Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

CMMC: 5 Things To Watch Amid Pause On Upcoming Requirements

CRN by CRN
July 21, 2026
Home News
Share on FacebookShare on Twitter


The pause on the next phase of the Cybersecurity Maturity Model Certification (CMMC) program has prompted major questions about how the government plans to verify the protection of sensitive data by defense contractors.

The Future Of CMMC

The recent U.S. Department of War decision to pause the next phase of the Cybersecurity Maturity Model Certification (CMMC) program has prompted major questions about how the government plans to verify the protection of sensitive data by defense contractors.

Last week, the department suspended CMMC Phase II requirements that would have made independent, third-party assessments obligatory for many defense contractors beginning Nov. 10. Federal officials have also launched a 60-day review of the program, with a stated focus on reducing the cost and complexity facing smaller contractors.

[Related: MSPs Need To Keep CMMC Compliance Top Of Mind]

But according to MSP executives and CMMC experts who spoke with CRN, the move should not be interpreted as a reversal of the security requirements underlying the program.

“The knee-jerk reaction from anyone who falls in scope [of the program] is that they think they don’t have to do it anymore—the proverbial ‘CMMC is dead,’” said Reagan Roney, CEO of Sterling, Va.-based Solvere One. “It is not. That’s not what they’re saying.”

Crucially, Phase I of CMMC remains in effect, allowing the department to require Level 1 and Level 2 self-assessments. Contractors must also continue meeting existing requirements for protecting controlled unclassified information (CUI). For affected businesses, the pause should be viewed as more time to prepare for future CMMC obligations—not as permission to abandon the efforts, Roney said.

“This is breathing room to get things done,” he said. “This isn’t, ‘Let’s stop because we don’t have to comply.’”

What follows are five things to watch for amid the pause on upcoming CMMC requirements.


The 60-Day Review

One key question is whether or not the Department of War’s review will lead to significant modifications to the existing program. The department has said it plans to seek feedback from defense contractors, cybersecurity providers and CMMC assessors. The review is expected to focus heavily on whether the program’s costs and administrative requirements are disproportionately impacting smaller businesses, and making it more difficult for them to compete for defense contracts.

Without a doubt, as the Phase II requirements were looming, a “lot of our clients were starting to feel that pressure,” said Atul Bhagat, president and CEO of Vienna, Va.-based BASE Solutions. Likewise, John Hill, CEO of San Antonio-based TechSage Solutions, said the costs of preparing for and completing a CMMC assessment can be particularly challenging for smaller contractors. “A lot of the smaller contractors simply can’t afford to do it,” Hill said. “The assessments are costly. The preparation is costly.”


A More Segmented Approach?

One possible outcome of the 60-day review could be a more segmented approach that places different requirements on smaller subcontractors based on how they handle CUI, according to experts. One option might be to limit certain small businesses to lower-level requirements if they do not maintain digital CUI in their environments, according to Eric Rockwell, CEO of Inovo InfoSec and certified third-party assessment organization CMMC One. The department could also place greater responsibility on large contractors to control how CUI is shared with smaller firms, he said. But even if the review changes who must receive a certification, contractors should not expect that the underlying obligations to protect government information will disappear, executives said. “If you want to continue doing that business, you’ve got to keep pressing on,” Hill said.


The Future Of Third-Party Assessments

A major long-term question is around the ultimate fate of independent, third-party assessments. The inception of CMMC came after audits and cybersecurity incidents made it clear that self-attestation by contractors was not producing the right level of security. “The buddy system doesn’t work,” Rockwell said. “Everybody was falsely reporting a perfect score in [achieving compliance] and that didn’t work. That’s why CMMC is here—to validate the results.”

Federal officials, however, have criticized third-party assessments as too costly and onerous. They have not disclosed whether it’s possible the independent assessment model could be eliminated or signaled whether it’s likely to be reinstated in some form.


Impact On Third-Party Assessors

The outcome of the review could have major implications for Certified Third-Party Assessment Organization (C3PAO) firms. Many assessment organizations have spent years preparing to perform CMMC certifications, Rockwell said, noting that building his assessment organization required a “huge investment” that might not pay off if the department substantially alters its approach.

At the same time, it’s clear that the assessment system had faced a significant challenge around capacity, MSP executives said. There were not nearly enough authorized organizations and assessors to evaluate all of the companies that have been expected to need certifications, executives said. The pause recognizes that many contractors are not ready and that there is “too much demand and not enough supply” among assessors, said Jeremy Young, director of community at Huntress. Therefore, one potential development to watch for will be whether the department uses the pause to boost efforts to expand assessment capacity. Other possibilities are that the department might reduce the number of companies that are required to achieve third-party certification or replace traditional assessments with another form of verification.


How Self-Assessments Are Enforced

Even without a requirement for third-party certification on the immediate horizon, contractors still remain responsible for accurately representing their cybersecurity posture, MSP executives noted. “This is a liability shift—now they are self-assessing again, but you’re still on the hook,” Bhagat said.

CMMC Phase I allows the department to include Level 1 and Level 2 self-assessment requirements in contracts. Contractors must submit their results and attest that the information is accurate—and they must also continue implementing and operating the applicable safeguards. For an organization subject to Level 2 requirements, that includes 110 security requirements and hundreds of associated assessment objectives. “The only thing they put the brakes on is requiring a certified third-party assessment with a CMMC certification number in SPRS (Supplier Performance Risk System) after Nov. 10,” Rockwell said.

The bottom line is that contractors should not treat the pause as a reprieve because the government can still choose to review their self-assessments, Huntress’ Young said. “You still have to protect CUI. You still have to [implement] all of these controls,” he said. “You are now just [self-assessing], but they are reserving the right to audit, at any time, your self-assessment.”



Source link

Tags: Cybersecurity
CRN

CRN

Next Post
Buda AI Launches Cloud-Native Multi-Agent Workspace to Transform How Teams Work with Artificial Intelligence

Buda AI Launches Cloud-Native Multi-Agent Workspace to Transform How Teams Work with Artificial Intelligence

Recommended.

Nearly One-Quarter of Japanese Consumers Are Considering Switching Internet Providers Citing Quality Issues as the Leading Factor, According to New Airties Survey

Nearly One-Quarter of Japanese Consumers Are Considering Switching Internet Providers Citing Quality Issues as the Leading Factor, According to New Airties Survey

January 27, 2026
Oracle expects to increase OCI margins by 30-40% | Computer Weekly

Oracle expects to increase OCI margins by 30-40% | Computer Weekly

December 11, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
Anaconda Extends AI-Native Application Development With Acquisition

Anaconda Extends AI-Native Application Development With Acquisition

May 1, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
This Scammer Used an AI-Generated MAGA Girl to Grift ‘Super Dumb’ Men

This Scammer Used an AI-Generated MAGA Girl to Grift ‘Super Dumb’ Men

April 21, 2026
AT&T Vs. Verizon: How The Country’s Biggest Carriers Fared In Q4 2025

AT&T Vs. Verizon: How The Country’s Biggest Carriers Fared In Q4 2025

January 30, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio