Close
Close

Managed IT Services

  • Managed IT Services Full-service IT management covering monitoring, maintenance, security, and support.
    Managed IT Services
  • Co-Managed IT Services Flexible IT support that works alongside your internal IT team.
    Co-Managed IT Services

Cybersecurity & Compliance

AI & Data Intelligence

Let's Chat Get in Touch

Denver

6251 Greenwood Plaza Blvd.

Suite 200

Greenwood Village, CO 80111

(303) 586-7188

Minneapolis-St. Paul

300 2nd Street NW
New Brighton, MN 55112

(612) 659-9800

San Antonio

45 NE Loop 410

Suite 500

San Antonio , TX 78216

(210) 764-3507

Long Beach

3738 Bayer Avenue #104
Long Beach, CA 90808

(562) 795-6726

Dallas-Fort Worth

7950 Legacy Drive

Suite 400

Plano, Texas 75024

(972) 810-3194

Blog graphic titled 'CMMC Is Paused. Why Organizations Should Not Hit Pause Too.' with the MyTech Partners logo, showing an IT professional reviewing code and system monitors in a data center.

CMMC Paused: What the DoW’s Announcement Actually Means

With insights from Jesse Jarvie, Eric Volbrecht, and Nathan Austin

Cybersecurity Maturity Model Certification (CMMC) should be evaluated as a business decision, not a compliance reflex. The question for leadership is straightforward: does certification protect enough revenue, reduce enough risk, or create enough opportunity to justify the investment? 

For some organizations, certification can protect a critical relationship or open a meaningful market. For others, “not now” may be the smarter answer.

Click Above To Watch The Entire Session

  • Not every organization should pursue CMMC certification. 
  • The right question is not only what certification costs, but what business outcomes it can unlock. 
  • Technology debt and compliance debt often drive much of the first-year investment. 
  • Certification can reduce supply-chain risk and help qualified organizations compete for work. 
  • Security culture, operational resilience, insurance readiness, and artificial intelligence readiness can create value beyond compliance.

In a recent session, we discussed what the Cybersecurity Maturity Model Certification pause actually means for manufacturers and other organizations supporting Department of Defense work. The pause created uncertainty, but uncertainty is not the same thing as cancellation. 

The practical question is not whether a headline changed. It is what changed for your business, what did not, and how to use the time in front of you.

Table of Contents

The Cybersecurity Maturity Model Certification program was not canceled; Phase 2 of the rollout was paused for review. 

November 10 had been the planned starting enforcement date for Phase 2. The pause provides time to review the implementation details and determine whether that deadline or related requirements should change. We expect to learn more around September 15, 2026, but September 15 is an expected update point, not a replacement compliance deadline. [EDITOR’S NOTE: The Department of War has paused CMMC Phase 2 for 60 days, with an additional 15-day administrative period. Putting the possibility of updated details around October 1st, 2026].

The distinction matters because stopping completely can be just as expensive as moving too quickly. Organizations need enough clarity to protect current contracts without spending against requirements that do not apply. A pause is extra decision time, not a permission slip to stop paying attention. 

No. A pause in certification rollout does not erase the security obligations already written into relevant contracts. 

Organizations need to separate future certification mechanics from current data-protection responsibilities. If a contract requires sensitive information to be protected, the pause does not remove that language. Treating a process review as permission to ignore security would be like hearing that the building inspector rescheduled and deciding the roof no longer needs to keep out rain. The appointment matters, but so does the actual job. 

The market reaction has ranged from “CMMC is dead” to “we are continuing as planned.” The responsible position sits between those extremes: understand your contract, understand your information, and make a business decision based on evidence rather than rumor. 

Organizations that handle Controlled Unclassified Information still need to protect it and understand how it moves through the business and supply chain. 

Controlled Unclassified Information (CUI) is sensitive information at the center of many Level 2 conversations. Leadership teams should know where it is stored, who can access it, which suppliers or service providers receive it, and what evidence supports the controls protecting it. The responsibility can extend beyond manufacturers to engineering firms, professional services organizations, logistics providers, technology companies, and other organizations supporting Department of Defense work when contract requirements and information handling bring them into scope. 

Self-attestation also carries responsibility. The organization making the claim needs evidence that applicable controls are operating as required. Confidence is useful, but evidence is better.

Organizations that expect CMMC to matter to current contracts or future growth should generally keep improving readiness. 

A short pause is small compared with a readiness program that can take months. If requirements return in a similar form, continued preparation reduces last-minute pressure. If details change, well-chosen security, governance, and documentation improvements can still strengthen the organization. 

Not every organization needs Level 2 certification. Before committing significant resources, confirm whether the business accesses, stores, processes, or transmits the information driving the requirement. Manufacturing is a strong and visible audience for CMMC, but the decision applies to any in-scope supplier or service provider in the Defense Industrial Base.

Use the pause to replace assumptions with documented answers. 

Start with contracts and information flow. Identify the clauses that apply, map where sensitive information lives, and test the evidence behind each claimed control. Then connect readiness to the business plan: protect important revenue, support credible growth, and avoid over-investing in requirements that do not apply. 

The organizations in the strongest position will not be the ones that guessed the next announcement correctly. They will be the ones that understand their environment and can respond when guidance changes.

Has CMMC been canceled? 

No. The source discussion describes a pause affecting Phase 2 of the rollout, not elimination of the overall program. 

Is October 1, 2026 a new compliance deadline? 

No. October 1, 2026 is the point when additional information is expected. The previously planned timeline may change. 

Does the pause remove current data-protection obligations? 

No. Organizations still need to follow the security obligations in their contracts and protect Controlled Unclassified Information when they handle it. 

Does CMMC apply only to manufacturers? 

No. Manufacturing is a major audience, but requirements can also affect other suppliers and service providers supporting Department of Defense work when their contracts and information handling bring them into scope. 

Should an organization stop preparing? 

If CMMC is likely to matter to current contracts or growth plans, continued readiness work may be the practical choice. 

Do not let uncertainty make the decision for you. Treat the pause as an opportunity to gain clarity, strengthen what matters, and prepare for more than one possible outcome. Next, evaluate whether the investment itself makes business sense in “Is CMMC Worth It? The Business Case.”

Authors

Mytech Partners delivers managed and co-managed IT services, cybersecurity consulting, Microsoft 365 consulting, and AI consulting to help organizations reduce risk and eliminate IT friction since 2000.

Ready to Make IT Easy?

Let’s talk about your organization, your goals, and how our SmartBusiness Suite Managed IT Services can eliminate recurring issues and simplify technology for your entire organization.

Let's chat!

Fill out the form below to begin getting connected