CMMC Pause Explained: What Defense Contractors Should Know
- clairekelley0
- Jul 24
- 4 min read
We have used the past week and a half to sit back and watch the CMMC storm online. We have seen the champagne popping contingent that is sure that CMMC is dead, and the CMMC die-hards that don't expect any significant changes exchanging barbs on LinkedIn and other online venues. We expect the truth to be somewhere in the middle, and we want to share our thoughts on what this pause could mean.

First, let's clear up some of the facts of the current situation. While the current suspension pauses the requirement for third-party certificates, it does not pause the underlying security requirements that have been in place for years. It is important to remember that NIST SP 800-171, has been and remains a requirement for all DIB contractors that create or receive CUI as part of a DoW contract. The Department of War made it clear that DFARS 252.204.7012 is still in force, and DIB contractors must protect CUI with a NIST 800-171 compliant cybersecurity system.
The Department is aiming to lower barriers for small and non-traditional businesses that have been overwhelmed by compliance costs. For the prepared organization, this is a window to solidify defenses.
Title 32 (The CMMC Rule): This is the document that describes the complete CMMC program, and it is important to know that 32 CFR Part 170 has not gone away. The entire CMMC Program is still functioning.
C3PAOs are still performing CMMC Level 2 assessments and recording results in DoW’s eMASS portal.
The CAICO continues to train and certify cybersecurity Professionals as CCPs and CCAs.
The DIBCAC continues to assess candidate C3PAOs while reauthorizing existing C3PAOs.
DCSA continues to perform Tier 3 background investigations on certified CMMC ecosystem members.
Title 48 (The Rollout Pause): The Department of War has hit the pause button on Phase 2 of Title 48, requiring a C3PAO-issued certificate as a condition for winning a new contract. Phase 1 is still in effect requiring DIB contractors that receive CUI to self-attest their NIST SP 800-171 cybersecurity system in place.
The CMMC Phase 2 suspension is a logistical realignment rather than an end to the program, necessitated by the reality of having over 100,000 companies requiring assessments but only 110 authorized C3PAOs. This pause addresses that logistical bottleneck. While mandatory third-party assessments are paused, cybersecurity requirements like NIST SP 800-171 r2 remain mandatory, and contractors must continue to self-affirm their Level 1 and Level 2 protections in the Supplier Performance Risk System (SPRS).
The Cyber-AB and C3PAOs remain fully operational, continuing to offer training, advisory support, mock assessments, and third-party assessments during this 60-day review period.
For DIB contractors, suspension of the third-party mandate increases the personal stakes for leadership. Here is the immediate reality:
The 60-Day Reform Task Force: The Department has put together a task force to do a full, top-to-bottom review of the program, with their final report due by September 11, 2026. They are looking to align everything with the new Acquisition Transformation System (ATS) to make sure cybersecurity moves as fast as the mission requires.
The RFI Mission: There is an open Request for Information (RFI) on SAM.gov right now, and you have until August 14, 2026, to weigh in. This is your chance to tell the Task Force about your real-world experience and help shape what the future of CMMC looks like. (https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view)
Phase 1 is Still Active: Even though Phase 2 is paused, Title 48 Phase 1 is very much alive. This means you are still required to self-attest your security scores in the Supplier Performance Risk System (SPRS).
The DIBCAC Pivot: Since the DIBCAC has stopped working on CMMC Level 3 assessments, they suddenly have a lot of free time and labor on their hands. Expect them to use that extra capacity to ramp up non-voluntary assessments of your existing security requirements.
Executive Liability and the FCA: Without a third-party assessment organization acting as a buffer, the legal pressure is now squarely on DIB contractors’ senior leadership. If an executive signs off on an annual affirmation claiming a perfect score without the evidence to back it up, they could be penalized under the False Claims Act, especially since whistleblowers are financially incentivized to report inaccuracies.
The mission has not stopped, and neither should you. We will continue to share the latest briefings from The Cyber AB and help you navigate this transition. Let us use this pause to ensure our organizations are properly prepared to protect the national security information entrusted to us. Our warfighters deserve nothing less.
About AXIOTROP, LLC:
AXIOTROP's mission is to make CMMC compliance accessible, attainable, and sustainable for small and medium-sized businesses in the Defense Industrial Base (DIB), so they remain competitive and positioned to win government contracts. As a C3PAO, we can support DIB contractors during their preparation or their assessments.
We simplify the path to certification by working closely with businesses to right-size their CMMC program to their specific scope and contract requirements, resulting in successful assessments, expanded contracting opportunities, and a stronger security posture.




Comments