MacZine
The MacTech Solutions Newsletter
Issue Nº 005 ·

From the field · CMMC

CMMC Phase 2 Is Paused. Your Compliance Clock Isn't.

DoD paused CMMC Phase 2 certification to review the program — the DFARS and NIST 800-171 obligations under it did not. What to do during the review.

The Pentagon has suspended CMMC Phase 2 certification requirements and opened a review of the program that was supposed to enforce them — a genuine reprieve for any contractor staring down an assessment deadline, and the single riskiest moment in this program's short life for anyone who reads a pause as a stand-down order.

What actually paused

Start with what the DoD's review covers, and what it doesn't. The suspension applies to CMMC Phase 2 certification requirements — the third-party assessment schedule and the contract clauses that would have started requiring a C3PAO sign-off. It does not rewrite DFARS 252.204-7012, the clause that has obligated safeguarding of covered defense information to the NIST SP 800-171 standard since 2017, and it does not touch your standing obligation to keep an honest score in SPRS. CMMC certification was always the verification layer bolted onto requirements that predate it. Pausing the verification layer doesn't repeal the thing it was built to verify.

That distinction is easy to lose in a press release and expensive to lose in a contract review. If your System Security Plan cites 252.204-7012, that citation didn't get an asterisk this month.

The mistake this pause invites

Every program we've run through a CMMC pause or rewrite before — 1.0 to 2.0 was the last one — produces the same pattern. Budget gets redirected the moment a certification deadline looks soft. POA&M items lose their owners. Evidence collection, which only works as a habit captured at the moment work happens, goes quiet. Then the review concludes, the requirement returns in some form, and the program that coasted is further behind than it was before the pause, because six months of undocumented work is six months of reconstruction, not evidence.

A review of a certification program is not evidence the underlying security requirement was wrong. It's normal for a young federal rulemaking to have its enforcement mechanics revisited — that's what happened between CMMC 1.0 and 2.0, and the 800-171 obligation underneath survived that rewrite untouched. Betting your posture on the review concluding "compliance wasn't necessary after all" is not a bet the last several years of DIB cybersecurity rulemaking supports.

What we're doing with clients during the review

We're not treating this as a quiet period. Three things stay in motion for every client we support:

  • Monitoring the rulemaking, not the headlines. We track DoD guidance, interim rule text, and contracting-officer direction as the review proceeds, and we flag the difference between "reported" and "final" — a distinction that matters when a program office asks what changed.
  • Keeping evidence current regardless of the certification calendar. Posture work doesn't stop because the assessment schedule did. MacTech Codex keeps mapping controls to evidence and tracking posture against NIST SP 800-171 on its own clock, and EnclaveWatch keeps producing Vault-resident audit trail, drift validation, and a signed evidence export on a weekly ISSO review cadence — none of that machinery cares whether Phase 2 is currently enforceable.
  • Translating whatever comes out of the review into specific action. When the review concludes — reinstated Phase 2 on a new timeline, a revised mechanism, or something else entirely — we tell every affected client exactly what changed for their contracts and what, if anything, they need to do differently. That's a notification, not a fire drill, because the posture work never stopped.

What this does not mean

We'd rather state the limits plainly than let a client discover them later. We don't know the review's terms of reference, its expected completion date, or whether it will reinstate Phase 2, revise it, or replace it with something else — nobody outside the Department does yet, and we won't guess in print. This pause also doesn't touch contract-specific clauses already in force on your current awards; if you're unsure what your contract actually requires right now, that's a contracting-officer question, not a newsletter answer. And a paused certification requirement is not a signal to stop tracking CUI flow, stop reviewing access, or stop exporting evidence — the controls exist because the risk they address didn't pause either.

Where this leaves a program office

The programs that come out of this review period ahead are the ones that treated the pause as a scheduling change, not a scope change — scoping stayed disciplined, the SSP kept getting updated in the same change window as the system, and evidence kept accumulating on its own cadence. If your CMMC Level 2 program is mid-build, this is the moment to tighten the boundary and the evidence pipeline, not to shelve them. If you want a second set of eyes on where your posture actually stands while the certification mechanics are in flux, start a readiness conversation or talk to us — we'll tell you plainly what the pause changes for your contracts and what it doesn't.