Back to Blog
    CMMC

    The CMMC Pause Is Not a Holiday

    James McMurrySeptember 23, 20266 min read

    Most of the CMMC noise this summer has been about the suspension. Too many shops heard “pause” and put the binder back on the shelf.

    That reading is wrong. And the Department has been telling you so in plain language.

    What was suspended is narrow: the Phase II push toward outside C3PAO assessments before award. CMMC itself did not go away. Your NIST SP 800-171 obligations, your SPRS score, and your self-assessment affirmations are still live. Proof of security can still be demanded. The difference is who holds the pen, and how often the Department expects that proof to be real.

    One more clock to watch: the 60-day reform review that started with the July 13 suspension is ending. A final decision is expected any day now. Some people inside the conversation are pointing at September 28. Treat that as a planning date, not a rumor to ignore. Be prepared. If you used the pause to stop control work or evidence collection, you are already late.

    Here is what we believe, and why the July announcement and the CIO’s September remarks point the same direction.

    Prediction, the coming future, now.

    • Self-attestation is not a temporary reprieve. It is becoming the operating model.
    • Point-in-time scoring dies as the thing that matters. Continuous reporting and continuous evidence collection replace it.
    • Proof of security can be asked for at any time, by the government or by your prime.
    • “Brilliant at the Basics” is the likely floor the Department will push as expected practice for the DIB, not optional hygiene tips.
    • CMMC is not going away. The C3PAO gate is what went away.
    • Contractors who treated the suspension as a free pass will not coast. They will have more catch-up work, not less, when continuous verification and foundational practice become the measure.

    That is not wishful product positioning. It is how the Department has been talking about the problem.

    July 13: what actually got suspended

    On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements that had been set to take effect November 10, 2026. Phase I self-assessment requirements stayed firmly in place. The Department stood up a CMMC Reform Task Force and opened an RFI on reforming the program and cutting compliance burden for the DIB.

    The CIO’s line that day matches the thesis. Robust cybersecurity and operational resilience remain critical. The action does not eliminate the legal requirement for industry partners to protect federal data. Under Secretary Duffey was more blunt still: they were halting complex audits and stopping the requirement for third-party assessors. They were not telling you to stop securing the environment.

    Read that carefully. The audit factory paused. The security obligation did not.

    The same July package asked industry how commercial cybersecurity capabilities, platforms, and managed services should be recognized inside a compliance or risk framework. That is not the language of “wait for the next binder exercise.” That is the language of continuous capability from providers who are already watching environments, if the Department can figure out how to accept the evidence.

    September 9: the CIO named the failure mode

    At the Billington CyberSecurity Summit on September 9, DoW CIO Kirsten Davies said the quiet part out loud.

    Compliance equals compliance. Compliance does not equal security. Compliance equals a point-in-time check of where you are right now. Cybersecurity is a dynamic process. It needs to be contiguous and continuous, and it needs to be at the pace of the threat.

    That is the Department telling you what the next version measures: whether you are secure right now, not whether you passed an assessment last spring.

    She also made clear the pause is not a downgrade in seriousness. Cybersecurity remains critical across the defense industrial base, especially as attacks arrive at speed and scale the old model never matched. Separately, she flagged a gap CMMC never covered well: cyber resilience for manufacturing and operational technology, not only the handling of federal data. That lines up with the Brilliant at the Basics campaign the CIO’s office is pushing for DIB partners: foundational IT and OT practices that reduce technical debt, cut lateral movement, and keep evidence close to the live environment.

    Assessors asked the obvious question back: if the third-party gate softens, how does the Department prove the DIB is following federal policy? Davies said that still has to be resolved. Continuous evidence and self-assessment that can survive a government look are the only answers that fit her own critique of point-in-time checks.

    What did not change while everyone argued about Phase II

    The September 3 class deviation carried the Phase II suspension into contracting instructions. Contracting officers remove or revise third-party CMMC assessment requirements. Baseline obligations remain.

    You still implement NIST SP 800-171 Rev 2. You still post and affirm an SPRS score. That score is a representation to the government. The False Claims Act still applies to false or reckless ones. The government and your primes can still assess your implementation. DOJ’s LOGZONE settlement is the reminder people keep forgetting: a self-reported 110 and a later government score of -170 is a 280-point gap with real money attached, and that enforcement path did not depend on a C3PAO visit.

    So yes, the November 2026 C3PAO cliff eased. The duty to back up your score did not.

    If you heard “holiday,” you are behind

    Shops that stopped control work, stopped evidence collection, or treated SPRS as a paperwork exercise misread July and September the same way.

    The Department suspended the outside audit gate. It kept self-assessment. It said compliance theater is the problem. It asked how commercial tools and managed services fit. It published Brilliant at the Basics as the practical floor for DIB partners. None of that says “wait.” All of it says “show me continuously.”

    The catch-up cost for people who idled is going to be worse than the cost of staying current. Continuous verification rewards environments that already produce evidence. It punishes environments that only produce binders when someone schedules a visit.

    With a reform decision expected any day (and September 28 in some timelines), the window to get evidence production working before the next instruction drops is short. Be prepared.

    What “good” looks like under this reading

    • Treat self-assessment as permanent, not provisional.
    • Build evidence as a byproduct of operations: identity, asset inventory, segmentation, vulnerability prioritization, monitoring, backup integrity, OT boundaries where you manufacture. That is Brilliant at the Basics in practice, not a poster.
    • Assume someone can ask for proof on short notice: DCMA, a prime, a program office. If your score cannot be reconstructed from live telemetry and current configurations, it is not a score. It is a hope.
    • Use commercial security capability the Department already asked about in the July RFI. Managed detection and continuous control evidence are closer to what Davies described than a once-a-year assessment binder.

    That is the model behind JAXBERT:SECURE. Argillite (managed detection), TACT-IO (vulnerability and risk), and Milbert (identity threat detection) feed continuous evidence into JAXBERT. The SOC protects the environment. What the stack finds becomes the evidence behind the self-assessment and the SPRS score. Continuous verification is not a future buzzword for us. It is how you survive a world where the C3PAO left and the obligation stayed.

    Argillite, TACT-IO, and Milbert feed continuous evidence into JAXBERT:SECURE for self-assessment, SPRS, and continuous verification

    Argillite, TACT-IO, and Milbert feed continuous evidence into JAXBERT:SECURE.

    Bottom line

    CMMC did not leave. The C3PAO requirement did.

    July 13 told you the Phase II audit gate was suspended and self-assessment stayed. September 9 told you point-in-time compliance is the failure mode and continuous verification at the pace of the threat is the direction. Brilliant at the Basics is the practical standard the CIO’s office is already teaching the DIB. The 60-day review decision is due any day now. Some are saying September 28. Be prepared.

    If you used the pause to stop, start again now. The next ask will not be “when is your assessment scheduled.” It will be “show us you are secure today.”