CMMC Phase II Pause Does Not Suspend Defense Contractors' Cybersecurity Obligations

The temporary halt to CMMC Phase II rollout is creating confusion in the Defense Industrial Base — but compliance requirements haven't gone anywhere.

CMMC Phase II Pause Does Not Suspend Defense Contractors' Cybersecurity Obligations

What the CMMC Phase II Pause Actually Means — and What It Doesn't

A pause in the implementation of Cybersecurity Maturity Model Certification (CMMC) Phase II has sent ripples through the Defense Industrial Base (DIB), prompting a wave of questions from contractors, compliance officers, and IT teams scrambling to understand what, if anything, has changed. The short answer: the pause affects the formal certification rollout timeline, but it does not suspend any existing data security obligations that contractors already carry under federal law and regulation.

CMMC is the U.S. Department of Defense's (DoD) framework for verifying that contractors who handle sensitive federal information meet specific cybersecurity standards. Phase II was designed to extend third-party certification requirements to a broader segment of the DIB. While the administrative machinery around that certification process has hit a speed bump, the underlying legal requirements — particularly those stemming from the Defense Federal Acquisition Regulation Supplement (DFARS) and NIST Special Publication 800-171 — remain fully operative. Contractors who breathe a sigh of relief and deprioritize their security programs in response to this pause are misreading the situation in a potentially costly way.

Cybersecurity professional reviewing compliance documentation on a laptop
Defense contractors must maintain cybersecurity standards regardless of CMMC Phase II certification timelines

Understanding the CMMC Framework and Why Phase II Matters

The Cybersecurity Maturity Model Certification program was developed by the DoD to address a persistent and well-documented vulnerability: defense contractors, particularly small and mid-sized firms, have historically struggled to implement and sustain adequate cybersecurity practices. Adversaries — including state-sponsored actors — have exploited this gap to exfiltrate Controlled Unclassified Information (CUI) from contractor networks, sometimes bypassing the Pentagon's own hardened systems entirely by targeting the supply chain.

CMMC maps onto a tiered model. Level 1 covers basic cyber hygiene for companies handling Federal Contract Information (FCI). Level 2, which is the heart of Phase II, requires compliance with all 110 security controls outlined in NIST SP 800-171 and, critically, mandates third-party assessment for most contractors handling CUI. Level 3 is reserved for companies supporting the DoD's most sensitive programs and requires government-led assessments.

According to reporting from Federal Times, the DIB comprises more than 300,000 companies, ranging from large prime contractors to small businesses providing niche components or services. The vast majority of these firms lack dedicated security teams, making compliance a significant operational and financial burden. It is precisely this segment of the supply chain that Phase II targets — and that is now left in a state of uncertainty by the pause.

"A pause in certification timelines should never be read as a pause in your legal obligations. DFARS clauses don't get suspended because rulemaking slows down — contractors who treat this as a compliance holiday are taking on serious risk."

— Defense cybersecurity compliance analyst, speaking on background

DFARS and NIST 800-171: The Obligations That Never Paused

The foundational compliance obligation for most defense contractors predates CMMC entirely. DFARS clause 252.204-7012, which has been in force for years, requires contractors that process, store, or transmit CUI to implement the security requirements described in NIST SP 800-171 and to report cyber incidents to the DoD within 72 hours. This clause is a contractual requirement — it is embedded in the terms of existing government contracts and does not require any further rulemaking to be enforceable.

NIST SP 800-171 itself outlines 110 security requirements across 14 families, covering everything from access control and audit logging to incident response and system integrity. Contractors are expected not only to implement these controls but to maintain a System Security Plan (SSP) documenting how they do so, and a Plan of Action and Milestones (POA&M) tracking any gaps and their remediation timelines. According to NIST's official guidance, these are living documents — not one-time checkboxes.

The pause in CMMC Phase II does not alter any of this. What it delays is the requirement for formal, third-party certification as a condition of contract award. But the underlying security controls, documentation requirements, and incident reporting obligations remain in full effect. Contractors who have not yet achieved full compliance with NIST 800-171 are still in violation of their existing contractual obligations — and that exposure is real, regardless of where the CMMC rulemaking process stands.

