This week the Department of War announced an immediate suspension of CMMC Phase II, the mandatory third-party certification requirement that was set to take effect November 10, 2026. The announcement changes the certification timeline for defense contractors across the country, including here in Hawaii and Guam, where DoD work and DoD subcontracting make up a significant share of the local business base.
If you have spent the last year preparing for a C3PAO assessment, or worrying about how to fund one, this is genuinely welcome news. But it is also easy to misread. A pause on the audit requirement is not the same as a pause on cybersecurity obligations, and the distinction matters for how you plan the rest of this year. Here is what changed, what did not, and how we recommend you respond.
Read the official release from the Department of War.
What’s Changing
The hard deadline for third-party CMMC assessment, known as C3PAO certification, is paused. This was the requirement that would have forced qualifying contractors to complete a formal outside audit of their cybersecurity controls by November 2026.
DoD leadership cited a severe capacity gap behind the decision. More than 100,000 companies in the defense industrial base would have needed a C3PAO assessment, but only about 100 assessors were available to conduct them nationwide. Independent estimates put the annual compliance cost for small and mid-size businesses at more than $7 billion.
DoD CIO Kirsten Davies put it plainly: “So the math just simply doesn’t math for small to medium-sized businesses to even get compliant by the transition date.” Under Secretary of Defense Michael Duffey framed the pause as a way to protect the industrial base itself, saying it is meant to “keep more companies in the DIB who would otherwise be forced out of the market at a time when we need them most.”
For contractors who were racing to book an assessor before the November deadline, this removes the immediate time pressure. It does not remove the underlying expectation that contractors protect controlled unclassified information.
What Isn’t Changing
This is the part worth reading twice, because it is easy to mistake a pause on third-party certification for a pause on cybersecurity requirements. It is not.
DFARS clause 252.204-7012 has required contractors handling controlled unclassified information to implement NIST SP 800-171 since December 31, 2017. That obligation exists independent of CMMC and is completely unaffected by this week’s announcement. If your contracts include this clause, and most DoD contracts of any size do, you are still expected to have those controls in place.
Phase 1 self-attestation requirements built on top of that obligation also remain in effect. That includes submitting your score to the Supplier Performance Risk System (SPRS), maintaining your Plan of Action and Milestones (POA&M) for any open items, and completing annual affirmations. These requirements are enforced through NIST SP 800-171 self-assessments and, in some cases, government-led reviews.
Davies was direct about the intent behind the pause: “We are not reducing cybersecurity through this measure. We are reducing the red tape.” She added a point worth remembering as budgets get planned for next year: “Every dollar spent on security is a wise dollar spent… that is not money that is spent in vain.”
In short, the audit requirement is paused. The security requirement is not.
What’s Next
DoD has stood up a CMMC Reform Task Force to review the program in full. It is expected to report findings within 60 days, informed by an upcoming industry Request for Information. DoD has not ruled out further changes to the program, up to and including possible cancellation. Davies described the range of outcomes still on the table as “a possibility for a number of avenues.”
That uncertainty is exactly why we would not recommend treating this as a reason to stop working on your compliance posture. A 60-day review, followed by whatever rulemaking process comes after it, can easily stretch well beyond 60 days in practice. Waiting for certainty before you act on cybersecurity is rarely a winning strategy in defense contracting, and it is not one we would advise here.
Intech’s Recommendation
This next part is our take, not a Department of War requirement.
Because Level 2 self-attestation is unaffected by this pause, and because the Task Force’s review could just as easily revise the third-party certification requirement as eliminate it, we recommend continuing to work toward CMMC Level 2 self-attestation readiness rather than pausing your efforts.
Here is the reasoning. Organizations that keep their SPRS score current and stay on top of their POA&M items now will be in a stronger position no matter which direction this goes, whether the C3PAO requirement returns in its original form, comes back revised, or is dropped entirely. The NIST SP 800-171 controls, and the DFARS 7012 clause that requires them, are not going anywhere. Those are the foundations the entire CMMC framework was built on, and they predate CMMC by seven years.
Contractors who use this pause as a reason to stand down risk finding themselves behind again the moment the Task Force publishes its findings, whatever they turn out to be. Contractors who use this window to close out POA&M items and tighten their self-attestation posture will be ready regardless of the outcome.
What We’re Watching
We are tracking this review closely and will share updates as the Task Force’s work progresses and as the industry RFI opens for comment. In the meantime, your DFARS 7012 obligations, your SPRS score, and your POA&M are the things that matter most, and none of them changed this week.
If you have questions about how this affects your specific contracts, reach out anytime. We are happy to walk through where your organization stands today and what the next 60 days should look like for your compliance roadmap.