Skip to content
Article reader Listen + reading controls
LISTEN + READ YOUR WAY

Article reader

Preparing the reader…

0:00 0:00
Reading settings
Text size
100%

The CMMC suspension is an organizational knowledge test

Cybersecurity certification was never going to be just another audit for the companies that build and support U.S. defense systems. Preparing for it changed budgets, architectures, hiring plans, subcontractor relationships, and the everyday work connecting cyber teams with engineers, contracts staff, and program leaders.

Then, on July 13, 2026, the Department of Defense (DoD) suspended the planned transition to Phase II of the Cybersecurity Maturity Model Certification (CMMC) program. The Department also halted later implementation milestones and opened a 60-day review of the program.

The announcement brought meaningful relief from the coming expansion of third-party assessments. It did not, however, abolish CMMC or erase the contractual duty to protect defense information. Phase I continues, and the underlying safeguarding and reporting requirements remain in force.

That leaves defense organizations with a harder question than whether to keep preparing for an assessment: Which parts of the CMMC effort were merely certification overhead, and which parts became necessary organizational capability?

The distinction matters because a compliance program leaves behind more than policies and evidence. It also changes who talks to whom, how work moves between teams, where decisions are recorded, and whether an organization can accurately explain the security of its systems. Those capabilities are slow to build and surprisingly easy to lose.

What actually changed

Two similar names have caused much of the early confusion. CMMC 2.0 is the program architecture the Department announced in 2021 and later established in Title 32 of the Code of Federal Regulations (CFR), Part 170. Phase II is one stage in that program's implementation schedule. It had been set to begin on November 10, 2026, when more contracts would start requiring Level 2 third-party certification.

The July announcement suspended that transition; it did not repeal the rule. The accompanying implementation memorandum tells program managers that, during the suspension, they may designate only Level 1 self-assessments or Level 2 self-assessments. They may not designate Level 2 assessments by a CMMC Third-Party Assessment Organization (C3PAO) or Level 3 assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Solicitations and contracts affected by the change are to be amended or modified.

In practical terms, three layers remain important:

  • Organizations handling Federal Contract Information (FCI) may still be subject to the annual Level 1 self-assessment and affirmation associated with the 15 safeguards in Federal Acquisition Regulation (FAR) 52.204-21.
  • Organizations handling Controlled Unclassified Information (CUI) may still face a Level 2 self-assessment every three years, an annual affirmation, and the 110 requirements aligned with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2.
  • Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 continues to require adequate security for covered contractor systems, applicable safeguarding of covered defense information, cyber-incident reporting, and flow-downs to relevant subcontractors.

The Department's current CMMC guidance confirms that implementation remains in Phase I. DFARS 252.204-7012 still includes the 72-hour cyber-incident reporting requirement and provisions affecting external cloud providers.

Contractors also remain responsible for telling the truth about their security posture. In June 2026, the Justice Department announced a False Claims Act settlement with LOGZONE over allegations that the company knowingly failed to meet contractual cybersecurity requirements. A 2025 settlement with MORSECORP involved admissions concerning missing controls, an inadequate system security plan, and an overstated NIST SP 800-171 score.

The assessment path has changed. The obligation to know—and accurately represent—the condition of the system has not. Every organization still needs to read its own solicitations, contracts, modifications, and flow-downs before deciding what work to stop.

What comes next is still uncertain

The Department has been clearer about the problems it wants to solve than about the program that will follow the review.

Its reform Request for Information (RFI), open through August 14, 2026, asks industry to identify the largest cost drivers in CMMC and NIST SP 800-171, distinguish requirements that reduce risk from those that mainly create overhead, and explain how commercial platforms, managed services, and other approaches might provide equivalent or better protection at lower cost. It also asks how self-attestation might be streamlined without sacrificing operational resilience.

Those questions point toward a more risk-sensitive and less burdensome model. They do not tell us whether the Department will narrow third-party certification, rely more heavily on self-attestation and government sampling, recognize commercial security capabilities, differentiate suppliers by the sensitivity of their data, or combine several of those approaches.

Another unresolved issue sits behind the review. NIST superseded SP 800-171 Revision 2 with Revision 3 in 2024, but the current CMMC baseline and the interim direction remain tied to Revision 2. Before the suspension, the regulatory agenda included a planned amendment to 32 CFR Part 170 to manage that transition. The relationship between the standards update and the broader CMMC reform is now another open question.

No one outside the policy process can responsibly promise what the successor will look like. Organizations should prepare for several plausible outcomes rather than betting the security program on one prediction.

The capability hidden inside compliance

Most of the visible output of CMMC preparation is documentary: system security plans (SSPs), plans of action and milestones (POA&Ms), policies, inventories, network diagrams, data-flow diagrams, supplier requirements, assessment evidence, and scores.

The more valuable result often lives between those artifacts.

