CMMC Phase 2 Is on Hold. Your Cybersecurity Obligations Aren't.


Posted August 3, 2026 by ICSIUSA

ICSI helps government contractors and construction firms cut through the July 2026 CMMC suspension — and prove the compliance they've already paid for.
 
ANNAPOLIS, MD – July’26 — On July 13, 2026, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program the milestone, set for November 10, 2026, that would have made independent third-party (C3PAO) assessments a condition of contract award for companies handling Controlled Unclassified Information (CUI). The Department also launched a 60-day reform review and a public request for information, leaving the program's long-term shape uncertain. For thousands of government contractors and construction firms that spent the last two years and real budget preparing for that deadline, the natural reaction is relief and, right behind it, confusion about what they still have to do.

According to International Computer Services, Inc. (ICSI), a managed IT and security services provider that has served regulated industries since 1987, the pause is being widely misread. The audit timeline moved. The underlying legal and security obligations did not.

"For two years we told contractors the third-party audit was coming, and a lot of them spent real money getting ready for it," said Max Sedghi, VP of Client Success at ICSI. "Now that audit's been paused but I'd caution anyone against reading that as 'stand down.' The self-assessment you post to SPRS is still a formal attestation. The security requirements written into your contract haven't moved. And the False Claims Act still applies to a score you can't actually back up. If anything, the pause makes your self-attestation matter more, because for the foreseeable future there's no assessor coming to catch the gaps for you."

What Actually Changed on July 13

The suspension halts the planned expansion to mandatory third-party assessments. During the review period, contracting officers may include only CMMC Level 1 (Self) or Level 2 (Self) requirements in new contracts, and agencies will strip C3PAO or Level 3 language out of existing contracts by modification before the next option period. A newly formed CMMC Reform Task Force will report to the DoD CIO within 60 days, drawing on industry feedback due August 14, 2026. Officials cited assessor-capacity shortages and compliance costs — not a reduced security bar — as the reason for the pause.

What Did Not Change

This is a policy pause, not a repeal. The CMMC Program Rule and the DFARS clauses remain on the books, and the obligations contractors already carry are untouched:

Phase 1 self-assessments are still required in applicable solicitations, with scores posted to the Supplier Performance Risk System (SPRS).
The NIST SP 800-171 security baseline still applies. DFARS 252.204-7012 obligations to protect Federal Contract Information (FCI) and CUI remain fully in force.
A false or unsupported self-attestation still carries False Claims Act liability — a risk that grows in relative weight now that self-assessment is the enduring standard rather than a stepping stone to an audit that would have surfaced the gaps.
Why the Gap Still Hurts

ICSI points to the same recurring reasons compliance spending doesn't always translate into compliance confidence — reasons the pause does nothing to fix:

Point-in-time fixes, not ongoing management. A consultant-led assessment captures a single moment; systems, staff, and vendors change every quarter after that.
Self-attested SPRS scores that were never independently validated. Many contractors submitted a score without confirming it would actually hold up under scrutiny — and with third-party audits paused, no one else is checking it either.
System Security Plans and POA&Ms that go stale. Documentation built for the initial push often isn't maintained as infrastructure changes.
Subcontractor and flow-down gaps. Primes are still expected to verify that their subs meet the same standard — something many smaller firms don't realize applies to them.

What ICSI Recommends Now

For companies caught between relief and uncertainty, ICSI recommends validation over new spending: a gap assessment that reviews what's already been purchased and implemented, an independent check of the current SPRS score against actual requirements, a refresh of the SSP and POA&M documentation, and ongoing monitoring to keep it all current as the reform review plays out — ideally at a fixed monthly cost, so compliance doesn't become another open-ended spend.

ICSI offers this through its Compliance-as-a-Service and Managed Security Service Provider (MSSP) programs, built specifically for government contractors, construction firms, and other regulated businesses.

"The smart move right now isn't to panic, and it isn't to stop," said Max Sedghi, VP of Client Success at ICSI. "It's to validate what you already bought confirm your SPRS score would actually hold up, keep your documentation current, and be ready to move the day the rules firm up again. Compliance didn't go away. It just got quieter, and quiet is exactly when companies let it slip."

About ICSI – International Computer Services, Inc.

Founded in 1987, ICSI is a managed IT services and consulting firm headquartered in Annapolis, Maryland, serving businesses and organizations for nearly four decades. As a leading Maryland IT company, ICSI delivers customized, secure, and scalable technology solutions to clients across the Mid-Atlantic region and nationwide.

ICSI proudly serves businesses throughout Maryland, Northern Virginia, Washington, DC, Texas, and Florida, with additional office presence in Tampa, Florida, supporting clients along the East Coast and beyond.

Regional IT Service Areas Include Annapolis, Arlington, Alexandria, Baltimore, Beltsville, Bethesda, Bowie, Catonsville, Clinton, College Park, Columbia, Falls Church, Fairfax, Frederick, Greenbelt, Hyattsville, McLean, Raleigh, Reston, Rockville, Silver Spring, Tampa, Sarasota, Austin, Houston, Dallas, and more.

Industries Served - Medical practices, nonprofit organizations, real estate agencies, construction companies, consulting firms, engineering groups, and professional services organizations rely on ICSI for managed IT services in Maryland and across the U.S.

Media Contact:
ICSI
Phone: 410.280.3000
Website: www.icsi.com
--- END ---
Contact Email [email protected]
Issued By ICSI
Phone 4102803000
Business Address 1612 McGuckian St, Suite 200, Annapolis, MD 21401 United States
Country United States
Categories Business
Last Updated August 3, 2026