Skip to content
Back to Blog
RegulationsOctober 9, 202610 min readMy MSP TechMy MSP Tech

CMMC Phase 2 Pause: What SMB and Mid-Market IT Leaders Need to Know

Quick Answers for Property & Facility Managers

What does the CMMC Phase 2 pause mean for SMB and mid-market businesses?

CMMC Phase 2 contractual requirements are paused, but existing cybersecurity obligations remain in effect. Businesses with applicable defense contracts should continue meeting DFARS 252.204-7012 and NIST SP 800-171 requirements, maintaining security evidence, and monitoring solicitations for updated CMMC language while the Department of Defense reviews implementation timing and model changes.

Should companies stop preparing for CMMC while Phase 2 is paused?

No. Pausing Phase 2 does not eliminate the need for cybersecurity readiness. Organizations should continue closing NIST SP 800-171 gaps, documenting policies and technical controls, validating incident-response processes, and planning for assessment requirements. These improvements support current contract obligations and reduce disruption if CMMC requirements resume or change.

Could CMMC move to NIST SP 800-171 Revision 3?

A transition to NIST SP 800-171 Revision 3 is under review, but it is not yet a confirmed CMMC requirement. The reform process is considering both implementation timing and whether the CMMC model should be updated. Until the Department of Defense announces a decision, organizations should verify contract language and avoid treating Revision 3 as mandatory.

CMMC Phase 2 remains paused during a Department of Defense review

The Department of Defense has paused implementation of CMMC Phase 2, which had been scheduled to begin on November 10, 2026. The pause followed the creation of a CMMC Reform Task Force to review industry concerns and recommend potential changes to the program.

For IT directors, operations leaders, and business owners at SMB and mid-market companies, the key distinction is that the pause applies to Phase 2 contractual implementation requirements—not to cybersecurity obligations already established in contracts or regulations. The Cyber AB has stated that core CMMC program elements remain operational, including C3PAO Level 2 assessments, training, professional examinations, and practitioner support.

The review may address implementation timing and whether the CMMC model should be updated to align with NIST SP 800-171 Revision 3. A Department of Defense decision is expected later in October, but until formal guidance is issued, businesses should avoid assuming that any proposed change is final.

Existing NIST SP 800-171 and DFARS obligations still matter

The Phase 2 pause does not remove applicable requirements under DFARS 252.204-7012 or NIST SP 800-171. Organizations handling Federal Contract Information or Controlled Unclassified Information should review the exact language in their contracts, task orders, and solicitations rather than relying on general CMMC headlines.

For many defense contractors, the immediate priority remains demonstrating that required security controls are implemented and supported by reliable evidence. This includes access control, multifactor authentication where required by the environment and contract, configuration management, audit logging, incident response, media protection, personnel security, and system integrity.

A managed IT or managed cybersecurity provider can support this work through endpoint detection and response, managed detection and response, vulnerability management, Microsoft 365 security configuration, identity administration, security awareness training, backup validation, and documented incident-response procedures. The provider should also be able to explain which controls it operates, which controls remain the customer’s responsibility, and how evidence is retained.

What a possible NIST SP 800-171 Revision 3 transition could change

NIST SP 800-171 Revision 3 is a potential future consideration, not a confirmed replacement requirement under the current CMMC pause. A transition could affect control interpretation, assessment preparation, system security plans, policies, procedures, technical configurations, and evidence collection.

IT leaders should therefore separate two types of work. First, address foundational weaknesses that are important under any credible security framework, such as unsupported operating systems, excessive privileges, weak authentication, incomplete asset inventories, untested backups, and inadequate logging. Second, track control-specific changes that should not be implemented solely on speculation before the Department of Defense publishes authoritative direction.

Organizations that already map controls to NIST SP 800-171 should preserve that work in a version-controlled format. A provider or internal team should identify where policies, technical safeguards, and assessment evidence depend specifically on Revision 2. That creates a manageable starting point if Revision 3 becomes part of the reformed CMMC program.

How the pause affects CMMC assessments and procurement decisions

The Cyber AB has indicated that the CMMC program continues to operate even though Phase 2 contractual requirements are suspended. C3PAOs can continue conducting Level 2 certification assessments, and related training and professional services remain available. However, the timing and contractual effect of an assessment may depend on the organization’s specific contract position and current Department of Defense instructions.

Before authorizing a large assessment or remediation project, business leaders should confirm the commercial objective. The project may be driven by an active contract, a pending solicitation, a prime-contractor requirement, customer security expectations, cyber-insurance conditions, or broader risk reduction. A clear business case helps prevent overbuilding for an uncertain future rule while preserving progress on required protections.

When evaluating an MSP or managed security provider, buyers should request evidence of experience with defense contractors and NIST SP 800-171 programs. Important criteria include support hours, response-time commitments, escalation procedures, security certifications, experience with Microsoft 365 and controlled environments, vulnerability-management processes, incident-response capability, and the ability to produce organized audit evidence.

Practical CMMC readiness actions for commercial IT teams

SMB and mid-market organizations can use the pause to improve readiness without waiting for the final reform decision.

