CMMC

CMMC Uncertainty Is a Challenging Leadership Moment

Share this

By Seiso’s CMMC Experts

What we know

On Monday, the Department of War (DoW) announced the suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, including the CMMC Third-Party Assessment Organization (C3PAO) assessment and certification requirements that were scheduled to begin appearing in contracts on November 10, 2026. Phase I has not been suspended: contractors remain subject to applicable self-assessment and Supplier Performance Risk System (SPRS) affirmation requirements.

Organizations should review how the change affects their current CMMC plans, including assessment timing, documentation, remediation activities, and ongoing governance responsibilities. The following are points of interest when considering the DoW’s reasoning for the temporary suspension.

  • Lack of certification progress: Few assessments have been completed, which the DoW attributed to a shortage of qualified assessors. This may also point to a lack of readiness by the organizations seeking certification, as increasing pressure from their customers or primes continue to rise.
  • Cost burden for small businesses: High assessment, remediation, and management costs raised concerns about the speed to market, created barriers to entry, and stifled innovation. This is an area where Seiso has identified quality technology partners and flexible solutions that meet the rigors of CMMC Level 2 (L2), while reducing management overhead for our CMMC customers.

To date, fewer than 2,000 defense contractors have achieved CMMC Level 2 certification. The Defense Industrial Base, DIB, was unlikely to meet the November 10th deadline, risking a supply chain unable to fulfill DoW demands.

What’ happens Next?

  • A 60-day CMMC Reform Task Force will evaluate the program and report back in September of 2026.
  • A Request for Information (RFI) has been released, seeking industry feedback1.
  • All prior cybersecurity requirements remain in force.

 

Seiso’s Evaluation & Advice

Seiso views the Phase II pause as a security leadership and risk management decision point—not a reason to slow down. The certification timeline may change, but the business risks tied to Federal Contract Information (FCI), Controlled Unclassified Information (CUI), supplier assurance, customer trust, contract eligibility, and executive attestation remain. Contractors should use this period to prove that their cybersecurity program is operating effectively, that leadership has defensible visibility into risk, and that CMMC activities are embedded into governance rather than treated as a one-time certification exercise.

  1. Treat self-attestation as an executive risk decision: Submitting and maintaining an SPRS score is a leadership representation of cybersecurity posture. Executives need to know what the score means, what evidence supports it, where control gaps remain, and how unsupported claims can create contractual, customer, and False Claims Act exposure.
  1. Separate compliance activity from security effectiveness: A System Security Plan (SSP), policy set, or Plan of Action and Milestones (POA&M) is not enough. Leadership needs evidence that controls are implemented, operating consistently, monitored, and tied to measurable risk reduction across systems that process, store, or transmit FCI and CUI.
  2. Use the pause to strengthen governance discipline: Resilient contractors will maintain a steady cadence for risk reviews, evidence validation, remediation tracking, vendor oversight, incident readiness, and leadership reporting regardless of external certification timing.
  3. Prepare for continued customer and prime scrutiny: Prime contractors and customers will continue asking suppliers to explain their CMMC posture, SPRS score, CUI scope, remediation plan, and governance model. A credible risk narrative is essential and must be backed by technical evidence.
  4. Choose operating models that reduce risk, not just audit burden: Managed, enclave-based, and shared-responsibility approaches can reduce complexity, but only when they clearly define scope, accountability, evidence ownership, operational monitoring, vendor dependencies, and long-term sustainability.

What Does it all mean?

For leadership teams, the central question is no longer simply whether to continue toward certification. The real question is whether the organization can demonstrate control over CUI-related risk in a way that is accurate, repeatable, and credible to customers, primes, auditors, and executives.

