Coming Soon: Outcomes of the DoD's CMMC Review & Phase 2 Pause
On July 13, 2026, the U.S. Department of Defense/Department of War (DoD/DoW) issued a press release announcing a pause on Phase 2 of CMMC rollout and a 60-day “study of the future of this program.” The review period ended on September 11, 2026, so findings and recommendations are expected in the coming days to weeks. In this article, we’ll review the current status of the CMMC program and what to watch for in the near future.

Current Status of the CMMC Phase 2 Pause & Review
First and foremost, it’s crucial to understand what the current pause is and what it isn’t. The DoD has paused Phase 2 of the CMMC phased implementation plan, which has put the requirement for defense suppliers to undergo a third-party assessment of Level 2 practices on hold.
On September 3rd, the DoD issued a class deviation memo instructing contracting officers to remove and/or exclude Level 2 third-party assessment requirements from solicitations and contracts, meaning the on-ramp for requiring certification by a C3PAO has been extended, at least temporarily.
However, this does not rescind the underlying security requirements. Companies handling Controlled Unclassified Information (CUI) are still required to implement the practices outlined in NIST SP 800-171 per Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, even if they are not required to undergo a third-party assessment.
Preliminary Feedback
At an event last week, DoD Chief Information Officer, Kirsten Davies, discussed several of the key themes identified in the responses to the department’s request for information (RFI) and ongoing efforts to gather feedback from advisory groups, such as the Cyber AB, as well as CMMC Third-Party Assessor Organizations (C3PAOs) and small businesses within the DIB:
There is a significant gap between point-in-time compliance demonstrated through an assessment and long-term information security and operational resilience. Among others with similar concerns, Dr. Thomas Graham of Redspin highlighted this with a cogent recommendation for overhauling the POA&M process in a manner which avoids “hard fail” scenarios and supports the “maturity” aspect of the CMMC program.
The department needs to do more to address security risks associated with operational technologies (OT) commonly found in industrial and manufacturing environments (e.g., SCADA systems, PLCs). Such systems and related processes do not neatly align with practices designed for traditional computing devices like PCs, servers, and mobile phones. Businesses need better guidance on how to secure such systems to ensure CMMC is more than an exercise in box-checking.
An Updated Cost Estimate from SBA
The U.S. Small Business Administration (SBA) issued a news release on the same day the DoD announced the CMMC Phase 2 pause. In it, they highlight the importance of protecting sensitive information while acknowledging the potentially devastating financial burden the program, in its current form, imposes on small businesses.
They also provide updated cost estimates for implementing the requirements associated with CMMC Level 2: $388,600 for small businesses which are permitted to self-assess and $593,800 for those requiring a third-party assessment.
As a company which primarily works with small and midsize businesses, we’ve seen firsthand how quickly the bills can stack up. We’ve seen companies have to weigh the costs and consequences of replacing outdated equipment critical for their operations against those of achieving CMMC compliance.
This is not to say that the requirements should cease to exist or that the cost of implementation is sufficient justification for lax security (especially given the requirements have been in effect since December 2017). It’s simply to acknowledge the reality of the situation because we cannot cure the affliction unless we identify the contributing factors.
What’s Next
With the preliminary review period having ended on September 11, we expect to see the DoD issue additional guidance and outline a path forward in the coming days to weeks.
As we, and many others, have pointed out, there are aspects of the program which could be re-evaluated to promote genuine cyber resilience over nominal compliance and to do so in a manner which doesn’t cripple the small and midsize businesses which are instrumental to protecting service members and the systems they depend on.
In the meantime, companies should continue their efforts to implement robust, common-sense information security practices that work in the real world. Using NIST SP 800-171 as a guide, organizations can drastically reduce their risk of suffering a successful cyberattack.
Closing Thoughts
Regardless of how the details shake out, building a strong foundation of cybersecurity positions your organization for success by limiting the risk to your systems and information. When so much of our both personal and professional lives depends on digital technologies, protecting that information just makes sense.
At Triumvirate Cybersecurity, we’ll keep an eye on the changing technological and regulatory landscape so we can provide practical guidance to SMBs in the DIB and beyond. Until then, contact us if you could use a hand ensuring your organization is not just compliant, but protected.









