New Report: The State of AI Governance 2026

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

CMMC Readiness Can’t Pause Just Because Phase 2 of the Program Did

Federal Assessments | CMMC

Published: Sep 1, 2026

When the Department of War (DoW) suddenly paused CMMC Phase 2.0 on July 13, 2026, it caught the defense industry off guard. With the third-party assessment requirements halted just months before their go-live date in November 2026, there’s much speculation that compliance activities will also be held up. However, a few things haven’t changed because of the pause: Phase 1 self-assessment requirements are still due, the False Claims Act exposure for inaccurate attestations hasn’t gone anywhere, and the obligation to protect Controlled Unclassified Information (CUI) under NIST 800-171 remains fully in effect. For the defense industrial base, treating this pause as a reason to slow down is the wrong takeaway. 

In this episode of the Government Technology Insider podcast, host Lucas Hunsicker discussed the practical implications of the CMMC 2.0 pause with Doug Barbin, President and National Managing Principal at Schellman. Barbin explained why the announcement, despite its abruptness, wasn’t entirely unexpected, why identifying and tracking CUI as it moves from primes down through layers of subcontractors continues to be the biggest ongoing challenge, and why the majority of Schellman clients are still moving forward with the certification. He also looked ahead to the DoW’s 60-day review, the significance of responding to the Request for Information (RFI), and where he sees emerging solutions helping smaller contractors shrink their compliance footprint.

“None of those requirements went away as part of this. The only thing that was paused was how it was going to be validated. The key message is: you need to continue to do what you were doing, and should have been doing, to protect the CUI within your environment and within your control.” – Doug Barbin 

 

About Douglas Barbin

As President and National Managing Principal, Doug Barbin is responsible for the strategy, development, growth, and delivery of Schellman’s global services portfolio. Since joining in 2009, his primary focus has been to expand the strong foundation in IT audit and assurance to make Schellman a market leading diversified cybersecurity and compliance services provider. He has developed many of Schellman's service offerings, served global clients, and now focuses on leading and supporting the service delivery professionals, practice leaders, and the business development teams. Doug brings more than 25 years’ experience in technology focused services having served as technology product management executive, mortgage firm CTO/COO, and fraud and computer forensic investigations leader. Doug holds dual-bachelor's degrees in Accounting and Administration of Justice from Penn State as well as an MBA from Pepperdine. He has also taken post graduate courses on Artificial Intelligence from MIT and maintains multiple CPA licenses and in addition to most of the major industry certifications including several he helped create.