CMMC Compliance Still Matters: What Defense Contractors Should Do Now

By Scott Dawson
August 4, 2026

The Department of War recently decided to pause Phase II of the Cybersecurity Maturity Model Certification rollout. This has caused confusion across the Defense Industrial Base.

Some contractors may interpret the announcement to mean that CMMC has been cancelled or that protecting Controlled Unclassified Information (CUI) is no longer a priority. That is not the case.

The government has temporarily paused the planned expansion of certain third-party certification requirements while it reviews the program. However, Phase I self-assessment requirements remain in effect, and defense contractors must continue protecting sensitive government information.

For small businesses in the defense supply chain, the practical message is simple:

The CMMC assessment schedule may change, but your cybersecurity and contractual responsibilities have not gone away.

What Did the Government Change?

On July 13, 2026, the Department of War announced that it was suspending the transition to Phase II of the CMMC implementation plan. Phase II had been scheduled to begin on November 10, 2026, and would have significantly expanded the number of contracts requiring a CMMC Level 2 assessment performed by a Certified Third-Party Assessment Organization (C3PAO).

The Department also established a task force to review the CMMC program and recommend ways to improve cybersecurity while reducing unnecessary cost and administrative burden, particularly for small and nontraditional defense contractors.

This action affects the timing and use of certain CMMC assessment requirements. It does not remove the responsibility to safeguard government information. The Department specifically stated that all defense contractors and subcontractors remain contractually obligated to protect covered defense information under DFARS 252.204-7012. Read the Department’s announcement.

CMMC Level 2 Has Not Been Cancelled

It is important to distinguish between CMMC Phase II and CMMC Level 2.

CMMC Phase II is a stage in the government’s planned implementation schedule. CMMC Level 2 is the security level generally associated with contractors and subcontractors that handle CUI.

Level 2 is based on the 110 security requirements in NIST SP 800-171 Revision 2. These requirements cover areas such as:

  • Access control
  • Employee awareness and training
  • Configuration management
  • Incident response
  • System monitoring
  • Risk assessment
  • Security assessments
  • Media protection
  • Identification and authentication

Suspending a phase of the rollout does not eliminate these safeguards or the contractual clauses that may require a contractor to implement them.

The Defense Supply Chain Still Needs to Be Secure

Cybersecurity remains a major concern throughout the Defense Industrial Base. Small manufacturers, technology providers, professional service firms and other subcontractors may hold information that could be valuable to foreign adversaries and cybercriminals.

This information can include engineering drawings, technical specifications, manufacturing data, contract information, system details and other sensitive records.

A cyber incident involving a small subcontractor can affect a much larger program. That is why prime contractors and government customers will continue evaluating cybersecurity risk throughout their supply chains—even while parts of the CMMC program are being reviewed.

Defense contractors may still be expected to:

  • Protect CUI in accordance with NIST SP 800-171
  • Comply with applicable DFARS cybersecurity clauses
  • Maintain an accurate System Security Plan, or SSP
  • Complete the appropriate CMMC self-assessment
  • Maintain a current assessment score in the Supplier Performance Risk System, or SPRS, when required
  • Submit annual affirmations
  • Preserve evidence showing that security requirements are implemented
  • Report covered cyber incidents when applicable
  • Meet cybersecurity requirements imposed by prime contractors or other customers

The Department has said it will continue enforcing cybersecurity compliance through self-assessments and selected government-led assessments during this interim period. See the Department’s additional explanation.

Self-Assessment Still Requires Real Compliance

For some small contractors, a CMMC Level 2 self-assessment may be sufficient for current opportunities. However, “self-assessment” does not mean simply checking a box or stating that the company plans to become compliant.

Your assessment should be supported by evidence that the applicable security requirements are actually implemented and operating.

A defensible CMMC self-assessment generally requires:

  • A clearly defined CUI environment and assessment scope
  • An accurate and current SSP
  • Implemented technical and administrative controls
  • Policies that match the organization’s actual practices
  • Employee cybersecurity training
  • Configuration settings, logs, reports and other supporting evidence
  • An accurate assessment score
  • Documentation of any remaining corrective actions
  • Leadership review and affirmation

Companies should be very careful when they report controls as implemented.

This is important when controls are incomplete, undocumented, or only planned. Unsupported cybersecurity representations can create contractual, financial and legal exposure.

CMMC compliance is therefore not just an IT responsibility. Company leadership must understand the organization’s obligations and be confident that any assessment, score or affirmation is accurate.

Prime Contractors May Continue Requiring Proof

A change to the government’s implementation schedule does not automatically remove these requirements.

  • A prime contractor may set the requirements.
  • A customer may also set them.
  • They may also come from a subcontract.
  • They may also come from a purchase order.

Prime contractors remain responsible for managing risk within their supply chains. Depending on the program and the information being shared, they may continue requesting:

  • SPRS assessment information
  • CMMC or NIST SP 800-171 questionnaires
  • Written compliance representations
  • Information about the contractor’s CUI environment
  • System Security Plan details
  • Corrective-action plans
  • Independent assessment results
  • CMMC Level 2 certification

CMMC certification may also remain a competitive differentiator. The Cyber AB confirmed that the CMMC ecosystem is still operational. Authorized C3PAOs can keep performing voluntary Level 2 certification assessments. Read The Cyber AB’s statement.

Before changing your compliance or assessment plans, review your contracts and speak directly with your prime contractor or customer. If a requirement has changed, request written confirmation.

