Government
The CMMC Pause Isn’t a Security Pause: What DoD’s Latest Memo Really Means for Contractors
Organizations pursuing CMMC Level 2 should stay focused on control effectiveness, not certification timelines.
The Department of War/Defense (the DoD) recently issued Class Deviation 2026-O0025 Revision 3, implementing updates to DFARS Part 240 and directing contracting officers to align contracts and solicitations with the DoD’s decision to suspend advancement to CMMC Phase 2 requirements. While some contractors immediately focused on the possibility of delayed certification requirements, the real story is much more important:
The DoD has reduced pressure on certification timelines, but it has not reduced expectations for cybersecurity maturity.
What Changed?
The memorandum directs DoD acquisition officials to:
- Permit CMMC Level 1 and Level 2 self-assessments.
- Suspend the planned November 2026 transition to CMMC Phase 2 (the phase mandating CMMC Level 2 audits and certifications).
- Amend active solicitations and contracts that contain affected CMMC requirements.
- Continue requiring compliance with NIST SP 800-171 through DFARS 252.204-7012.
While for some defense contractors this represents a temporary easing of certification requirements, for their security teams, however, the message should not be interpreted as a relaxation of compliance obligations.
What Didn’t Change?
This is the most important part of the memorandum. The DoD explicitly retained:
- NIST SP 800-171 Rev. 2 requirements
- DFARS 252.204-7012 obligations
- Cyber incident reporting requirements
- Supply chain security requirements
- Government assessment authority
In other words: The controls still matter.
The DoD is not stepping away from cybersecurity. Instead, it is temporarily adjusting how contractors demonstrate compliance.
Why Control Effectiveness Matters More Than Ever
Many organizations spent the last two years preparing for a certification event. The strongest organizations focused on something different: Control effectiveness.
A Level 2 assessment is ultimately intended to answer a simple question: Can your organization consistently protect Controlled Unclassified Information (CUI)?
That answer has never depended solely on obtaining a certification. It depends on whether:
- Multifactor authentication is actually enforced.
- Access reviews are performed.
- Audit logs are monitored.
- Vulnerabilities are remediated.
- Incident response processes are tested.
- Security awareness training changes employee behavior.
- Policies translate into operational practice.
Those are effectiveness questions, not certification questions.
What This Means for Prime Contractors
The memorandum directs contracting officers to update affected solicitations and contracts. As those modifications occur, prime contractors should expect to review and update corresponding subcontractor flow downs. For prime contractors, now is the ideal time to:
- Review current subcontract language.
- Identify flow downs tied specifically to CMMC Phase 2 requirements.
- Confirm alignment with updated prime contract language.
- Continue validating NIST SP 800-171 implementation throughout the supplier ecosystem.
Smart primes will use this period to improve supply chain assurance rather than simply defer compliance activities.
What This Means for Subcontractors
Subcontractors should not view this memorandum as a reason to pause readiness efforts. Instead, they should:
- Engage with prime contractors regarding anticipated contract modifications.
- Continue implementing NIST SP 800-171 controls.
- Maintain evidence of control operation.
- Strengthen SSPs and POA&M management.
- Continue preparing for future CMMC assessments.
The organizations that continue investing in cybersecurity maturity now will be far better positioned when certification requirements ultimately return.
The Emerging DoD Trend: Security Outcomes Over Compliance Theater
The broader memorandum is focused on simplifying acquisition regulations while strengthening protections around:
- Supply chain security
- Chinese military company restrictions
- Semiconductor sourcing
- Cyber incident reporting
- Protection of DoD employee information
- Foreign-made unmanned aircraft systems
Taken together, these updates indicate a larger trend: The DoD is becoming increasingly concerned with demonstrable security outcomes, not merely compliance paperwork. Contractors that can prove operational effectiveness will be in a much stronger position than organizations that focus solely on obtaining a certificate.
Our Recommendation
For organizations pursuing CMMC Level 2, the right response to this memorandum is not to slow down. It’s to stayed focused. Continue building:
- Effective controls
- Repeatable processes
- Defensible evidence
- Measurable cybersecurity maturity
The timeline for mandatory certification may have moved. The expectation to protect CUI has not.
The DoD’s latest memorandum pauses aspects of CMMC implementation, but it does not pause cybersecurity. Organizations that continue maturing their NIST SP 800-171 control environment today will be the organizations best positioned for future assessments, contract opportunities, and increasing supply-chain scrutiny.
Note for Thrive Managed GRC Program clients: If your organization is currently preparing for a CMMC Level 2 assessment, rather than slowing down readiness efforts, now is an excellent time to perform a control-effectiveness review, validate objective evidence, and ensure that your operational implementation aligns with your SSP. The organizations that treat this pause as an opportunity to strengthen maturity, rather than delay compliance, will realize the greatest long-term benefit.