The future of CMMC has rarely been less clear. In an industry that spent years bracing for mandatory assessments, the sudden Phase II pause in July 2026 left defense contractors, government employees, C3PAOs, and MSPs all asking the same question: what happens now?
The reactions have split along predictable lines. Some insist nothing has meaningfully changed and that contractors should keep pursuing C3PAO assessments as planned. Others are arguing the opposite, that continuing to pursue assessments during the pause is a waste of time and money. Some have even suggested the Department might do away with third-party assessments altogether and instead pursue noncompliant contractors through the False Claims Act, turning enforcement into the primary lever of compliance.
Nobody knows what the Department will decide next year, next month, or even next week. But we can look at what’s actually been said, what’s being prioritized, and what the threat landscape demands, and use that to sketch out the most likely paths forward.
What’s on the Record
Very little has been said publicly about the Department of War’s plans for CMMC following the Phase II suspension this summer. DoW CIO Kirsten Davies has played her cards close to the chest, and the CMMC Reform Task Force has yet to make any substantive announcements about the framework.
However, that doesn’t mean that there aren’t clear clues about what’s most important to the current administration.
Speed and combat readiness are the DoW’s priorities. Secretary Pete Hegseth’s Arsenal of Freedom Initiative has made clear that the Department of War wants capabilities in the hands of the warfighter faster, with less friction along the way. Kirsten Davies, the DoW CIO, has echoed this mandate repeatedly. Most recently, DOW Deputy Secretary Steve Feinberg signed a memo directing the Department of War to eliminate audit, accounting and compliance requirements and open up competition. The stated goals include optimizing for speed and volume and unleashing private industry.
CMMC is too costly and too complex. The response to the CMMC Reform Task Force’s RFI this summer was overwhelming, and the message from small and mid-sized defense contractors was consistent. Businesses described assessment costs that ran well beyond what they’d budgeted, timelines that stretched for months, and a documentation burden that pulled staff away from the work the contracts were actually meant to fund. For many companies, Level 2 compliance has been an untenable burden.
The DIB threat landscape presents unique challenges. While the government decides what to do about CMMC, the threats facing the Defense Industrial Base remain serious and numerous. Supply chain compromises continue to give adversaries a way into prime contractors through smaller subcontractors, AI-enabled attacks are lowering the skill and cost required to run effective phishing campaigns, and nation-state actors have made clear that the DIB is a high-priority target. Whatever new form CMMC might take, it will ultimately have to produce security outcomes that hold up against these kinds of cyberattacks.
Operational resilience is the order of the day. Across MSPs, MSSPs, and internal security teams throughout the DIB, the consensus is that operational resilience is the goal. The old model of data confidentiality has largely centered on keeping CUI out of the wrong hands, an important goal, but not the only priority anymore. The emerging model of operational resilience asks a broader question: if an organization is compromised, how quickly can it detect the intrusion, contain it, and keep operating?
Taken together, these four data points don’t tell us what the Department will do about CMMC. But they tell us what pressures are shaping the decision, which is enough to start narrowing down the possibilities. Below, we outline three potential outcomes of the Phase II pause.
Possibility 1: The End of NIST 800-171
What we’re seeing beneath the Phase II suspension is a deeper dislike of the underlying NIST SP 800-171 standard. As early as February or March of 2026, Davies was communicating skepticism around CMMC in industry conversations.
Meanwhile, the language justifying the Phase II suspension has centered on C3PAO assessor availability and cost. But if you look closely, the RFI itself has a different focus. It’s asking about the underlying NIST standard and controls. If the concern were really just bandwidth, the RFI would have looked more like a staffing and budget survey.
Davies’ messaging since day one has emphasized the switch from data confidentiality, which is the focus of NIST 800-171, to data resiliency. This is also the focus of Secretary Hegseth and the Arsenal of Freedom, prioritize resiliency, speed, and delivering modern capabilities to the warfighter. From that standpoint, 800-171 is bureaucratic red tape that’s actively getting in the way of the DoW’s goals.
With that in mind, there is a chance that the DoW will announce a move away from 800-171 to another, currently unknown standard. But we think this is fairly unlikely. It would require a regulatory master play to replace the foundational standard the entire DIB compliance ecosystem is built on, and it would be an extremely heavy lift, both politically and operationally. While it’s not impossible, it seems improbable from everything we know so far.
Possibility 2: A Return to the Status Quo
The second possibility is a return to the status quo. Under this scenario, the Phase II pause would end, CMMC Level 2 assessments would resume roughly as they were designed (probably on a slightly extended timeline), and the DoW would move forward with NIST SP 800-171 Rev. 3 within the next year.
