By Kevin Plexico, Deltek senior vice president of information solutions, a seven-time Wash100 awardee and a GovCon Expert
As the Department of War reviews the future of CMMC, contractors have an opportunity to strengthen the capabilities that matter regardless of the certification timeline.
Few cybersecurity initiatives have generated as much discussion across the government contracting community as the Cybersecurity Maturity Model Certification, or CMMC, which is why the July 2026 announcement from the Department of War suspending Phase 2 implementation caught so many organizations by surprise. After years of preparing for assessments, strengthening internal controls and investing significant time and resources into compliance, many contractors are now asking the same question: What does this mean for us now?
It’s the right question. But I believe there’s another important one to consider: “What shouldn’t change because of this announcement?”
While the implementation timeline may evolve over the coming weeks, the business realities that drove CMMC in the first place have not. Protecting Controlled Unclassified Information, or CUI, strengthening cybersecurity across the Defense Industrial Base and demonstrating operational maturity remain strategic priorities, not only for the Department of War, but for every contractor entrusted with sensitive government information.
That distinction is important because the current pause affects the certification process, not the importance of the cybersecurity practices organizations have been working to build. Existing contractual obligations tied to NIST SP 800-171 and DFARS requirements remain in place where applicable, and the business case for improving cybersecurity is just as compelling today as it was before this announcement.
For many organizations, the announcement understandably creates uncertainty. For leadership teams, however, it also creates an opportunity.
Over the past several weeks, we’ve spoken with contractors across the defense industrial base, from companies preparing for their first CMMC assessment to organizations with mature cybersecurity programs already in place. As a team that works closely with government contractors navigating compliance, operational readiness and business performance challenges, we’ve seen that while every organization is evaluating the announcement through a different lens, the underlying concerns are remarkably consistent. Leaders want to know whether they should continue investing, whether planned assessments should move forward, and how this pause may affect future contract requirements.
If anything, this moment reinforces why organizations invested in cybersecurity maturity in the first place. The value was never supposed to come from earning a certification alone. It came from strengthening the organization’s ability to protect sensitive information, reduce operational risk and build confidence with government customers and partners. Those outcomes remain just as valuable today as do the DFAR compliance requirements in contracts for handling CUI.
The Most Important Question Isn’t “What’s Next?” It’s “Are We Ready?”
As organizations wait for additional guidance, I would encourage leadership teams to shift the conversation away from trying to predict what the Department of War may decide over the next 60 days and instead focus on the questions they can answer today. The answers to those questions will continue to matter regardless of how the implementation timeline evolves.
- What has actually changed? During the suspension, program managers and requiring activities may only designate CMMC Level 1 (Self) or Level 2 (Self) in solicitations — Level 2 (C3PAO) and Level 3 (DIBCAC) are off the table, and no waivers will be issued while the review is underway. This isn’t purely forward-looking: where a solicitation or contract already carries a C3PAO or DIBCAC requirement, program offices must amend it, with contracting officers directed to strip the requirement out at the next modification or before the next option period. What hasn’t moved is Phase 1 — Level 1 and Level 2 self-assessments, SPRS scoring and annual affirmations remain fully in force, as does the underlying DFARS 252.204-7012 obligation to safeguard covered defense information.
- If CMMC assessments resumed tomorrow, would we be ready? Readiness is about far more than scheduling an assessment. It reflects whether your organization has built repeatable processes, maintained current documentation and established governance that consistently supports cybersecurity objectives. This is an ideal opportunity to revisit your System Security Plan, validate where CUI resides across the organization and ensure policies accurately reflect day-to-day operations rather than assumptions made months ago.
- Are we strengthening a cybersecurity program, or simply preparing for an audit? Organizations that view cybersecurity as an operational capability rather than a compliance exercise are better positioned to adapt as requirements evolve. The pause also creates time to address gaps that may have been deferred during certification preparation. Mature governance, executive accountability, employee awareness and continuous improvement strengthen the business regardless of when an assessment occurs.
- Are our current investments creating long-term value? Many contractors are reassessing planned technology and compliance investments. Rather than asking whether to delay those initiatives altogether, leaders should consider whether those investments improve visibility, strengthen governance, automate manual processes, or reduce organizational risk. If the answer is yes, they’re likely delivering value well beyond a single certification milestone. Organizations that maintain momentum during periods of uncertainty are often the best positioned when requirements become clearer.
Looking Beyond the Next 60 Days
Government contractors don’t have the luxury of operating only when conditions are certain. Market dynamics evolve. Customer expectations change. Regulatory requirements mature. The organizations that consistently outperform are those that build resilient operations capable of adapting as circumstances change.
The same principle applies here. Every investment made to strengthen governance, improve documentation, mature cybersecurity practices and reinforce operational discipline continues to position contractors for long-term success. Those capabilities reduce organizational risk, strengthen customer confidence and prepare organizations for whatever form the next phase of CMMC ultimately takes.
That’s why I don’t view this pause as a reason to slow down. I view it as an opportunity to become even more prepared. Complying with the DFAR clause for handling CUI remains a requirement many contractors are obligated to follow with or without CMMC. It also provides a source of competitive differentiation and preparedness for whatever form CMMC takes going forward.














