CMMC Readiness Can’t Pause Just Because Phase 2 of the Program Did 

Become an Insider.

Get Government Technology Insider news and updates in your inbox.

Get started by entering your email below.

Related Content

More Content

When the Department of War (DoW) suddenly paused CMMC Phase 2.0 on July 13, 2026, it caught the defense industry off guard. With the third-party assessment requirements halted just months before their go-live date in November 2026, there’s much speculation that compliance activities will also be held up. However, a few things haven’t changed because of the pause: Phase 1 self-assessment requirements are still due, the False Claims Act exposure for inaccurate attestations hasn’t gone anywhere, and the obligation to protect Controlled Unclassified Information (CUI) under NIST 800-171 remains fully in effect. For the defense industrial base, treating this pause as a reason to slow down is the wrong takeaway. 

In this episode of the Government Technology Insider podcast, host Lucas Hunsicker discussed the practical implications of the CMMC 2.0 pause with Doug Barbin, President and National Managing Principal at Schellman. Barbin explained why the announcement, despite its abruptness, wasn’t entirely unexpected, why identifying and tracking CUI as it moves from primes down through layers of subcontractors continues to be the biggest ongoing challenge, and why the majority of Schellman clients are still moving forward with the certification. He also looked ahead to the DoW’s 60-day review, the significance of responding to the Request for Information (RFI), and where he sees emerging solutions helping smaller contractors shrink their compliance footprint. 

“None of those requirements went away as part of this. The only thing that was paused was how it was going to be validated. The key message is: you need to continue to do what you were doing, and should have been doing, to protect the CUI within your environment and within your control.” – Doug Barbin 

Skip to content