CMMC Phase 2 Is Paused. Your Cybersecurity Obligations Are Not.

CMMC Phase 2 Is Paused. Your Cybersecurity Obligations Are Not.

CMMC Phase 2 Is Paused. Your Cybersecurity Obligations Are Not.

Data security on a tablet with touchscreen technology and a hand with a finger pointing at itWhat the Department of Defense review means for contractors handling Controlled Unclassified Information (CUI) and why this is the wrong moment to slow down.

The Department of Defense has temporarily suspended implementation of CMMC Phase 2 while conducting a 60-day review of the program. Understandably, the announcement has raised questions across the Defense Industrial Base: What happens to our certification timeline? Do we still need to invest in compliance right now?

The timeline may be changing. The underlying requirements are not.

What Has Not Changed

Organizations that handle CUI are still required to meet NIST SP 800-171 and comply with applicable DFARS 252.204-7012 requirements. Self-assessments, accurate SPRS reporting where required, and strong day-to-day cybersecurity practices all remain essential to supporting government contracts.

– A pause in the certification process is not a pause in the obligation to protect sensitive information.

Check Your Contracts Before You Change Your Plans

It is also worth remembering that the Department of Defense is not the only party setting expectations. Some prime contractors continue to require third-party CMMC certification or assessments as a condition of doing business, and those contractual requirements may remain in effect regardless of the Phase 2 pause.

Before adjusting any compliance plan, review your active contracts and confirm your customers’ current expectations directly. A program-level pause does not automatically release you from a commitment you have already signed.

Use The Pause As An Opportunity

We encourage organizations to treat this review period as time gained rather than time off. Improving policies, implementing technical controls, training employees, and documenting processes will continue to deliver value regardless of how the CMMC program ultimately evolves, and every one of those efforts reduces real risk in the meantime.

Self-attestation Carries Real Weight

As certification timelines shift, many organizations may need to self-attest to their compliance with NIST SP 800-171. Because these attestations carry significant responsibility for company leadership, they should be supported by objective evidence and, wherever possible, an independent evaluation.

That is why we continue to recommend:

  • Readiness Assessments – to measure overall preparedness.
  • Mock Audits – to simulate a formal CMMC assessment.
  • NIST SP 800-171 Gap Assessments – to identify and address compliance gaps.

How PJR Can Help

For organizations preparing to meet third-party certification obligations, Perry Johnson Registrars (PJR) is here to help. While PJR is not yet an authorized C3PAO and does not currently perform CMMC certification assessments, we can help with readiness and pre-assessment checks that are led by Lead CMMC Certified Assessors (LCCAs) using a structured, audit-based approach.

An independent assessment provides confidence that your compliance claims are accurate, well documented, and ready to withstand scrutiny. Whether you are preparing for future CMMC certification, supporting a self-attestation, or meeting a prime contractor’s third-party assessment requirement.

Moving Forward With Confidence

Our team will continue monitoring developments and sharing updates as they become available. Whether you are preparing for future certification or strengthening your cybersecurity program today, PJR is here to help you move forward with confidence.

To discuss a Readiness Assessment, Mock Audit, or NIST SP 800-171 Gap Assessment, contact Perry Johnson Registrars, Inc.