.
The goal is to develop a more practical and scalable approach that protects sensitive information without creating unnecessary barriers for organizations seeking to do business with the government.
Why Strong Cybersecurity Still Matters
Although the certification timeline has been put on hold for now, the reason CMMC exists has not.
Organizations throughout the Defense Industrial Base continue to face cyber threats targeting sensitive government information, intellectual property, and critical business systems. The purpose of CMMC has always been to strengthen the security of the defense supply chain by helping ensure contractors have appropriate safeguards in place to protect that information.
Whether your organization ultimately completes a third-party assessment or a different compliance process is introduced, strong cybersecurity remains an important part of doing business with the federal government.
Many of the practices encouraged by CMMC, including multi-factor authentication, secure backups, access controls, employee security awareness training, and documented security policies, are widely recognized best practices that help reduce risk for organizations of every size
Five Steps Your Business Should Take Now
Whether your organization is already preparing for CMMC or simply looking to strengthen its cybersecurity program, these practical steps can help position your business for whatever comes next.
- Determine Whether CMMC Applies to Your Organization
Review your current contracts and customer requirements.
If you work with the Department of War, handle Controlled Unclassified Information, or support organizations that do, understanding your obligations should be your first step.
- Continue Building Your Cybersecurity Program
Many of the security controls associated with CMMC represent widely accepted cybersecurity best practices.
Areas such as multi-factor authentication, endpoint protection, vulnerability management, secure backups, and employee awareness training remain valuable regardless of certification timelines.
- Review Your Documentation
One of the biggest challenges organizations face during security assessments is documentation.
Policies, procedures, risk assessments, incident response plans, and system security documentation should all be reviewed and updated regularly.
Strong documentation not only supports future compliance efforts but also helps your organization respond more effectively to security incidents.
- Address Known Security Gaps
If you’ve already completed a cybersecurity assessment or gap analysis, now is an excellent time to resolve outstanding issues.
Waiting until certification requirements return could create unnecessary pressure. Taking action now allows your organization to spread improvements over time rather than rushing to meet a future deadline.
- Stay Informed
The Department’s review is expected to result in additional guidance.
Organizations should monitor official announcements and work with trusted cybersecurity partners to understand how future changes may affect their business. Remaining informed today can help avoid surprises tomorrow.
What This Means for Your Business
The pause of CMMC Phase II has understandably generated questions for organizations across the defense supply chain. While the certification timeline is being reviewed, businesses should continue focusing on the cybersecurity practices that protect sensitive information and support customer requirements.
Organizations that invest in strong security controls, maintain up-to-date documentation, and stay informed as new guidance is released will be better prepared for whatever comes next, whether that’s a revised CMMC rollout or evolving customer expectations.
Need Help Strengthening Your Cybersecurity Program?
Whether your business is working toward CMMC readiness or simply looking to strengthen its cybersecurity program, having the right technology and security strategy can make all the difference. Centriworks helps organizations assess risk, strengthen security controls, and implement practical solutions that support both day-to-day operations and evolving compliance requirements.
Contact Centriworks to learn how we can help your business build a stronger, more resilient cybersecurity foundation.
Frequently Asked Questions
Will organizations that were already working toward CMMC need to start over?
No. Investments in security controls, documentation, and cybersecurity processes will continue to provide value. Regardless of how the Department updates the program, organizations that have already made progress toward CMMC readiness are likely to be in a stronger position than those that wait.
How long will the CMMC Phase II review take?
The Department has announced a 60-day review of the program, but it has not yet provided a revised implementation timeline for Phase II. Organizations should monitor official Department announcements for updates on future requirements.
Where can businesses find the latest information about CMMC?
The best source for updates is the Department of War Chief Information Officer (DoW CIO), which publishes official information about the CMMC program. Businesses should also stay in contact with their customers and trusted cybersecurity advisors, as contract requirements and implementation guidance may continue to evolve.
We’re ready to help you work smarter.
Call us at (865) 524-1124 or use this contact form. Let us know what you’d like to know more about and one of our experts will be in touch with you soon.

