1 min read
The Million-Dollar Choice: Why We’re Betting Big on CMMC (And Why You Should Too)
*Update: There has been a pause on third-party certification by the Department of War. You can read their announcement here.* If you’re a defense...
3 min read
Chris McKewon : Aug 27, 2026, 2:32:43 PM
Short answer: No, CMMC compliance requirements haven't gone away. In July 2026, the Department of War paused the CMMC Phase 2 rule that would have made third-party Level 2 certification mandatory this November. But the self-assessment requirements that took effect in November 2025 are still fully in force, and companies that fall behind on them are taking on real legal and business risk, regardless of the paused deadline.
The Cybersecurity Maturity Model Certification (CMMC) exists to make sure sensitive defense information, whether Controlled Unclassified Information (CUI) or Federal Contract Information (FCI), is protected consistently across the defense supply chain. That chain runs deep. Thousands of businesses that never touch a battlefield or a shipyard are still part of it, supporting primes as subcontractors, suppliers, and service providers. If your company holds any Defense contracts, even as a small subcontractor three tiers removed from the prime, this affects you.
Last month brought real news on this front: the Department of War suspended the Phase 2 requirement that would have made third-party certification mandatory this November, pending a 60-day program review. No new timeline has been set.
For a lot of business owners, that sounds like a reprieve. It isn't, at least not in the way it might seem.
The self-assessment requirements that took effect last November are still fully in force. Under DFARS 252.204-7012, companies still need to evaluate themselves against the 110 security controls in NIST SP 800-171 and submit their scores. What changed is who's checking your work, not whether the work needs to be done.
Here's what makes this different from a typical regulatory deadline: the consequence isn't a fine, it's ineligibility. Primes are already tightening their own supply chains around self-assessment scores, and subcontractors who can't demonstrate readiness risk being quietly replaced, not because they did anything wrong, but because they weren't ready when a prime came looking. For a lot of businesses, defense work isn't a side revenue stream, it's core to the business. Losing that eligibility isn't a compliance footnote, it's a real threat to revenue and jobs.
There's a second layer of risk too. If a company signs an annual affirmation claiming a compliance level it can't actually back up, that exposes the business to False Claims Act liability, and that risk exists whether or not a third-party audit is ever scheduled. The audits didn't stop. They just changed hands.
I'd rather frame this as an opportunity than a warning. The businesses that treat CMMC as a genuine investment in their operations, not just paperwork to survive an audit, are the ones that will come out ahead. Strong cybersecurity practices build trust with primes and clients well beyond what's required on paper. In a contracting environment that's only going to get more competitive, being demonstrably ready is a differentiator, not just a requirement.
The businesses that have built their reputation supporting the defense mission reliably and well haven't earned a pass just because a certification requirement got delayed. A delayed deadline doesn't change that responsibility; it just changes how it's being measured right now. The companies that keep doing the work, deadline or no deadline, will be the ones still standing at the table when it matters.
The pause won't last, and primes aren't waiting around either. Xceptional's CMMC compliance team can tell you exactly where you stand today, on your terms, not theirs, so you're not scrambling when either one comes calling.
Book Your Free Strategy Session →
1 min read
*Update: There has been a pause on third-party certification by the Department of War. You can read their announcement here.* If you’re a defense...
1 min read
If you run a small-to-medium Defense Industrial Base (DIB) firm, you’ve likely heard the rumor echoing around industry roundtables: "CMMC audits are...
1 min read
Data compliance has become a major talking point over the past few years. With the rise in cloud computing and the shift to work-from-anywhere...