The Department of Defense’s recent actions regarding the Cybersecurity Maturity Model Certification (CMMC) program have created uncertainty across the Defense Industrial Base (DIB). Many contractors spent years preparing for third-party assessments, only to see the DoD pause implementation and begin a comprehensive review of the program.
Now that additional guidance has been released, organizations are asking the same question: Should we continue pursuing CMMC readiness, or should we wait for the DoD to tell us what comes next?
What’s Changed?
Most contractors are already aware that the DoD paused implementation of CMMC Phase 2 earlier this summer. Since then, the Department has taken another significant step by directing contracting officers to remove third-party assessment requirements from contracts while the review is underway. This means mandatory C3PAO assessments are effectively on hold pending the outcome of the reform effort.
The review was initiated in response to concerns about compliance costs, administrative burden, and the impact on small and medium-sized businesses within the defense supply chain. The DoD has collected extensive industry feedback and is evaluating potential changes to the program.
What Has Not Changed?
Despite the headlines, several important requirements remain intact. Organizations handling Controlled Unclassified Information (CUI) are still expected to comply with NIST SP 800-171 security requirements. Self-assessment requirements remain in effect, and existing DFARS cybersecurity obligations have not been removed.
Just as importantly, DoD leadership has repeatedly signaled that the current effort is focused on reforming CMMC rather than eliminating cybersecurity expectations altogether. Protecting CUI remains a priority, and few observers expect the Department to abandon verification of cybersecurity controls entirely.
In short:
- NIST 800-171 is not going away.
- Self-attestation is not going away.
- Protection of CUI is not going away.
- Cybersecurity requirements in defense contracts are not going away.
The real question is how compliance will be verified in the future.
Our View: What Is Most Likely Coming?
While no formal recommendations have been released, we believe the DoD is moving toward a more risk-based approach to compliance verification.
The Department did not simply delay assessment timelines. It paused implementation, launched a reform task force, sought extensive industry feedback, and subsequently removed third-party assessment requirements from contracts during the review. Those actions suggest the DoD is evaluating more than implementation dates.
Our expectation is that the future model may include:
- Continued self-attestation for lower-risk contractors. Increased use of government-led reviews or selective audits.
- Independent assessments focused on contractors handling higher-risk CUI or supporting critical defense programs.
- Greater emphasis on demonstrable security outcomes and less emphasis on compliance administration.
Whether these predictions prove accurate or not, one thing appears consistent across all current discussions: organizations will still be expected to protect CUI and comply with NIST SP 800-171.
Our Recommendation
For contractors that are still working toward compliance, the pause should not be viewed as a reason to stop.
Organizations should continue investing in:
- NIST SP 800-171 implementation
- Security documentation and evidence collection Incident response capabilities
- Identity and access management
- Vulnerability management
- Security awareness training
- Continuous monitoring and governance processes
These capabilities remain valuable regardless of how the certification program evolves.
For organizations that have already made significant investments and are assessment-ready, we generally recommend continuing with planned readiness and assessment efforts unless there is a compelling business reason to delay.
The latest developments have reduced the urgency of certification, but they have not reduced the value of demonstrating compliance through an independent review.
The Bottom Line
The DoD’s recent actions indicate that changes to the CMMC program are likely coming. What those changes look like remains uncertain.
What is clear is that cybersecurity requirements are not disappearing.
For most organizations, the best course of action is to continue building toward NIST SP 800-171 compliance while monitoring future DoD guidance. For organizations that are already assessment-ready, the value of demonstrating compliance through independent validation remains strong, even as the regulatory landscape continues to evolve.
The compliance framework may change. The need to protect CUI will not.
Frequently Asked Questions
Contact Advanced Business Solutions:
- Phone: 502-896-2557
- Web: AdvancedBusinessSolutions.com
- Office: 1745 Payne Street, Louisville, KY 40206







