What the CMMC Phase II Pause Means for Your Compliance Program
by Jon Forisha on Aug 12, 2026
This is a recap of a RADICL webinar featuring Bridget Falk (Field Marketing & Events Manager) and Victor Cich (CCA, Compliance Consulting Lead).
The CMMC Pause, in Plain Terms
On July 13th, the Department of War suspended the CMMC Phase II requirements. The important part: that doesn't mean the entire program is scrapped, it's just the Phase II requirement for third-party certification.
A 60-day study is now underway to determine the program's future, with a full task force assigned to study the impact on the ecosystem. This is the latest turn in CMMC's long and uneven rollout, and it's not even the first time CMMC has been paused. We saw the same thing happen with CMMC 1.0.
Some defense contractors are reading the Phase II pause as permission to slow down their implementation and compliance efforts, but that's not something we'd recommend. As people in the ecosystem have pointed out, CMMC compliance isn't really "compliance with CMMC", it's compliance with NIST 800-171.
What Changes vs. What Stays the Same
What changes: CMMC Phase II C3PAO certification requirements are paused. This is not your Level 1 self-assessment or Level 2 self-affirmation; those are still requirements under DFARS and the FAR 52.204-21 and DFARS 252.204-7012 clauses which you will likely find in your DoD contracts.
The November 10th deadline everyone's been anticipating is indefinitely paused, and contract clauses tied to Phase II certification requirements are on hold. Assessments can still be scheduled with a C3PAO, but they're no longer contractually required. Getting one remains a strong form of insurance against False Claims Act exposure.
What stays the same: DFARS 252.204-7012 still applies to all existing contracts that include it. Adversaries haven't paused anything, and nation-state threat actors are still targeting the defense industrial base as fervently as they were before. Prime flow-down and insurance requirements remain in force because primes still want assurance that the CUI data they're sharing with you is properly protected.
Your Continued Obligations
DFARS 252.204-7012 remains a binding contract clause for covered defense information, CTI, and export-controlled data (ITAR). Implementation costs typically run higher than certification costs, but don't slow down. False Claims Act enforcement is still active, and a costly False Claims Act hit can put a small company out of business.
Self-assessments and SPRS score submissions are still expected. DIBCAC assessments are still happening. If you submitted a self-assessment with a POA&M and "get-well" dates, you should still follow through. Updating your SPRS score regularly shows a contracting officer you're actively progressing rather than gaming the system.
Bottom line: Contractual exposure hasn't moved — only the certification timeline has. NIST 800-171 and DFARS 7012 obligations have not paused. Only the Level 2 and Level 3 certification requirements have.
Highlights from the July 2026 Cyber AB Town Hall
The Cyber AB held its July 2026 town hall on July 28th, which was its first public event since the suspension.
Key takeaways:
- "CMMC implementation" isn't really a thing. CMMC is strictly the verification mechanism for conformity to NIST 800-171 Revision 2. Much of the "CMMC is too expensive" sentiment actually reflects implementation costs, not certification costs — and certification costs have dropped roughly 50% over the last several months.
- Completed assessments remain limited. As of the town hall, there were 1,866 completed (passing) assessments, against an estimated 118,000–180,000 contractors who will eventually need one.
- The real bottleneck is assessor capacity. There were 1,082 CCAs and only 637 Lead CCAs at the time of the town hall. Every assessment needs three assessors, and the math doesn't support the original November timeline.
- DIBCAC is still active. DIBCAC continues assessing candidates and authorizing C3PAOs, and eMASS remains open. These are both signs the 32 CFR framework is staying intact.
- The CMMC Reform Task Force will spend 60 days reviewing the ecosystem, including RFI responses, SMB market input, and Cyber AB feedback, with recommendations expected roughly 15 days later.
Likely drivers behind the reform include an unclear definition of CUI data size (intersecting with the forthcoming FAR CUI Rule and NIST 800-171 Revision 3), certifications being overly focused on compliance rather than security outcomes, high assessment costs, and a slow-moving assessor background-check pipeline that currently takes from 10 months up to a year.
Don't Buy Into Compliance Theater
The pause is not a reason to slow down on real security investment. NIST 800-171 and CMMC are intended to be the start of your security journey, not the end. The paperwork and checkbox exercises were never the point. The point is building real procedures, SOPs, and habits that reduce risk.
Use this pause productively: run a gap assessment against NIST 800-171 and prioritize the five-point requirements, which were flagged by the ecosystem as the highest-risk items for a reason.
Where Reform Is Likely Headed
Although right now we can only speculate what the Department of War will determine for CMMC's future, there are certainly clues and logical paths forward.
More likely: A leaner, faster path to certification for the SMB market; clearer scoping guidance for smaller contractors; and tighter alignment between CMMC and NIST 800-171 Revision 3 under a future "CMMC 3.0," likely with an extended adoption timeline.
Less likely: CMMC or NIST 800-171 compliance disappearing entirely; a return to the original November 10th Phase Two timeline; or assessments becoming optional for CUI, CTI, ITAR, or other export-controlled/critical data.
Q&A Highlights
Should subcontractors still work toward CMMC compliance?
