CMMC Phase 2 Pause: What You Need to Know About the DoW's Strategic Pause
Published: Sep 21, 2026
On July 13, 2026, the Department of War (DoW) initiated a pause on CMMC Phase 2, Level 2 certification requirements that were set to take effect on November 10, 2026. While the timing caught many in the defense contractor ecosystem off guard, the move reflects a broader, more pragmatic approach to cybersecurity compliance that prioritizes flexibility and real-world impact.
Why Did the DoW Pause CMMC Phase 2?
The pause wasn't arbitrary. The DoW, prompted by concerns from the Small Business Administration and industry stakeholders, recognized that small and medium-sized defense contractors were facing a disproportionate burden from the certification requirements. The DoW then opted to pump the brakes and reassess.
This isn't the first time CMMC has been paused for recalibration. During the 1.0 to 2.0 transition in 2021, similar adjustments were made resulting in a slight reduction in requirements. The current pause suggests that the DoW is willing to iterate, which is a sign of maturity in a relatively new program.
Reimagining CMMC Compliance: Lessons from Other Frameworks
Much of the discussion has centered on assessment costs and team composition requirements. But speakers in this debate suggest the real opportunity lies in rethinking the fundamental approach to compliance.
Unlike CMMC's current 100% compliance requirement, frameworks like PCI DSS and FedRAMP have embraced flexibility:
- PCI DSS allows alternative implementations and compensating controls, meaning you don't need to meet the letter of the law if you meet the intent.
- FedRAMP operates on a risk-based model where agencies review assessment findings and accept residual risk. Zero findings aren't expected, but managed risk is.
The question on the table is should CMMC adopt a similar approach?
PCI DSS has spent 20+ years refining its model, learning from market feedback and evolving gracefully. The compliance ecosystem has benefited from clear guidance on shared responsibility including outsourcing payment processing to a third party, which reduces organizational risk to near zero.
CMMC can learn from this maturity. One proposal that is gaining traction is to introduce enduring exceptions and temporary deficiencies into CMMC, allowing organizations to leverage cloud and managed service providers more effectively. This isn't about lowering security standards; it's about recognizing that externally managed services can reduce overall risk.
The Challenge with CUI Marking
Another pain point emerged: Controlled Unclassified Information (CUI) marking. Contractors often don't know what they're receiving as CUI or what they might produce that qualifies as CUI, making scoping difficult in the CMMC process. The solution is better contracting officer guidance upfront and more disciplined marking practices to avoid over-scoping.
When everything gets marked CUI out of caution, it cascades downstream through the supply chain, forcing a 15-person engineering firm to meet the same security requirements as a prime contractor, even for items like a diagram of a bolt for an F-16.
CMMC Assessment Costs and Flexibility
The current assessment process mandates three Certified CMMC Assessors (CCAs) for every evaluation, even for small companies. Compare this to FedRAMP, which allows more flexibility in team composition. Similarly, the rigid three-phase assessment structure could benefit from flexibility that allows C3PAOs to adapt to client business processes.
CMMC Certification Gap: What Contractors and Prime Suppliers Really Need to Know
The CMMC deliverable itself isn't the problem, it's the path to get there. And there's a secondary issue: what contracting officers expect versus what CMMC produces. This gap needs closing through clearer guidance and communication.
For contractors considering CMMC certification, the consensus is clear: Don't panic. Understand your "why," by considering if you’re pursuing CMMC because a prime demands it, or because DoW contracts require it. That distinction matters.
If you've already done the work, there's little downside to completing certification. Even if CMMC evolves, demonstrating commitment to security above the minimum will likely be valued. Primes still need to manage supply chain security, and the government doesn't have staff to audit everyone, meaning third-party certification remains pragmatic.
The Future of CMMC
CMMC is still in its infancy compared to PCI, FedRAMP, and ISO. The pause represents an opportunity to learn from mature frameworks and build a more resilient, flexible program that drives real security without unnecessary burden.
The conversation revolves around focusing resources on what matters most. To continue this conversation or learn more about the CMMC Phase 2 pause and its implications, contact us today.
About Douglas Barbin
As President and National Managing Principal, Doug Barbin is responsible for the strategy, development, growth, and delivery of Schellman’s global services portfolio. Since joining in 2009, his primary focus has been to expand the strong foundation in IT audit and assurance to make Schellman a market leading diversified cybersecurity and compliance services provider. He has developed many of Schellman's service offerings, served global clients, and now focuses on leading and supporting the service delivery professionals, practice leaders, and the business development teams. Doug brings more than 25 years’ experience in technology focused services having served as technology product management executive, mortgage firm CTO/COO, and fraud and computer forensic investigations leader. Doug holds dual-bachelor's degrees in Accounting and Administration of Justice from Penn State as well as an MBA from Pepperdine. He has also taken post graduate courses on Artificial Intelligence from MIT and maintains multiple CPA licenses and in addition to most of the major industry certifications including several he helped create.