CMMC Phase II: The Deadline Is Gone. The Problem Isn’t.

cmmc phase two portnox

Schedule a Portnox Cloud demo today.

Contents

Last week, the Department of Defense suspended CMMC Phase II. Not delayed. Not “under review with a new target date.” Suspended, effective immediately, with a 60-day task force to figure out what comes next.

If you’ve spent any time in or around the Defense Industrial Base over the last few years, you know what that means for a lot of budget conversations happening this week. The November 10 deadline that was driving RFPs, staffing decisions, and a fair number of “we need to be compliant by Q4” sales cycles just evaporated. If your security roadmap existed because a form said you had to hit a maturity level by a certain date, that pressure is gone.

Here’s the part worth sitting with: nothing about your actual risk changed.

What the announcement actually says

DoD CIO Kirsten Davies framed this as cutting bureaucratic burden that was pushing small and mid-sized companies out of the DIB, citing SBA data on compliance costs. That’s a legitimate problem. CMMC assessments are expensive, the timelines were brutal for smaller contractors, and there’s a real argument that the program was optimizing for paperwork over outcomes.

But read past the headline and the obligations that actually matter didn’t move:

  • Phase I self-assessment requirements are still in effect
  • NIST SP 800-171 Rev 2 compliance is still enforced, just through self-assessment and select government-led reviews instead of formal certification
  • DFARS 252.204-7012 still requires contractors to safeguard covered defense information, full stop

So, what actually got suspended is the certification machinery. What didn’t get suspended is the reason the certification machinery existed in the first place.

This is the gap between compliance and security, on full display

I’ve said some version of this a hundred times: compliance frameworks are a proxy for security, not a substitute for it. When the proxy gets suspended, people have two options. Some will treat it as permission to deprioritize the work. Others will recognize that the underlying threat model, nation state actors going after the defense supply chain through its weakest links, didn’t get a task force review. It’s still out there this morning.

The DIB has been a preferred target for exactly the reason CMMC existed: thousands of contractors, wildly inconsistent security maturity, and a lot of sensitive data sitting behind whatever access controls each company happened to have in place. A pause on certification requirements doesn’t change the attack surface. It just changes who’s required to prove they’ve addressed it, and on what timeline.

Where this actually leaves DIB contractors

If you’re a contractor who was racing toward Phase II certification, you now have room to breathe, but not a reason to stop. A few things worth doing with that room:

  • Keep your Phase I self-assessment current. It’s not going anywhere and it’s the baseline DoD is still checking.
  • Treat NIST 800-171 as the standard, not CMMC-as-certification. The controls are the point. The badge was always secondary.
  • Use the RFI window. DoD explicitly said the task force is synthesizing industry feedback on compliance challenges. If your pain point was cost or complexity rather than the actual security bar, that’s the moment to say so.
  • Don’t let identity and access control slide just because the audit pressure did. Most of what 800-171 actually asks for, knowing who’s on your network, what device they’re using, and whether that device meets your posture requirements, doesn’t require a certification to be worth doing. It requires visibility you either have or don’t.

The reason that last bullet is listed last isn’t an accident, it’s usually the one that quietly slides first. Self-assessment against 800-171 tends to get treated as a documentation exercise: policies written, spreadsheets updated, evidence filed. But the control families that matter most for the DIB’s actual threat model aren’t documentation problems. Knowing what’s connecting, verifying posture continuously rather than at audit time, extending that same scrutiny to non-human identities like service accounts and machine credentials, none of that gets accomplished by a policy document. A network either enforces those things or it doesn’t.

That last point is where I’ll admit some bias. Access control enforcement that’s tied to device posture and identity, not just a network perimeter, isn’t something you build because an assessor is coming. It’s something you build because the alternative is finding out the hard way which vendor in your supply chain had the weakest controls. Most of 800-171’s access control and identification/authentication families (3.1 and 3.5, if you’re mapping controls) come down to one question: can you actually see and enforce policy on every device and identity touching the network, human or not, before it connects. CMMC didn’t invent that need. It just gave it a deadline. The deadline’s gone. The need stayed exactly where it was.

If you’re using this window to figure out which controls are worth prioritizing regardless of what happens to certification, we mapped all 110 controls across the 14 CMMC 2.0 domains a while back.

Share

About the Author

Picture of Garrett Gross

Garrett Gross

Garrett Gross is Field CISO at Portnox, where he leads pre- and post-sales strategy and serves as the company's public-facing voice, representing Portnox through speaking engagements and press commentary on identity, access, and zero trust.

About the Author

Picture of Garrett Gross

Garrett Gross

Garrett Gross is Field CISO at Portnox, where he leads pre- and post-sales strategy and serves as the company's public-facing voice, representing Portnox through speaking engagements and press commentary on identity, access, and zero trust.

Related Reading

Security Trends

We Just Got Our First AI Insider Threat, and Nobody’s Ready for It

July 22, 2026
Articles

Portnox CFO Bryce Birdsong Named One of Austin’s Best CFOs

July 22, 2026
Application SecurityNetwork SecuritySecurity Trends

VPN Security Vulnerabilities: What the Headlines Miss

July 16, 2026

Portnox Reports Strong H1 Growth for 2026

X