  • Define your risk ownership model: Assign clear ownership for CMMC, cybersecurity risk, CUI scope, remediation decisions, supplier risk, and executive reporting. Compliance gaps persist when ownership is implied instead of operationalized.
  • Validate the defensibility of your SPRS score: Tie every score decision to evidence, implementation status, compensating controls, and a realistic remediation plan. Treat the score as a risk representation, not a static compliance artifact.
  • Reassess your CUI boundary: Confirm which systems, users, vendors, workflows, and repositories are in scope. Scope clarity reduces cost, focuses remediation, and prevents unsupported attestations.
  • Convert the Plan of Action and Milestones (POA&M) into a governance tool: Prioritize remediation based on risk, contract impact, customer expectations, and operational feasibility. Leadership needs recurring visibility into overdue actions, accepted risk, dependencies, and funding decisions.
  • Sustain readiness through mature Governance, Risk, and Compliance (GRC): Use ongoing governance, evidence review, vendor risk oversight, regulatory monitoring, and readiness reporting to keep the program current after the initial assessment or remediation effort is complete. See below for more information on how Seiso utilizes our vGRC model to maintain continuous compliance before, and during, regulatory change.

Q & A

  • Do we still need to work on CMMC? Yes. The Phase II pause does not remove existing cybersecurity obligations, customer expectations, or the need to maintain accurate self-assessment records in SPRS.
  • Should we still complete a readiness assessment? Yes. A readiness assessment helps confirm whether your SSP, scope, evidence, control implementation, and SPRS score can withstand customer, prime, government, or legal scrutiny.
  • Is CMMC Level 2 certification still valuable? It is, especially where primes, customers, or competitive bids value independent validation. Seiso can help determine how certification, readiness, and managed compliance support can be the right near-term, and long-term investment.
  • What does a virtual Governance, Risk, and Compliance (vGRC) managed services include? Seiso’s vGRC managed services support the ongoing work required to keep the program current, including governance reviews, evidence quality checks, POA&M tracking, vendor risk management, regulatory change monitoring, and SPRS affirmation support.
  • Can Seiso help if we are not ready for a C3PAO assessment? Yes. Seiso can help prioritize remediation, improve documentation, strengthen evidence, and build an operational compliance cadence before a formal assessment or customer review.
  • The Department’s announcement may reduce near-term certification pressure for some organizations, particularly small businesses facing assessment cost and resource constraints. It does not reduce the obligation for leadership to understand, document, and manage cybersecurity risk tied to federal contract requirements.

Your Next Steps

You should validate your current SPRS score, confirm CUI scope, review your SSP and POA&M, determine whether prime or customer requirements still apply, and decide whether you need assessment, readiness, or ongoing vGRC support.

How Seiso Can Help – Assess, Build, Manage

Seiso helps organizations move beyond checklist compliance by connecting CMMC activity directly to business risk, executive decision-making, and sustainable governance. We validate scope, evidence, and control implementation; clarify attestation exposure; prioritize remediation based on risk; and establish a managed compliance rhythm that stands up to customer, prime, and regulatory scrutiny.

As your CMMC expert, Seiso brings implementation, assessment, and managed governance experience together. We help contractors prepare for CMMC’s varying outcomes while giving leadership the insight needed to make defensible decisions about cybersecurity risk, compliance investment, and long-term program sustainability.

Our Services Include:

  • Risk-informed CMMC assessment: Evaluate CUI scope, control implementation, evidence quality, POA&M status, SPRS score defensibility, and leadership-level risk exposure.
  • Readiness and remediation planning: Translate gaps into prioritized actions that account for risk reduction, contract impact, operational effort, budget, dependencies, and customer expectations.
  • Ongoing virtual Governance, Risk, and Compliance (vGRC) managed services: Maintain a recurring governance cadence for review of evidence, risk reporting, vendor oversight, remediation tracking, regulatory monitoring, and executive readiness.

If your organization is reassessing its CMMC roadmap, Seiso can help turn uncertainty into a clear execution plan. Schedule a CMMC risk and readiness conversation to validate your CUI scope, SPRS score, remediation priorities, governance cadence, and the role ongoing vGRC managed services should play in keeping the program defensible over time.

1  Specifically, DoW is soliciting input on protecting federal data and uplifting operational resilience against cyber-attacks while also reducing compliance costs and administrative burdens. The DoW is seeking industry input on ideas such as DIB usage of existing commercial cybersecurity capabilities, leveraging and optimizing self-attestation capabilities, and streamlining cybersecurity compliance.

More From Seiso Notes