Gross Mendelsohn Blog

CMMC May Have Paused — But Your Preparation Shouldn't

Written by Josh Beitler | Oct 7, 2026, 2:22:00 PM

When the Department of Defense recently announced a temporary pause in the rollout of mandatory third-party cybersecurity maturity model certification (CMMC) Level 2 assessments, many contractors breathed a sigh of relief.

For some organizations, that relief quickly turned into a dangerous assumption: "We have more time, so we can slow down."

Not so fast.

While portions of the assessment rollout may be under review, the cybersecurity requirements themselves haven't gone away. Organizations handling Controlled Unclassified Information (CUI) are still expected to implement NIST SP 800-171 controls, maintain supporting documentation and accurately assess their cybersecurity posture.

The destination hasn't changed. Only part of the roadmap has.

For contractors that continue moving forward, this pause may actually create an opportunity.

What Changed?

The recent announcement has generated plenty of questions across the Defense Industrial Base.

Here's what changed:

  • The Department of Defense has temporarily paused the expansion of mandatory third-party CMMC Level 2 assessments while it conducts a program review

  • Depending on contract requirements, some organizations may continue using self-assessments to demonstrate compliance

What Didn't Change?

Several critical requirements remain in effect:

  • NIST SP 800-171 security controls are still required

  • Organizations remain responsible for protecting CUI

  • Self-assessments must be accurate and supported by evidence

  • Annual affirmations still serve as a formal certification of your cybersecurity posture

The standard hasn't changed. The government has simply paused part of how compliance is verified.

More Time Doesn't Mean Less Work

One of the biggest mistakes contractors can make right now is assuming they can delay preparation because mandatory assessments have been postponed.

The reality is that achieving CMMC readiness takes time.

Organizations still need to:

  • Implement technical and administrative controls

  • Develop and maintain required policies and procedures

  • Remediate security gaps

  • Collect evidence supporting each security requirement

  • Train employees

  • Establish repeatable cybersecurity processes

None of these activities happen overnight.

Organizations that wait until assessment requirements return may find themselves scrambling to complete months of work in a compressed timeframe.

Why Independent Assessments Still Matter

Even if your current contracts only require a self-assessment, there are significant benefits to pursuing an independent assessment today.

An outside evaluation can help organizations:

  • Identify gaps that internal teams may overlook

  • Validate the effectiveness of existing controls

  • Strengthen confidence in compliance efforts

  • Prepare for future assessment requirements

Perhaps most importantly, it allows you to move on your timeline rather than someone else's.

Expect Demand to Surge

We've seen this before. When compliance deadlines approach, organizations that delayed preparation often begin looking for help at the same time.

As demand increases, qualified assessors become harder to schedule, timelines stretch and organizations may find themselves racing against contract requirements.

Companies that prepare now can avoid that last-minute rush and position themselves ahead of competitors who choose to wait.

CMMC Is About More Than Compliance

It's easy to view CMMC as another regulatory requirement.

But at its core, CMMC is about demonstrating that your organization can responsibly protect sensitive information.

Strong cybersecurity practices help organizations:

  • Build trust with customers and prime contractors

  • Reduce operational and cybersecurity risk

  • Improve resilience against evolving threats

  • Pursue future contract opportunities with confidence

The organizations that see CMMC solely as an audit requirement often miss the bigger picture.

The organizations that treat cybersecurity as a business advantage tend to be far better positioned for long-term success.

Cross the Finish Line

Temporary policy changes come and go. Strong cybersecurity doesn't.

Organizations that continue investing in compliance efforts today aren't just preparing for a future assessment. They're strengthening their security posture, protecting sensitive information and positioning themselves for new opportunities.

Instead of asking, "How long can we wait?"

The better question is: How quickly can we be ready?

Need Help?

Whether you're preparing for a self-assessment, evaluating your current cybersecurity posture or working toward future CMMC requirements, our team can help you understand where you stand and what steps to take next.

Contact us here or call 800.899.4623 to start the conversation and keep your organization moving forward.