In the past few years, CMMC has been a key revenue driver for many MSP and Compliance Consultants. Now, a pause that sounds simultaneously vague and ominous was just announced—which might leave you wondering, what now?
This can feel like a lot to digest and there’s a lot of noise right now about what this means. In my opinion, the right response is neither “stop all CMMC work” nor “continue every assessment expense unchanged.”
Read on to find out what you can do to best position yourself through this phase—and into the next, no matter what the updated timeline may look like.
Key Considerations:
- The Facts: What We Know About the CMMC Level 2 Pause
- What the CMMC Phase II Suspension Changes
- Which Contractor Obligations Remain
- How MSPs Should Adjust Client Plans and Spending
- How ControlMap Helps MSPs Keep CMMC Work Moving
- What Happens Next
The Facts: What We Know About the CMMC Level 2 Pause
On July 13, 2026, the U.S. Department of War suspended the transition to Phase II of the Cybersecurity Maturity Model Certification program while a 60-day review is conducted. The change pauses the planned expansion of Level 2 third-party assessments by C3PAO’s while the Department reviews the cost and structure of the program.
Here are some good references to learn more:
- Hunton’s Legal Summary of DoW pause
- CyberAB Statement (Jul 15, 2026)
- DoW’s announcement: 60 day pause review for Phase II announcement
What continues to remain in effect are existing cybersecurity requirements already attached to contracts. It does not eliminate applicable self-assessments, SPRS obligations, NIST SP 800-171 requirements, or the need to support submitted scores with current evidence.
For MSPs, this is not a reason to stop helping clients prepare, but it is a time to reach out to your clients and have a real conversation about what this change means for them. Looking at the silver lining, it’s actually an opportunity to move clients away from deadline-driven compliance projects and toward a repeatable program for managing controls, evidence, gaps, and remediation over time.
For organizations closely connected to prime contractors, continuing as planned will often make the most sense because the legal mandates and contractual obligations already exist. Prime contractors also establish their own cybersecurity expectations for subcontractors, independent of the DoD's implementation timeline. As a result, reduced federal pressure does not necessarily mean reduced commercial pressure.
As Kyle Lai, President and CISO of KLC Consulting and our past webinar guest, shares:
| Regulatory Element | Current Status | Action Required |
|---|---|---|
| CMMC Phase II Rollout | Suspended pending 60-day task force review. | Monitor updates; coordinate expectations with your prime partners. |
| DFARS 252.204-7012 | Active and unchanged | Maintain strict compliance with current safeguarding clauses. |
| NIST SP 800-171 Rev 2 | Enforced via mandatory self-assessments | Ensure your System Security Plan (SSP) and POAMs are accurate. |
| C3PAO Assessments | Fully operational and available on a voluntary basis. | Highly recommended for competitive positioning and risk reduction. |
1. What the Phase II Suspension Changes
Phase II had been scheduled to begin on November 10, 2026. It would have expanded the use of CMMC Level 2 assessments conducted by Certified Third-Party Assessment Organizations as a condition of contract award.
During the suspension:
- Department program managers and requiring activities may only designate CMMC Level 1 self-assessments and CMMC Level 2 self-assessments
- Voluntary C3PAO Level 2 certification assessments are not halting
- The eMASS and SPRS systems remain fully operational to process and record assessment activity
- CMMC Level 2 Certificates remain valid for 3 years
The Department has also established a CMMC Reform Task Force to conduct a 60-day review of the program. No replacement date for Phase II has been announced.
The review is intended to reduce the cost and administrative burden placed on small and non-traditional defense contractors. The U.S. Small Business Administration estimates that total CMMC compliance costs can reach approximately $593,800 for a small business requiring third-party certification. It also estimates that more than 120,000 small Defense Industrial Base businesses could have been seeking support from roughly 100 approved assessors.
The certification model may change. Contractors and MSPs should not assume what the final model will look like until the Department completes its review.
2. What Contractor Obligations Remain
The suspension does not mean defense contractors can stop protecting Federal Contract Information or Controlled Unclassified Information.
The Department has confirmed that:
- Phase 1 self-assessment requirements remain in place
- Level 2 self-assessments remain aligned with NIST SP 800-171 Revision 2
- Existing DFARS requirements for safeguarding covered defense information remain effective
- Select government-led assessments may continue
- Contractors must continue meeting the cybersecurity requirements that apply to their contracts
Where applicable, contractors must maintain a current NIST SP 800-171 assessment and verify that the summary score is posted in the Supplier Performance Risk System.
The exact requirement still depends on the client’s contract, solicitation, information, assessment level, and systems within scope.
For some clients, the suspension may change the timing of a formal assessment. It does not change the need to understand and meet current contractual obligations.
3. How MSPs Should Adjust Client Plans And Spending
Now’s not the time to stop your CMMC work, but to adapt it. MSPs should take advantage of this time to deepen their client relationships and help clients confirm what currently applies, preserve the work already completed, and focus spending on real contractual, security, and commercial needs.
Some key steps to follow:
1) Confirm the Client’s Current Requirements
Start with the contract, not the headline. Clients with an assessment already scheduled should speak with their contracting, legal, and assessment contacts before cancelling or changing it.
Make sure to review:
- Current contracts and active solicitations
- Applicable CMMC and DFARS requirements
- Whether the client handles FCI or CUI
- Where that information is stored, processed, and transmitted
- Which contractor, MSP, cloud, and third-party systems touch it
- The client’s current assessment and SPRS status
- Where evidence is permitted to be stored
- Which responsibilities belong to each party
2) Limit and Defend the CUI Boundary
Scoping is not only about identifying every system that might touch CUI. It is also about limiting unnecessary access.