The move to Rev. 3 in particular would fit with the Department’s focus on operational resilience. It emphasizes things like continuous monitoring over point-in-time compliance, ongoing governance over set-and-forget implementation, and operational supply chain risk management over one-time questionnaires.
Rev. 3 also adds more organizationally defined parameters (ODPs), which let the DoW tailor certain requirements to the real-world risk a given contractor faces rather than applying a single rigid standard across the board. On paper, all these shifts line up with the operational resilience the DoW says it wants.
This outcome would certainly be the best path for the C3PAOs in the ecosystem. It lets them continue conducting the assessments they’ve spent years building their business around, and it preserves the careful infrastructure they’ve created around the current framework.
Still, we think a full return to the status quo is unlikely. Reversing course entirely would mean admitting that the Phase II pause accomplished little, and that’s a hard position to walk back. More importantly, it wouldn’t address the cost and complexity problems the RFI responses attested to this summer. (Our C3PAO Report lays out those issues in detail.) Going back to the way things were would leave all those underlying problems in place without a solution.
Possibility 3: The Likely Middle Ground
The third and most probable outcome is a middle-of-the-road approach where the DoW doesn’t completely overhaul the CMMC regulatory structure, but it doesn’t return to business as usual either. Instead, this scenario would see the Department making targeted changes to the existing order.
That likely means keeping the C3PAO system in some form, since dismantling third-party assessments entirely would return the DIB to its pre-CMMC state of self-attestations and honor systems. But it probably also means shrinking the footprint of Level 2 assessments. Instead of roughly 50% contractors requiring a full third-party assessment, the Department might narrow that down to something closer to 10%, reserving independent assessment for the organizations handling the most sensitive information or posing the greatest risk.
In this scenario, we might also see more progressive assessment tiers based on contract sensitivity, a narrower set of controls under assessment at each level, or some combination of both. Whatever the specifics, the goal would be the same, address the cost and complexity concerns of CMMC without discarding the underlying security requirements altogether.
This path would offer a compromise to the DIB, and it would require the least political risk of the three options while still producing something resembling reform.
It certainly wouldn’t satisfy everyone, especially the C3PAOs who would have to change their business model, but it would let the DoW position itself as an ally of industry while still preserving the core architecture it spent years building.
What We Shared With the Reform Task Force
Sentinel Blue submitted a public response to the RFI, and much of what we suggested maps directly onto the pressures outlined above. Here’s a distillation of some of the key recommendations we shared in our comments.
On cutting cost and complexity for small and mid-sized contractors: We recommended re-architecting the certification assessment itself. Right now, two Certified CMMC Assessors (CCAs) must participate in every assessment, with a third performing quality assurance. We think that number is higher than it needs to be, and Certified CMMC Professionals (CCPs) could be part of the solution. We also recommended narrowing the scope of what gets assessed, focusing primarily on the handful of requirements that most benefit from independent review, and we argued for a more collaborative process overall, one where a failed control can be remediated without triggering an instant failure.
On change management: We recommended the Department stop treating every significant change to a certified environment as grounds for full reassessment. NIST 800-171 requires a change management process, so certified organizations have already demonstrated they have one. When the DoW wants visibility into a specific change, a delta assessment focusing narrowly on what actually changed would provide that assurance at a fraction of the cost.
On increasing assessment capacity: We recommended that, instead of reviewing all 110 CMMC controls at one organization per week, a DIBCAC team could review a handful of the highest-risk requirements (things like multi-factor authentication) across ten organizations in the same timeframe. The Department would trade depth at a few companies for visibility across many, and the DIB as a whole could properly prioritize the most impactful security controls.
On streamlining the standard: We recommended eliminating the requirement to use FedRAMP Moderate cloud solutions, which currently limits organizations to a narrower set of tools than what’s available on the commercial market and pushes some toward shadow IT. We also recommended eliminating the FIPS-validated cryptography requirement, which would let organizations adopt modern security capabilities more readily than the current standard allows.
On improving operational resilience: Finally, we recommended moving to NIST 800-171 Rev. 3, which would add meaningful security capability while eliminating some of the lower-impact requirements, and which gives the Department the ability to set organizationally defined parameters to tailor requirements to real-world risk.
Staying Ready for Whatever Comes Next
We can’t tell you which of these three outcomes will happen. What we can tell you is that none of them involve a world where you’ll never have to demonstrate your security posture again. In the future, it might come from a DIBCAC, a C3PAO, or a prime passing down requirements to you, but in every scenario you’ll still need know where your CUI lives, and you’ll still need to provide current documentation.
Until the DoW says more, and regardless of what the assessment requirements end up looking like, the right move is to stay adaptable and keep prioritizing good security. The organizations that come out ahead won’t be the ones that gambled on one outcome or another; they’ll be the ones that were focused on building their security and resilience all along.