CMMC Phase II is paused. What now? Free webinar. Watch Now →

CMMC Is Paused. Should You Be? Contractors Weigh In

When the Department of War announced the suspension of CMMC Phase II requirements on July 13, 2026, defense contractors were given something many had been asking for: more time.

But more time has also created a new question: What should organizations actually do with it?

The Department suspended the transition to Phase II, which had been scheduled to begin November 10, 2026, and launched a 60-day review of the program. Phase I self-assessment requirements remain in effect, and contractors are still required to protect federal data and meet applicable cybersecurity obligations, including NIST SP 800-171 Rev. 2 and DFARS 252.204-7012 requirements.

The CMMC ecosystem has not stopped either. The Cyber AB reported in July that nearly 2,000 defense contractors had already achieved CMMC Level 2 certification, and its August response to the Department’s reform effort reported more than 110 C3PAOs operating in the ecosystem.

To understand how companies are responding in practice, Alluvionic hosted CMMC During the Pause: What Contractors Are Doing Now, bringing together organizations at very different points in the CMMC journey.

The panel featured:

  • Seni Lebron, Commercial BD & Project Manager at Alluvionic, as moderator
  • Dave Sullivan, Cybersecurity & IT Operations Manager at Alluvionic and CMMC Certified Assessor
  • James Castellano, IT Director at Southeast Aerospace, which recently achieved CMMC Level 2 certification
  • Kevin Juhl, PE, Director of the Industrial Group at GBA and leader of the organization’s CMMC task force, currently working through remediation

Their experiences differed, but the message was remarkably consistent: the pause may change the certification timeline, but it does not erase the reasons organizations started preparing in the first place.

1. The CMMC Pause Is About Timing, Not the End of Cybersecurity Requirements

The first priority for contractors is understanding exactly what changed.

CMMC Is Paused. Should You Be? Contractors Weigh In

The Department’s July announcement suspended the move into Phase II and paused upcoming implementation milestones while the CMMC Reform Task Force reviews the program. At the same time, the Department explicitly stated that Phase I remains in place and that defense contractors and subcontractors remain responsible for protecting covered defense information.

For organizations trying to sort through the headlines, Alluvionic’s CMMC Phase II Suspension FAQs provides a detailed breakdown of what remains in effect.

During the webinar, Sullivan encouraged contractors to use the additional time to go back to their actual contracts, identify the cybersecurity requirements that apply, and confirm they are meeting them. That includes understanding the systems, people and data that fall within scope, maintaining accurate compliance documentation, and being prepared to respond appropriately to a cyber incident.

DFARS 252.204-7012, for example, continues to require covered contractors to provide adequate security and rapidly report qualifying cyber incidents within 72 hours.

The practical takeaway: don’t make compliance decisions based on the word “pause” alone. Start with the requirements that actually apply to your contracts.

2. If the Business Reason Hasn’t Changed, Neither Should the Goal

For GBA, the announcement prompted an immediate question on everyone’s minds: Can we stop?

The answer was no.

Juhl explained that GBA originally began pursuing CMMC because of the federal work it performs and the future contracts it wants to remain eligible to pursue. The timing may have shifted, but those business reasons remain.

Kevin Juhl“Remembering why you got into this in the first place” is critical, Juhl said.

His advice to other contractors was to step away from the day-to-day complexity and reconsider the bigger picture. If the organization still intends to pursue work that requires strong protection of CUI or expects customers and primes to demand CMMC readiness, stopping may simply create a larger problem later.

For GBA, the pause has actually created room to re-evaluate and expand its planned CMMC scope to support additional anticipated work.

The pause can be used to change the pace, sequencing or cost profile of readiness without abandoning the objective.

3. Stopping Can Cost More Than Continuing at a Sustainable Pace

One of the less obvious risks of stopping is losing momentum.

CMMC readiness typically competes with employees’ normal responsibilities. Juhl noted that if GBA completely paused its program, the people involved would return to their day jobs, priorities would shift and restarting the initiative later could become significantly more difficult.

“If we stopped, if we paused, we would totally lose all of our momentum.” — Kevin Juhl

Southeast Aerospace reached the same conclusion from the opposite side of the journey.

Castellano’s organization completed its assessment shortly before the Phase II suspension. Looking back, his biggest warning to companies now considering waiting was simple:

James Castellano“Don’t wait until last minute.” — James Castellano

He explained further:

“Take this pause as an opportunity to move forward at a good pace, and save yourself the sleepless nights trying to understand the requirements when you’re not a CMMC expert.”

The technical implementation was only part of the work. Policies, procedures, documentation, evidence and preparation took substantially more effort than he initially anticipated. Southeast Aerospace ultimately pushed its assessment back twice to make sure the organization was truly ready.

Rather than treating the pause as permission to procrastinate, contractors can use it to move through readiness at a more manageable pace and reduce the last-minute pressure that comes with a fixed assessment deadline.

