On July 29, 2026, Insight Assurance hosted a webinar on CMMC phase two and the current state of the program as it moves through a pause and potential redesign. The session focused on what the pause actually means, what requirements are still in force, and how defense contractors should think about compliance planning while the future direction of the program is still being reviewed.

What we covered

The session was designed for defense contractors, subcontractors, and compliance leads trying to understand how the CMMC landscape is changing and what they should do next. Topics included:

  • Why the phase two pause does not mean CMMC is going away
  • What requirements remain in place during the pause
  • Why phase two was never a universal certification deadline
  • How self-attestation changes the risk profile for level one and level two organizations
  • Why incorrect SPRS scoring can create False Claims Act exposure
  • What stays valid for three years and what that means for planning
  • How CPOs and EMASS remain operational during the pause
  • The cost of CMMC preparation and assessment
  • What changes may come next, including possible movement to NIST SP 800-171 Revision 3
  • Why organizations already well along in the process may still want to keep moving

The gap most organizations do not see coming

The biggest risk right now is assuming the pause means a break from compliance obligations. It does not.

Many requirements remain in place, including phase one self-assessments, SPRS submission, annual affirmations, DFARS 7012, NIST SP 800-171 Revision 2, and prime-to-sub flowdown requirements. Existing certifications also remain valid for three years, and CPOs and EMASS continue to operate.

For level one and level two organizations, self-attestation becomes even more important during this period. The score submitted to SPRS needs to accurately reflect the environment and implementation status. If it does not, the organization may face False Claims Act risk.

That makes scoping one of the most important parts of the process. Inventorying in-scope assets, verifying them against the applicable controls, and making sure the score is defensible are all essential steps.

What may come next

The review process may lead to several changes, including a possible waiver-style path for startups in the DIB, a shortened assessment process for some small businesses, and a transition from NIST SP 800-171 Revision 2 to Revision 3.

Rev. 3 introduces a few important changes:

  • Controls decrease from 110 to 97
  • Requirement statements increase from 320 to 420
  • Organizational Defined Parameters are introduced

That means the framework may become more detailed, even if the number of controls goes down.

Cost was also part of the discussion. While some assessment figures are often overstated, preparation and assessment costs still depend on scope, maturity, and complexity. For organizations already underway, the three-year validity of certification also matters when thinking about long-term planning.

Should organizations keep going?

For some organizations, the right move is to keep moving forward. If they are already deep into preparation or close to readiness, continuing may reduce future risk and preserve momentum.

For others, especially organizations just starting out or smaller vendors in the defense industrial base, it may make sense to wait and see how the review process unfolds before making major investments.

The most important thing is to stay grounded in the current requirements, understand what is still active, and avoid assuming the pause changes the underlying compliance expectations.

Insight Assurance helps organizations navigate CMMC assessments and readiness. If you have questions about what the process looks like for your organization or want to understand what an engagement would involve, get in touch.