What the DOW Actually Paused
The suspension applies to a single Phase II requirement: the mandate to obtain an assessment from a certified third-party assessor organization (C3PAO) for CMMC Level 2 contracts. That requirement is now on hold.
Everything else in the current phase stays in place. Under Phase I, which began on Nov. 10, 2025, DOW continues to include CMMC Level 1 (self) and Level 2 (self) requirements in solicitations and contracts whenever a contractor may handle FCI or CUI. Two points define the change:
- The mandatory C3PAO third-party assessment for Level 2 contracts is suspended, not eliminated.
- In place of mandatory outside audits, DOW will continue to rely on self-assessments and select government-led assessments, or spot checks, to verify compliance.
In short, DOW aims to keep third-party auditors from becoming a bottleneck while preserving current security requirements.
Why the DOW Hit Pause
The DOW Chief Information Officer (CIO) is establishing a CMMC Reform Task Force to conduct a 60-day review of the program. The goal is to align CMMC with the Secretary's Acquisition Transformation Strategy, which prioritizes speed to capability, lowers barriers for small, medium and non-traditional businesses and aims to replace bureaucratic compliance with scalable, resilient cybersecurity measures.
Cost is the driving concern. The suspension cites Small Business Administration (SBA) findings that CMMC has imposed compliance burdens on more than 100,000 small businesses, with individual certification costs approaching $600,000. The move also reflects a broader debate inside the government over how to balance defense security needs against the burden compliance places on industry.
To gather input, DOW issued a Request for Information (RFI) posing seven questions on cost drivers, which controls deliver the most risk reduction, which controls create disproportionate burden and how self-assessments could be streamlined. Responses are due by noon ET on Fri., Aug. 14, 2026.
What Did Not Change
Most cybersecurity requirements that apply to DoW contracts exist outside the CMMC program, so the pause leaves them fully in force. If you handle FCI or CUI, you are still obligated to:
- Safeguard FCI and CUI in accordance with your contract
- Implement the 110 security controls in National Institute of Standards and Technology (NIST) SP 800-171 Rev. 2
- Meet the requirements of Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, which the CIO confirmed remains in effect
- Rapidly report cyber incidents to DOW
- Complete self-assessments, post scores to the Supplier Performance Risk System (SPRS) and submit annual affirmations of continuous compliance
Enforcement has not paused either. The Department of Justice continues to pursue False Claims Act cases through its Civil Cyber-Fraud Initiative. If you attest to a compliance posture you cannot support, or report an inaccurate SPRS score, you remain exposed to significant penalties, whether or not a third-party audit is required.
Why You Should Keep Preparing
A paused deadline can feel like permission to slow down. For AppGate customers, it is not. Three realities make continued preparation the only sound course:
Compliance takes time. Building the necessary security controls and reaching full Level 2 compliance can take six to 12 months. If you stop now, you the work you have done will not carry forward, and you will have to begin again later.
CMMC is not canceled. The program could return in a substantially similar form after the 60-day review. Halting your program today simply creates a difficult backlog to clear later, likely under time pressure.
The requirements may expand elsewhere. As DoW reconsiders CMMC, other parts of the government are moving in the opposite direction. The Federal Acquisition Regulation (FAR) Council's proposed CUI rule, updated on June 23, 2026, would extend similar safeguarding and incident-reporting requirements to CUI across all federal contracts. If that rule is finalized as drafted, a narrower CMMC scope may offer little relief. Many contractors and subcontractors have already invested years preparing. This is not the moment to call that work off.
How AppGate Helps You Meet CMMC Requirements
The controls at the heart of CMMC and NIST SP 800-171 center on who can access what, and how tightly that access is governed. This is exactly where Zero Trust Network Access (ZTNA) applies. AppGate ZTNA gives defense contractors a direct-routed Zero Trust foundation that supports the access-focused requirements assessors and self-assessments scrutinize most closely.
With AppGate ZTNA, you can:
- Enforce least privilege access so users and devices reach only the specific resources their role requires, supporting NIST 800-171 access control requirements
- Verify identity before any connection using multi-factor authentication and identity-driven policy, mapping to identification and authentication requirements
- Make protected resources invisible with single packet authorization (SPA), which cloaks systems from unauthorized users and shrinks your attack surface
- Contain threats through micro-segmentation, which limits lateral movement across east-west traffic and helps isolate CUI environments
- Apply consistent policy across on-premises, cloud and hybrid IT environments, so your security posture holds wherever your data lives
By reducing the attack surface and enforcing access at a granular level, AppGate ZTNA helps you strengthen the self-assessment scores you post to SPRS today and stand ready for third-party assessments when they return.
Keep Moving Forward
The pause is real, but narrow in scope. The DOW has delayed one requirement while it looks for ways to reduce cost and burden, all while holding firm on its expectation that contractors protect defense information. The organizations that keep building toward CMMC compliance now will be the ones ready to compete when the full framework takes hold.
Download our eBook, "CMMC 2.0: Mapping AppGate ZTNA Access Controls for Defense Contractors," to see how AppGate supports your CMMC and NIST SP 800-171 requirements.