Consider what it takes to answer a seemingly simple question about the boundary of a system. Someone has to know where CUI enters, which applications process it, where it is stored, how identity is managed, which suppliers can reach it, and who owns each exception. Cyber specialists may interpret the requirement, but developers understand the application, platform engineers understand the infrastructure, contracts staff understand the flow-down, and program leaders understand the mission consequence. No single person holds the whole answer.

Over time, teams learn how to assemble that answer. They learn which engineer can explain an unusual integration, which supplier assertion needs to be challenged, where a vulnerability handoff tends to stall, and who has authority to accept or escalate a risk. Some of that knowledge can be written down. Much of it is tacit: it resides in judgment, experience, working relationships, and practiced routines.

That is a familiar problem in organizational research. Nonaka's theory of organizational knowledge creation describes knowledge as developing through a continuing interaction between tacit and explicit forms. Argote and Ingram's research on knowledge transfer shows that organizational knowledge is embedded not only in people, but also in tasks, tools, and the relationships among them.

The documents matter, too, when people use them as part of the work. A good SSP gives different functions a shared picture of system boundaries, responsibilities, and implementation choices. A current POA&M can connect technical debt with mission risk, funding decisions, and executive accountability. A data-flow diagram gives a security architect, developer, contracts professional, and program manager something concrete to examine together.

Carlile calls artifacts that help specialized groups work across knowledge boundaries “boundary objects”. Bechky's study of occupational communities likewise shows that people in different professions do not automatically share meaning; they have to build it through interaction. Okhuysen and Bechky's review of organizational coordination explains how plans, routines, schedules, and meetings create accountability, predictability, and common understanding.

Seen that way, a CMMC program is partly an operating model for coordinating security work. If its artifacts exist only for an assessor, they are expensive theater. If teams use them to make decisions, manage handoffs, and reveal changes in risk, they are part of the organization's security infrastructure.

The suspension puts that distinction in full view. Ceremonial work can be retired. The coordination capability should not be discarded with it.

The case for slowing down

There are good reasons for the Department to reconsider the rollout. The U.S. Government Accountability Office (GAO) found that DoD planning had not fully addressed external factors that could impede implementation, including assessment capacity, costs that might drive small firms away, and the unresolved move from NIST SP 800-171 Revision 2 to Revision 3. GAO counted only 92 authorized C3PAOs as of December 2025. The Department later acknowledged a serious mismatch between available assessment capacity and the number of companies likely to need one.

For smaller and nontraditional suppliers, the cost was not merely inconvenient. It could determine whether entering or remaining in the defense market made economic sense. A certification model intended to protect the industrial base can become counterproductive if it excludes innovative firms without producing a proportionate reduction in risk.

The suspension also gives organizations permission to ask harder questions about their own programs. How much time goes into improving identity, segmentation, logging, recovery, and incident response? How much goes into reconstructing evidence, reconciling duplicative documents, or preparing for inconsistent assessor interpretations? Those activities sometimes overlap, but they are not the same.

Adler and Borys describe the difference between enabling and coercive bureaucracy. A procedure can help people understand and improve their work, or it can operate mainly as surveillance and burden. The present review is an opportunity to remove the coercive parts of CMMC while preserving the structures that make secure work easier.

It is also a chance to shift attention from whether a control exists on paper to whether it changes risk. The Cybersecurity and Infrastructure Security Agency's (CISA) Cross-Sector Cybersecurity Performance Goals prioritize a limited set of practices with high risk-reduction value. The NIST Cybersecurity Framework (CSF) 2.0 provides an outcome-oriented language for connecting governance, risk, and operations. Neither replaces a contract requirement, but both can help leaders judge whether compliance work is producing a defensible security outcome.

The danger in standing down

The obvious response to a suspended requirement is to stop spending against it. The trouble is that organizations rarely pause only the waste.

The approaching assessment had acted as a forcing function. It concentrated executive attention, protected remediation funding, convened people across professional boundaries, and gave old security debts a deadline. Once that pressure recedes, delivery work will compete successfully for the same people and money. A temporarily canceled governance meeting or evidence review can quietly become the new operating norm.

The loss is not limited to momentum. Knowledge acquired through practice decays when the practice stops. Darr, Argote, and Epple documented rapid depreciation in knowledge gained through learning by doing. David and Brachet found that turnover and skill decay contribute to organizational forgetting. If a preparation team is dissolved, contractors roll off, and cross-functional routines disappear, restarting later will involve much more than reopening the SSP.

Handoffs are especially fragile. Contract intake has to reach architecture. Architecture decisions have to reach engineering backlogs. Vulnerabilities have to move from discovery to ownership and remediation. Incidents have to move from detection to contractual reporting. Supplier obligations have to move from the prime contract to the people who manage subcontractors. Each handoff carries context that is easy to lose when the people stop working together.

Evidence decays as well. Systems, configurations, users, suppliers, and threats continue to change during a policy review. A control narrative that was accurate in June may be misleading by December. If evidence collection stops while an old score remains visible, confidence can rise at the same time that the organization's knowledge becomes less reliable.

This is the central organizational risk of the suspension: the assessment machinery can be rebuilt. A lost network of relationships, routines, judgment, and trust takes longer.

