The Pentagon just suspended CMMC Phase 2 third-party assessment requirements. Before you treat that as a hall pass, read what DoD CIO Kirsten Davies actually said: the current instantiation "doesn't math." That's a program under review, not a program being killed.
Your competitors who spent the last 18 months deprioritizing CMMC prep because "it keeps slipping" are making that same mistake again right now. The question isn't whether Phase 2 is paused. It's what this pause signals for your positioning — and whether you're using it to get ahead or to fall further behind.
What Actually Happened
DoD suspended plans to ramp up CMMC third-party assessments as part of a formal review. The stated rationale: the program had become too bureaucratic and burdensome, particularly on small business contractors who lack the internal resources to absorb C3PAO assessment costs and timelines. The review is examining "scalable cybersecurity approaches" — language that suggests the final CMMC structure may look different from what's currently in the DFARS.
What's actually in suspension: the Phase 2 requirement for C3PAO (third-party) assessments on contracts above Level 1. What's still live: existing DFARS 252.204-7012 requirements, the ongoing inclusion of CMMC clauses in new solicitations, and the expectation that contractors maintain and can demonstrate compliance.
The practical read: DoD is recalibrating the verification machinery. The underlying expectation that you're actually protecting CUI is unchanged.
The Competitive Angle Nobody's Talking About
Here's the uncomfortable truth this pause surfaces. For the past two years, CMMC has functioned as a soft filter — not because assessments were being enforced, but because the threat of assessment changed BD behavior. Some small businesses spent real money getting compliant (or close to it). A larger group kept kicking the can.
The pause hands the can-kickers a temporary reprieve. It doesn't give them a compliance posture.
When Phase 2 requirements resume — revised or not — the contractors who used this window to get their documentation, SSP, and POA&M in order will move faster through any future assessment process. The ones who treated the pause as confirmation that CMMC is vapor will start from scratch. Again.
There's also a solicitation-level angle worth tracking. Contracting officers at DoD components are still writing CMMC requirements into draft RFPs right now. The suspension affects assessment mandates, not the drafting practices of individual program offices. If you're evaluating a DoD opportunity with a CMMC Level 2 clause and you're reading the suspension as "we can ignore this," you're reading it wrong.
What Smart BD Shops Are Doing Right Now
Auditing their active pipeline for CMMC exposure. Which of your current opportunities or recompetes have CMMC Level 2 or 3 language? Map those now. The suspension doesn't affect solicitations already in flight with CMMC clauses — it affects the assessment enforcement timeline for future contracts.
Not canceling planned C3PAO prep work. If you were already mid-stream on getting your System Security Plan buttoned up or working toward a CMMC Level 2 readiness assessment, do not stop. The review is examining how assessments happen, not whether they're required. Pausing your prep now means re-spinning it when requirements firm up — with less runway.
Watching the post-quantum cryptography signal. This isn't unrelated. DoD is simultaneously pushing post-quantum cryptography requirements into the CMMC framework. The PQC angle could actually make the revised CMMC structure more demanding in certain areas, not less. If you're focused on the Phase 2 pause and missing the PQC insertion, you're reading the wrong headline.
Using the pause to differentiate. If your competitors are coasting, this is a window to get ahead on compliance posture and make it part of your capability narrative in proposals and capability briefings. Contracting officers evaluating small businesses know the suspension happened. A vendor who can credibly demonstrate CMMC readiness in this environment stands out precisely because most can't.
That range — based on industry estimates from assessment firms and GovCon compliance consultants — is real money for a sub-$10M firm. The suspension doesn't eliminate that cost; it pushes it to a later date that isn't clearly defined. That ambiguity is a risk management question, not a permission slip.
Reading the DoD CIO's Language
When Davies said the math "simply doesn't math," she wasn't signaling that cybersecurity requirements are going soft. She was signaling that the implementation model — specifically, the cost and timeline burden of C3PAO assessments on the small business industrial base — is unsustainable at scale.