Yes. Primes are still asking for certification. If you have questions about your specific prime's requirements, reach out directly and ask whether a self-assessment will suffice for now.
If a company never handles CUI, is a good self-assessment sufficient?
Complete a Level 1 self-assessment against the FAR 52.204-21 requirements. A Level 2 self-assessment with a POA&M in place is still a good idea — NIST 800-171 is a strong security baseline even without marked CUI.
Where should we focus our security budget for the next few months?
Focus on the five-point requirements regardless of certification status: MDR, vulnerability scanning, and MFA. Evaluate a 24/7 vSOC versus a single person managing security for your environment, and ask your MSP for a shared responsibility matrix (SRM) that maps to NIST 800-171 requirements.
Full Webinar Transcript
Bridget: All right, it looks like we've slowed down the amount of people hopping in, so let's not keep the people waiting. My name is Bridget Falk. I am our Field Marketing and Events Manager here at RADICL, and I have the great pleasure of introducing Victor, who is a CCA and runs our compliance consulting. Victor, please tell the people about yourself and let's get started.
Victor: Yeah, thank you, Bridget. So my name is Victor. Again, I manage the compliance consulting program here at RADICL. I've been a part of the CMMC ecosystem since 2019. Before that, I was helping some of the larger primes get ready for NIST 800-171, going all the way back to 2017, and then working on the classified side of the house, building out RMF and NIST 800-53. That's my background.
Bridget: Yeah, thank you. And we'll get started — so, next slide, please.
Victor: All right. So today we're really going to be covering a few different items. They are, as follows: what changes as a result of the Phase Two pause, and what stays the same; your continued obligations under DFARS and NIST 800-171; the latest from the July 2026 Cyber AB town hall — we're really going to call out some of the major things they discussed; and then how to avoid investing in compliance bureaucracy that doesn't improve your actual security. And then from there, we're going to discuss where reform is likely headed next in the CMMC ecosystem. And then after that, we'll open it up for Q&A.
All right, so the pause, in plain terms — what it is, what's going on. I'm guessing most of you have really heard what's going on in the ecosystem, since you're here. On July 13th, the Department of War suspended the CMMC Phase Two requirements. The big thing is that's not the entire program — it's just the Phase Two requirement requiring certifications. There is a 60-day study now underway to determine the program's future. There's a full task force that is being assigned to it to really study the impacts on the ecosystem, all of that. Hopefully we get some really great answers at the end of that.
This is the latest turn in CMMC's long and uneven rollout — it's not the first time CMMC has been put on pause. We first saw that back with CMMC 1.0, and honestly, I was kind of expecting something like this to happen. It wasn't specifically this, but I have been talking about some bottlenecks and issues I've been seeing in the ecosystem, and we'll discuss more of those later on.
Some contractors are reading this Phase Two pause as a green light to slow down on their implementation and compliance efforts, and I do want to talk about that a little bit further in. Again, that's not something I would recommend. Again, CMMC compliance, as people have been calling out, is not actually compliance with CMMC — it's compliance with NIST 800-171. Next slide, please.
Awesome. So, what changes with this pause and what doesn't. The big thing, again, is that CMMC Phase Two C3PAO certification requirements are paused. Now, again, this is not your self-assessment or self-affirmation for Level One or Level Two — those are still requirements under DFARS, and the FAR 52.204-21 and DFARS 252.204-7012 clause. So that part is not going away.
That November 10th deadline that we've all been talking about for the last year is now indefinitely paused. We should hear some updates after the 60 days, plus the 15 days to write up the recommendations. The contract clauses tied to the Phase Two certifications are on hold — again, that is specifically the certification requirement. We saw that in some of the larger RFPs that were coming out requiring a certification. That's what's changing.
Again, not the self-assessment or self-affirmations. Assessments can still be scheduled with a C3PAO, but they are not required by contract — again, that's where that flip goes in this requirement. In that press release, the C3PAO assessments are still happening, but again, they're not a requirement. It is a really, really great insurance against the False Claims Act to get those done.
If you've already scheduled and paid for your assessment, we are seeing some companies back out from their assessments. But again, it's not a requirement, but it is still a very good idea to get one. Again, you have that insurance of saying, "Hey, I've had a third party come in and verify that I am compliant with NIST 800-171 Revision 2 requirements."
Now, what stays the same? DFARS 252.204-7012 still applies to all existing contracts that have it. So if you're a company coming into the ecosystem saying, "Hey, I just heard CMMC is paused, I don't need to do this anymore" — yes, you do. And I would say, unfortunately, but ultimately, you do need to do it. It is still a requirement, even going into space and putting in that self-assessment or self-affirmation — it is still a requirement. Still keep pushing towards NIST 800-171, because it is still contractually required. You still have to follow FAR 52.204-21 and all of the related contract clauses to DFARS 7012. So you still have all of those. Those are still extremely important, and you are obligated to continue pushing for that.
On top of that, adversaries are still targeting the defense industrial base. They haven't paused anything. Yes, the Department of War has paused the certifications, but nation-state threat actors, or even hacktivists, or anything like that, are still targeting the DIB. And we're seeing companies still get targeted and hit — there are still incidents going out. You still have all your reporting requirements, all of that. So do not stop any of that side of your work and your compliance.