How to use the pause

The sensible posture is neither to continue every CMMC ritual nor to dismantle the program. It is to preserve the capabilities that will matter under almost any credible successor while removing work that served only the suspended assessment regime.

Start with the contracts

Before changing budgets or roadmaps, create a current-obligations register grounded in actual solicitations, contracts, modifications, clauses, and flow-downs. Separate what is required now, what the July memoranda suspended, and what the organization has chosen to maintain because it reduces operational or mission risk.

For each obligation, identify the source, the systems and data in scope, the accountable owner, the evidence location, the last validation date, open exceptions, and the next decision point. Contracts, legal, cyber, engineering, and program leadership should agree on the record. A department-wide announcement is not a substitute for reading the contract.

Keep a control spine

Do not preserve an assessment binder for its own sake. Preserve a connected account of how the organization protects important information.

For each material security outcome, maintain the threat or failure being addressed, the applicable contract and control requirements, the systems and suppliers in scope, the implementation, the operating owner, the evidence source and its freshness, known exceptions, and remediation decisions. Map that information to NIST SP 800-171 Revisions 2 and 3 and to outcome-oriented frameworks such as CSF 2.0.

This “control spine” should live close to the work—in architecture repositories, configuration systems, ticketing workflows, and operational telemetry—rather than being reconstructed before an audit. It can support self-assessment now, government or third-party review later, and internal risk decisions throughout.

Every evidence artifact should answer a useful question: What condition does this reveal? How quickly would it show a change? Who acts when it fails? If an artifact cannot support a contract obligation or a real decision, it is a candidate for simplification, automation, consolidation, or retirement.

Keep the handoffs alive

Retain a small cross-functional core even if the assessment team shrinks. Pair people across cyber, engineering, program, and contracts boundaries. Continue system-boundary walkthroughs, evidence reviews, incident exercises, and restoration tests at a cadence justified by risk rather than by the old assessment calendar.

Record why consequential decisions were made, not just what the final policy says. Name backups for critical roles. Let those backups participate in the work before the primary person leaves. The International Organization for Standardization's (ISO) 30401 work on knowledge management treats knowledge as something that exists within and between people, teams, and organizations. Retention therefore depends on continued interaction, not merely on document storage.

Invest for more than one future

Some parts of the roadmap remain sound whether the Department restores a narrower certification model, expands self-attestation with government sampling, or moves toward outcome- and resilience-based requirements.

Those durable investments include knowing where CUI flows; reducing unnecessary CUI scope; managing identity and privileged access; maintaining asset and configuration visibility; detecting and remediating vulnerabilities; logging consequential activity; rehearsing incident response and recovery; managing supplier dependencies; and preserving honest evidence about control performance.

The adaptable layer includes assessment method, evidence packaging, scoring logic, certification cadence, assessor relationships, and the exact mapping between revisions of NIST SP 800-171. Keep that layer modular. A policy change should require a remapping exercise, not the reconstruction of the security operating model.

Use the review to learn

Organizations with direct experience should consider responding to the RFI before August 14. A useful response will do more than argue that CMMC costs too much or that every control is essential. It will connect specific costs with observable security effects.

That means separating implementation effort from assessment-preparation effort; identifying controls that prevented, detected, or contained real events; documenting duplicative artifacts and inconsistent interpretations; measuring effects on delivery time, staffing, architecture, and supplier participation; and proposing lower-cost ways to preserve assurance.

This is valuable internal work even if the organization never submits a response. A leadership team that can explain which practices reduce risk, which improve coordination, and which exist only to satisfy an assessment convention is already better prepared for the next framework.

A practical 90-day posture

In the first 30 days, validate contract-specific obligations, pause new commitments tied solely to suspended assessments, preserve the cross-functional core, review open POA&Ms, and identify evidence that is becoming stale.

During the Department's review, test the most consequential handoffs. Automate expensive evidence collection where it improves operational visibility. Map Revision 2 controls to Revision 3 and CSF outcomes. Reconsider CUI scope. Quantify both compliance burden and security effect. Submit evidence to the RFI if it would improve the policy discussion.

When new direction arrives, compare it with the obligations register and the existing roadmap before making another wholesale change. Rebaseline funding and staffing, update supplier communications, and retire only the work that no longer serves a contractual, legal, security, or coordination purpose.

Keep the capability, change the machinery

The third-party assessment model created real costs, bottlenecks, and incentives for performative compliance. The Department is right to ask whether a different mechanism can protect defense information without unnecessarily narrowing the industrial base.

But the old model also forced organizations to make hidden dependencies visible. It brought together people who did not naturally share a language. It gave unresolved security work a path to executive attention. At its best, it created routines and artifacts that helped an organization understand itself.

Some of that scaffolding should come down. The load-bearing knowledge should not.

The organizations best prepared for whatever follows will not be those that preserve every CMMC ritual, nor those that declare the work over. They will be the ones that can tell the difference between compliance theater and durable capability—and keep the latter alive while the rules change around it.

Policy and research trail

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.