Executive Summary
Recent announcements regarding the temporary pause in CMMC Level 2 contract enforcement have created significant uncertainty across the Defense Industrial Base (DIB). Many contractors are asking whether they should delay assessments, pause implementation efforts, or reconsider their certification timelines.
In this month’s CMMC Connect, Redspin’s team of CMMC assessors discusses what the pause actually means, what has not changed, and what contractors should be doing while the Department of War gathers industry feedback.
Drawing on experience conducting more than 100 CMMC assessments and recent conversations with Department of War leadership, the panel explains why organizations should continue strengthening their cybersecurity programs, preparing for assessments, and improving their implementation of NIST SP 800-171 regardless of current headlines.
In This Discussion
This session answers questions including:
- Does the CMMC Level 2 pause mean I should stop preparing?
- Is NIST SP 800-171 still required?
- Should contractors continue pursuing third-party assessments?
- What are Redspin assessors seeing across the Defense Industrial Base?
- What should contractors do while the Department of War reviews the program?
- How can organizations use this time to improve assessment readiness?
Does the CMMC Level 2 Pause Mean Contractors Should Stop Preparing?
No.
One of the strongest messages throughout the discussion is that contractors should continue preparing for CMMC assessments despite the temporary pause in Level 2 contract enforcement.
The panel explains that the Department of War is gathering feedback on implementation costs, third-party validation, Controlled Unclassified Information (CUI) identification, and other aspects of the program. However, none of those discussions eliminate the underlying cybersecurity requirements that contractors are already expected to meet.
Organizations that pause implementation now may find themselves behind when enforcement resumes.
Damian Golladay: “DFARS 7012 is not going anywhere.”
The panel recommends using this period to strengthen cybersecurity, improve documentation, and continue preparing for assessment.
Is NIST SP 800-171 Still Required?
Yes.
The webinar reinforces that NIST SP 800-171 remains the foundation for protecting Controlled Unclassified Information within the Defense Industrial Base.
Likewise, DFARS 252.204-7012 remains in effect.
The temporary enforcement pause does not change these contractual cybersecurity obligations.
Organizations should continue:
- Implementing required security controls
- Maintaining accurate SPRS scores
- Identifying where CUI resides
- Improving documentation
- Preparing evidence for future assessments
The panel emphasizes that these activities improve cybersecurity regardless of future CMMC program updates.
Are Contractors Continuing with CMMC Assessments?
According to Redspin’s assessment team, yes.
Despite uncertainty surrounding the enforcement timeline, most contractors continue moving forward with readiness activities, consulting engagements, and third-party assessments.
Felice Flake: “Every single one of my clients said, ‘Full steam ahead.'”
The panel notes that while some organizations have delayed scheduling formal assessments, very few have stopped preparing altogether.
Instead, many are using additional time to strengthen technical controls and improve documentation before certification becomes contractually required.
What Are Redspin Assessors Seeing in the Field?
One advantage of CMMC Connect is that it reflects observations from assessors actively working across the Defense Industrial Base.
The panel explains that organizations continue asking many of the same questions:
- Should we wait?
- Will requirements change?
- Are assessments still happening?
- How much documentation is enough?
- What will assessors focus on?
While future adjustments to the program remain possible, Redspin’s assessors continue seeing organizations improve cybersecurity, complete readiness assessments, and prepare for certification.
The conversation reinforces that cybersecurity maturity remains valuable regardless of enforcement timelines.
Should Organizations Focus on Documentation or Security?
The panel discusses a common misconception that CMMC assessments are primarily documentation exercises. Documentation remains essential because it demonstrates consistency, repeatability, and organizational maturity. However, documentation alone is not enough. Organizations must also demonstrate that security controls operate effectively through technical implementation, operational processes, testing, and continuous improvement. Future refinements to CMMC may continue emphasizing measurable cybersecurity outcomes alongside written policies and procedures.
How Should Contractors Use the Current Pause?
The panel encourages organizations to treat the current pause as an opportunity rather than a delay.
Recommended activities include:
- Reviewing NIST SP 800-171 implementation
- Validating backup and recovery procedures
- Improving system documentation
- Updating SPRS scores
- Identifying and protecting CUI
- Conducting internal readiness reviews
- Preparing assessment evidence
- Participating in the Department of War Request for Information
Organizations that continue improving cybersecurity today will be better prepared regardless of how the current review concludes.
Common Misconceptions
Myth: The CMMC program has been canceled.
Reality: The current action is a pause in Level 2 contract enforcement while the Department of War gathers industry feedback. The underlying cybersecurity requirements remain in place.
Myth: Organizations should stop preparing for assessments.
Reality: Redspin’s assessors continue seeing contractors move forward with implementation, readiness activities, and assessment preparation.
Myth: NIST SP 800-171 no longer applies.
Reality: NIST SP 800-171 and DFARS 252.204-7012 continue to provide the cybersecurity foundation for organizations handling CUI.
Practical Recommendations
Based on the discussion, Redspin recommends that contractors:
- Continue implementing NIST SP 800-171.
- Maintain accurate SPRS scores.
- Know where Controlled Unclassified Information resides.
- Continue preparing for third-party assessments.
- Improve documentation and technical implementation together.
- Participate in the Department of War’s Request for Information.
- Avoid making business decisions based solely on headlines.
Questions Answered
- What does the CMMC Level 2 pause actually mean?
- Should contractors delay CMMC certification?
- Is NIST SP 800-171 still required?
- Does DFARS 252.204-7012 still apply?
- What are assessors seeing across the Defense Industrial Base?
- Should organizations continue preparing for assessments?
- What should contractors do during the current pause?
About CMMC Connect
CMMC Connect is Redspin’s monthly live Q&A series featuring experienced CMMC assessors and consultants who have completed more than 100 CMMC assessments. Each session addresses the questions defense contractors are asking today, shares observations from real assessments, and provides practical guidance for navigating evolving CMMC requirements.
This month’s discussion focuses on the CMMC Level 2 enforcement pause, what it means for contractors, and why organizations should continue strengthening cybersecurity and preparing for future assessments.
