Publication

Leadership Cannot Pause: What Executives Should Be Doing Now During the CMMC Phase II Suspension

September 9, 2026

The Department of War’s decision to suspend Phase II of the Cybersecurity Maturity Model Certification (CMMC) program created understandable questions across the Defense Industrial Base. For some organizations, the pause may feel like permission to slow down.

Leadership should resist that instinct.

What Is Still Required During the CMMC Pause?

The Department has not removed the underlying obligation to protect sensitive government information. Phase I self-assessment requirements remain in place, and contractors are still responsible for safeguarding covered defense information under existing DFARS requirements.

The pause is better viewed as an opportunity to strengthen the organization’s compliance strategy before the next implementation milestone arrives.

Why CMMC Is Not an IT Project

One of the most persistent misconceptions about CMMC is that it belongs to the IT department.

IT plays a major role, but compliance reaches much farther.

  • Contracts, regulatory, operational, and legal teams need to understand cybersecurity requirements and where Controlled Unclassified Information, or CUI, may be involved.
  • Procurement teams need to understand which vendors and subcontractors may receive Federal Contract Information, or FCI, and CUI. 
  • Human resources may own onboarding, offboarding, training, and personnel-related controls. 
  • Facilities may be responsible for physical access. 
  • Operations may need to understand how sensitive information moves through business processes.

Leadership has to connect those pieces.

The CMMC requirements reflect that breadth, covering areas such as access control, awareness and training, configuration management, incident response, media protection, personnel security, physical protection, and system integrity.

CMMC may be a cybersecurity requirement, but compliance is an organizational responsibility.

How to Use the Pause to Reengage the Organization

The pause gives executives an opportunity to step back from certification mechanics and look at the broader program.

Leadership should ask:

  • Does each department understands its role?
  • Are clearly assigned? 
  • Has IT has been carrying work that actually belongs elsewhere in the organization?

This is also a good time to confirm what information is being protected, where it resides, and which people, systems, vendors, and business processes are in scope.

A stronger approach starts with the data.

  • Where does FCI or CUI enter the organization? 
  • Who uses it? 
  • Where is it stored? 
  • Which systems process or transmit it? 
  • Which vendors or subcontractors touch it?

Those questions help define the CMMC boundary and can reduce unnecessary complexity.

How to Build a CMMC Roadmap Across Departments

Once leadership understands the environment, the organization can build a more useful roadmap.

That roadmap should identify:

  • Owner - which department owns each requirement
  • Evidence - what evidence demonstrates compliance
  • Gaps - what gaps remain to be done
  • Cost - what remediation will cost
  • Dependencies - what dependencies could delay implementation

A training requirement may involve human resources and cybersecurity. A subcontractor flow-down issue may involve legal, procurement, and contracts. Physical security may require facilities changes. Incident response may require leadership, communications, legal, cyber insurance, and outside forensic support.

Breaking the program into workstreams makes compliance easier to manage and gives leadership a more accurate picture of progress.

It also helps prevent a common problem: IT believing a requirement has been addressed while another part of the organization has not completed the process, documentation, or operational change needed to support it.

Check In with IT - But Do Not Hand It Off to IT

The pause is also a good time for executive leadership to have a candid conversation with the IT team.

Not simply, “Are we CMMC compliant yet?”

A better discussion covers:

  • Whether IT has the resources it needs
  • What technical gaps remain
  • What work depends on another department
  • Where decisions have been delayed because ownership is unclear

Leadership should also understand whether the System Security Plan accurately reflects the environment, whether policies are actually being followed, whether remediation projects are funded, and whether the current Supplier Performance Risk System (SPRS) posture aligns with operations.

This is where organizations often discover the difference between documentation and readiness.

A policy may require multifactor authentication, but that does not mean it is deployed everywhere it should be. An incident response plan may exist, but leadership may never have exercised it. Vendor contracts may contain cybersecurity language, while no one is consistently validating subcontractor requirements.

CMMC readiness depends on more than having the right documents. It depends on whether the organization can demonstrate that its practices are operating as intended.

Do Not Lose Sight of the Purpose

It is easy for CMMC discussions to become dominated by certification levels, assessment procedures, SPRS scores, and deadlines.

The purpose is more fundamental.

The government is trying to protect sensitive information that supports federal missions and national security. Organizations participating in the Defense Industrial Base are expected to understand where that information exists and protect it throughout its lifecycle.

That perspective can help leadership make better strategic decisions.

If the organization can reduce where CUI exists, limit who has access to it, and simplify the systems that process it, the compliance burden may become more manageable.

Sometimes the best compliance strategy is not another piece of technology. It is designing the environment so fewer systems and people require access in the first place.

What Leadership Should Be Doing Now

The Department has not yet announced exactly how the next phase of CMMC implementation will proceed. What has not changed is the need to protect sensitive government information and demonstrate that required cybersecurity practices are actually in place.

Leadership should use this period to:

  • Validate the organization’s roadmap
  • Confirm ownership across departments
  • Review progress with IT
  • Address known gaps 
  • Ensure remediation efforts are adequately funded

Executives should also understand whether vendors and subcontractors are part of the environment, whether contractual flow-downs are being handled appropriately, and whether the organization is building a program it can sustain after an assessment is complete.

The goal should not be to prepare for one certification event. It should be to build a repeatable way of protecting sensitive government information as part of doing business.

The Pause Is Time. Use It Well.

The future shape and timing of CMMC implementation may continue to evolve, but waiting for another deadline before addressing known gaps would waste a valuable opportunity.

The fundamentals remain important: understanding sensitive information, controlling access, training employees, managing vendors, preparing for incidents, maintaining secure systems, and demonstrating that those practices actually work.

The pause gives leadership room to reconnect departments, validate strategy, and make sure cybersecurity compliance is being treated as a business responsibility rather than an IT assignment.

That is time worth using.

Contact our Tech, Privacy & Cyber Risk Team

Ice Miller brings together a multidisciplinary team of government contracts, regulatory, and compliance attorneys, along with cybersecurity and CMMC program strategy experience, to help organizations navigate CMMC as a coordinated business program. Are you ready to turn the pause into progress? Contact our team to get started.

This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.

Related People

Related Categories

<p>Sign up now to receive periodic updates from Ice Miller&rsquo;s legal professionals.</p>

Sign up now to receive periodic updates from Ice Miller’s legal professionals.

Subscribe

Firm Highlights