The other big thing that we are still seeing is prime flow-down and insurance requirements remain in force. I have yet to see a prime — unless something's come out in the last couple of days — say, "Hey, we are not requiring NIST 800-171 to be upheld anymore," or anything like that. Your reporting requirements to them, your affirmations to them — one of the big ones, L3Harris, I haven't seen a press release, unless something has come in in the last couple of days, saying they're backing off of their certification requirements. They still have the power to state the Department of War is not requiring this, but we want to ensure that our data that we're giving to you, and that you're going to be a custodian of, is properly protected.
And that C3PAO assessment is a fantastic way for them to actually prove that. Again, if they've got flow-down requirements, and you get hit with an incident because you're not compliant, they can possibly be held liable for not verifying that down the road. Again, it's going to be a little bit more protection on the legal side for them. Next slide, please.
Awesome. So your obligations, again, they didn't go away. DFARS 252.204-7012 still remains a binding contract clause for covered defense information — CUI, CTI, or any export-controlled data. You still have these requirements. Just because CMMC Phase Two got put on hold doesn't mean you can stop marching towards your implementation of NIST 800-171, or any of those additional export-controlled contract clauses. NIST 800-171 compliance is still required — again, that's DFARS 7012. Pause or no pause, you still need to push forward with it. That is a bit of a hard pill to swallow for a lot of contractors out there — I'm seeing the implementation cost hit a lot harder and be more expensive than the certification costs. So again, you still have this requirement — still keep pushing for it.
Don't slow down or pause. False Claims Act enforcement is still being conducted. So don't pause — that's a big risk, and if you get hit by a False Claims Act, and you're a small company, it can put you out of business. So don't stop this now. Self-assessments and the SPRS score submissions are still expected. DIBCAC assessments are still happening, so still keep conducting your self-assessments for NIST 800-171, and your SPRS and CMMC Level One and Level Two self-affirmations.
If you've got that contract clause, you still have to actually submit those — so keep doing those. Again, it is a requirement. If you have put in a self-assessment in the past and you have a POA&M with get-well dates, follow that — don't stop. That is going to be a huge red flag if you pause it, and then your contracting officer asks, "Hey, can I get an updated SPRS score," or your get-well dates stated you'd be done with everything by August 31st and you haven't done that, and you don't even respond.
That can cause them to raise a red flag and say, "Hey, we need to come audit you," and then potentially open up a False Claims Act investigation. You don't want to open your company up to that sort of liability and risk. So again, keep those self-assessments up to date, especially if you're making major progress towards your self-assessment.
If you go up 30 to 50 points, put in a new score — putting in those new scores like every month or two shows the contracting officer that you are making progress and you're not just stagnant, hitting that loophole of, "Hey, I'm going to submit a new POA&M every six months." Ultimately, CMMC and NIST 800-171 are the baseline of good security, and you want to start pushing for that.
It's not always going to cover you if there's a threat actor that's going after your information, but you can still make significant progress on protecting your proprietary information. Primes are still flowing security requirements down to their subs. Again, if you've got a prime that's saying you need to have a certification, I don't care what the Department of War said — unfortunately, you need to follow what they say if you want to work with them. If that changes in the near future, I'm going to be putting up blogs and some other videos as well, and news updates. We'll make sure to update our customer base and our news base as well, letting you know — for example, "Such and such a company decided to pause their certification requirements." Just to let you know.
So again, at the moment, that's still a requirement. We're still seeing certification requirements come from primes, but that can possibly change in the near future. Now, the contractual exposure hasn't moved — only the certification timeline has. Again, I keep harping on this, and I'm going to call it out a few more times: your NIST 800-171 and DFARS 7012 contractual obligations have not paused. It's just the certifications — Level Two and Level Three certifications. That's the only thing that has been paused. Nothing else has stopped. So again, don't stop your progress — keep marching forward. I don't think CMMC is going anywhere at all. There's been too much invested in the ecosystem and verification. Next slide, please.
Awesome. So now this is going to be some of the bigger news that's been coming out of the Cyber AB town hall. Again, this is the first public event they've had since the release of the suspension. The Cyber AB held its July 2026 town hall shortly after the suspension, which was conducted on July 28th — so about two days before this webinar. The big things that I'm calling out here are what I think are the really large things to note. There's a lot of information in their slide deck and in that recording, and a lot of great questions were asked. So if you want to go look at that and watch the recording, feel free — they usually upload the full recording with the slide deck to their website, cyberab.org, usually within a couple of days of the town hall.
But the big things they wanted to call out: CMMC "implementation" is not really a thing. It's often used in the context of the cost of conforming to NIST 800-171. Again, CMMC is strictly the verification mechanism for conformity to NIST 800-171 Revision 2, specifically at this time. So there's a bit of an issue we've seen in the ecosystem — people are saying "CMMC is super expensive, we're spending tens of thousands, I've even heard hundreds of thousands of dollars to get compliant." That's an issue. "I don't want to do this." And they're misunderstanding — comparing the certification cost to the actual implementation cost of NIST 800-171.