Enclaves, restricted administrative paths, dedicated personnel, and clear system boundaries can reduce the number of MSP systems and employees brought into scope.
An RMM, PSA, remote access tool, or other MSP system is not automatically in scope simply because the MSP uses it. The answer depends on whether it stores, processes, transmits, protects, or provides access to FCI or CUI.
The goal is a boundary that is limited, operationally realistic, and supportable.
3) Keep Meaningful Remediation Moving
The certification timeline was only one reason to fix missing controls.
Weak identity management, incomplete policies, unprotected backups, poor access controls, and missing incident response procedures still create real security and operational risk. They can also leave a contractor unable to support the score or statements it has submitted.
The Department continues to recommend conducting a careful self-assessment, identifying unmet requirements, and correcting gaps.
MSPs should prioritize:
- Current contractual obligations
- Accurate SPRS information
- High-impact security gaps
- Evidence supporting implemented controls
- Work that protects the client regardless of the final certification model
They should not push every client into an expensive third-party assessment without a contractual, customer, or commercial reason to do so.
4) Make Every Assessment Supportable
A self-assessment should reflect what is implemented today, not what the client hopes to implement later.
MSPs can help validate technical controls, organize evidence, document gaps, and coordinate remediation. They should not make compliance representations or complete affirmations on the contractor’s behalf.
Not every CMMC requirement belongs to IT. Personnel security, physical security, governance, contracting, and business processes require participation from the contractor’s leadership and other departments.
Accurate records matter. The Department of Justice has continued to pursue False Claims Act matters involving alleged failures to meet cybersecurity requirements in government contracts.
These cases do not automatically make an MSP responsible for a contractor’s affirmation. They do show why unsupported scores and claims create risk.
5) Maintain the Records Behind the Score
Security environments change. Employees leave. Systems are replaced. Policies expire. Configurations are updated. Evidence that supported a conclusion six months ago may no longer represent the current environment.
MSPs should help clients maintain:
- A current System Security Plan
- Evidence mapped to applicable requirements
- Accurate implementation statements
- Documented gaps and remediation owners
- POA&M dates and supporting work
- Records showing how the environment has changed
CMMC should be treated as an ongoing program, not a one-time document collection project.
4. How ControlMap Helps MSPs Keep CMMC Work Moving
A shifting deadline doesn't make compliance work disappear—it just changes the timeline. MSPs still need accurate assessments, organized evidence, assigned remediation, and clear client accountability. Without a structured approach, that work tends to scatter across spreadsheets, shared drives, and email threads, making it nearly impossible to manage consistently across clients.
ControlMap gives MSPs a single place to handle that work. Rather than starting from scratch with each engagement, teams can build a baseline from their standard tech stack, policies, and evidence expectations, then clone and tailor it per client. From there, the platform keeps assessments, evidence, and remediation tied together—so when something changes, the downstream impact is visible.
Key capabilities include:
- Assessing clients against CMMC and NIST SP 800-171 requirements
- Assigning requirements, evidence requests, and remediation tasks with due dates
- Collecting evidence through supported integrations, uploads, and direct requests — then organizing it for internal review, client review, or assessor delivery
- Tracking gaps, risks, and remediation across all client environments from a single MSP portal
- Generating SSP, POA&M, assessment, and supplier score reporting
- Mapping evidence across frameworks like SOC 2 or ISO 27001 to reduce duplicate work
A quick note on scope: ControlMap supports the organization, documentation, and management of CMMC compliance work. It doesn't provide certification, replace a C3PAO or qualified advisor, or submit information to SPRS—but it can make the work between now and that finish line a lot more manageable.
5. What Happens Next
The Department is accepting industry feedback through a public Request for Information on CMMC reform. Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB). Your active participation in this RFI is highly encouraged.
Responses are due by August 14, 2026 at 12:00 p.m. ET.
MSPs have direct visibility into the operational cost of:
- Collecting and reviewing evidence
- Managing multiple client environments
- Coordinating responsibilities across several providers
- Translating requirements into technical projects
- Preparing documentation for assessment
- Maintaining the program after the initial assessment
Useful feedback should include real examples, costs, and time estimates.
It could also address opportunities to reuse reliable commercial security data, reduce repetitive evidence work, clarify service-provider responsibilities, and improve guidance for small contractors.
The Cyber AB will host a national Town Hall on Tuesday, July 28, 2026, at 6:00 PM EDT to address the Phase II pause and outline next steps. You can register directly on The Cyber AB website.
The Bottom Line: GRC Work Carries On
CMMC Phase II is paused. The work required to protect federal information and support a contractor’s security claims continues.
MSPs should use this period to help clients confirm their obligations, limit unnecessary CUI exposure, correct meaningful security gaps, and maintain the evidence behind every assessment.
The final certification model may still change. The need for a current, defensible, and well-managed compliance program will not. And that’s what MSPs can focus on now.
Additional Resources:
- DoW Memo July 13, 2026: https://dowcio.war.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf.
- CyberAB Statement July 15, 2026: https://cyberab.org/News-Events/Press-Releases/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements.
- Cyber AB national Town Hall on Tuesday, July 28, 2026, at 6:00 PM EDT to address the Phase II pause and outline next steps. Register here: The Cyber AB website.
- Request For Information: Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB). Your active participation in this RFI is highly encouraged. Please note submissions are due by August 14, 2026 12:00 PM EDT.
- Hunton’s Legal Summary of DoW pause
- CyberAB Statement Jul 15, 2026
- DoW’s announcement: 60 day pause review for Phase II announcement
This article provides general information and is not legal or contracting advice.