Update on the CMMC Pause: What We’ve Learned So Far
It’s been a few weeks since DoW paused CMMC Phase 2. Here’s what we’ve learned so far.
Risk Level
Read Time
Quick recap: on July 13, 2026, the Department of Defense (DoD) suspended CMMC Phase II, the phase that was set to require third-party certification starting November 10, 2026, and opened a 60-day CMMC Reform Task Force review of the whole program. What didn't change: Phase I self-assessments, DFARS 252.204-7012, DIBCAC's authority to run government-led assessments, and False Claims Act exposure for anyone who misrepresents their compliance. Recent settlements, including MORSE Corp's $4.6 million and Georgia Tech Research Corporation's $875,000, made clear that liability attaches to the false certification itself, not to whether a breach ever happens. We covered all of that in our last post, along with why this pause is a window to get your house in order rather than a reason to coast.
What we didn't cover: the same week, at the Authorized C3PAO meeting, the Cyber AB shared some of the reasons DoD's Office of the Chief Information Officer (OCIO) gave for the pause. Specifically, five issues with the program were outlined as the drivers behind the Department's decision, ranging from undefined CUI to outdated standards to CMMC being too focused on compliance. Some of these will sound like chatter you've seen repeated across LinkedIn as proof the whole thing is crumbling. Some of them are legitimate operational problems worth fixing. Almost none of them mean what companies think they mean for their obligations right now. Let's go through the reasoning point by point.
“Nobody can even tell me what counts as CUI.”
This is probably the most legitimate complaint on OCIO's list, and honestly the root of most of CMMC's flow-down headaches. Contractors don't have the authority to decide whether something is CUI; they depend on the government to portion-mark it correctly, and that isn't happening consistently. Most CUI is getting marked at the document level rather than portioned out, and contracting officers who aren't sure what's sensitive in a contract tend to mark the whole document CUI just to be safe.
That drags an entire supply chain into 110 Level 2 controls for information that may never have been sensitive to begin with, and it hits hardest at the bottom of the chain, where a small supplier providing one component can end up needing a full C3PAO assessment because a prime marked an entire package CUI several tiers up. Better portion marking would meaningfully shrink the number of companies that actually need Level 2. It's a real design flaw worth fixing.
It's not a reason to assume you're off the hook while it gets sorted out. If information has been marked CUI on a contract you hold, you treat it as CUI until a contracting officer changes that in writing.
“CMMC doesn't address OT, contractor resiliency, or production line agility.”
True, and also more of a scope decision than a gap. Operational Technology (OT) is treated as a Specialized Asset precisely because assessors already recognize OT can't meet all 110 Level 2 requirements. It still gets addressed in the System Security Plan and still needs protection through physical security controls and network segmentation, but it's evaluated with compensating controls rather than held to an impossible standard.
As for resiliency and agility, NIST SP 800-171 was built to protect confidentiality, full stop. If OCIO wants CMMC to also govern integrity and availability, that's a real policy conversation worth having, but it's a conversation about expanding what's required, not evidence that today's requirements are broken.
“The NIST standards are outdated.”
Also true, and worth knowing regardless of what the task force decides. NIST SP 800-171 Revision 2, the version currently being enforced, only remains in place because of a DoD waiver, and it dates back to 2020. Revision 3 was published in 2024 and is considerably more current.
Here's the part that matters for you: a FAR clause already moving through final rulemaking will apply Revision 3 across federal agencies, not just the DoD. The standards are already heading toward the exact update OCIO is asking for. That's a reason to build your program to plan for the newer, stricter revision now, not a reason to assume the current one doesn't count.
“CMMC is too focused on compliance.”
There are areas for improvement here. In this first year of CMMC Phase 1, we’ve performed more than 40 assessments. More than half of failed requirements can't go on a POA&M, meaning a single gap can sink certification outright. Assessors are discouraged from giving remediation advice mid-assessment to preserve independence, some C3PAOs cap documentation fixes even tighter than DIBCAC's own precedent, and interpretation of the requirements varies enough from assessor to assessor that two companies with similar environments can land in different places.
The stakes are high enough that a little more room for a collaborative, corrective approach would probably improve security rather than weaken it, and we'd like to see that change too. But this is an argument for showing up prepared, not for treating the current pass/fail reality as optional in the meantime.
“False Claims Act threats alone are enough to make everyone comply, so why bother with third-party certification?”
This is the argument we'd push back on hardest, because it's already been tested and it didn't work. The underlying DFARS 252.204-7012 requirements have existed since 2017, six years before certification entered the picture, and in that time only around 1,800 of the roughly 80,000 contractors expected to eventually need certification have actually gotten certified.
That gap isn't a shortage of C3PAOs or assessors, it's a shortage of readiness. Plenty of companies have operated on DoD contracts for years without fully implementing the requirements, and since the pause, the discussions across LinkedIn and industry forums has leaned toward relief that they “knew they wouldn't have to do CMMC” after all. The False Claims Act settlements from the past year say otherwise, and the companies most likely to gamble on that reasoning tend to be smaller ones operating with less scrutiny, exactly the companies who can least afford an $875,000 settlement, let alone millions.
“So where does that leave you?”
This is the reasoning that helped drive the pause, and some of it describes real design flaws worth fixing, which is presumably why the task force has 60 days to work through them. But every one of these five points is an argument about what should change about how certification works, not about whether the underlying obligation to protect defense information disappeared. It didn't, and the companies treating this pause as a green light are the ones most likely to end up on the wrong side of a False Claims Act complaint or scrambling for an assessment slot once the task force reports back.
You don't need to guess where you stand, and you shouldn't wait for a government-led assessment to find out the hard way. If you’re not pursuing certification because of the pause, C3PAOs like Hive Systems are still the best equipped resource to help you get compliant, report an accurate store, and prepare for future requirements. We show you exactly where your implementation holds up, where it falls short, and because we’re not certifying you, we can tell you what to fix before it becomes a finding on a government assessment or a line in a False Claims Act complaint.
Ready to see where you actually stand?
Follow us - stay ahead.