CMMC 2.0 is Paused. Your Cybersecurity Work Shouldn’t Be.

Resources

Arctic IT News, Articles and Events

CMMC 2.0 cybersecurity work

Publish Date

October 7, 2026

Tags

CMMC 2.0 | DoD | Gap Assessments | Incident Response Plan

When the Department of Defense paused part of the Cybersecurity Maturity Model Certification (CMMC) 2.0 program this summer, some organizations may have wondered whether they could put their CMMC work on hold too.

That would be a risky assumption.

The current pause suspends CMMC Phase II requirements, including the broader rollout of mandatory Level 2 third-party certification assessments that had been scheduled to begin November 10, 2026. Phase 1 self-assessment requirements remain in effect. It’s important to note that the broader cybersecurity responsibilities tied to CMMC have not disappeared. Organizations still need to protect sensitive information, understand their security posture, maintain required documentation, and continue the work needed to meet applicable requirements.

My advice: don’t stop working on this.

For organizations already preparing for CMMC, the pause can be useful. It creates more time to tighten controls, improve documentation, identify gaps, and prepare for whatever comes next.

 

What is the current state of CMMC?

The biggest source of confusion is the word “pause.” A pause can sound like the program itself has stopped. In actuality, the scope of what may be changing with CMMC is much narrower. The third-party assessment requirement for CMMC Level 2 was put on hold, while self-assessment and existing cybersecurity responsibilities remain part of the picture.

Organizations handling Controlled Unclassified Information (CUI) under applicable DoD contracts still need to be addressing the underlying security requirements, such as:

  • NIST SP 800-171 Rev 2
  • Applicable DFARS requirements
  • Self-assessments
  • System Security Plans (SSP)
  • Plans of Action and Milestones (POA&Ms)

The pause also does not give organizations room to overstate their compliance. Knowingly making inaccurate representations about implemented cybersecurity controls can create significant contractual and legal risk, including potential False Claims Act exposure. For contractors, the safest approach is to make sure all written documentation reflects the real environment.

 

Why Did CMMC hit the brakes?

The conversation around CMMC has always involved more than cybersecurity controls. Cost, staffing, assessment capacity, and implementation complexity also matter. According to the DoD’s cost projections, a Level 2 third party assessment could cost anywhere from $105,000–$118,000 (including the triennial assessment and two annual affirmations).

This burden on small and mid-sized businesses is one of the major concerns surrounding the program. Preparing for certification can require significant investments in technology, consulting, documentation, security tools, and internal staff time. For organizations without a dedicated cybersecurity team, understanding what the requirements mean in practice can be difficult.

There is also a potential capacity challenge within the C3PAO market. It’s estimated that 80,000 companies need assessments, while the number of certified assessment organizations is only around 100.  Even when an assessor is available, the process can take weeks rather than days. Those details matter, but the larger point is that scaling a certification program across a large and diverse defense industrial base is difficult.

 

Focus on your security foundation now

The most useful way to approach CMMC right now is to stop treating certification as the entire goal. The certification matters because future contracts may require it. However, the real value lies in the implementation of the controls, which are designed to protect sensitive information and reduce organizational risk.

Organizations should continue making progress in areas that will remain valuable regardless of how the assessment model changes:

  • Start with the security controls that apply to your environment. Review where your organization currently stands and identify
  • Make sure your System Security Plan accurately describes your systems, boundaries, processes, and controls.
  • Review open POA&Ms and determine which issues can be addressed now.
  • Collect evidence showing that policies and controls are actually being followed.

Documentation also deserves particular attention. Organizations often underestimate how much documentation is required. An incident response plan is one example. A requirement may look straightforward on paper until someone realizes the organization has never documented what employees should do when an incident occurs, who needs to be notified, how the event should be contained, or how the response should be recorded.

The same issue appears across access control, employee responsibilities, system configuration, data handling, monitoring, and other areas. CMMC preparation often exposes processes an organization has been doing informally for years.

The extra time created by the pause gives organizations an opportunity to turn those informal practices into repeatable, documented processes.

 

Use the CMMC 2.0 pause as a runway

For organizations already working toward CMMC, momentum still matters. Treat the pause as a runway to get your environment squared away. Organizations can use the current window to ask practical questions about their environment:

  • Are our security controls operating the way our documentation says they are?
  • Is our SSP current and accurate?
  • Can we produce evidence that supports our self-assessment?
  • Do employees understand their cybersecurity responsibilities?
  • Do we have an incident response plan that people could actually follow?
  • Are known gaps being tracked and addressed?
  • Do our technology choices support the type of information we handle?

Those questions are useful even if the CMMC assessment process changes.

I would also caution against pushing forward so aggressively that you make expensive decisions based on an uncertain future. Keep moving on the security work you already know is necessary, while holding back from unnecessary acceleration until more is known about the final direction of the program.

 

Some parts of CMMC could still change

The Department is currently reviewing the CMMC program, and the final direction of that review is not yet known. The role of third-party assessments, the scope of future certification requirements, and other implementation details could change. Trying to predict the final outcome can quickly become a distraction. In the grand scheme of it all, organizations have more control over the condition of their own cybersecurity program than they do over future policy decisions. The best strategy is to prepare for the requirements you already understand and monitor the areas that remain unsettled.

  • If third-party assessments return broadly, strong preparation will help.
  • If self-assessments become more important, strong preparation will still help.
  • If certain assessment requirements are narrowed, the organization will still benefit from better security controls, clearer documentation, and stronger incident response processes.

The work does not suddenly lose its value because the verification process changes.

 

A pause is not a pass

CMMC is still evolving, and more changes may come. Organizations do not need to rush into every possible investment while the program is under review. They also should not assume that a delayed assessment means cybersecurity work can be pushed aside.

Use this time wisely. Strengthen your environment, fix your known weaknesses, clean up your documentation, and build evidence. Make sure the policies on paper match what is happening in practice.

Arctic IT can support organizations during that process through CMMC gap assessments, SSP development, POA&M support, self-assessment preparation, and ongoing monitoring of changes to the program. If you’re in need of one or more of these services, connect with us today to get started.

Remember, CMMC is a marathon...not a sprint. The CMMC timeline may continue to change. The need to protect sensitive information does not.

Kevin F

By Kevin Fassanella, Director of Security & Compliance at Arctic IT