Do You Still Need CMMC Compliance? A C3PAO Explains Who Must Comply and What the Phase 2 Pause Really Changed

If you build components, pour concrete, write software, or run a machine shop that touches defense work, you have probably heard three different answers to the same question this year. One person says CMMC is on hold. Another says your prime contractor still expects a third-party certificate before the next award. A third says none of it matters until the government makes up its mind. That contradiction is exhausting when you are also running production, answering customer security questionnaires, and trying to plan next year’s budget.

To sort out what is true right now, we sat down with Mike Crandall, CEO of Digital Beachhead, a Colorado Springs cybersecurity firm and authorized CMMC Third-Party Assessment Organization (C3PAO). Mike spent 21 years in the Air Force helping build cybersecurity practices before the discipline had a name, and his firm now conducts the formal assessments that certify defense contractors at CMMC Level 2. The full conversation is in the video above. This article organizes what he shared, adds the regulatory record behind it, and answers the questions we hear most often from operations leaders in the defense supply chain.

The Short Answer: CMMC Is Paused at Phase 2, Not Cancelled

CMMC is still in effect, and the confusion comes from what was paused. On July 13, 2026, the Department of War (formerly the Department of Defense) Chief Information Officer, Kirsten Davies, suspended Phase 2 of the CMMC rollout, which was scheduled to begin requiring third-party assessments in new contracts on November 10, 2026. The same announcement stated that all Phase 1 self-assessment requirements remain firmly in place. Phase 1 has been active since November 10, 2025, and it is what most contractors are operating under today.

The pause became binding contract language on September 3, 2026, when the Department issued Revision 3 of Class Deviation 2026-O0025. That deviation directs contracting officers to remove third-party assessment requirements from new and existing solicitations and contracts while the review continues. It also states that the suspension does not affect the underlying obligation to comply with NIST SP 800-171 Revision 2. In plain terms, the government stopped requiring someone else to check your work. It did not stop requiring the work.

A CMMC Reform Task Force spent the summer reviewing the program from top to bottom. The Department received more than 1,100 responses to its request for information and held listening sessions attended by more than 3,000 people, according to remarks Davies made on September 9. The task force’s recommendations were due to the CIO in mid-September, and the Cyber AB has indicated that industry may see the public version between late September and early October. Mike spoke with Davies directly at Black Hat this summer, and his read is that her own language has shifted from “suspension” to “pause.” A pause implies the program resumes. Nothing he heard suggested the underlying requirements are going away.

Who Needs CMMC Compliance?

CMMC applies to any company that holds a Department of War contract or subcontract and handles one of two categories of federal information. The level you need depends on which category touches your systems, not on your industry, your headcount, or how sensitive your product feels to you.

Level 1: Federal Contract Information

Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release. If your company has a government contract at all, you almost certainly handle FCI. CMMC Level 1 covers this category with 15 basic safeguarding requirements drawn from FAR 52.204-21, verified through an annual self-assessment and an affirmation by a company executive in the Supplier Performance Risk System (SPRS).

Level 2: Controlled Unclassified Information

Controlled Unclassified Information (CUI) is the category that pulls most manufacturers into Level 2. CUI is not classified, but the government has determined it should not be public. Technical drawings, specifications, and performance data for a component on a defense platform are common examples. If CUI is processed, stored, or transmitted on your network, Level 2 requires you to implement all 110 security requirements in NIST SP 800-171. Under Phase 1, you may satisfy Level 2 through a self-assessment reported in SPRS. A third-party certification assessment by a C3PAO remains available, and as we cover below, many prime contractors still expect one.

The Industries That Get Surprised

The requirement follows the data, not the industry label, which is why companies outside traditional aerospace keep getting pulled in. Mike described a large construction company his firm recently certified at Level 2. The debate inside that company was whether they handled CUI at all. The answer was yes, because the blueprints for what they were about to build were designated CUI. We work with a client in a similar position: a concrete contractor whose projects include SCIFs and missile silos. From the outside, concrete is concrete. From the government’s perspective, the drawings for a hardened facility are controlled information, and the company that receives them has to protect them.