4. Scoping May Be One of the Highest-Value Activities to Do Now

If an organization wants to reduce unnecessary CMMC cost, Sullivan pointed to scoping as one of the most valuable areas to revisit.

Organizations need a clear understanding of where CUI exists, who needs access to it, what systems process it and which technologies or external providers touch the environment.

Getting that wrong can create problems in either direction.

“If you over-scope, you are just spending way more money than you need to.” — Dave Sullivan

Underscoping, however, creates its own risk because systems or data that should have been protected may be left outside the compliance boundary.

Southeast Aerospace offers a practical example. The company initially considered bringing its entire organization into scope but ultimately determined that only eight users needed to be included. It implemented an enclave solution that helped narrow the CUI environment and reduce the number of systems and users subject to the program.

Contractors revisiting their own boundaries can also review Alluvionic’s resources on CMMC readiness, scoping and assessment preparation.

5. Documentation and Evidence Are Where Readiness Becomes Real

When asked what he wished he had understood earlier, Castellano needed only one word:

“Documentation.”

A company may have cybersecurity technology in place and still struggle during an assessment if it cannot demonstrate what is implemented, how it is managed and whether documented processes match actual operations.

Castellano recommended starting documentation early and using a gap assessment or pre-assessment before committing to the formal assessment process. For Southeast Aerospace, the pre-assessment helped answer questions, guide implementation and build confidence before the C3PAO assessment.

Sullivan reinforced the same point from an assessor’s perspective. Readiness is not simply about having a security tool or configuration.

“It’s about proving it.” — Dave Sullivan

Evidence must be both appropriate to the requirement and sufficient to demonstrate that the organization is consistently meeting it. That means aligning technical configurations, policies, procedures and evidence rather than treating each as a separate compliance exercise.

This focus on proof is also why CMMC should not live exclusively within IT. Successful readiness requires coordination across contracts, operations, HR, leadership and other business functions. Read more in CMMC Is More Than IT: Building the Team You Need to Succeed.

6. Certification Is a Beginning, Not the Finish Line

For organizations that have already achieved Level 2 certification, the work changes, but it does not disappear.

Castellano described life after certification as maintaining the processes the organization worked so hard to establish: scheduled reviews, training, configuration baselines, patching, documenting changes and maintaining records.

The difference is that those practices are now built into how the company operates.

“There is a process, there is a procedure, and we can follow it.” — James Castellano

Certification has also affected Southeast Aerospace’s business conversations. According to Castellano, feedback from program management has been positive because certification removes uncertainty for customers and primes and can support new business opportunities.

That competitive value remains relevant during the pause. The Cyber AB has emphasized that C3PAO assessments remain available even though mandatory Phase II implementation has been suspended.

Other contractors are seeing the business case as well. In a recent Alluvionic customer story, ITI Engineering pursued Level 2 certification to protect multi-million-dollar defense opportunities.

7. CMMC Requires Real Time and Cross-Functional Ownership

The panel also addressed a question many organizations underestimate: How much internal effort does CMMC actually require?

There is no universal answer because the workload depends heavily on organizational size, scope, technology, existing maturity and the amount of work handled by outside providers.

GBA’s experience provides one example. Its core CMMC task force includes approximately five people doing much of the work, with another group providing oversight. Juhl estimated that the non-IT members often spend roughly five to 10 hours per week on CMMC work, while IT resources may spend substantially more.

One of GBA’s biggest lessons was that technical teams and operational teams initially believed they understood one another better than they actually did. The organization eventually had to return to basics, with business teams explaining how work was performed and IT explaining the technology and compliance implications.

The experience reinforces an important reality: CMMC readiness is not simply a cybersecurity implementation. It is an organizational change effort.

Use the Pause to Build a Stronger Position

No one knows exactly what the CMMC Reform Task Force will ultimately recommend. The Department has said its review will focus on reducing unnecessary burden while maintaining meaningful cybersecurity protections, particularly for small, medium-sized and non-traditional businesses.

But organizations do not need to wait for every future detail before making progress.

Contractors can use this time to:

  • Confirm the requirements that apply to current and future contracts
  • Revisit CUI and CMMC scope
  • Address cybersecurity gaps
  • Improve documentation and evidence
  • Strengthen cross-functional ownership
  • Complete gap assessments or readiness reviews
  • Build sustainable processes instead of racing toward an assessment deadline

The pause created additional runway. The contractors in this discussion are using it not simply to wait, but to become better prepared for whatever comes next.

Watch the Full Webinar Replay

Hear the complete conversation from Seni Lebron, Dave Sullivan, James Castellano and Kevin Juhl, including their firsthand experiences with remediation, certification, leadership buy-in, scoping, assessment preparation and audience Q&A.

Watch CMMC During the Pause: What Contractors Are Doing Now

Need help determining what your organization should prioritize during the pause? Explore Alluvionic’s CMMC Compliance Services or access our free CMMC Readiness Toolkit.

Read From Our Blog

DOWNLOAD OUR PROJECT ASSURANCE® CHECKLIST

Fill out the form below to access our checklist that will ensure your project's success!