The CMMC Pause Is Almost Over: What to Do With the Time You Have Left

Picture this: leadership finally signed off on the Level 2 readiness sprint, your team is 60% through the System Security Plan (SSP), and then the headline hits — the Department of War has paused CMMC. Your VP of Contracts forwards it with one line: "Do we still need to keep doing this?" The honest answer is yes. And the more useful question isn't whether the pause matters — it's what you do with the time remaining before it's resolved.

Picture this: leadership finally signed off on the Level 2 readiness sprint, your team is 60% through the System Security Plan (SSP), and then the headline hits — the Department of War has paused CMMC. Your VP of Contracts forwards it with one line: "Do we still need to keep doing this?"

The honest answer is yes. And the more useful question isn't whether the pause matters — it's what you do with the time remaining before it's resolved.

1. What actually happened, and what happens next

On July 13, 2026, the Department of War suspended the transition into CMMC Phases 2, 3, and 4 while a newly formed CMMC Reform Task Force reviews the program. The public comment period on that review closed August 14, 2026. The task force is expected to report its recommendations to the DoW CIO on or about September 13, 2026 — which, as of this writing, is one week away.

That's the part most coverage of this story misses: this isn't a settled situation you can file away. It's an open one, closing soon. Whatever comes out of that report — tightened requirements, a redesigned framework, a further delay — will set the terms for the next phase of your compliance work. The organizations that use the time between now and then wisely will be the ones ready to move the moment there's clarity.

This is not a repeal, and it's not a rule change. It's a pause on the phase-in schedule — the calendar that determines when new contract requirements land in DoW solicitations — while the task force evaluates whether the program's structure, timelines, and assessment capacity are working as intended.

2. What's paused, and what isn't

This is where we're seeing the most confusion, so it's worth being precise.

Paused:

  • The transition to Phase 2, originally set to begin November 10, 2026, which would have made Level 2 C3PAO certification a condition of award for applicable contracts.
  • Phase 3 and Phase 4 milestones, including expanded Level 3 (DIBCAC) assessment requirements.

Still fully in force:

  • Phase 1, live since November 10, 2025 — CMMC Level 1 or Level 2 self-assessment as a condition of award for applicable solicitations.
  • DFARS 252.204-7021, obligating contractors to hold the required CMMC level at time of award.
  • DFARS 252.204-7012, your existing incident reporting and CUI safeguarding obligations, which predate CMMC entirely.
  • NIST SP 800-171 Rev. 2 are still the requirements for a Level 2 CMMC certification.
  • SPRS scoring and annual affirmations — contracting officers are still verifying compliance status through SPRS before award and before option-period exercises.

If your organization handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), none of your underlying obligations changed on July 13. What changed is the calendar for when mandatory third-party certification arrives — and DoW program offices retain the discretion to include self-assessment requirements in contracts in the meantime.

It's also worth a quick, honest note: the DoW's pause governs DoW contracting officers. It doesn't govern your prime. Several primes have kept their own supplier certification deadlines in place regardless of what DoW paused — a reminder that "the government paused it" and "nobody is asking me for it" are two different statements.

3. Why the pause is not a reason to slow down

We've already fielded a version of “so we have more time now, right?" from more than one contractor this summer. We understand the instinct — a paused deadline feels like permission to breathe. But treating this pause as a stand-down is a mistake, for three reasons.

  • The review could tighten requirements, not loosen them. A task force studying "whether the program is working as intended" is just as likely to recommend accelerated timelines or stricter assessment criteria as it is to recommend delay. Betting your posture on a specific outcome is a bet you don't need to make.
  • Your competitors aren't standing still. The contractors who use this window to close real gaps — not paper over them — will be ready to bid confidently the moment Phase 2 resumes. The ones who paused internal effort will be scrambling again, on a shorter runway than they had this time.
  • Your CUI is still a target regardless of what phase is active. Threat actors don't check the DoW's rulemaking calendar before attempting to access defense supply chain data. The risk CMMC exists to address hasn't paused.