Should Small Businesses Continue Preparing for CMMC?

Yes. Small defense contractors should continue strengthening their cybersecurity programs and preparing to demonstrate compliance.

Stopping your CMMC preparation could create several business risks:

  • Existing DFARS requirements may still apply.
  • Prime contractors may continue requiring cybersecurity evidence.
  • An inaccurate SPRS score may be questioned during a government review.
  • Unprotected CUI may remain vulnerable to cyberattacks.
  • Future solicitations may include new or revised CMMC requirements.
  • A contractor that cannot demonstrate compliance may lose access to defense opportunities.
  • Restarting a stalled compliance program can be expensive and time-consuming.

Cyber threats have not paused. Neither has the need to protect sensitive information across the defense supply chain.

The most practical approach is to keep improving your security program. Also, make a thoughtful decision about when to schedule a third-party assessment.

Defense Manufacturer CMMC
DIB CMMC Compliance
DOW CMMC 2026 Update

Do You Still Need a C3PAO Assessment?

Not every contractor needs to schedule a C3PAO assessment immediately. The right timing depends on your contracts, customers, business goals and current state of readiness.

You may decide to delay an assessment if:

  • No current contract or customer requires certification.
  • They scheduled your assessment only because of the former Phase II deadline.
  • Significant implementation work remains.
  • Your SSP, policies or evidence are not ready.
  • Waiting would not affect your eligibility for defense work.

You may decide to continue toward certification if:

  • A current or prospective customer requires it.
  • Certification is needed for an upcoming contract opportunity.
  • Your organization is already prepared for assessment.
  • A prime contractor views certification as an important supplier qualification.
  • Independent verification would strengthen customer confidence.
  • Certification supports your long-term defense market strategy.

Even if you postpone the formal assessment, you can continue implementing requirements, gathering evidence and correcting gaps. This will put your business in a stronger position when an assessment becomes necessary.

What Small Defense Contractors Should Do Now

Use this period to strengthen your compliance program rather than putting it on hold.

1. Review Your Contractual Requirements

Identify the DFARS clauses, CMMC requirements and customer-specific cybersecurity terms that apply to your company.

2. Confirm Where CUI Is Stored and Processed

Determine which employees, systems, applications, devices and service providers have access to CUI. A clearly defined scope can make compliance more manageable and affordable.

3. Validate Your NIST SP 800-171 Implementation

Evaluate each applicable requirement based on what is currently implemented—not what you intend to implement later.

4. Update Your System Security Plan

Your SSP should accurately describe your current environment, security controls, responsibilities and system boundaries.

5. Collect and Organize Evidence

Policies alone are not enough. Maintain records showing that your security practices are operating, including logs, screenshots, configurations, training records and review reports.

6. Check Your SPRS Score

Make sure your reported score is current, supportable and consistent with your actual implementation.

7. Ask Customers What They Expect

Contact your prime contractors and customers to determine whether they still require CMMC certification or will accept a supported self-assessment.

8. Create a Practical Remediation Plan

Prioritize gaps based on contractual importance, cybersecurity risk, cost and implementation time.

9. Reevaluate Your Assessment Timeline

Base your decision on customer requirements and business opportunities—not solely on the previous Phase II implementation date.

The Bottom Line

CMMC is still active, and cybersecurity compliance remains essential for companies that want to participate in the Defense Industrial Base.

Although the Phase II rollout has been suspended while the government reviews the program, defense contractors and subcontractors must continue protecting covered defense information. Phase I requirements remain in place, DFARS obligations continue to apply and customers may still require evidence that your cybersecurity program is working.

Small businesses should view this period as an opportunity to make steady, practical progress. Companies that maintain accurate documentation, implement the required safeguards and preserve assessment evidence will be better prepared for customer requests, government reviews and future CMMC developments.

Get Practical CMMC Help for Your Small Business

Core Business Solutions helps American small businesses understand and meet their CMMC, DFARS and NIST SP 800-171 responsibilities.

Our experienced cybersecurity consultants can help you:

  • Determine which requirements apply to your business
  • Identify and scope your CUI environment
  • Complete a CMMC or NIST SP 800-171 gap assessment
  • Develop your System Security Plan
  • Create required policies and procedures
  • Validate your self-assessment and SPRS score
  • Implement missing cybersecurity controls
  • Organize evidence for an assessment
  • Prepare for a C3PAO assessment when the time is right
  • Protect CUI within a secure, limited environment

Whether you need to improve your self-assessment, respond to a prime contractor’s request or continue preparing for CMMC Level 2 certification, Core Business Solutions can provide a clear and manageable path forward.

Talk with a Core Business Solutions CMMC consultant today.

Core Business Solutions, established in 2000, is a Registered Practitioner Organization through the Cyber-AB and has been providing consulting and technical solutions for NIST/CMMC for over 5 years. Ty Elliott is a Cyber-AB RP and Lead CMMC Consultant for Core Business Solutions and directs our Cybersecurity Services solutions including CMMC. Ty has over 20 years of experience in Management System implementations, software development, IT services, and certifications.

Registered Practitioner Organization Logo

Related Articles:

ITAR Compliance for Small Businesses

ITAR Compliance for Small Businesses

ITAR/EAR Compliance: What You Need to Know Many small manufacturers and suppliers assume export compliance rules only apply to large defense contractors or companies shipping products overseas. In...