That's a bureaucratic efficiency critique, not a security posture retreat. DoD still needs contractors who can protect CUI. They're trying to figure out a verification mechanism that doesn't price out the small business base entirely.
The most likely outcome of this review isn't "CMMC disappears." It's "CMMC gets restructured with a tiered or self-attestation pathway for lower-complexity contractors, while higher-sensitivity programs keep or increase third-party assessment requirements." That's been the direction of travel since CMMC 2.0 replaced CMMC 1.0.
If that's the direction, here's what it means for BD: firms that can credibly self-attest — because their documentation, access controls, and incident response processes are actually built out — will have a lighter compliance burden. Firms that have been waiting for the assessment requirement to force them to get compliant will find themselves unable to self-attest honestly. That's a proposal loss waiting to happen.
The BD Decision Framework
Apply the same logic you'd use on any compliance-heavy bid. This connects directly to how you should be thinking about bid strategy on compliance-gated opportunities more broadly — the question isn't just "can we comply?" but "what does our compliance posture do to our win probability?"
A few questions worth forcing through your capture process on any active DoD opportunity right now:
- Does this solicitation's PWS or requirements section reference CMMC Level 2 or Level 3? If yes, the suspension doesn't change the contractual requirement.
- Is our SSP current, accurate, and defensible? Not "will we pass an assessment" — "could we stand behind this document in a debrief?"
- Are we tracking the DoD CIO review output? The revised rule or class deviation will matter. Put it on your pipeline risk register, not your someday reading list.
- What are our likely competitors doing? If the field is mostly small businesses who've been deferring compliance work, a firm that's ahead can make that a differentiator in their past performance narrative and capability briefings.
For how this fits into broader patterns around requirements being shaped before solicitations drop, it's worth cross-referencing what we've covered on wired RFPs — the same dynamics that produce wired requirements also produce compliance clauses that are written for a specific vendor's posture.
The Bottom Line
The CMMC Phase 2 suspension is a buying opportunity, not a get-out-of-jail card. DoD is restructuring the verification mechanism because the current one is breaking small business participation in the defense industrial base. That's a real problem they're trying to solve — but the solution will still require you to actually secure your systems and document it.
The firms that use this window to get ahead on compliance posture will be better positioned whenever the revised requirements land. The firms that use it as an excuse to keep deferring will be exactly where they are today, only with less time to react.
The pause is the signal. What you do with it is the strategy.
Frequently Asked Questions
Does the CMMC Phase 2 suspension mean I don't need to comply with cybersecurity requirements on current DoD contracts?
No. DFARS 252.204-7012 and the underlying NIST SP 800-171 requirements remain contractually enforceable on any contract that includes those clauses. The suspension affects the Phase 2 C3PAO assessment mandate for new contracts — it doesn't remove existing contractual obligations or change the CUI handling requirements your active contracts already require.
Should I cancel or delay my planned CMMC assessment prep work?
Only if you're certain the specific contracts in your pipeline have no CMMC clauses and you're not pursuing DoD work that handles CUI. For most small businesses with active or planned DoD pipeline, pausing prep work now means restarting it under time pressure when the revised requirements are published. The cost of getting ahead is lower than the cost of scrambling later.
How long is the suspension expected to last?
DoD hasn't published a specific timeline for completing the review. Given the complexity of revising DFARS provisions and the interplay with the emerging post-quantum cryptography requirements DoD is trying to integrate into CMMC, industry estimates range from several months to over a year. Track the DoD CIO's office for formal guidance rather than relying on secondary reporting.
If my competitor hasn't started CMMC compliance work, does the suspension level the playing field?
Operationally, yes — for now. Competitively, no. Firms with documented compliance posture, a current SSP, and a credible POA&M can demonstrate readiness in capability briefings and proposal responses today. Firms without that documentation can't, regardless of what the assessment enforcement timeline looks like. The suspension delays the audit; it doesn't change who's actually prepared.
Field notes for federal small business contractors. Sharp, direct, and free of the consultant-speak that dominates the GovCon trade press. We help BD leaders allocate proposal capacity better — fewer wasted bids, more wins on the bids that matter.