Flow-down is the other path most companies do not see coming. When a prime contractor receives CUI under a contract, DFARS 252.204-7012 requires the prime to flow the safeguarding requirements down to any subcontractor that will handle that information. If you build a subassembly and ship it to a large prime, the prime’s contracting team will ask what CMMC level you hold. The part you fabricate may not seem sensitive to you, but the specification you received in order to build it probably is.

What Compliance Actually Means, and Why It Is Not the Same as Security

A compliance framework is a defined standard that a government agency or law says you must meet. Most of the frameworks you have heard of, including HIPAA, PCI, and CMMC, trace back to standards published by the National Institute of Standards and Technology (NIST). CMMC selected NIST SP 800-171, a set of 110 requirements written specifically to protect CUI on non-federal systems. Compliance means you can demonstrate that those requirements are implemented.

Security is what you get when those requirements are implemented well. Mike put it plainly in our conversation: you can meet a checklist and still do very little for your actual security. Davies made the same point at the Billington CyberSecurity Summit on September 9, describing compliance as a point-in-time check on a problem that is continuous, and stating that compliance does not equal security. That distinction is why the Department wants to move toward something more dynamic. It is also why the businesses that treat CMMC as the foundation for a real security program come out ahead of the ones that treat it as paperwork.

The relationship between the two runs in a specific direction. Your executive team sets policy: what the company requires for passwords, access, incident response, and the rest. Your technical team implements and enforces those policies. Compliance provides the yardstick that tells both groups whether the result meets the standard. Without that yardstick, you are trusting that the person handling your security knows what they are doing, with no way to measure it.

Assessment Is Not the Same as Audit

One vocabulary point matters more than it sounds. CMMC is an assessment, not an audit. An audit typically measures you against fixed values set by the auditor. A CMMC assessment measures you against the requirements you defined for yourself within the framework. If your policy states a twelve-character minimum for passwords and the assessor finds systems enforcing eight, you have failed your own criterion. The assessor does not tell you what your password length should be. The assessor validates that you meet what you said you would do.

This is worth understanding because it puts responsibility for sensible choices back on the company. You can define a weak standard and meet it. But if the Department later reviews your program after an incident, “we set it to two characters and enforced it” is not a defense anyone wants to give. Passphrases of fifteen characters or more are easier to remember and far harder to crack than a short, complex password, and choices like that are where compliance and security start working together instead of against each other.

Can You Self-Assess? Yes, and You Carry the Risk

Under Phase 1, self-assessment is the path most contractors are on, and it is a legitimate route to contract eligibility. The risk is in what you are signing. A Level 2 self-assessment requires you to evaluate every one of the 110 requirements, and each requirement contains multiple assessment objectives defined in NIST SP 800-171A. Across Level 2, there are 320 objectives. To claim a requirement is met, every objective under it must be met.

Mike’s example is multifactor authentication. Most business leaders log into Microsoft 365 with a second factor and reasonably assume the MFA requirement is covered. The objectives under that requirement are more specific. One of them asks whether multifactor authentication is enforced for local access to privileged accounts, which is a different technical implementation from your daily cloud login. A company that answers “met” based on everyday experience, without checking each objective, has made a false statement to the government without intending to.

That is where the False Claims Act enters the conversation. When a senior official affirms your CMMC status in SPRS, the company is making a certification to the federal government. On September 1, 2026, the Department of Justice announced that Honeywell Aerospace agreed to pay $2,042,518 to resolve allegations that a business unit failed to comply with NIST SP 800-171 on one of its networks between April 2020 and December 2023 while submitting claims for payment. The case began with a whistleblower, a former employee, who will receive $375,823 of the settlement. In June 2026, LOGZONE Inc. paid $507,144 to resolve similar allegations that surfaced through a routine government audit. The claims in both matters were allegations only, and neither company admitted liability, but the pattern is clear. Enforcement did not pause when Phase 2 did.

