Austin Justice in front of White House

Your CMMC Just Got Cheaper. Your Responsibility Didn't.

July 14, 20264 min read

Your CMMC Just Got Cheaper. Your Responsibility Didn't.

If you've seen today's announcement that the Department of Defense is suspending the rollout of CMMC Phase 2, you might be wondering what it means for your business.

The short version?

This is good news for you.

For at least the next 60 days, the Department of Defense has paused the rollout of mandatory third-party CMMC certifications while it reviews the program.

(See the actual memo here: https://federalnewsnetwork.com/wp-content/uploads/2026/07/CIO-CMMC-Reform-Memo_26-P-1023.pdf?hss_channel=lcp-348902)

That likely means one thing for many companies:

Your path to compliance just became less expensive.

But before you celebrate too much, there's one important distinction to understand.

The Department of Defense did not announce that protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) is no longer required.

They announced they're re-evaluating how to verify you are protecting it.

Those are two very different things.

The cybersecurity requirements behind CMMC still exist today. The contractual obligation to protect CUI and FCI still exists. If you're handling sensitive government information, the expectation that you safeguard it has not changed.

What appears to be under review is the certification process itself.

From my perspective, that's a good thing. If you've been on one of my calls, listened to our podcast, or heard me speak, you've probably heard me say the same thing for years: the certification process has become more burdensome than it needs to be. There is unnecessary administrative overhead that disproportionately impacts small businesses.

If the Department of Defense can reduce unnecessary cost, eliminate administrative burden, and make certification more practical without lowering the security bar, that's a win for everyone in the Defense Industrial Base...and frankly, a win for us taxpayers.

So what should you do?

My recommendation is simple:

Keep moving forward.

If you were implementing NIST SP 800-171 (what the certification standard is designed to validate) yesterday, continue implementing it tomorrow.

If you were documenting policies, deploying security controls, or improving your environment, don't stop.

In fact, this announcement may actually work in your favor.

Instead of rushing toward an expensive certification deadline, use this opportunity to finish implementing your compliance program while the Department of Defense determines what the future verification model looks like. Whether the review lasts 60 days or results in a longer implementation timeline, you'll be in a much stronger position by focusing on the work that actually improves security.

Whether the outcome is a delayed timeline, a streamlined assessment process, lower certification costs, or something else entirely, organizations with mature cybersecurity programs will be in the strongest position.

One thing I would caution against is assuming the problem has disappeared.

Cyber threats haven't gone away, and we're involved in several military conflicts.

The government's need to protect sensitive information hasn't gone away.

Prime contractors still have every reason to expect their suppliers to maintain strong cybersecurity practices.

The requirement to secure government information is bigger than any single certification program.

One thing I personally wonder about is what happens if third-party certification becomes less prominent.

If you've followed me for a while, you know I've always said that simply reporting an SPRS score without having the documentation, policies, procedures, and technical evidence to support it is risky.

Earlier this year, I had an investigator from the Department of War stop by our booth at a manufacturing trade show looking for leads related to ITAR fraud. That experience reinforced something I've believed ever since: the government takes false representations seriously.

If certification becomes less prescriptive, I could see the government placing greater emphasis on verifying what companies self-attest to. That might mean more requests for evidence, more spot checks, or other methods of validating compliance claims.

I don't know if that's where this review will end up, but it's one possibility companies should think about before assuming documentation no longer matters.

Exactly what that looks like remains to be seen.

So yes, I hope this is good news.

I hope compliance becomes more affordable.

I hope certification becomes more practical.

But until we know otherwise, my advice remains exactly the same:

Build the cybersecurity program your business needs.

Protect your customers' information.

Document what you're doing.

And be ready for whatever verification model ultimately comes next.

Your CMMC may have just gotten cheaper. Your responsibility didn't go away.


Austin Justice

Co-Host, CMMC Compliance Guide Podcast

Austin Justice

Austin Justice

Austin Justice is a dynamic IT professional whose passion for technology began in high school, where he started freelancing and quickly earned five IT certifications before graduation. His early achievements include competing at the national level for Cisco Networking and being one of just six youth in the nation to become a certified Panduit fiber and copper technician. Throughout his IT career, Austin has gained extensive experience, from pulling cable and providing help desk support to designing network infrastructures and consulting with companies during and after cyber breaches. His certifications encompass a wide range of expertise, including Cisco, SonicWALL, networking, hardware, and fiber and copper technologies. Beyond his tech-savvy pursuits, Austin shares a deep-rooted passion for cattle and ranching with his family. They raise Santa Gertrudis cattle, known for their exceptional qualities and genetics, and take pride in breeding animals that are highly sought after by other breeders.

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog