The Department of War (DoW) has announced the immediate suspension of CMMC Phase II, delaying the planned rollout of mandatory third-party cybersecurity assessments while the program undergoes a comprehensive 60-day review. The decision is intended to reduce compliance costs and administrative burdens, particularly for small and mid-sized defense contractors, while the Department evaluates how the program should evolve.
For many organizations throughout the Defense Industrial Base (DIB), the announcement raises an important question:
Should we pause our cybersecurity efforts?
The answer is simple: No.
What Changed?
The biggest change is that contractors will not be required to obtain CMMC Phase II third-party certification on the previously announced timeline. Instead, the Department of War will continue accepting applicable self-assessments while it reviews the future of the CMMC program.
This gives contractors additional time before formal certification requirements may return in a revised form.
What Hasn’t Changed?
This is where many companies misunderstand the announcement. Although Phase II certification has been suspended, the cybersecurity requirements that protect government information remain fully enforceable.
Organizations that handle Controlled Unclassified Information (CUI) or Covered Defense Information (CDI) are still required to comply with:
- DFARS 252.204-7012
- NIST SP 800-171
- Existing contractual cybersecurity obligations
- Required documentation supporting security controls and compliance efforts
In other words, protecting sensitive government information is still a contractual requirement—even without mandatory third-party certification.
Why This Matters
Some contractors may see this announcement as an opportunity to delay cybersecurity investments. That would be a mistake.
Cybersecurity requirements did not begin with CMMC, and they will not disappear if CMMC changes.
Government agencies continue to expect contractors to demonstrate reasonable protection of sensitive information. Organizations that stop their compliance efforts today may find themselves scrambling later if revised certification requirements are introduced or if new contracts continue to require documented NIST compliance.
Meanwhile, companies that continue strengthening their cybersecurity programs will be better positioned regardless of what happens next.
What Defense Contractors Should Be Doing Right Now
Rather than slowing down, contractors should use this additional time strategically.
Now is an excellent opportunity to:
- Complete implementation of remaining NIST SP 800-171 security controls.
- Update and strengthen cybersecurity policies and procedures.
- Improve System Security Plans (SSPs) and Plans of Action & Milestones (POA&Ms).
- Collect documentation and evidence supporting implemented controls.
- Address known compliance gaps before future certification requirements return.
- Prepare for future audits while improving overall cybersecurity maturity.
Organizations that invest in cybersecurity today aren’t simply preparing for CMMC—they’re reducing business risk, strengthening operational resilience, and protecting valuable government information.
The Opportunity Hidden in the Delay
For companies that have already invested in cybersecurity, this announcement should not be viewed as wasted effort.
In reality, the work completed over the past several years has improved security, reduced organizational risk, and positioned many contractors well ahead of competitors that delayed implementation.
The certification process may change. The need for strong cybersecurity will not.
How OPSPro Helps Government Contractors
At OPSPro, we understand that cybersecurity compliance is about more than passing an audit.
Our team helps government contractors build practical, sustainable compliance programs by assisting with NIST SP 800-171 implementation, documentation, compliance readiness, and ongoing support that aligns with current contractual requirements.
As the Department of War continues its review of CMMC, we’ll continue monitoring developments and helping clients prepare for whatever comes next.
Need Help Navigating the CMMC Changes?
Whether you’re just beginning your NIST SP 800-171 journey or preparing for future CMMC requirements, OPSPro can help you strengthen your cybersecurity posture while remaining aligned with today’s contractual obligations.
Contact OPSPro today to discuss your cybersecurity, compliance, and back-office support needs.
About OPSPro
OPSPro is a leading provider of outsourced business solutions, supporting companies with accounting and finance, HR, payroll, IT-managed services, and compliance. With deep expertise in government contract accounting and regulatory environments, OPSPro helps organizations nationwide build scalable systems, maintain compliance, and operate with clarity and confidence.