It's a huge difference. It costs a lot more, in my experience, to get compliant with NIST 800-171 compared to the certification costs. Now, a year ago, when certifications were first happening, there was a bit of a gold rush that I was seeing — certifications were very, very expensive. I've been seeing those come down over the last several months quite a bit, by easily 50%. And it's making it a lot easier, but it's still not completely affordable, especially for the super small companies, the mom-and-pop shops. That $40,000–$50,000 is a major, major cost that hopefully we will get some answers for down the road. Again, I've got some ideas I'm going to talk about a little bit later in this webinar about how I think the ecosystem is going to change — things like that.
Now, the other big thing that the Cyber AB called out was completed CMMC assessments as final. There are currently 1,866 assessments that have been completed — those are passing ones. Now, if we look at that number again, this is going to give some really key insight into why Phase Two was put on hold. We've heard a couple of different numbers — 118,000 companies needing to be certified, up to 180,000, all of that. And we were expecting 20 to 30% of the contracts in November to have this certification requirement. Now, if we're seeing that there's only 1,800 companies that have gotten certified — for me, that's a huge, huge flag as to why the requirement was put on hold.
Now, it's not just on the OSCs, or the organizations seeking certification, as to why there aren't more. There's a major bottleneck in the ecosystem, and that's going to go into the CCAs and Lead CCAs that we've got listed below. Now, a CCA, for anyone that doesn't know, is a Certified CMMC Assessor, and a Lead CCA is just the lead management role. So as of two days ago, there are 1,082 CCAs out there — that's a 9% increase — and there are only 637 Lead CCAs out there. And again, that's a 7% increase. That is not a lot, especially when you need three assessors on an assessment. So you need a Lead CCA, a regular CCA, and a quality assurance individual, who has to be a CCP or a Lead CCP. So that's three assessors for one assessment.
If it's taking 3 to 5 days to conduct an assessment — I've heard some C3PAOs are getting them done a little quicker — the math doesn't add up. So, out of the 1,082 CCAs, 637 of those are Lead CCAs, so that leaves roughly 445 that are not Lead CCAs. And I will also state that some of those CCAs are not conducting assessments. I've heard countless times that some of the more reputable RPOs, such as RADICL, have CCAs who are not conducting assessments. I'm a prime example of that — not all of those CCAs are actively working assessments.
So there's just not enough assessors to go around to actually hit that original goal for November of getting through all of these assessments. I was expecting probably 20,000 would be the number needed to stay on schedule. We're like just under 10% of that. So again, that's why I'm not surprised the Department of War came out and paused the certification requirement — there's just not enough time to get everyone through, not enough assessors, it's expensive. There's so many issues in the ecosystem that need to be solved in that task force being built for the 60-day review.
They're looking at the Request for Information from CMMC.gov, all of that, to really understand what recommendations they can give leadership on moving forward. Next — actually, let's go back one more. So DIBCAC is continuing to assess candidates and authorize C3PAOs — for me, that's a pretty good sign that CMMC isn't going anywhere. If they had paused those, I'd be very concerned that assessments are not going to be a requirement. Again, eMASS is open — they're still keeping the 32 CFR part of the ecosystem completely alive.
Now, the bigger thing is DIBCAC is continuing to assess OSCs — so the SMB market, or even the market as a whole, for NIST 800-171 assessments. We've seen quite a few come through — again, these are usually tied to a False Claims Act red flag that's been raised, and DIBCAC is coming in to do an assessment. Again, those are very high-impact assessments — they are not fun to go through. You will usually deal with some really frustrating interpretations from those teams. It is very stressful for your organization, and you do not want to fail those, because that can lead to False Claims Act fines, all of that. Next slide, please.
Next, we've got the CMMC Reform Task Force. Again, that is the task force and group that is going to go through the Request for Information, or RFI, looking at everything in the ecosystem, talking to the SMB market, the SBA, and the Cyber AB. The Cyber AB is a part of this task force now. So they're going to be reviewing things for 60 days, then approximately 15 days after that, they're going to have a write-up with recommendations. Again, this is the government we're talking about — I don't know if that 15-day mark is going to actually be hit. It'd be amazing if it was, but I don't know if it will be.
Now, the likely drivers that the Cyber AB is calling out as behind this reform: again, there's no clear definition of the size or scope of CUI, and this is making conformity and certification to a standard extremely problematic. Now, this is going to tie into some of the other events going on in the ecosystem, and even outside of the defense industrial base. So we've got the FAR CUI Rule, which is supposedly coming out later this year — I've been told around December — that is supposed to make the identification of CUI in new contracts easier. There's going to be a new DD Form, and it should make it easier and more streamlined to identify what the CUI data is.
Now, we did hear — I think it was earlier this month, or the end of last month — that there was an update to the FAR CUI Rule. It's not a surprise to me that this is happening alongside that, just because they could be seeing the FAR CUI Rule is pushing towards NIST 800-171 Revision 3, and those are it's a massive undertaking to switch from Revision 2 to Revision 3. Revision 2 is outdated, so it's going to be a whole rewrite of the rule.