300K+DIB companies subject to CMMC requirements
110Security controls in NIST SP 800-171
72 hrsCyber incident reporting window under DFARS
3CMMC certification levels

Breaking Down CMMC Compliance Levels and What Each Demands

CMMC Level Target Contractors Assessment Type Key Requirements
Level 1 Handles FCI only Annual self-assessment 17 basic cybersecurity practices (FAR 52.204-21)
Level 2 Handles CUI Third-party (C3PAO) for most; self-assessment for select programs All 110 NIST SP 800-171 controls; SSP + POA&M required
Level 3 Critical/classified programs Government-led (DIBCAC) NIST SP 800-172 advanced controls on top of Level 2

The table above illustrates that even at Level 1 — the baseline — contractors must conduct annual self-assessments and attest to compliance. Misrepresenting compliance status in a self-assessment carries significant legal risk under the False Claims Act, a point the Department of Justice has signaled it takes seriously. In recent years, the DoJ has used the False Claims Act to pursue contractors who certified compliance with cybersecurity requirements they had not actually met, as detailed in coverage by Law360.

Why the DIB Supply Chain Remains a High-Value Target

The threat context that motivated CMMC in the first place has not paused alongside Phase II. Nation-state actors, particularly those linked to China, Russia, Iran, and North Korea, continue to actively target defense contractors as a route into sensitive U.S. military programs. A landmark example — cited frequently in policy discussions — involved the breach of contractors supporting the F-35 Joint Strike Fighter program, where adversaries reportedly obtained detailed design schematics through supply chain vulnerabilities rather than direct DoD network intrusions.

More recently, the Cybersecurity and Infrastructure Security Agency (CISA) and its partners have published joint advisories warning about persistent targeting of the defense industrial base. According to CISA's advisory library, contractors in sectors including aerospace, advanced manufacturing, and electronics remain among the most actively targeted segments of the U.S. economy. A pause in CMMC implementation does nothing to lower that threat level.

Server room with security monitoring systems
Defense supply chain networks remain a high-priority target for nation-state cyber actors

For developers, IT decision-makers, and small business owners operating as defense subcontractors, the practical implication is straightforward: the threat environment is unchanged, and the contractual obligations are unchanged. What has changed is that third-party certification may not be required for contract award on the current timeline — but that certification was always designed to verify compliance, not create it.

Practical Steps Contractors Should Take During the CMMC Phase II Pause

For organizations that have been treating CMMC Phase II as their primary compliance deadline, the pause presents both a risk and an opportunity. The risk is the temptation to deprioritize investment in security controls and documentation. The opportunity is using the additional time to build a genuinely robust security posture rather than one built purely to pass an audit.

Compliance professionals and IT teams should consider the following actions during this period:

  • Conduct or update your NIST 800-171 self-assessment: The SPRS (Supplier Performance Risk System) score derived from this assessment is already required under DFARS and is actively reviewed by contracting officers. A stale or inaccurate score is a red flag.
  • Review and update your System Security Plan (SSP): The SSP must accurately reflect your current environment. If your infrastructure has changed — cloud migrations, new SaaS tools, remote work configurations — your SSP needs to reflect that.
  • Maintain and mature your POA&M: A Plan of Action and Milestones is not just a documentation exercise. It signals to auditors and contracting officers that you are actively managing your compliance gaps, not ignoring them.
  • Evaluate your CUI handling practices: Many contractors underestimate the volume of CUI flowing through their systems. Email, collaboration platforms, and cloud storage all need to be assessed for CUI exposure.
  • Prepare for third-party assessment: The pause does not mean C3PAO assessments will never happen. Organizations that use this window to close gaps will be in a far stronger position when Phase II resumes than those who wait.

For organizations using cloud infrastructure to store or process CUI, it is also worth noting that CMMC and NIST 800-171 requirements apply to cloud environments. Cloud Service Providers (CSPs) used for CUI must meet FedRAMP Moderate baseline or equivalent requirements. This is a frequently overlooked compliance gap, particularly among smaller contractors who have migrated to commercial cloud platforms without verifying their compliance posture, as noted in analysis published by Gartner

Originally reported by RSS App New Cybersecurity Feed. Summarised and curated by European Purpose.