Home / Article
The CMMC Audit Paused. Should You Pause Collecting Evidence?
Your CFO saw the CMMC pause headline and asked why the compliance budget still exists. This article answers with fresh industry data, not opinions.
What did the new report find?
On October 1, 2026, Redspin released its third annual study of the defense industrial base. The defense industrial base is the network of companies that supply the Department of War. The report surveyed contractors that store, process, or transmit CUI and FCI. CUI is Controlled Unclassified Information. FCI is Federal Contract Information (PR Newswire).
The headline finding is momentum. 78.2% of respondents kept moving toward CMMC certification or had already reached Level 2. Only 21.9% delayed certification or slowed their efforts.
Three in four respondents said certification is worth it even without an award at stake. 68.8% cited independent cybersecurity validation. 62.5% cited commitment to protecting CUI. 58.3% cited a stronger cyber posture.
Spending tells the same story. Between 75.4% and 84.4% of respondents reported no change in cybersecurity spend across technology areas. Increases outnumbered decreases, especially in managed services, cloud infrastructure, governance tools, and NIST and DFARS consulting.
Certification spend did dip. 20.3% paused spending on CMMC certification itself. Another 3.1% cut it. Every respondent who paused 800-171 consulting or security operations had also paused their CMMC work. The pullback was specific to the audit, not to the underlying security.
Why did most contractors keep going?
Your prime contractor is one reason. Only 23.3% of primes are relaxing CMMC requirements for their subcontractors. 39.5% are still deciding. On the subcontractor side, 76.6% have heard nothing from their prime about the pause. Only 10.6% say their prime relaxed the requirements.
The phased government timeline matters. It is not the only timeline that matters. If your prime sets a third-party assessment date, that date controls your business.
The contract rules never moved. DFARS 252.204-7012 has required adequate security for covered defense information since 2017 (DFARS 252.204-7012). For covered contractor systems, that means the NIST SP 800-171 controls. The CMMC program rule itself remains law at 32 CFR Part 170. The July 13 suspension froze the phase-in schedule (Department of War). It did not repeal the rule.
Late adopters are most likely to slow down, per the report. That group also has the largest gap to close if the pause ends.
What should you do this week?
First, ask your prime about its CMMC expectations. Most primes have not relaxed anything. Assume yours has not until you hear otherwise.
Second, keep your NIST 800-171 implementation current. The report shows the contractors pausing audits kept their 800-171 work going. Follow the majority.
Third, recheck your posted SPRS score against your live systems. SPRS is the Supplier Performance Risk System. Your annual affirmation is a signed claim about that score. It must match reality.
Fourth, keep collecting evidence continuously. Screenshots go stale the day they are taken. Evidence pulled from your live tenant stays current and reruns after every fix. SSP is the System Security Plan. SAR is the Security Assessment Report. POA&M is the Plan of Action and Milestones. PolicyCortex does this on Azure. 33 collectors read live configuration and check it against NIST 800-53 and 800-171. It re-verifies after each fix and builds the SSP, SAR, and POA&M documents from the evidence.
Sources
- PR Newswire: New 2026 Redspin Report Finds Sustained DIB Cybersecurity Commitment
- Redspin: Committed to the Mission, the 2026-2027 CMMC report
- Department of War: suspension of CMMC Phase II requirements, July 13, 2026
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program
Next step
Still unsure whether your posted score matches your real controls? See how PolicyCortex collects the proof from your Azure tenant.