So again, they might come back and say, "Hey, we recommend you adjust to a 'CMMC 3.0' update to Revision 3," with these organizationally defined parameters that we've stated we recommend. Now again, that's probably tied in with that as well. And on top of that, we did hear that there's an update to the CMMC rule coming out, again tying NIST 800-171 Revision 3 into the ecosystem. We were expecting this, and this is kind of the perfect storm — after Revision 3 was released, there were a lot of questions back then of, "Hey, what do we do? Do I need to rewrite my entire program, my SSP?" And the DoD came out and said, "Hey, for now, adhere to Revision 2, not Revision 3."
We have been expecting that there's going to be something coming out pushing towards Revision 3 — all of these things combined into that perfect storm is probably what's driving some of this CMMC reform. The other big thing is CMMC certifications are overly focused on just compliance, not just the security. A lot of it is just a check-the-box exercise. And we even called this out in our RFI comments — CMMC is the baseline for good security, so you don't want to just pause and say, "Hey, I'm checking the box, I'm not going to look at this for six months." That is an issue that we've been seeing in the ecosystem. That's one thing that's probably going to be called out — these checkbox requirements might go away. We don't know, but again, it is overly focused on just compliance and not the actual security posture.
Now, CMMC also costs too much and is driving companies out of the defense industrial base. And when I say CMMC costs too much, I'm not just talking about the implementation costs — yes, that's a portion of it — but the certification costs. A lot of companies have been complaining that the cost of an assessment is extremely expensive, especially if you fail, then you have to pay for it again. Some of these assessments are $40,000–$45,000 on average. So if you're paying $80,000–$90,000 because you've failed an assessment, it's ridiculous, and a lot of companies have been pretty frustrated over that.
So we might see — and this is my opinion right here — some C3PAOs out there might have been interpreting the 32 CFR, the CMMC rule, a little bit wrong. The 32 CFR calls out that there needs to be a Lead Assessor, a CCA, and a CCP for QA in assessments. What I'm seeing is the Lead Assessor there the entire time, and usually 50% of the time they're not saying anything — they're not asking questions. They might come out and say your Lead needs to be there 10% of the time, to hop in and make sure the CCP is conducting the assessment correctly, since the CCA is going to ask all the questions. That way the Lead CCA can jump between multiple assessments and actually manage — that's what the Lead CCA is supposed to be doing. They're supposed to be managing the assessment process, managing the teams, and making sure the assessments are going correctly.
If they're in one assessment at a time, they're not jumping around — they're slowing down the ecosystem from getting through compliance. And honestly, it's my opinion that it's a waste of resources to have two assessors in there where half the time one of them isn't asking questions, they're just listening to the other. Those meetings are recorded — you can bring in AI to possibly transcribe and give meeting notes to the Lead CCA, who can then streamline the process and say, "Okay, you did a good job, I don't disagree with anything, let's kick this assessment over to the CCP for QA." They look at it for five to ten hours and say, "Okay, no issues, you're good to go, let's push this forward."
That could be an amazing way to streamline the entire assessment, which then saves money, because if you're not paying for a Lead CCA to be in there for the entire assessment, then you can cut the assessment costs by $10,000–$15,000. That is an amazing way to save money for the SMB market. There's been some other rumblings out there that they might say just the five-point requirements in NIST 800-171 are going to be assessed by C3PAOs, and all those one-point requirements can be self-assessed. That's another way they can bring down the costs. Again, there's a lot of ideas that I have heard for cost savings that can be done.
So those might be some things that are driving the reform, and hopefully we get some really great answers at the end of the 60-day period. The current environment — again, this is kind of what they were calling out — CMMC is always evolving. Again, we've seen that in the past, CMMC 1.0 to 2.0, and then on top of that, NIST 800-171 Revision 2 to Revision 3, we're going to eventually see a "CMMC 3.0" or "4.0."
Again, CMMC is not going away — it's going to keep evolving. It's expanding out possibly to other departments and agencies, or at least NIST 800-171 will. So again, that's what we're seeing — there's always room for improvement, or at least from what I have seen. Again, I've already called out some of these for the costs, but the big thing I'm seeing right now is a lot of these CCAs — again, we saw the 1,082 CCAs out there — there are hundreds, if not more, in the pipeline right now who have passed their exam. They're ready to get authorized, they're just waiting on their Tier 3 suitability background check. That's the equivalent of a secret clearance, but they're not actually getting the clearance, and it's taking ten months to a year to get that.
That is a major, major hole in the ecosystem that can be plugged — using a public trust background check, or a normal criminal background check, is an easy way to speed up the number of assessors and open up that pipeline. Now, the other thing they're calling out is that certifications remain the best insurance against the False Claims Act. Now, again, we know DIBCAC is still going out and reviewing and doing assessments. Again, if you want to save your company from fines, you can always get a certification — those are not going away, you can still pay for one. The cost of a certification is much cheaper than a False Claims Act fine, and possibly having to pay back any of those additional payments, or anything like that.
