Do you remember that feeling in college when your professor postponed the mid-term by a few days?
You most likely had an initial feeling of relief, quickly followed by the realization that you still had to know the material. At least you had more time to prepare (or more time to fret).
Many of us have those same mixed emotions about the Department of Defense’s (DOD’s) recent decision to suspend the next phase of the Cybersecurity Maturity Model Certification (CMMC) program. The announcement changes how and when certain defense contractors will be assessed. But it doesn’t change the need to protect sensitive information from the threats those organizations face.
What CMMC Really Is
At its core, CMMC is the DoD’s method for verifying that contractors and subcontractors have implemented required cybersecurity practices for protecting Federal Contract Information and Controlled Unclassified Information.
The requirements vary based on the sensitivity of the information involved. Some organizations must demonstrate basic safeguards, while those handling Controlled Unclassified Information generally must implement the 110 security controls contained in NIST Special Publication 800-171 Revision 2.
CMMC adds an assessment process intended to give the government greater confidence that those protections are actually in place and not just promises in a proposal or policy document.
CMMC is a system for validating that defense contractors are doing what they were already required to do.
What the DoD Actually Suspended
On July 13, 2026, the DoD announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect on November 10, 2026. Phase II would have significantly expanded the use of independent third-party assessments for organizations seeking certain Level 2 contracts.
The Department cited concerns that the cost and administrative burden of certification were discouraging smaller businesses from participating in these contracts. It established the CMMC Reform Task Force to conduct a comprehensive review and make recommendations within 60 days.
For the time being, implementation remains in Phase I. Level 1 and eligible Level 2 organizations will continue to conduct self-assessments and submit required affirmations. The DoD may also perform selected government-led assessments.
That is a meaningful policy change, but it is not a suspension of cybersecurity responsibilities.
The DoD made that point explicitly: defense contractors and subcontractors remain contractually responsible for safeguarding covered defense information under DFARS 252.204-7012. During the review, compliance with NIST SP 800-171 Revision 2 will continue to be enforced through self-assessments and selected government assessments.
And in case you are wondering, those self-assessments must be accurate and supportable. Knowingly submitting an inaccurate score or falsely representing cybersecurity compliance can create significant exposure under the False Claims Act.
A Passing Score Is Not the Same as Security
One risk in any compliance program is that organizations prepare for the assessment instead of preparing for the threat.
That approach can produce a passing score while leaving the organization vulnerable.
Effective cybersecurity is an ongoing operation. It means knowing where sensitive information resides, controlling who can access it, keeping systems patched, using multifactor authentication, monitoring suspicious activity, training employees and preparing to respond when something goes wrong.
Having these controls in place is essential regardless of how, or whether, compliance is being directly assessed.
Use the Pause to Build, Not Wait
Organizations that were preparing for a third-party CMMC assessment may decide to reconsider their timelines and spending. Some may decide that a formal assessment no longer makes immediate business sense.
The more productive response is to separate the certification project from their security objectives. Review which activities were being performed primarily to satisfy the assessment, and which ones materially reduce risk. Continue the cybersecurity work that strengthens the organization, even if the documentation or certification schedule changes.
That should include several practical priorities:
- Understand what sensitive information your organization receives, creates and shares.
- Define the systems, people and vendors that fall within the security boundary.
- Correct high-risk weaknesses rather than allowing plans of action to become permanent placeholders.
- Validate self-assessment results with evidence and technical testing.
- Treat cyber risk as an executive and operational issue, not simply an information technology assignment.
The organizations that take this approach will be prepared regardless of what emerges from the DoD review. More importantly, they will be better equipped to withstand the cyber threats that exist today.
The Real Measure of Cyber Maturity
CMMC will continue to evolve, and the government may adjust how compliance is assessed. But uncertainty about the certification process should not create uncertainty about the need for cybersecurity. Adversaries are not suspending their operations while the government evaluates its assessment model.
At RELI, we see the recent announcement as an opportunity to refocus the conversation. Certification matters, but the real objective is protecting the information, systems and missions that we have been entrusted to support.
Organizations should use this opportunity to understand their actual exposure, continue closing meaningful security gaps and build cybersecurity into everyday operations.
Because the test got postponed; the cyber threats didn’t.