The Fed just paused CMMC Certification
- Jul 16
- 5 min read
So what does that mean for you and your business?

Monday July 13th was a big day for the CMMC industry. According to a press release from the Department of War, the certification deadline of November 10th was put on pause for the next 60 days so that they can re-evaluate the program to "reduce unnecessary government red tape."
I was tired of reading acronym-filled official reports about this, so I decided to write a clear, honest article to help you decipher the real-world implications this has for you and your business and included some Q&A's for you below:
Q: I heard that CMMC is dead! Yay! Now I don't need to do all this complicated security stuff, right?
A: If it were only true and CMMC was unnecessary to keep us safe. CMMC is a federal ruling, not a policy memo and the Department of War can't erase it by announcement alone. What changed on July 13th is the third-party certification requirement that had a deadline of November 10th, the one that everyone was stressing out about. It's been suspended while DoD runs a 60-day review. Essentially, they froze the third-party certification industry that grew around the impending deadline.
Q: Why the sudden change? Don't get me wrong, the relief is nice, but I've been stressing out about this for months! A: The administration concluded that the cure was becoming worse than the disease. With compliance costs reportedly reaching up to $600,000 per firm, small and non-traditional businesses were fleeing the Defense Industrial Base (DIB) rather than dealing with the red tape. Supported by the Small Business Administration (SBA), the Pentagon decided that keeping innovative companies in the supply chain to speed up production was a higher priority than enforcing administrative compliance. Q: So what CMMC requirements do I actually need to pay attention to?
A: The CMMC phase I roll-out that required you to self-assess remain in effect, in every active contract.
That means that you're still going to have to meet the requirements of CMMC level 1 and CMMC level 2 at your company, but instead of paying a 3rd party auditor to double-check your company for level 2, you will need to self-attest to meeting them yourself. That is of course, until the DoW decides if and when you will need a team of auditors to show up. To be clear however, you must still comply with the NIST SP 800-171 Rev 2 framework and safeguard Controlled Unclassified Information (CUI) under existing DFARS regulations.
Q: What if I sort-of / almost meet the compliance requirements and just decide to say I'm compliant. Am I in the clear?
A: Because the Pentagon only suspended Phase II (the mandatory third-party audits), the rules of Phase I are still in effect. This means you aren't just falling back to the old days of vaguely claiming NIST compliance. You still have to follow the specific CMMC self-attestation process, namely:
Your SPRS Score. You must still score your company's compliance against the 110 NIST controls and upload that exact score to the government's Supplier Performance Risk System (SPRS).
The Executive Sign-Off. A senior company official must formally self-attest in the system that your SPRS score is accurate and that your company is implementing the required security measures.
The SSP and POA&M. You must maintain an active System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) for any controls you haven't fully implemented yet.
Also don't forget those policies, procedures and evidence you should have at the ready in case you actually are asked to produce them by the DoW, DoJ or Prime Contractor.
In short, you are still doing a "CMMC Level 2 self-assessment," and the standard you are grading yourself against is NIST 800-171 R2. The major change is simply who is checking your homework. Instead of paying an external C3PAO auditor to verify your company before you can bid on a contract, you are verifying it yourself.
A word of warning on self-attestation: Because a company executive must formally sign off on that SPRS score, faking your score or vastly overstating your security posture opens the door to massive whistleblower lawsuits and penalties under the False Claims Act. The enforcer just shifted from a private auditor to the Department of Justice.
Q: What should I do next?
A: While the newly formed CMMC Reform Task Force spends the next 60 days gathering industry feedback and report back with a revised, "less bureaucratic" plan, you will still need to reach self-attested status. The auditors are going to sit in limbo for now, which is a bit of a relief as it gives you more time to get your company operating in a compliant manner.
Predictions
It's hard to put a finger on what the Fed will announce after their 60 day investigation, but I can make the following predictions about what's not likely to happen:
1) The NIST SP-800 171 framework is not likely to be re-written in 60 days. That's the 110 practices and subsequent 320 requirements that CMMC level 2 is based on. It's very comprehensive, well written and thorough in terms of running an organization with sound cybersecurity practices. I doubt they're just going to rip it up and start from scratch.
2) They're not likely to stick with the November 10th deadline. Running an organization in a compliant manner takes time to implement. It's as simple as that. Industry experts conservatively estimate this to take between 12-18 months, and that's with focused effort. Companies are busy fighting other threats to their business - employee recruitment and retention, AI upheaval, rising costs and an uncertain economy. When push comes to shove, the focus is going to be on keeping the business alive and profitable, putting compliance on the back burner.
According to that same DoW report, they quote costs of $600,000 for organizations to re-structure and invest in technology, practices and people to become and maintain compliance. In my opinion, that number is conservative for mid-sized companies and exaggerated for small ones. Either way, you're looking at a significant investment in time and capital and with such a short deadline, meeting it for any sized organization is a major challenge.
3) They're not likely to abandon CMMC certified assessors
The career path to becoming a CMMC Certified Assessor (CCA) is not short, not easy and not cheap. It also takes a certain background in skill and personality type, that I may add is quite rare, in order to reach this level of expertise.
The CCA skill set is highly valued, coveted and necessary to protect our Defense Industrial Base (DIB) and these individuals are collectively in charge of checking to make sure that participating companies are adequately securing government data, property and resources so that we can all sleep well at night. It's not likely that the Fed would remove the certification requirement of this ecosystem or make these CCA's walk the plank, but they may find a way to soften the security requirements and extend the 3rd party certification deadline.
This is an evolving drama but I hope that this article brought you some relief and clarity about where things stand today, July 17th, 2026. Thank you for your trust and please feel free to reach out if you have any questions CMMC or cybersecurity in general.
Stay safe out there.
-Attila






Comments