Again, from experience, we've seen millions of dollars in fines for some of these companies, so paying $45,000 for an assessment compared to a few million is a drop in the bucket. And we've definitely seen where, if a company is certified and reaches out and says, "Hey, you've been scheduled for a DIBCAC assessment" — the company has been able to come in and say, "Hey, I just got a C3PAO assessment a week ago, or a month ago, here's the results, here's the C3PAO," and they just uploaded everything to eMASS. DIBCAC turns around and says, "Okay, you're good to go," and they cancel the assessment. So again, it's an added benefit — C3PAO assessments, from what I've seen, are much easier than DIBCAC's. DIBCAC sometimes has some bizarre interpretations that I have seen, that I do not agree with — none of the C3PAOs I've talked to agree with them either, none of the CCAs or Lead CCAs. It's just completely out there.
So again, it's easier and cheaper to go through a certification than to go through a DIBCAC assessment. Again, it's a risk, and a little bit of insurance to save you some money and heartache. Next slide, please.
All right, so the big thing I want to talk about now is really just: don't buy into the compliance theater. A lot of CMMC has been theater — a lot of snake-oil salesmen, and a lot of "the sky is falling" right now with this pause. A pause is not a reason to slow down on your real security investment. Again, NIST 800-171 and CMMC are the start of your security journey — it is not where you should end.
Ultimately, you need a strong security back end — a strong MSP, MDR, and vSOC to protect you. Now, I know a 24/7 vSOC is not a Level Two requirement — you see that more at Level Three — but having that added security to triage an incident, then do a deep dive on it, and tell you, "Hey, we found this issue, your EDR agent flagged it but didn't do a deeper look at it, we found this issue, here's our recommendation" — or even when it comes to incident response, having that vSOC there for an incident response team is amazing. I've lost track of how many times a vSOC has found something, or an agent like Defender or CrowdStrike has flagged something, and they're like, "Hey, we think this is a false positive," but our analyst goes in and finds something real.
Again, this is the bare minimum, the basics of proper security, and where you should grow from — especially if you are in the DIB and you are accelerating fast, going through Series A, Series B, and getting funding. Spend the money on security. You don't want to have a ransomware attack that takes down your entire infrastructure, or lose all of your proprietary information. These are the risks we're looking at protecting against. It's not just a checkbox. So again, the paperwork and checkbox exercises were never the point of CMMC — it's to build proper procedures, SOPs, and habits.
That's what NIST 800-171 and CMMC are trying to do — again, it's to better protect you, better protect your company, your information, and the country. Again, the goal has always been to reduce the risk, not produce a certificate. So if you care about your security posture, and you've got leadership saying, "Hey, this is paused, we can stop," say, "These are the risks that we're seeing right here, we recommend you push forward, and we still do everything," because there are ransomware attacks that happen every day, zero-day exploits that we see. You don't want to be caught unaware and lose thousands, if not millions, of dollars because you lost data. If your infrastructure gets hit with an incident, your servers get locked down, and you've got deliverables, you could lose a contract because you're locked out and there's nothing you can do.
So again, NIST 800-171 is teaching you the basics of how to get compliant — not just compliant, but to improve your security posture. So keep pushing forward. Spend the time from the pause closing the real gaps in your security. If you are just getting started, or you're halfway through, do a hard gap assessment against NIST 800-171 and figure out what your major risks are. A really good way to look at those — look at those five-point requirements. Those are what the Department of War and the ecosystem has identified as major risks. Try and chase those down, create great processes and procedures around them, and improve your tech stack to really improve things.
Again, it's not just about a checkbox, it's about improving your security. And that's one of the things we're most passionate about — we use CMMC to teach and say, "Hey, you're doing this process, there's a better way to do it, and better technology that you can utilize to improve your security posture." Next slide, please.
All right, so I think this is going to be one of the last slides, if I remember correctly, and then we'll open it up to Q&A. So, where reform is likely headed — again, a lot of this is going to be more opinion and best guesses, based on rumblings I've heard from the ecosystem. I'm expecting a leaner, faster path to certification. Again, I've called out some of those ideas I've heard — I think that's where they're going to go. They need to make it easier and cheaper for the mom-and-pop shops and the SMB market to get certified, not just compliant. That's going to have a bit of a higher price tag, but there's always cheaper ways to come in and learn about what technology you can use.
So that's what I'm expecting there. I'm expecting clearer scoping guidance for some smaller contractors. Again, I've lost count of how many times I've spoken to a contractor, even a customer or a prospect, who says, "I don't know what CUI I have, I don't know where to start, what to scope, or even what to do to start." So I'm expecting a lot more guidance from the Department of War and this reform task force to make it easier for these smaller companies.
Next is going to be tighter alignment between CMMC and the existing requirements — again, that's going to be NIST 800-171 Revision 2 to Revision 3. I am expecting a change to a "CMMC 3.0," where they're going to say, "We're pushing things back, possibly a couple of years, where you need to adhere to Revision 3, but we're giving you more time to get certified and ready."
