New! AI Board Member: Walk into every meeting knowing nothing was missed. Request early accessarrow_forward
Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

What survived the CMMC pause?

August 6, 2026
6 min read
Matt Goodrich

Matt Goodrich

Solution Sales Director

If you own any part of your company's Cybersecurity Maturity Model Certification (CMMC) program, you've had a long couple of weeks.

The Department of War suspended Phase II on July 13. The November assessment deadline is gone, a task force has 60 days to recommend what comes next, and officials have not ruled out ending the program in its current form.

The reaction across the defense industrial base moved fast and mostly in one direction. Budgets frozen. Projects shelved. Readiness calls pushed to next year.

If that's the conversation happening at your company right now, it's worth slowing down. What got suspended is narrower than the coverage suggests, and your position got riskier in the process.

The test paused. The requirement didn't move.

CMMC was built to verify something that already existed.

DFARS 7012 has been standard in defense contracts since 2016. It obligates you to protect covered information using NIST 800-171. Your company agreed to that years ago, probably before anyone started talking about certification.

CMMC arrived in 2020 to check whether contractors were actually doing it. In July, the government paused the checking. The obligation stayed exactly where it was.

That distinction matters most when you look at the budget. When people quote six-figure CMMC costs, the assessment itself is a small slice, generally tens of thousands every three years. The rest went into implementation, which 7012 already required. Cancel the program now and most of what you cancel was never the certification.

Why your exposure went up

Katie Arrington, who built CMMC, has leaned on the same analogy for years. We accept rules of the road, licenses, seat belts, insurance that tracks whether we follow them, because we share the road and one careless driver can hurt someone besides himself. The information superhighway is no different. That's why the requirements exist in the first place.

Here's what the pause did to that picture.

Picture the state pulling its patrol cars off the road (e.g. removing the audit requirement under CMMC). The limit holds at 55, and you could drive 85 tomorrow with nobody there to stop you. But the patrol car was never the reason for the number. The ticket was always the cheapest thing that could happen to you at 85. The expensive ones are the guardrail you crash into, your car, the other driver you injure, their car, your insurance rates, your license.

Here's what stayed on the road when the patrol car left:

  • DFARS 7012, still in every affected contract
  • NIST 800-171, unchanged as the standard you're measured against
  • Self-assessment and the annual affirmation, both still required
  • DIBCAC, which can still show up and move quickly once it does
  • The Justice Department, which has been prosecuting False Claims Act cases over inaccurate cybersecurity representations and has not slowed down
  • Your primes, who can require whatever they want from their supply chain, and many intend to keep requiring proof

Now the part that gets lost.

Your affirming official signs a statement that your security posture is what you claim. Contracts get awarded on the strength of that signature. Until July, a C3PAO was going to review the claim before it counted.

That reviewer is gone for at least a year. The signature still happens.

And False Claims Act exposure never ran through CMMC to begin with. It attaches to the representation itself, which is why DOJ has been bringing these cases since well before certification existed. CMMC was the patrol car. The FCA is the guardrail, and nobody moved it.

So the paperwork got lighter and the exposure got heavier, at the same time.

What to do between now and September

The task force reports in September. Three things are worth your attention until then.

Keep going. Whatever you were building was required before July and is required now. Stopping means restarting later, usually under a deadline you don't control.

Check your score honestly. If you suspect it's generous, correcting it now through a documented corrective action puts you in a far stronger position than having someone else find it later.

Get your evidence in order. With scheduled assessments off the table, what protects you is being able to demonstrate what you're actually doing on short notice, without rebuilding it from scratch each time. (Hint: this is exactly what Diligent is built to do for CMMC and every other framework or regulation you're on the hook for)

What we're watching next

Over the coming weeks we'll cover:

  • What the reform task force recommends in September
  • The proposed FAR CUI rule, which would extend these same protection requirements across the entire federal government, well beyond defense, and points at a newer revision of the standard than CMMC uses
  • How the government is rethinking verification itself, including FedRAMP's 20x initiative, which is arriving at a similar conclusion from a completely different direction: that checking security once every three years has run out of road.

One thing you can do this month

Alongside the suspension, the Department published a request for information. It asks contractors directly what compliance costs, which controls deliver real security, and which ones fall short. Responses are due at noon Eastern on Friday, August 14.

If you've done this work, respond. Opportunities like this are rare. The people rewriting the rules are asking the people living under them what actually works.

One thing worth keeping straight. Burdensome and useless belong in separate categories. Some requirements cost real money and earn it. Others are cheap and hollow. Treating them as one bucket is how a review meant to reduce cost ends up producing a weaker baseline that helps nobody.

Tell them what the paperwork cost you. Tell them what the security bought you. They're asking both questions.

Still have questions?

The next 60 days matter.

Whether the task force keeps CMMC largely intact, reshapes it, or replaces parts of it entirely, the same challenge remains: demonstrating that your security program is real, repeatable and defensible. The organizations that come out of this period strongest won't be the ones that paused everything. They'll be the ones that used the uncertainty to tighten their controls, improve their evidence and understand where their real exposure sits.

That's exactly what we're watching right now.

We're hosting a live webinar on August 12 2026 with our partners at 38North and A-LIGN to discuss what the pause means in practice, what we're hearing from contractors across the defense industrial base and the decisions security, compliance and operations leaders should be making before the task force reports in September.

We'll bring together the advisor's perspective, the assessor's perspective and the platform perspective, with plenty of time for questions and discussion.

Register for the webinar

Explore More

CMMC boardroom meeting with 6 professionals

Blog

· Sep 10, 2025

· 6 min read

CMMC is here: Why waiting is the biggest risk

By The Diligent team

CMMC is now mandatory for DoD contractors. Learn why delaying compliance is the biggest risk, how it impacts contracts, and the benefits of early certification.

Professionals assessing risks related to CMMC certification

Blog

· Sep 12, 2025

· 5 min read

Why CMMC exists: Security is only as strong as your weakest link

By The Diligent team

Understand CMMC's role in securing the defense supply chain. Protect sensitive data, avoid weak links, and maintain contracts.

GovRAMP boardroom meeting

Blog

· Sep 23, 2025

· 6 min read

GovRAMP: The next chapter in public sector cloud security 

By The Diligent team

GovRAMP brings FedRAMP cloud security to state & local governments. Learn how it reshapes public sector compliance & why GRC platforms are key to audit readiness.