If you’re a federal contractor (or you’re thinking about becoming one), you may have seen the recent news about CMMC. 

The short version is that the Department of Defense has suspended the planned rollout of Phase 2 of the Cybersecurity Maturity Model Certification program and launched a 60-day review of the program. Phase 2 was scheduled to expand third-party assessments beginning November 10, 2026. The Department says the current Phase 1 requirements remain in effect. 

That’s a pretty significant development. But it also creates an opportunity for a little confusion. 

And, if you’re a contractor who has been putting off cybersecurity work because you were waiting for the government to tell you exactly what you had to do, you might be tempted to think: 

“Well, I guess I have some more time.” 

Maybe. But I wouldn’t bet my business on it.

A Delay Is Not a Get-Out-of-Compliance-Free Card

Let’s start with what actually changed. 

The Department of Defense has paused the planned expansion of CMMC requirements and is reviewing the program. That means some of the requirements contractors were preparing for may change, particularly the expansion of third-party assessments. 

But the cybersecurity requirements themselves did not suddenly disappear. The current DFARS rules still require contractors and subcontractors to provide adequate security for covered contractor information systems. Contractors subject to NIST SP 800-171 requirements may also still be required to have a current DoD assessment. 

And where a contract requires CMMC, the current rules still require the appropriate CMMC status at contract award and, where applicable, throughout the life of the contract. In other words, the government hit the brakes on part of the CMMC rollout. It didn’t hit the brakes on cybersecurity. That’s an important distinction.

Compliance Isn’t the Same Thing as Security

Here’s where I think businesses sometimes get themselves into trouble. They start thinking about compliance as a deadline: We have until November. Our assessment isn’t until next year. The government hasn’t required this yet. We’ll deal with it when the contract requires it. 

The problem is that cybersecurity doesn’t work that way. A deadline is an administrative requirement; a compromised account is an actual problem. A regulation can tell you that you need multifactor authentication, but it can’t stop someone from stealing an employee’s password. A framework can require backups, but it can’t restore your data after ransomware if you never bothered to test those backups. An assessment can show that you don’t have adequate controls, but it can’t go back in time and protect the information that was stolen six months earlier. 

Compliance is important. But compliance is not the goal. Security is the goal. Compliance is just one way of demonstrating that you have taken that security seriously. 

So What Should a Federal Contractor Do Right Now?

If you were already working toward CMMC, I wouldn’t stop. In fact, this may be one of the better opportunities you’re going to get because you now have some additional breathing room. 

Don’t spend the next 60 days trying to predict exactly what the Department of Defense is going to decide. None of us knows what the final version of the program will look like after the review. Instead, work on the things that are unlikely to become a bad investment. 

Figure Out What Information You’re Actually Handling

Do you handle Federal Contract Information? Do you handle Controlled Unclassified Information? Where does that information live, who has access to it, and what computers, cloud services, applications, email accounts, file shares, and other systems touch it?

You’d be surprised how many businesses can’t answer those questions with much confidence. 

Figure Out Where You Actually Stand

NIST SP 800-171 contains 110 security requirements. You don’t need to implement a complicated compliance program just because somebody handed you a spreadsheet with 110 boxes, but you do need to understand where you currently stand. 

What’s working? What’s missing? What’s documented? What’s being done but not documented? And, perhaps most importantly, what are you doing because it’s actually secure versus what are you doing because someone told you to check a box? 

Fix the Obvious Problems

You don’t need a government deadline to fix an employee account that doesn’t have MFA, replace an unsupported firewall, or stop giving everyone in the company administrative privileges. You don’t need a CMMC assessment to recognize that your backup strategy is questionable if you’ve never successfully restored anything from it. 

These are security problems whether or not they’re currently sitting on a compliance checklist. 

Document What You’re Doing

This is the part that many businesses overlook. You may actually have pretty good security practices, but if nobody has documented those practices, established policies, assigned responsibility, or demonstrated that the controls are being maintained, you may have a difficult time proving it. 

Good security needs good documentation. Not documentation for documentation’s sake. Documentation that reflects what your business actually does. 

The Delay Could Actually Be Good News

It may seem strange to say that a compliance delay is good news, but I think it can be. 

The original CMMC rollout created a lot of pressure, particularly for small businesses that were trying to figure out what they needed to do, what systems were in scope, what CUI actually meant for them, and how much all of this was going to cost. A pause gives businesses some breathing room. 

If you’ve been putting off cybersecurity work because you were worried about an impending CMMC deadline, this is a chance to approach the problem more intelligently.  

Don’t Build Your Security Program Around a Moving Target

There’s another reason I wouldn’t recommend waiting for the government to make up its mind. CMMC may change. The requirements may change. The assessment process may change. The timeline may change. Cybersecurity threats aren’t waiting for any of that. Neither are your employees, your vendors, your customers, or the criminals trying to get into your network. 

The fundamentals of good cybersecurity aren’t particularly mysterious: 

  • Protect your identities. 
  • Control access. 
  • Keep systems patched. 
  • Secure your endpoints. 
  • Protect your email. 
  • Maintain reliable backups. 
  • Segment sensitive information where appropriate. 
  • Monitor your environment. 
  • Train your people. 
  • Have a plan for what happens when something goes wrong. 
  • Know what you have and where it is. 

Those things will still matter whether CMMC looks exactly like it does today, looks a bit different six months from now, or gets replaced by something else entirely. 

If All This Sounds Daunting…

If all of this sounds a little daunting, you’re not alone. Compliance can get complicated quickly, particularly when you’re trying to figure out the requirements while also running a business. A good IT or cybersecurity partner can help you determine what’s actually required, identify where you’re falling short, prioritize the work, and help you build a security program that makes sense for your business rather than simply checking boxes on a compliance spreadsheet.  

Make sure to look for a partner who understands both cybersecurity and compliance, and who will give you practical answers instead of simply selling you another pile of technology.  

So, Should You Wait?

No, but you also don’t need to panic. If you’re a federal contractor, the recent CMMC announcement should probably change how you approach compliance, not whether you approach it. 

Take advantage of the breathing room. Use this time to understand your requirements, identify your gaps, improve your security, and document what you’re doing. If the government changes the rules, you’ll be in a much better position to adapt. If the government doesn’t change the rules, you’ll be much closer to being ready. 

And if something happens to your business before either of those things occurs, you’ll be glad you weren’t waiting for Washington to tell you that cybersecurity was important. 

The government can delay a compliance deadline, but it can’t delay a cyberattack.