So again, that's one of the big things I'm expecting that's fairly likely. What's going to be less likely — and again, these are my opinions — CMMC compliance and NIST 800-171 compliance requirements disappearing altogether. There are major reasons why NIST 800-171 and CMMC are in place. First, we saw that NIST 800-171 was a self-affirmation, a self-assessment, and there were major loopholes — like 80% of the industry was non-compliant. We're seeing that right now — there has been this major rush of companies trying to get compliant because they haven't been for years. So that's really what drove CMMC — there needed to be a checks-and-balances system in the ecosystem so they could really ensure companies were being compliant.
Now, again, I don't think the requirements are going anywhere. We're looking at protecting data, we're looking at protecting that data from nation-state threat actors — China, Iran, North Korea, Russia. They're going for the small shops, because they know they don't have the tech stacks and security postures to protect their proprietary information, which they can then take and reverse-engineer some of our more classified programs. We've already seen that a few times in the ecosystem already.
Now, the other thing that I think is going to be a little less likely is a return to the original Phase Two timeline. I really don't think November 10th is going to be the new or updated timeline — I think they're going to push it back. I would expect at least 60 to 90 days. My opinion is it's going to be longer — there are too many major pipeline issues that we're running into. I don't think we're going to see this hit January 1st or January 10th, 2027. I think it's going to be further out. We need to build more of the backbone and structure of the ecosystem to actually support it.
Now, next is assessments becoming optional for critical data. I've heard some companies think, "Hey, this is going to be optional." If you're dealing with Controlled Unclassified Information, ITAR, or any export control data, anything dealing with space, weapon systems, things like that — don't expect any of this to go away, at least the self-assessments and the conformity requirements. This is critical data that you will most likely need to protect, and again, I don't see this going away for that data, just because nation-state threat actors are still targeting our SMB market.
Victor: Awesome, I think that's the next slide, and I think that's going to open it up to Q&A. So, any questions?
Bridget: All right, thank you, Victor. We did have some questions come through. The first one is: we were expected to be certified by 11/10 — or was it a phased approach, meaning to be certified sometime between 11/10 of '26 and 11/10 of '27?
Victor: Yes, so what I've been telling our customers prior to the pause is: if you are pursuing a new contract for November 11th or November 12th, and you see that clause, that's where you need it. If you're just working on an existing SBIR/STTR Phase Two award, and it's good for three years, and you're not planning on going for any new contracts, you don't have that certification requirement — or at least that's what I was expecting, just because your current contracts have just that self-assessment. So it was more of a phased approach, not just a hard deadline of "if you're not certified by November 10th, you can't do any work." I wasn't even expecting all contracts to have that certification requirement in there — again, I was expecting maybe 20 to 30% of them. So again, I was expecting a phased approach, but we don't know, and we won't know until they restate the phased approach for Phase Two.
Bridget: All right, next question. How would a small organization tackle these requirements?
Victor: That is a very, very fun question. The big thing is to start small. Figure out where your data is, what systems interact with it, and then build a plan from there. Once you sit down and have a plan — "okay, this is where my data is, these are the systems that touch it, and these are the people that touch it" — you can then reach out to an RPO, such as RADICL, to start discussing. "Hey, we want to have a plan, we don't know what technologies we can use." A good RPO will say, "Hey, here are the different things you can do to build out your infrastructure, here are the options, the pros and cons of each one, which one would you like?" And then they will usually have partners who will say, "Hey, we can go implement this for you," or give you guidance on implementing it yourself. That's where I would start. Again, it doesn't need to be super expensive to get compliant — you can build something for much cheaper yourself. If you've got a little bit of tech background and experience building out infrastructure, it can be very small and still pass.
Bridget: Should we still work towards CMMC compliance as subcontractors?
Victor: Yes. So I'm still seeing all those primes still require or ask for those certifications. Again, maybe I haven't heard something that's come out that they're telling subs otherwise, but from everything I've been told, they are still requiring compliance — so don't stop. If you have a question for your prime — I'll use L3Harris as an example, they had a July 30th timeline of wanting you certified — if you're not going to make that, or if you've got questions on that, reach out to your prime. Ask, "Hey, you wanted a certification, is this still a requirement, or does a self-assessment work?" So just open the door for communication. Again, they're probably going to be expecting questions from you. Don't hold back — if you're not asking the question, you're not going to get an answer, which again is going to be an issue for you down the road if you're not communicating with your prime.
Bridget: Okay, next question. If a company never handles CUI data, is a good self-assessment going to be an acceptable requirement?
Victor: Okay, so if you don't handle any CUI and you don't plan to, what I usually say is: do a Level One self-assessment, or an assessment against the first 15 requirements called out in Level One — that ties into the FAR 52.204-21 clause. Do that self-assessment, and then if any company is trying to push back and say, "Hey, you need a certification," you don't have any CUI, you don't have anything marked, and it's just a prime requiring it, push back and say, "I don't have this data, I've completed my Level One assessment, I'm good to go." But if you want to be safe, still complete that Level Two self-assessment and have a plan of action in place for any gaps you have. Again, NIST 800-171 is the baseline of your security — they are really good to have in place, even if you don't have any marked CUI. You have personally identifiable information, you have your employees' information you want to protect as best as possible, and these security requirements really are a good starting point for you to get there.
