Thought Leadership

CMMC May Be Delayed, But Your Cybersecurity Obligations Are Not

If you’ve been following recent developments around the Cybersecurity Maturity Model Certification (CMMC), you’ve likely seen that the Department of Defense has suspended the planned Phase II rollout and placed the program under review. While this has created uncertainty around certification timelines, it is important to understand what has not changed.

Organizations throughout the Defense Industrial Base (DIB) supply chain are still required to comply with existing DFARS cybersecurity requirements, including DFARS 252.204-7012 and the protection of Controlled Unclassified Information (CUI). Self-assessment requirements and adherence to NIST SP 800-171 remain in effect.

What This Means for Contractors and Subcontractors

The pause in CMMC implementation should not be viewed as a pause in cybersecurity expectations.

Defense contractors are still expected to:

  • Protect Covered Defense Information (CDI) and Controlled Unclassified Information (CUI)
  • Maintain and document NIST SP 800-171 security controls
  • Conduct required self-assessments and maintain SPRS reporting where applicable
  • Report cyber incidents in accordance with contractual obligations
  • Demonstrate due diligence in safeguarding sensitive government information

In many cases, prime contractors continue to flow these requirements down through

their supply chain, meaning subcontractors may still be required to demonstrate cybersecurity maturity regardless of CMMC’s final form.

The Smart Approach: Stay the Course

Whether CMMC ultimately returns in its current form or emerges as a revised framework, the underlying cybersecurity requirements are unlikely to disappear. Organizations that continue strengthening their cybersecurity programs today will be better positioned to win and retain defense contracts, meet existing DFARS obligations, reduce risk, and respond to future requirements with less disruption.

How Mainstream Technologies Can Help

Mainstream Technologies helps DIB organizations assess their current cybersecurity posture, identify gaps against NIST SP 800-171 requirements, and build practical compliance roadmaps that improve both security and contract readiness.

Let’s schedule a conversation about your organization’s current compliance status and discuss the most effective next steps.

  • Industry

  • Challenges

  • Solution

  • Categories