By John Grancarich, EVP, Head of Defense & Intelligence, Fortra
The recent pause affecting the implementation of Cybersecurity Maturity Model Certification (CMMC) Phase II has understandably generated questions across the Defense Industrial Base (DIB). For many organizations, the immediate reaction has been to ask whether compliance timelines will shift, whether assessment preparation can be slowed, or whether security investments can be deferred until additional guidance emerges.
Those questions are understandable. They are also focused on the wrong issue.
While implementation timelines may evolve, the underlying security requirements that drove CMMC’s creation have not changed. The Department of Defense still depends on contractors to protect Controlled Unclassified Information (CUI).
Adversaries continue targeting defense contractors, supply chains, and critical technology providers. Federal cybersecurity expectations remain in place. And the contractual obligations associated with protecting sensitive information have not suddenly disappeared.
While this pause may affect the mechanics of certification, it does not change the importance of protecting sensitive data.
Understanding What Has and Has Not Changed
One of the challenges with discussions surrounding CMMC is that organizations sometimes treat the framework as though it exists in isolation.
In reality, CMMC was built on foundations that predate the certification model itself. At the center of those foundations is NIST SP 800-171, which establishes the security requirements for protecting Controlled Unclassified Information in non-federal systems and organizations.
For many defense contractors, contractual obligations tied to DFARS 252.204-7012, security requirements derived from NIST SP 800-171, incident reporting obligations, and broader federal cybersecurity expectations remain in effect regardless of changes to CMMC implementation timelines.
In other words, a pause in certification activity should not be interpreted as a pause in security responsibility.
Organizations that postpone cybersecurity improvements based solely on certification timing may ultimately find themselves further behind when assessments resume. More importantly, they may increase operational and contractual risk during the interim.
The Bigger Risk: Treating Compliance as a Calendar Event
One of the most common mistakes organizations make is viewing compliance as a project rather than a capability.
When that happens, security initiatives often become tied to external deadlines. Resources are allocated when an assessment approaches and then reallocated elsewhere when timelines change.
The problem with this approach is that adversaries do not operate on compliance schedules.
The same data that will eventually be assessed under CMMC remains valuable to nation-state actors and cybercriminal organizations today. Sensitive technical information, program documentation, engineering data, and operational information do not become less attractive simply because certification timelines move.
Organizations that suspend readiness efforts may discover they have unintentionally created gaps in areas such as:
- Access controls
- Privileged account management
- Multifactor authentication
- Data protection
- Audit logging
- Asset visibility
- Security documentation
- Evidence collection
These are not merely audit concerns. They are foundational security capabilities.
Where Many Contractors Still Struggle
After numerous discussions across government, defense contractors, and allied defense organizations, a recurring theme emerges: most organizations do not struggle with understanding why security matters.

They struggle with understanding where sensitive information actually resides and how it moves.
Many organizations have spent years focusing on systems and infrastructure. Increasingly, the challenge is understanding the data itself.
Common readiness gaps include:
Access and Authorization
Organizations frequently maintain broad access models that evolve over time as teams, contractors, and programs expand. Rights accumulate faster than they are reviewed, creating unnecessary exposure.
Information Sharing
Sensitive information often moves between organizations, subcontractors, cloud services, collaboration platforms, engineering environments, and operational systems without a consistent framework for handling and protection.
Documentation and Evidence
Many organizations have implemented security controls but struggle to demonstrate them consistently through policies, procedures, artifacts, and audit evidence.
Supply Chain Visibility
Prime contractors may have strong visibility into their own security posture while having significantly less insight into how subcontractors and external suppliers handle controlled information.
These challenges become more significant, not less, during periods of regulatory uncertainty.
Protecting Controlled Information During the Pause
Rather than slowing readiness efforts, organizations should use this period to strengthen areas that often receive less attention during formal compliance projects.
A useful starting point is surprisingly simple: know where your controlled information resides.
Organizations should be able to answer fundamental questions such as:
- What CUI do we possess?
- Where is it stored?
- Who has access to it?
- How is it shared internally?
- How is it shared externally?
- Which systems process it?
- Which suppliers interact with it?
Many security programs become more effective when they begin with visibility into sensitive information rather than visibility into infrastructure alone.
This is particularly important as organizations adopt cloud services, AI-enabled workflows, collaborative platforms, and increasingly distributed operating models.
Don’t Forget the Supply Chain
One of the most important lessons from recent years is that cybersecurity is no longer confined within organizational boundaries.
Defense programs are executed through increasingly interconnected networks of suppliers, technology vendors, consultants, and subcontractors.
As a result, a contractor’s security program is only as strong as its ability to manage risk across those external relationships.
Organizations should use this period to:
- Reassess supplier security expectations
- Review subcontractor handling requirements
- Validate data-sharing processes
- Clarify responsibility boundaries
- Improve third-party visibility
Waiting until assessments resume to address these issues often creates unnecessary friction and risk.
Maintaining Assessment Readiness
Organizations do not need to maintain a full-scale compliance war room during the pause. They do, however, need to preserve momentum.
Practical actions include:
- Continuing implementation of NIST SP 800-171 controls
- Maintaining Plans of Action and Milestones (POA&Ms)
- Updating system security documentation
- Collecting and organizing evidence
- Conducting periodic internal assessments
- Reviewing access-control processes
- Improving incident response readiness
- Tracking changes to protected environments
The goal should be to reduce future assessment effort, not create additional work later.
Organizations that continue operating as though an assessment could occur tomorrow will typically be in a far stronger position than organizations that suspend readiness activities entirely.
Evolving Compliance Into a Sustainable Security Program
Perhaps the most productive way to view the current situation is as an opportunity to mature beyond compliance-driven security.
The most effective security programs are not built around passing assessments. They are built around protecting information, enabling operations, and managing risk.
When organizations focus exclusively on certification, they often optimize for audits.
When organizations focus on understanding, controlling, and protecting sensitive information, compliance becomes a natural outcome of good security practices.
The organizations that emerge strongest from the current period of uncertainty will not necessarily be those that waited patiently for the next implementation update. They will be the ones that used the time to strengthen visibility, improve governance, mature data protection practices, and build sustainable security capabilities.
Looking Ahead
The CMMC Phase II pause may alter certification timelines, but it does not change the fundamental responsibility to protect controlled information.
Defense contractors should view this period not as a reason to slow down, but as an opportunity to improve readiness, reduce risk, and strengthen the security foundations that will remain relevant long after any particular compliance deadline changes.
Ultimately, CMMC was never intended to be the destination. It is a mechanism for improving cybersecurity across the Defense Industrial Base. That mission remains as important today as it was before the pause.
About the Author
John Grancarich is Executive Vice President and Head of Defense & Intelligence at Fortra, where he leads the company’s defense and intelligence business unit in support of the global national security community.
John regularly engages with leaders across defense, intelligence, and allied organizations to understand how data security challenges are evolving in mission environments. His work focuses on helping organizations protect sensitive information as it moves across systems, organizations, supply chains, and emerging AI-driven workflows.
A recognized expert in data security, John advocates for data classification as a foundational security control and for security policies that travel with the data itself. He frequently speaks on data-centric security, Zero Trust, coalition operations, allied information sharing, and the long-term resilience of security strategies in national security environments.
Previously, John served as Fortra’s Chief Strategy Officer, where he helped transform the company into a focused cybersecurity provider with data security at the center of its strategy. Earlier in his career, he founded Product Fuse and held leadership roles across cybersecurity, digital forensics, and legal technology. He is co-author of Internet Fraud Casebook: The Worldwide Web of Deceit.

