Is CMMC Going Away?
Posted in CMMC, News, NIST Audit, NIST SP 800-171 Consulting
Is CMMC Going Away? Here’s What Defense Contractors Need to Know
Over the past few weeks, one question has dominated conversations across the Defense Industrial Base: “Is CMMC going away?”
This question makes sense. Recently, the Department of War paused the rollout of Level 2 of the Cybersecurity Maturity Model Certification (CMMC) program while it reviews how the program is being implemented. Some headlines about the pause have made contractors think that CMMC has been canceled or dropped completely.
There’s no need to worry.
Even though the timeline has changed, defense contractors are still expected to meet cybersecurity standards. If your business handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), you still need to protect it with the right security measures. For most contractors, it’s best to keep preparing rather than wait for more updates.
What Happened?
On July 13, 2026, the Department of War announced that it was suspending the implementation of CMMC Phase II, delaying the planned rollout of mandatory third-party CMMC Level 2 assessments while a newly established task force evaluates possible improvements to the program.
Leaders from the Department said they want to keep strong cybersecurity rules but make them simpler and less expensive, especially for small- and mid-sized businesses that work with the Defense Industrial Base.
The review is expected to take approximately 60 days, after which the Department will provide recommendations on the program’s future direction.
The main point is that even though the schedule changed, the need for cybersecurity has not.
So, Is CMMC Going Away?
The short answer is no, you don’t need to worry about CMMC going away.
There’s no sign that CMMC has been canceled or will be discontinued.
The Department has only paused one phase while it looks for ways to improve the program. Your current cybersecurity requirements still apply, and if your company handles sensitive government information, you’re still expected to protect it properly.
You can think of it like a highway construction project.
If road crews pause construction to redesign an interchange, it doesn’t mean the highway is being abandoned. The destination is still the same, but the route might change.
The same idea still applies to CMMC, and it has not changed.
The Department is only reviewing how cybersecurity requirements are put in place, not whether they should exist at all.
Why Was Phase II Suspended?
A major concern with the original rollout was the amount of work it created for contractors.
Many businesses said they spent a lot of time and money getting ready for third-party assessments, and they also had to wait a long time because there weren’t enough Certified Third-Party Assessment Organizations (C3PAOs).
Small manufacturers, engineering firms, software developers, and subcontractors often found the certification process especially tough.
The Department recognized these concerns and said the review is meant to keep strong cybersecurity but make compliance more practical and manageable for everyone in the Defense Industrial Base.
What Has Not Changed?
Even though the headlines talk about the suspension, several key cybersecurity expectations haven’t changed.
Companies that handle Controlled Unclassified Information are still expected to implement appropriate security safeguards.
NIST SP 800-171 continues to serve as the primary security framework for protecting Controlled Unclassified Information.
Prime contractors continue to evaluate subcontractors based on their cybersecurity maturity.
Cybercriminals continue targeting defense contractors with ransomware, phishing attacks, supply chain compromises, and credential theft.
It’s important to remember that even though the compliance timeline has changed, the business risks from weak cybersecurity are still there. This doesn’t mean things have gotten worse—just that the risks haven’t changed.
Cyber threats don’t wait for new regulations, so keeping your protections in place helps your business stay ready and resilient.
Why NIST SP 800-171 Still Matters
Some people now think they don’t need to worry about NIST SP 800-171 anymore, but that’s not true. In fact, the opposite is true. NIST SP 800-171 is still one of the most widely recognized standards for protecting Controlled Unclassified Information.
Its 110 security requirements cover critical areas such as:
- Access control
- Multi-factor authentication
- Security awareness training
- Incident response
- Audit logging
- Configuration management
- Vulnerability management
- System monitoring
These controls are valuable no matter what happens with CMMC, because they lower cybersecurity risk and make your business more resilient.
Many businesses discover that implementing NIST 800-171 improves operational security, strengthens customer confidence, and reduces cyber insurance concerns long before a formal assessment ever occurs.
What Defense Contractors Should Do Now
Instead of seeing the current pause as a reason to stop getting ready, contractors should see it as a chance to get ahead.