Mike asked Davies directly about companies that self-attest in good faith and turn out to be wrong. Her answer, as he relayed it, was that annotating a score you have not achieved is a potential false claim regardless of intent, the same way a driver who did not know the speed limit is still responsible for speeding. Intent may matter for penalties. It does not make the statement true.

The data suggests many contractors are more confident than their evidence supports. A Kiteworks survey of 273 defense contractors conducted in the days after the July 13 announcement found that 96 percent were confident their self-attested SPRS score would hold up under review, while only 29 percent could point to both a current SPRS submission and a FedRAMP-authorized platform for handling CUI. Nearly half did not know that Phase 1 self-assessment obligations continued through the pause. If you recognize your own company in those numbers, that is useful information, not a verdict.

How a Third-Party Assessment Changes the Risk Picture

A C3PAO assessment shifts who is validating the claim. Instead of your executive attesting alone, an authorized assessor examines evidence for each objective and issues a certificate. Mike’s understanding from his conversation with the CIO is that the government does not intend to pursue false claims cases against companies whose status was assessed and certified by a third party, which is a meaningful reason companies continue to schedule assessments voluntarily during the pause. He also noted that his firm will not accept an assessment engagement for a company it does not believe will pass. A C3PAO is not permitted to help you prepare and then assess you, so if the readiness is not there, the responsible move is to refer you to someone who can get you there first.

Why the Department Paused Phase 2

The pause was about capacity and cost, not about whether contractors should protect CUI. As of June 2026, there were 107 authorized C3PAOs in the Cyber AB marketplace, and the Cyber AB has reported roughly a thousand completed Level 2 certifications. The Department’s own estimates put the number of companies expected to need Level 2 at 80,000 or more. Davies described the gap in July with the phrase that has followed the program since: the math simply doesn’t math.

Small manufacturers were the specific concern. When Mike spoke with Davies, the example she used was a very small business that makes springs for a missile manufacturer. A company at that scale cannot absorb a five-figure assessment fee on top of implementation costs, and the more useful question may be whether it should be holding CUI at all or whether the prime should hold the data instead. That is the kind of structural question the task force was asked to examine, along with two others Davies has raised publicly: the operational technology on manufacturing floors, which the current program does not address, and inconsistent CUI marking by government program offices, which industry identified as a primary source of friction.

Congress has also moved on cost. The Senate’s version of the fiscal year 2027 National Defense Authorization Act includes a proposed grant program that would offer small businesses and nontraditional contractors up to $100,000 each toward the direct cost of a Level 2 assessment, capped at $50 million in total, with the Department directed to stand it up by July 2027. The provision has not become law as of this writing, and it covers the assessment, not the implementation. For reference, the Department’s own rulemaking estimated a Level 2 certification cycle at roughly $105,000 for a small entity over three years, and that figure explicitly assumes the NIST SP 800-171 work is already done. Implementation and ongoing operation are where most of the real spend lives, and none of that spending is optional under DFARS regardless of what happens to the assessment requirement. We have broken down the full cost picture in a separate article on CMMC compliance costs for small defense contractors.

What the Pause Did Not Stop: Your Prime Contractors

Prime contractors have their own risk calculus, and several are not waiting for the Department. Mike has spoken with contracting groups at large primes who told him they will continue to require third-party assessment from subcontractors on new work regardless of the pause. Their reasoning is simple. When a subcontractor’s inaccurate attestation surfaces, the False Claims Act exposure sits with the contract holder. A prime cannot verify 110 requirements across hundreds of suppliers, so a certificate from an authorized assessor becomes the mechanism it trusts.

Mike also came away from his conversation with Davies expecting the Department to offer some form of competitive advantage to companies that complete a formal assessment rather than self-assess, with details likely to arrive alongside the task force recommendations. If you are weighing whether to pursue certification during the pause, it is worth reading this as a market signal. Work tends to flow toward suppliers who represent less risk upstream, and a certificate is the cleanest way to represent that.

