Resources

CMMC's Phase II Pause Does Not Eliminate DFARS Obligations

Written by Jon Forisha | Jul 23, 2026

 

The Department of War's decision to suspend the rollout of CMMC Phase II has sparked a wave of emotion across the Defense Industrial Base and, in some corners, a dangerous misreading of what actually changed.

A 60-day review is now underway to address real problems: high compliance costs, a shortage of available third-party assessors, and onboarding barriers that risk pushing smaller, innovative companies out of defense work altogether.

But contractors who treat this pause as permission to stand down their security programs are setting themselves up for trouble in the future.

What's Actually Paused

The CMMC suspension applies specifically to the certification mechanics of Phase II: program offices can no longer require CMMC Level 2 C3PAO certifications or Level 3 DIBCAC assessments in active solicitations or contracts. Existing contracts will have those requirements stripped out at the next modification or option period, and pending solicitations are being amended accordingly.

Level 1 and Level 2 self-assessments, however, remain in place during the review period.

What Hasn't Changed

Here's the part getting lost in some very vocal relief: DFARS 252.204-7012 and the underlying legal obligation to safeguard covered defense information are still fully in force.

That DFARS clause (not CMMC certification) is what actually requires contractors to implement NIST SP 800-171. The CMMC certification program was always meant to verify compliance with an existing rule, not to create the rule itself. Pausing the verification step doesn't change the underlying requirement.

That distinction, and separating DFARS from CMMC, shows up clearly in how practitioners are responding to the news. In discussions among compliance professionals, the consensus is that companies can still be required to submit a Level 2 self-assessment score in SPRS, and a score below full compliance still triggers a Plan of Action and Milestones with a defined window to close the gaps; this 60-day pause changed none of that.

Several also pointed out that contractors remain exposed to False Claims Act liability for inaccurate SPRS submissions, and that DIBCAC assessments and prime requirements can still happen regardless of the Phase II freeze.

In short: the audit requirement paused, but the law didn't.

Why the Threat Picture Hasn't Slowed Down

Whatever timeline CMMC ultimately lands on, the adversaries targeting the DIB aren't waiting for it. Sophisticated threat actors are targeting defense contractors because they're after intellectual property, weapons-system data, manufacturing details, and durable footholds inside supply chains. 

To make matters worse, AI is lowering the skill and resource bar for reconnaissance, social engineering, and coordinated attacks at scale. That's a particular problem for the long tail of small and mid-sized contractors who may hold sensitive data without the security staff or budget of a prime. Smaller organizations tend to be less able to detect and defend against these kinds of nation-state threats, which is exactly why RADICL was founded.

A compliance framework, however well-designed, is only a point-in-time snapshot. It doesn't by itself tell you whether your organization can detect an adversary already inside your network, contain a compromise, or eradicate a threat before something sensitive walks out the door.

That operational capability (hardening, monitoring, threat hunting, and rapid response) matters independent of whatever certification model the Department eventually settles on. And for organizations who were building legitimate security programs on the path toward satisfying their CMMC requirements, this pause doesn't change much.

What Contractors Should Actually Do Right Now

The signal from both the official guidance and the practitioner community is remarkably consistent: separate the cost of third-party certification from the cost of actual security and compliance work, and only consider pausing the former.

Concretely, that means:

  1. Keep NIST SP 800-171 implementation moving. The 110 controls are still the standard the Department is enforcing throughout the pause.
  2. Maintain accurate self-assessments and SPRS scores. These remain a live requirement, not a formality, and misreporting them carries legal risk. Just last month, LOGZONE agreed to pay $507k to resolve allegations that it misrepresented its compliance.
  3. Close out POA&Ms and preserve evidence. Assessors (whether internal, government, or third-party) will eventually want to see everything.
  4. Keep pace on incident-response readiness. Detection and containment capability doesn't pause just because a certification deadline did.
  5. Prepare for whatever validation model emerges. A 60-day review is a reform window, not a repeal. It's worth noting here that CMMC has a long and storied history of rollout over the last eight years, and this is just the latest hiccup. Companies that used the equivalent lull during CMMC 1.0 to stand still were caught flat-footed when 2.0 arrived; there's little reason to expect a different outcome this time.

Contractors weighing where to actually cut spending during this window have a reasonable target: the C3PAO engagement itself, along with related mock assessment costs, are the pieces tied directly to the paused certification mechanism. Everything upstream of that, such as hardening, documentation, and response capability, is still required by law, still expected by primes, and still the only thing standing between a contractor and a costly intrusion.

The Bottom Line

CMMC Phase II may be on pause. But the obligation to protect Controlled Unclassified Information and Federal Contract Information is not, and neither is the intent of our adversaries trying to get at it. Companies that use this review period to strengthen their security posture will be in a stronger position no matter what the Department ultimately decides.

Companies that read the pause as permission to stop will find themselves exposed twice over: vulnerable to attack today, and unprepared for whatever comes out of the review.

Join Our Upcoming Webinar

Want more info on what to do now and what to expect when the pause ends? Register for our webinar on July 30, hosted by our compliance experts.