Bridget: Okay, if the rule is being restarted, is there a chance CMMC gets scrapped entirely, or is some version of it inevitable?
Victor: I think some version of CMMC is going to be inevitable. Again, I'm going to point back to what the Cyber AB has said — now, they've got some vested interest in it, because they're a direct contractor for the Department of War, and they're going to fight to keep it. But there's been so much money dumped into the ecosystem, I don't think it's just going to go away. There's going to be some major revisions probably, but again, those requirements — even if CMMC goes away — you still have that NIST 800-171 requirement, and you still need to adhere to that. That is absolutely not going away. Again, we're seeing that even across the board, and with the FAR CUI Rule, we're expecting NIST 800-171 to expand out to every federal agency and department across the country. So that is absolutely not going away. The certification requirement might, but that's just one portion of CMMC — the other portion is that self-assessment and being able to actually document, "Okay, this is what I meet, this is what I don't meet, these are the ones I don't hit, this is my POA&M," and having that structure in place. I think it's super useful. I don't think it's going anywhere. Again, I do expect those major revisions to come.
Bridget: A few more questions. If we've already started our SSP and POA&M, should we keep building them out during the pause, or wait?
Victor: Absolutely, keep building it out. Do not pause. Again, you've got that NIST 800-171 obligation — keep going, keep chugging along. The biggest thing I would suggest is, if you've done that initial gap assessment and you're building your SSP, look at those five-point requirements. Those should be the first ones you hit — again, those are the most critical, even outside of a certification program. There's a reason they're five points — they are very risky. Not patching your machines, not patching vulnerabilities — there are exploits all the time coming out, and keeping your machines up to date ties into a couple of five-point requirements. It's key. So keep pushing forward, keep trying to build out your own processes, and get that POA&M in place, making sure you're actually moving forward — even if CMMC certifications go away completely, which I doubt they will. Again, it's the best practice for you to keep pushing forward.
Bridget: Great, next question. Our prime is still asking about our compliance status — what do we tell them if CMMC itself is paused?
Victor: Yes, so again, I touched on this a little bit earlier, but I'm still seeing primes have those flow-down requirements and require or request affirmations, statements, and POA&Ms from their subs. So if they're still asking for it, again, they can go around the Department of War and say, "They might have paused it, but we're still going to require this if you want to work with us." Again, that could be a major issue down the road — they're independent contractors, they're the primes, they can require pretty much anything if you want to work for them. And that's one thing I do see them doing, and I know the Cyber AB is probably going to be leaning on some of those larger primes to really set the example for the ecosystem.
Bridget: Okay, this is our final question — so if there are any other questions out there, please send them in through the chat. But where should we be focusing our security budget for the next few months, if not on CMMC assessment prep?
Victor: That's a good question. I would probably say, let's have you focus again on those five-point requirements. Even if you're not pushing for CMMC, identify those major gaps and how you can build towards them, and actually improve your posture — get an MDR in place, do vulnerability scanning, those basics. There are some free tools you can use out there, even for multi-factor authentication — set those up. Identify those gaps, build a plan, spend your budget to actually increase your security posture. Don't just do the check-the-box of, "Oh, I've got Microsoft Defender, I'm good to go." Look at the pros and cons of having a full vSOC or security team, compared to having one person manage 100 devices. Having that 24/7 SOC, for example, is amazing, because if that person is on vacation and you run into a security incident — ransomware hits, they can't get back, they can't do anything, they can't quarantine machines — having that ability, and that team from an MSP, to support you is extremely valuable. So look at some of your options out there and try to spend that money in your budget, even before CMMC, on those things. If you're talking to an MSP and looking at building out that security stack, ask for an SRM — a shared responsibility matrix — they should be able to give it to you, and that will even cover you when CMMC Phase Two certifications do come back, or you're still pushing for that Level Two affirmation, because it can check off a bunch of requirements for you, which just makes your life easier.
Bridget: Okay, no new questions came in, so we will go ahead and begin wrapping up. On behalf of RADICL and Victor, we just want to thank you so much for your time today. I will be sending out an email post-event with a copy of the recording and the deck, and should you have any more questions, please feel free to reach out there. Or I can share Victor's email if you'd like to reach out to him directly. But we are here, we are available, and yeah — thank you again so much for your time.
- DIB Innovators (127)
- Podcast (126)
- Industry Analysis (103)
- Threat Hunting and Intelligence (28)
- Regulatory Compliance (24)
- Attack Surface and Vulnerability Management (15)
- CMMC (14)
- Zero Gravity Summit (11)
- General (6)
- Company (5)
- Security Operations & vSOC (5)
- Signal & Noise (5)
- Testimonials (5)
- Founder (4)
- Incident Response (3)
- Managed Security Operations (3)
- Operational Resilience (2)
- Threat Management (1)
- Webinar (1)
You May Also Like
These Related Stories

CMMC Compliance Deadline 2026: Key Dates That Affect Your DoD Contract

CMMC Enclave: What It Is, When It Works, and How to Build the Right Compliance Boundary


No Comments Yet
Let us know what you think