Certification Is a Three-Year Commitment, Not a Project

CMMC Level 2 runs on a three-year cycle. You are assessed once, you affirm annually in years two and three that your program has been maintained, and you are reassessed in year three. The part that catches companies off guard is what the second assessment looks like. During your first assessment, the assessor extends some leeway because you are being evaluated on a program you have just built. Three years later, the assessor expects to see history. If a control requires you to review audit logs and you can only produce six months of evidence because that is when you tightened things up for the reassessment, you have not demonstrated the control.

This is where compliance drift does its damage. Drift rarely comes from negligence. It comes from well-meaning people getting work done, a new hire who was never trained on the procedure, a system change that nobody recorded in the System Security Plan, or an IT provider that does not know which of its routine decisions touch a control. Mike’s observation is that companies who bring in a team for three months to pass an assessment and then return to business as usual face a much harder lift the second time, because they have to rebuild the program and they cannot manufacture three years of evidence. Companies that maintain the program continuously find the reassessment closer to a formality.

Choosing the Right Kind of Help

CMMC readiness sits at the intersection of three things: the compliance framework, the technology that implements it, and the way your business actually operates. Most providers are strong in one or two. A compliance consultant may know the framework cold but recommend a control implementation that slows down your shop floor, when several other implementations would satisfy the same requirement without the friction. A capable general-purpose IT provider may run your environment well but not recognize that a routine decision about backups or administrative access has just taken you out of compliance with a control they have never read.

Mike’s advice is to look for a partner that joins your team rather than one that visits. That means someone who understands the 110 requirements and the 320 objectives, who can operate the technology day to day, and who knows your business well enough to choose implementations that fit it. If your current provider treats CMMC as one more compliance acronym alongside HIPAA, the odds of drift are high. Readiness and assessment also need to be separate relationships, because a C3PAO cannot prepare you and then assess you. We have written more about how to sort through this in our guide to CMMC consultants versus managed service providers, and about the specific patterns behind why defense contractors fail CMMC assessments.

What to Do Between Now and the Task Force Report

You do not need to wait for the recommendations to make good decisions. The obligations you have today are the same ones you had in June, and they will be the same ones you have after the report is published. A few things are worth doing this quarter regardless of what the report says:

  • Confirm whether you hold CUI, where it lives, and what your contracts and prime flow-downs actually require.
  • Verify your SPRS submission is current and that the affirming official understands what they signed.
  • Walk your self-assessment at the objective level rather than the requirement level, and document evidence for each objective.
  • Keep the evidence trail running: dated policies, log reviews, training records, and change tickets.
  • Ask your prime contractors directly what they will require on the next award.

If you take one thing from this conversation, take this. The requirement to protect CUI under DFARS 252.204-7012 and NIST SP 800-171 has been in your contracts since 2017. CMMC added a certification layer on top of it, and that layer is the part that paused. The runway has been extended, but the destination has not moved.

Where to Start

If you are not sure where your company stands, a scoping conversation is the right first step. It takes about an hour, and you leave knowing whether you hold CUI, which CMMC level applies to you, and how far your current environment is from meeting it. You can schedule a conversation with our team here, or learn more about how we approach CMMC compliance for defense contractors. For the assessor’s side of the table, Mike Crandall and the team at Digital Beachhead can be reached at digitalbeachhead.com.

Sources

Share this article
LinkedIn
Facebook
X
Email
Print
Matthew Harvey in Colorado Springs
Matthew Harvey

Technology Strategist, CEO

From the time he repaired his first computer at age nine, Matthew Harvey has been determined to learn more about technology to prevent costly repairs. In 2006, he started Stepping Forward Technology where he helps business leaders in the Pikes Peak region build and execute the best IT strategy. Matthew is a passionate entrepreneur and servant leader, and an MSP Titans of the Industry finalist. He lives in Colorado Springs with his wife, Jennifer, and their three beautiful kids.