MSP, Compliance Management, Governance, Risk and Compliance

MSPs should use the CMMC pause to review client compliance gaps

COMMENTARY: The CMMC Phase II pause may have moved the assessment timeline, but it does not mean companies can stop preparing. Organizations handling CUI still need to keep their controls in place, document what they are doing, and meet existing contract requirements. For MSPs, this is a good time to check in with clients, clear up confusion, and help them decide whether to keep moving or adjust their plans. CMMC readiness still matters, even if the deadline changes.


The Department of Defense's decision to pause Phase II of the Cybersecurity Maturity Model Certification (CMMC) program for a 60-day review has raised an important question for organizations and the MSPs supporting them:

Does this change what they should be doing now?

The simple answer is yes, and it depends.

The key distinction is that Phase II implementation is under review—specifically, the requirement for Level 2 organizations to complete assessments conducted by Certified Third-Party Assessment Organizations (C3PAOs) as a condition of contract eligibility by November 2026. The CMMC program as a whole remains intact and has not been canceled.

To answer that question, security leaders and MSPs should focus on three things:

  • What remains required?
  • Where does the uncertainty actually sit?
  • Why should organizations continue preparing for CMMC while the review is underway?

Understanding those questions provides a clearer picture of what this announcement means and what it doesn't.

What is still required

A pause in implementation does not mean the broader compliance effort has stopped.

The current pause affects Phase II implementation, including the planned requirement for certain organizations to complete assessments through C3PAOs. It does not remove the cybersecurity expectations already tied to Department of Defense work.

Organizations that handle Controlled Unclassified Information (CUI) should continue implementing and maintaining the security controls required by their contracts. Work already underway to document policies, collect evidence, validate controls, and improve governance remains valuable regardless of any future implementation changes.

How organizations proceed during the review period, however, may differ.

For some smaller organizations, it may make sense to wait and see what comes from the review, particularly if it results in additional resources, options, or adjustments that better support their compliance journey.

For mid-tier organizations more closely connected to prime contractors, continuing as planned will often make more sense because the legal mandates and contractual obligations already exist. Prime contractors also establish their own cybersecurity expectations for subcontractors, independent of the Department of Defense's implementation timeline. As a result, reduced regulatory pressure does not necessarily mean reduced commercial pressure.

Organizations that are already assessment-ready, mid-assessment, or approaching a scheduled assessment may have little reason to change course. While implementation details may change, the business, legal, and liability benefits of achieving certification remain.

For MSPs, this creates an opportunity to level-set with clients, understand what they are hearing, clarify what has changed and what has not, and align compliance objectives with each client's business goals.

Where the uncertainty actually sits

Much of the discussion following the announcement has focused on what the review could mean for CMMC's future. It's helpful to distinguish between uncertainty about implementation and uncertainty about the program's long-term direction.

At this point, the review is focused on Phase II implementation and how to meet the Pentagon's cybersecurity goals while enabling small businesses to succeed. Affordability has also been highlighted as an important consideration, particularly in determining how small businesses can remain secure and continue participating in the Defense Industrial Base (DIB).

As a result, timelines, assessment requirements, or other aspects of the rollout may be adjusted once the review is complete. That is the purpose of the review process.

What remains consistent is the Department’s broader objective of improving cybersecurity across the defense supply chain. Organizations should continue to expect that protecting sensitive information, including CUI, and demonstrating effective security controls will remain priorities. For contractors subject to these requirements, those responsibilities are also tied to legal mandates and contractual obligations.

Viewed through that lens, the current uncertainty is less about whether cybersecurity requirements will exist and more about how specific implementation details may evolve over the coming months.

Why audit readiness should continue

Questions about timing naturally lead to another question: Should organizations continue preparing for assessments while the review is underway?

The answer depends on where an organization is in its compliance journey. Regardless, continuing to build audit readiness remains a practical approach because many of the activities that support CMMC compliance also strengthen an organization’s overall security practices.

Maintaining documentation, validating controls, collecting evidence, and identifying gaps are valuable practices regardless of when an assessment ultimately occurs. Those efforts strengthen an organization’s security posture, whether viewed through a compliance or operational lens.

Approaching compliance as an ongoing operational process also makes organizations more adaptable when requirements change. Whether the Department makes minor adjustments or more significant refinements to Phase II implementation, organizations that have continued building mature compliance practices will be in a stronger position to respond.

Rather than viewing readiness as something tied to a single certification deadline, organizations can use this period to continue building processes that support both compliance and long-term cybersecurity resilience.

Looking beyond the current review

While much of the industry's attention is focused on the outcome of the Department's review, the discussion also reflects a broader shift in how organizations approach compliance.

One of the broader lessons from this review is that compliance is becoming less about preparing for a single assessment and more about maintaining an ongoing understanding of an organization's security posture. Automation and AI are helping organizations reduce the manual effort required to collect evidence, monitor controls, and maintain documentation throughout the year.

These technologies don't replace the expertise required to build an effective compliance program, but they can reduce the manual effort needed to maintain readiness over time.

The Department's review may result in changes to Phase II implementation, and organizations will have the opportunity to adjust their plans as additional guidance becomes available.

In the meantime, the underlying principles remain the same. Building strong security practices, maintaining audit readiness, and understanding compliance obligations continue to provide value regardless of how the review ultimately shapes Phase II implementation. For MSPs and the organizations they support, this is a good time to stay informed, keep client conversations active, and continue building mature compliance practices.


ChannelE2E Perspectives columns are written by trusted members of the managed services, value-added reseller, and solution provider channels or ChannelE2E staff. Do you have a unique perspective you want to share? Check out our guidelines here and send a pitch to [email protected].

Dan Fox

Dan Fox is Group Product Manager, Risk at ScalePad, and co-founder of ControlMap. He focuses on cybersecurity compliance and risk management for MSPs and SMBs.

You can skip this ad in 5 seconds