  • Confirm which contracts, solicitations, and customer agreements contain DFARS 252.204-7012, CMMC, NIST SP 800-171, or related cybersecurity language.
  • Maintain an accurate inventory of endpoints, servers, cloud services, privileged accounts, applications, and systems that store or process Controlled Unclassified Information.
  • Review the system security plan, plan of action and milestones, network diagrams, asset lists, risk assessments, and control evidence for accuracy and current ownership.
  • Validate identity controls, multifactor authentication, conditional access, endpoint protection, email security, vulnerability scanning, patching, encryption, and centralized logging.
  • Test backup restoration and incident-response procedures, including notification responsibilities, evidence preservation, legal escalation, and communications with customers or prime contractors.
  • Establish a monitoring process for Department of Defense, Cyber AB, and contract-specific updates so that procurement and IT teams act on formal guidance rather than rumors.

How CMMC readiness connects to broader compliance and business risk

CMMC preparation can strengthen security programs beyond defense contracting. The same capabilities often support NIST Cybersecurity Framework governance, SOC 2 control evidence, HIPAA security safeguards, the FTC Safeguards Rule, and PCI DSS requirements, although the frameworks are not interchangeable.

For healthcare organizations, access controls, audit logging, risk analysis, backup, and incident response may support HIPAA obligations. Financial institutions subject to the FTC Safeguards Rule may benefit from documented risk assessments, encryption, multifactor authentication, service-provider oversight, and an incident-response plan. Organizations pursuing SOC 2 need evidence that controls operate consistently over time, while PCI DSS focuses on protecting payment-card data and its supporting environment.

These overlaps create an opportunity for a risk-based roadmap. A provider should map common safeguards across environments while preserving the specific requirements and evidence standards of each framework. It should not claim that CMMC compliance automatically establishes HIPAA, SOC 2, FTC Safeguards Rule, or PCI DSS compliance.

What to ask a managed IT or cybersecurity provider about CMMC

The CMMC pause makes provider selection more dependent on governance and adaptability. IT leaders should ask whether the provider has supported organizations with Controlled Unclassified Information, how it separates customer environments, and whether its technicians and security personnel understand least privilege, evidence preservation, and contract-driven requirements.

Buyers should also examine the service model. A useful agreement should define support hours, severity levels, response and resolution targets, after-hours escalation, maintenance windows, reporting, vulnerability remediation, backup testing, and incident-response responsibilities. For managed detection and response, ask whether monitoring is continuous, how alerts are triaged, what constitutes an escalation, and whether the provider can coordinate with internal leadership and outside counsel.

Finally, request a realistic implementation plan. A small professional-services firm with a limited number of managed endpoints may need a different project approach than a manufacturer, engineering company, aerospace supplier, or multi-site commercial operator with segmented networks and sensitive production systems. The right plan should prioritize contract obligations, business-critical systems, and durable security improvements while leaving room for final CMMC policy decisions.

Frequently Asked Questions

How much does CMMC readiness cost for an SMB?

CMMC readiness cost varies with the number of systems, users, facilities, Controlled Unclassified Information boundaries, existing controls, and required assessment support. A gap assessment, remediation roadmap, managed security services, documentation, and independent assessment preparation may all contribute to total cost. Buyers should request a scoped plan tied to contract requirements rather than a generic package.

Does the CMMC Phase 2 pause eliminate the need for a C3PAO assessment?

No. The pause suspends Phase 2 contractual implementation requirements, but C3PAO Level 2 assessment capabilities remain available. Whether an assessment is required, advisable, or commercially valuable depends on the organization’s contracts, solicitations, customer relationships, and formal Department of Defense guidance. Companies should confirm timing and scope before committing to an assessment.

Should organizations immediately upgrade from NIST SP 800-171 Revision 2 to Revision 3?

Organizations should monitor the potential Revision 3 transition but should not assume it is already mandatory for CMMC. They can prepare efficiently by fixing foundational security weaknesses, maintaining accurate inventories and system security plans, documenting control ownership, and identifying differences between framework versions. Formal contract language and Department of Defense guidance should drive major compliance changes.

What should a managed service provider deliver for CMMC support?

A capable provider should deliver clearly defined IT and security services, documented control responsibilities, asset and identity management, endpoint and email protection, vulnerability management, logging, backup testing, incident-response support, and organized evidence. The agreement should also specify SLAs, support hours, escalation paths, reporting, subcontractor roles, and limitations. Technology alone does not establish CMMC compliance.

Can CMMC controls support HIPAA, SOC 2, or FTC Safeguards Rule compliance?

CMMC-aligned practices can support broader governance because frameworks commonly address access control, risk management, logging, incident response, and system protection. However, CMMC does not automatically establish HIPAA, SOC 2, FTC Safeguards Rule, or PCI DSS compliance. Each framework has distinct scope, control language, evidence expectations, and accountability requirements.

What is the biggest business risk of waiting for the final CMMC decision?

The principal risk is confusing a temporary implementation pause with a suspension of underlying cybersecurity responsibilities. Delaying asset inventory, access control, vulnerability remediation, backups, incident response, and documentation can leave an organization exposed under existing contracts and make a later assessment more disruptive. A risk-based readiness program preserves flexibility while formal policy decisions are pending.

Related Reading on My MSP Tech

Find a Qualified Managed IT & Cybersecurity Contractor

Need help acting on this? Browse managed IT & cybersecurity providers in your area, or explore managed IT services like preventative maintenance, inspections, and emergency response. Are you a contractor? List your business on My MSP Tech to reach IT and operations leaders actively searching for help.

Sources

  1. insidedefense.com
  2. cyberab.org
  3. cmmc.com
  4. cmmc.com
  5. insidedefense.com
  6. natlawreview.com

Originally sourced from Inside Defense

CMMC Phase 2CMMC 2.0NIST SP 800-171managed cybersecuritydefense contractors