Executive Brief
The Department of War (DoW) recently hit pause on third-party certification requirements for Cybersecurity Maturity Model Certification (CMMC) Level 2. However, that doesn’t mean the clock has stopped for everything else.
The pause gives contractors more time to prepare, and how you spend it will show up in your next assessment, your next prime contractor conversation, and your next bid.
- DoW suspended the Certified Third-Party Assessment Organization (C3PAO) certification requirement on July 13, 2026, with a CMMC Reform Task Force reviewing the program for 60 days
- Phase 1 self-assessment requirements for CMMC Level 1 and Level 2, Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 requirements are unchanged
- A public Request for Information (RFI) tied to the review closes August 14, 2026, giving contractors a direct channel to weigh in
- The organizations that use this window to close gaps, tighten documentation, and stay engaged will be in a stronger position than those that treat the pause as a reason to wait
Dig deeper below to learn more.
Some contractors are reading the pause as license to slow down, but that read misses what changed: the verification mechanism, not the underlying standard. We broke down the details in CMMC Phase II Is Paused, Not Canceled.
What Paused and What Didn’t
There's a lot of noise right now about what the pause covers. Here's what changed, and what didn't.
Paused:
- The requirement for a mandatory C3PAO assessment to win or keep a CMMC Level 2 contract, originally set to begin November 10, 2026
- Related Level 3 government-led assessment milestones
ISI Insight: Any active solicitation or contract language requiring Level 2 (C3PAO) or Level 3 certification is being amended to remove it.
Not paused:
- CMMC Level 1 and Level 2 self-assessment requirements will continue appearing in solicitations
- DFARS 252.204-7012 obligations and the underlying NIST SP 800-171 Rev. 2 controls
- SPRS score submission and annual affirmations
- Prime contractor requirements for a C3PAO assessment, since some primes are keeping that bar in place
- Your obligation to protect CUI under existing contracts, regardless of certification status
ISI Insight: Without a third party checking your work, your self-attestation now carries more weight, not less. A self-assessment is only as strong as the evidence behind it.
The RFI Window is Time-Sensitive
The CMMC Reform Task Force, established by DoW Chief Information Officer (CIO) Kirsten Davies, is reviewing the program and is expected to report its recommendations to the DoW CIO on or about September 13, 2026. To inform that review, the Department published an RFI titled “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base,” and responses are due by 12:00 p.m. Eastern Time on August 14, 2026.
This is a narrow, direct channel to influence what CMMC could look like next.
- If C3PAO assessment costs, assessor availability, or documentation burden have affected your business, the RFI is the place to say so
- Responses are submitted by email under the instructions published with the RFI notice, not through a regulations.gov docket
- Most of the Task Force's questions are aimed squarely at small and mid-sized businesses, making this your best chance to shape what comes next
If your organization has not yet submitted input and this affects your business, this week is the time to do it.
How to Use this Pause Productively
The contractors who come out of this review period ahead are the ones treating it as a working window, not a waiting room.
- Validate your scope before anything else. Confirm where CUI lives, flows, and is stored today. Scope drives everything downstream, and it is the fastest thing to get wrong.
- Tighten your System Security Plan (SSP) to the objective level. Assessors validate against 320 assessment objectives, not just 110 control titles. If your SSP still reads at the control level, that gap does not disappear because a C3PAO is not currently required. Our guide on what should be in your SSP for CMMC Level 2 breaks this down further.
- Run or refresh a gap assessment. Compare your current implementation against NIST SP 800-171 Rev. 2 and be honest about what is fully implemented versus in progress.
- Get your Plans of Action and Milestones (POA&Ms) in order now. Certain requirements can never be deferred, and POA&Ms only work within tight scoring thresholds. Review what you can and cannot defer so your remediation plan holds up under any future assessment model.
- Organize your evidence like an assessor will ask for it. Screenshots, logs, and training records should be retrievable in minutes, not assembled the week before an assessment.
- Decide whether a Governance, Risk, and Compliance (GRC) platform or a lighter compliance stack fits your scope. This is a good window to make that call without assessment-week pressure. See Do You Really Need a GRC Platform for CMMC? for the tradeoffs.
- Submit your input to the RFI to help shape the future of CMMC. The deadline is August 14, 2026.
- Confirm expectations with every prime you support. Primes set their own expectations independent of the federal timeline, and if you work with multiple primes, the strictest requirement applies. Our breakdown of CMMC requirements for subcontractors covers how this plays out across the supply chain.
Keep leadership and budget aligned to your contract pipeline, not the federal rollout date. Readiness work completed now remains applicable under any outcome of the Task Force review. See CMMC Level 2 for Leadership in 2026.
Why Waiting Costs More
Pausing internal readiness work to match a paused federal requirement creates its own risk.
"Even with C3PAO reviews paused, the risk hasn't paused. This is the moment for contractors to strengthen compliance and clearly signal lower risk to primes and the government," says Ketan Patel, MBA, CISA, ISI's Senior Vice President, Compliance.
- The controls themselves have not changed, and the patterns that cause contractors to fail CMMC Level 2 assessments are just as present in a self-assessment as they are in a C3PAO assessment
- While Level 3 (DIBCAC) assessment designations are paused, DoW has said it will still use select government-led assessments to validate compliance, and contractors with a questionable posture, an inconsistent SPRS score, or a history of complaints are the most likely candidates for one
- Prime contractors evaluating subcontractors right now are looking for evidence-backed self-attestation as a signal of lower risk, at a time when competitors may have deprioritized that work
- If the Task Force recommends a faster path back to mandatory third-party assessment than expected, organizations that kept working will not be starting over
- A completed CMMC Level 2 (C3PAO) certification you already hold remains valid for its full three-year cycle and continues to signal readiness even while new certification requirements are paused
Your SPRS score, SSP accuracy, and POA&M discipline still need to reflect reality. That has not changed, and it will not change regardless of how the Task Force review concludes.
FAQs
Do I still need to submit an SPRS score during the pause?
Yes. Self-assessment and SPRS score submission requirements for CMMC Level 1 and Level 2 remain in effect. What is paused is the requirement for a C3PAO to independently verify that score for Level 2.
Should I cancel a C3PAO assessment I already have scheduled?
That depends on your contract pipeline and prime contractor expectations, not just the federal timeline. A voluntary C3PAO assessment can still provide independent validation that supports customer confidence and competitive positioning, even though it is not currently mandatory.
What happens if I do nothing until the Task Force reports back in September?
Your underlying compliance obligations remain in force the entire time, and any documentation, scoping, or remediation gaps will still be there when the review concludes. Waiting does not reduce the work; it only compresses the time to remediate.
Helpful ISI Links