Think of it like training for a marathon that’s been postponed for a few months.
You could stop training and hope to catch up later, or you could keep building your endurance while others fall behind.
On race day, the companies that kept preparing will be in a much better position.
The same logic applies to cybersecurity.
Now is a great time to review your System Security Plan (SSP), update your Plan of Action and Milestones (POA&M), check your technical safeguards, run vulnerability assessments, do penetration testing, and fix any remaining security gaps.
Businesses that work on their cybersecurity now may spend less time and money and have fewer surprises when new CMMC requirements are announced.
Why Cybersecurity Still Matters Even Without CMMC
It’s easy to see CMMC as just another government compliance program. But in reality, its purpose is much broader.
The Defense Industrial Base continues to face sophisticated cyber threats from criminal organizations and nation-state adversaries seeking intellectual property, research, manufacturing data, and sensitive government information.
No matter what happens with CMMC, these threats are still out there.
Strong cybersecurity does more than just help with compliance. It protects contracts, customer trust, and intellectual property. It also protects your contracts, customer trust, intellectual property, business continuity, and your company’s reputation.
Related Services
Preparing for future CMMC requirements starts with building a strong cybersecurity foundation. Tanner Security helps defense contractors reduce risk and improve compliance readiness through services that include:
- Cybersecurity Gap Assessments: Identify gaps before a formal assessment and develop a practical roadmap toward compliance.
- NIST SP 800-171 Gap Assessments: Evaluate current security controls against NIST requirements and prioritize remediation efforts.
- Penetration Testing: Validate whether security controls effectively protect systems from real-world cyberattacks.
- Vulnerability Assessments: Identify known security weaknesses before attackers can exploit them.
- Microsoft 365 and Cloud Security Assessments: Evaluate cloud environments that store or process Controlled Unclassified Information.
- Virtual CISO (vCISO) Services: Get expert cybersecurity leadership and ongoing compliance advice without paying for a full-time executive.
Is CMMC Going Away – Frequently Asked Questions
Has CMMC been canceled?
No. CMMC has not been canceled. The Department has paused the rollout of Phase II while reviewing the program, but cybersecurity requirements for defense contractors remain in place.
Is NIST SP 800-171 still required?
For contractors handling Controlled Unclassified Information, NIST SP 800-171 remains the primary cybersecurity standard for protecting sensitive government information.
Should companies continue preparing for CMMC?
Yes. Continuing to improve cybersecurity now will reduce future compliance efforts and better protect your business from evolving cyber threats.
What happens to Phase II?
Phase II implementation has been temporarily suspended while the Department conducts a comprehensive review of the CMMC program. Additional guidance is expected after the review concludes.
Will third-party assessments still happen?
The current pause affects the planned rollout of mandatory third-party assessments. The Department has indicated it will evaluate future implementation as part of its review.
Does this affect current government contracts?
Existing contractual cybersecurity obligations remain in effect. Contractors should continue to follow the security requirements in their contracts.
Can my company still benefit from preparing now?
Absolutely. Implementing strong cybersecurity controls improves operational security, reduces cyber risk, supports customer confidence, and positions your business for future compliance regardless of how the framework evolves.
What is the biggest mistake contractors can make right now?
The biggest mistake is assuming the pause means cybersecurity no longer matters. Waiting until new requirements are announced could leave your business scrambling to implement controls under tight deadlines while remaining exposed to cyber threats.
Is CMMC Going Away – Conclusion
So, is CMMC going away? No. The recent pause is just a change in how CMMC will be rolled out, not a change in how important cybersecurity is.
Cyber threats to the Defense Industrial Base keep changing, and companies that handle sensitive government information are still expected to protect it. Whether CMMC stays the same or changes, businesses that invest in cybersecurity now will be better prepared for the future.
Instead of asking if CMMC is going away, it’s better to ask:
“Is my company ready for whatever comes next?”
If you’re not sure, now is the perfect time to strengthen your cybersecurity, close any gaps, and get ready for whatever comes next.
Schedule a Call