Skip to content
EternaEdge

Defense & govcon

The CMMC pause is not a pass

21 July 2026 · 2m read · By EternaEdge

On July 13 the Pentagon suspended Phases 2 through 4 of the Cybersecurity Maturity Model Certification rollout — the phases that would have required third-party certification for many Level 2 contractors — pending a 60-day program review, with an industry request for information due August 14. Per analysis from Arnold & Porter, some contractors read the headline as a reprieve. It is not.

What remains fully in force is nearly everything that matters today: Phase 1 self-assessments, DFARS clause 252.204-7012, annual SPRS score affirmations, and the CMMC final rule itself at 32 CFR Part 170. The assessment clause, 252.204-7021, continues to appear in most new solicitations. The review may reshape how certification is verified — it does not change what must be protected, or the fact that executives now personally affirm their scores.

The risk of reading it as relief
  • False-affirmation exposure is live now. A signed SPRS affirmation that overstates a security posture is a False Claims Act problem regardless of which CMMC phase is active.
  • Adversaries do not pause with the program. The same month this review began, CISA and partner agencies attributed a decade of network-device collection against the defense industrial base to Russia's FSB Center 16.
  • Whatever the review changes, the direction is one-way: verification of contractor security is becoming a condition of doing defense business, not a differentiator.

The contractors who will absorb the eventual restart without pain are the ones treating the pause as schedule slack for real hardening — closing the gap between their affirmed score and their actual posture — rather than as permission to stop.

Perspective

Compliance frameworks describe a minimum. The programs adversaries target hardest need to know who is probing them, not just whether controls are documented. That is the difference between passing an assessment and defending a mission.

STRATUM — Cyber Threat is built for that second question: attack-surface exposure and threat-actor activity read with counterintelligence context, complementing — not replacing — the SIEM and compliance stack a contractor already runs. The review will end; the targeting will not have paused for it.

Next step

See it run on your domains of protection.

A demo walks the full arc — signal to case to defensible record — with the domains you protect in the room.