With insights from Jesse Jarvie, Eric Volbrecht, and Nathan Austin
Estimated read time: 8 minutes
Cybersecurity Maturity Model Certification (CMMC) should be evaluated as a business decision, not a compliance reflex. The question for leadership is straightforward: does certification protect enough revenue, reduce enough risk, or create enough opportunity to justify the investment?
For some organizations, certification can protect a critical relationship or open a meaningful market. For others, “not now” may be the smarter answer.

Click Above To Watch The Entire Session
Key Takeaways
- Not every organization should pursue CMMC certification.
- The right question is not only what certification costs, but what business outcomes it can unlock.
- Technology debt and compliance debt often drive much of the first-year investment.
- Certification can reduce supply-chain risk and help qualified organizations compete for work.
- Security culture, operational resilience, insurance readiness, and artificial intelligence readiness can create value beyond compliance.
In a recent session, we discussed what the Cybersecurity Maturity Model Certification pause actually means for manufacturers and other organizations supporting Department of Defense work. The pause created uncertainty, but uncertainty is not the same thing as cancellation.
The practical question is not whether a headline changed. It is what changed for your business, what did not, and how to use the time in front of you.
Table of Contents
What Was Actually Paused?
The Cybersecurity Maturity Model Certification program was not canceled; Phase 2 of the rollout was paused for review.
November 10 had been the planned starting enforcement date for Phase 2. The pause provides time to review the implementation details and determine whether that deadline or related requirements should change. We expect to learn more around September 15, 2026, but September 15 is an expected update point, not a replacement compliance deadline. [EDITOR’S NOTE: The Department of War has paused CMMC Phase 2 for 60 days, with an additional 15-day administrative period. Putting the possibility of updated details around October 1st, 2026].
The distinction matters because stopping completely can be just as expensive as moving too quickly. Organizations need enough clarity to protect current contracts without spending against requirements that do not apply. A pause is extra decision time, not a permission slip to stop paying attention.
Does the CMMC Pause Mean Compliance Is Dead?
No. A pause in certification rollout does not erase the security obligations already written into relevant contracts.
Organizations need to separate future certification mechanics from current data-protection responsibilities. If a contract requires sensitive information to be protected, the pause does not remove that language. Treating a process review as permission to ignore security would be like hearing that the building inspector rescheduled and deciding the roof no longer needs to keep out rain. The appointment matters, but so does the actual job.
The market reaction has ranged from “CMMC is dead” to “we are continuing as planned.” The responsible position sits between those extremes: understand your contract, understand your information, and make a business decision based on evidence rather than rumor.
What Requirements Still Apply Today?
Organizations that handle Controlled Unclassified Information still need to protect it and understand how it moves through the business and supply chain.
Controlled Unclassified Information (CUI) is sensitive information at the center of many Level 2 conversations. Leadership teams should know where it is stored, who can access it, which suppliers or service providers receive it, and what evidence supports the controls protecting it. The responsibility can extend beyond manufacturers to engineering firms, professional services organizations, logistics providers, technology companies, and other organizations supporting Department of Defense work when contract requirements and information handling bring them into scope.
Self-attestation also carries responsibility. The organization making the claim needs evidence that applicable controls are operating as required. Confidence is useful, but evidence is better.
Who Should Continue Preparing?
Organizations that expect CMMC to matter to current contracts or future growth should generally keep improving readiness.
A short pause is small compared with a readiness program that can take months. If requirements return in a similar form, continued preparation reduces last-minute pressure. If details change, well-chosen security, governance, and documentation improvements can still strengthen the organization.
Not every organization needs Level 2 certification. Before committing significant resources, confirm whether the business accesses, stores, processes, or transmits the information driving the requirement. Manufacturing is a strong and visible audience for CMMC, but the decision applies to any in-scope supplier or service provider in the Defense Industrial Base.
Who Should Continue Preparing?
Use the pause to replace assumptions with documented answers.
Start with contracts and information flow. Identify the clauses that apply, map where sensitive information lives, and test the evidence behind each claimed control. Then connect readiness to the business plan: protect important revenue, support credible growth, and avoid over-investing in requirements that do not apply.
The organizations in the strongest position will not be the ones that guessed the next announcement correctly. They will be the ones that understand their environment and can respond when guidance changes.
Frequently Asked Questions
Has CMMC been canceled?
No. The source discussion describes a pause affecting Phase 2 of the rollout, not elimination of the overall program.
Is October 1, 2026 a new compliance deadline?
No. October 1, 2026 is the point when additional information is expected. The previously planned timeline may change.
Does the pause remove current data-protection obligations?
No. Organizations still need to follow the security obligations in their contracts and protect Controlled Unclassified Information when they handle it.
Does CMMC apply only to manufacturers?
No. Manufacturing is a major audience, but requirements can also affect other suppliers and service providers supporting Department of Defense work when their contracts and information handling bring them into scope.
Should an organization stop preparing?
If CMMC is likely to matter to current contracts or growth plans, continued readiness work may be the practical choice.
Closing Thoughts
Do not let uncertainty make the decision for you. Treat the pause as an opportunity to gain clarity, strengthen what matters, and prepare for more than one possible outcome. Next, evaluate whether the investment itself makes business sense in “Is CMMC Worth It? The Business Case.”