4. What contractors should be doing right now

The organizations getting the most value out of this window are treating it as found runway, not found time off. "Keep working" is easy advice to give and hard to act on — so here's what it actually looks like, broken down by workstream.

Finish the self-assessment — don't just start it

  • If your Level 1 or Level 2 self-assessment has been "in progress" for months, set yourself a hard internal deadline in the next two weeks to score against all 110 NIST SP 800-171 practices — not just the straightforward ones.
  • Don't submit a score you can't defend. If your last SPRS submission is more than six months old, or your environment has changed — a new cloud tool, a remote workforce shift, a new subcontractor — revalidate the underlying evidence before resubmitting. A confident number that doesn't match reality is False Claims Act exposure, not a compliance win.
  • Assign an owner per control family (AC, IR, MP, and so on) instead of leaving one person to close all 110 practices alone. Fragmented ownership is the most common reason self-assessments stall for months at a time.

Turn open POA&M items into finished controls

  • Sort open items by remediation cost and time, not by convenience, and close the slow ones first. Architectural changes — network segmentation, encryption at rest, MFA rollout — take months; policy and documentation items take days. If Phase 2 resumes on a compressed runway, the slow items are what will hurt you.
  • Know the real limits of a POA&M: higher-weighted requirements (the 3- and 5-point practices) generally can't be deferred this way, and even eligible items typically need a closeout assessment within 180 days of a conditional score. "Documented" is meant to be temporary — don't let it quietly become permanent.
  • Re-date every open item this month. If a target date has already slipped once, it needs an actual remediation plan behind it, not another extension.

Get ahead of C3PAO demand

  • Start the conversation with a C3PAO now, even if you're not certification-ready yet. Assessor capacity is already tight, and when Phase 2 resumes, every contractor who waited will be calling the same handful of assessors at once.
  • If you're not sure whether you'd actually pass a C3PAO assessment today, a mock assessment or third-party gap review now is far cheaper than finding out mid-audit.
  • Confirm which deadline is actually yours. If a prime has already set its own certification requirement independent of the DoW timeline — and several have — that date, not November 10, is the one your business is really working against.

Revisit scope with fresh eyes

  • Re-walk your CUI flow map end to end: where CUI enters your environment, where it's stored, processed, and transmitted, and where it exits — including to subcontractors. New tools, vendors, or contract types since your last review can quietly pull new systems into scope.
  • Confirm your subcontractors' required level actually matches what they handle. It's not automatically the same as yours — a sub touching only FCI needs Level 1, one touching CUI needs Level 2, regardless of your own level.
  • If you've adopted any new SaaS, cloud storage, or collaboration tools in the past year, check whether they touch CUI and whether they meet the FedRAMP Moderate (or equivalent) bar. This is one of the most common — and most missed — sources of scope creep.

Keep your compliance team intact

  • Programs staffed and budgeted for a November deadline are the ones most at risk of quietly losing people or funding during a quiet period. If your compliance lead or engineers get reassigned now, rebuilding that capability once the timeline resumes costs more than retaining it through the review.

5. How Blue Mantle can help you use this window

As a defense contractor that has navigated CMMC ourselves, we know the difference between a compliance program that looks good on paper and one that holds up when a C3PAO assessor starts asking questions. That's the gap we help close.

If you're not certain where your organization stands heading into whatever comes out of the September review, we offer a complimentary 1-hour Gap Assessment — a clear, honest picture of your current readiness against CMMC Level 2 requirements. From there, our team can take you from gap analysis through SSP and POA&M development to full audit readiness, with the same rigor we hold ourselves to.

Schedule your free CMMC Gap Assessment and walk into whatever's next with confidence.

The review period ends soon. When it does, the contractors who kept building will be the ones still standing in the recompete — not explaining to leadership why they're starting over.

Sources referenced