Last week, the Department of Defense suspended CMMC Phase II. Not delayed. Not “under review with a new target date.” Suspended, effective immediately, with a 60-day task force to figure out what comes next.
If you’ve spent any time in or around the Defense Industrial Base over the last few years, you know what that means for a lot of budget conversations happening this week. The November 10 deadline that was driving RFPs, staffing decisions, and a fair number of “we need to be compliant by Q4” sales cycles just evaporated. If your security roadmap existed because a form said you had to hit a maturity level by a certain date, that pressure is gone.
Here’s the part worth sitting with: nothing about your actual risk changed.
What the announcement actually says
DoD CIO Kirsten Davies framed this as cutting bureaucratic burden that was pushing small and mid-sized companies out of the DIB, citing SBA data on compliance costs. That’s a legitimate problem. CMMC assessments are expensive, the timelines were brutal for smaller contractors, and there’s a real argument that the program was optimizing for paperwork over outcomes.
But read past the headline and the obligations that actually matter didn’t move:
- Phase I self-assessment requirements are still in effect
- NIST SP 800-171 Rev 2 compliance is still enforced, just through self-assessment and select government-led reviews instead of formal certification
- DFARS 252.204-7012 still requires contractors to safeguard covered defense information, full stop
So, what actually got suspended is the certification machinery. What didn’t get suspended is the reason the certification machinery existed in the first place.
This is the gap between compliance and security, on full display
I’ve said some version of this a hundred times: compliance frameworks are a proxy for security, not a substitute for it. When the proxy gets suspended, people have two options. Some will treat it as permission to deprioritize the work. Others will recognize that the underlying threat model, nation state actors going after the defense supply chain through its weakest links, didn’t get a task force review. It’s still out there this morning.
The DIB has been a preferred target for exactly the reason CMMC existed: thousands of contractors, wildly inconsistent security maturity, and a lot of sensitive data sitting behind whatever access controls each company happened to have in place. A pause on certification requirements doesn’t change the attack surface. It just changes who’s required to prove they’ve addressed it, and on what timeline.
Where this actually leaves DIB contractors
If you’re a contractor who was racing toward Phase II certification, you now have room to breathe, but not a reason to stop. A few things worth doing with that room:
- Keep your Phase I self-assessment current. It’s not going anywhere and it’s the baseline DoD is still checking.
- Treat NIST 800-171 as the standard, not CMMC-as-certification. The controls are the point. The badge was always secondary.
- Use the RFI window. DoD explicitly said the task force is synthesizing industry feedback on compliance challenges. If your pain point was cost or complexity rather than the actual security bar, that’s the moment to say so.
- Don’t let identity and access control slide just because the audit pressure did. Most of what 800-171 actually asks for, knowing who’s on your network, what device they’re using, and whether that device meets your posture requirements, doesn’t require a certification to be worth doing. It requires visibility you either have or don’t.
The reason that last bullet is listed last isn’t an accident, it’s usually the one that quietly slides first. Self-assessment against 800-171 tends to get treated as a documentation exercise: policies written, spreadsheets updated, evidence filed. But the control families that matter most for the DIB’s actual threat model aren’t documentation problems. Knowing what’s connecting, verifying posture continuously rather than at audit time, extending that same scrutiny to non-human identities like service accounts and machine credentials, none of that gets accomplished by a policy document. A network either enforces those things or it doesn’t.
That last point is where I’ll admit some bias. Access control enforcement that’s tied to device posture and identity, not just a network perimeter, isn’t something you build because an assessor is coming. It’s something you build because the alternative is finding out the hard way which vendor in your supply chain had the weakest controls. Most of 800-171’s access control and identification/authentication families (3.1 and 3.5, if you’re mapping controls) come down to one question: can you actually see and enforce policy on every device and identity touching the network, human or not, before it connects. CMMC didn’t invent that need. It just gave it a deadline. The deadline’s gone. The need stayed exactly where it was.
If you’re using this window to figure out which controls are worth prioritizing regardless of what happens to certification, we mapped all 110 controls across the 14 CMMC 2.0 domains a while back.