July 2026

CMMC Connect July 2026: What the CMMC Level 2 Pause Really Means for Defense Contractors

Executive Summary

Recent announcements regarding the temporary pause in CMMC Level 2 contract enforcement have created significant uncertainty across the Defense Industrial Base (DIB). Many contractors are asking whether they should delay assessments, pause implementation efforts, or reconsider their certification timelines.

In this month’s CMMC Connect, Redspin’s team of CMMC assessors discusses what the pause actually means, what has not changed, and what contractors should be doing while the Department of War gathers industry feedback.

Drawing on experience conducting more than 100 CMMC assessments and recent conversations with Department of War leadership, the panel explains why organizations should continue strengthening their cybersecurity programs, preparing for assessments, and improving their implementation of NIST SP 800-171 regardless of current headlines.

In This Discussion

This session answers questions including:

Does the CMMC Level 2 Pause Mean Contractors Should Stop Preparing?

No.

One of the strongest messages throughout the discussion is that contractors should continue preparing for CMMC assessments despite the temporary pause in Level 2 contract enforcement.

The panel explains that the Department of War is gathering feedback on implementation costs, third-party validation, Controlled Unclassified Information (CUI) identification, and other aspects of the program. However, none of those discussions eliminate the underlying cybersecurity requirements that contractors are already expected to meet.

Organizations that pause implementation now may find themselves behind when enforcement resumes.

Damian Golladay: “DFARS 7012 is not going anywhere.”

The panel recommends using this period to strengthen cybersecurity, improve documentation, and continue preparing for assessment.

Is NIST SP 800-171 Still Required?

Yes.

The webinar reinforces that NIST SP 800-171 remains the foundation for protecting Controlled Unclassified Information within the Defense Industrial Base.

Likewise, DFARS 252.204-7012 remains in effect.

The temporary enforcement pause does not change these contractual cybersecurity obligations.

Organizations should continue:

The panel emphasizes that these activities improve cybersecurity regardless of future CMMC program updates.

Are Contractors Continuing with CMMC Assessments?

According to Redspin’s assessment team, yes.

Despite uncertainty surrounding the enforcement timeline, most contractors continue moving forward with readiness activities, consulting engagements, and third-party assessments.

Felice Flake: “Every single one of my clients said, ‘Full steam ahead.'”

The panel notes that while some organizations have delayed scheduling formal assessments, very few have stopped preparing altogether.

Instead, many are using additional time to strengthen technical controls and improve documentation before certification becomes contractually required.

What Are Redspin Assessors Seeing in the Field?

One advantage of CMMC Connect is that it reflects observations from assessors actively working across the Defense Industrial Base.

The panel explains that organizations continue asking many of the same questions:

While future adjustments to the program remain possible, Redspin’s assessors continue seeing organizations improve cybersecurity, complete readiness assessments, and prepare for certification.

The conversation reinforces that cybersecurity maturity remains valuable regardless of enforcement timelines.

Should Organizations Focus on Documentation or Security?

The panel discusses a common misconception that CMMC assessments are primarily documentation exercises. Documentation remains essential because it demonstrates consistency, repeatability, and organizational maturity. However, documentation alone is not enough. Organizations must also demonstrate that security controls operate effectively through technical implementation, operational processes, testing, and continuous improvement. Future refinements to CMMC may continue emphasizing measurable cybersecurity outcomes alongside written policies and procedures.

How Should Contractors Use the Current Pause?

The panel encourages organizations to treat the current pause as an opportunity rather than a delay.

Recommended activities include:

Organizations that continue improving cybersecurity today will be better prepared regardless of how the current review concludes.

Common Misconceptions

Myth: The CMMC program has been canceled.

Reality: The current action is a pause in Level 2 contract enforcement while the Department of War gathers industry feedback. The underlying cybersecurity requirements remain in place.

Myth: Organizations should stop preparing for assessments.

Reality: Redspin’s assessors continue seeing contractors move forward with implementation, readiness activities, and assessment preparation.

Myth: NIST SP 800-171 no longer applies.

Reality: NIST SP 800-171 and DFARS 252.204-7012 continue to provide the cybersecurity foundation for organizations handling CUI.

Practical Recommendations

Based on the discussion, Redspin recommends that contractors:

Questions Answered

About CMMC Connect

CMMC Connect is Redspin’s monthly live Q&A series featuring experienced CMMC assessors and consultants who have completed more than 100 CMMC assessments. Each session addresses the questions defense contractors are asking today, shares observations from real assessments, and provides practical guidance for navigating evolving CMMC requirements.

This month’s discussion focuses on the CMMC Level 2 enforcement pause, what it means for contractors, and why organizations should continue strengthening cybersecurity and preparing for future assessments.