Cybersecurity

CMMC Phase II Suspended: What Defense Contractors Need to Do Now | Webinar

CMMC audits are paused, but your obligations aren't. Learn what changed, what's still required, and what to do next in this webinar.

Webinar

Jul 24, 2026

Webinar Date: Aug 27, 2026

The recent pause on CMMC has left a lot of business leaders asking the same question: what does this actually mean for us?

This webinar will deliver clarity. In 30 minutes, our experts will cut through the confusion, explain what the suspension really changed (and what it didn't), and lay out the practical steps to take now—so you can move forward with clarity and confidence.

Use the form below to save your spot at the live webinar on August 27th at 11 AM CT. 

Reserve Your Spot

What You’ll Take Away

  • What the CMMC phase II pause actually means, what comes next, and you still need to do to be compliant
  • How CUI and FCI impact your security responsibilities
  • Which SPRS reporting, documentation, and leadership accountability requirements are still in place
  • What you can do in the meantime to stay secure, compliant, and ready

A Rundown of the CMMC Phase II Suspension

In late 2025, the government hit pause on the CMMC certification audit requirement while it reviews the program.  

In plain terms, that means defense contractors aren't being required to pass a formal third-party CMMC audit right now.

But here's the key point: only the audit requirement changed. Everything else is still in place.  

The underlying security requirements under DFARS 252.204-7012 and NIST SP 800-171 still fully apply, and you're still responsible for self-assessments, accurate SPRS reporting, and proper documentation.

What Businesses Should Do to be Prepared for CMMC Going Forward

The CMMC audit requirement may be on hold, but your responsibilities haven't changed. Here's where to focus to stay ahead:

  1. Know what still applies: DFARS 252.204-7012 and NIST SP 800-171 remain fully in force—the pause on certification doesn't pause your obligations
  2. Verify your self-assessment is accurate: Your SPRS score and supporting documentation need to reflect reality, not good intentions. Getting this right matters more than ever
  3. Find and close your security gaps: Confirm the required controls are actually in place and working—not just checked off on paper
  4. Keep your documentation current: Accurate, up-to-date records are your proof of compliance and your foundation for eventual certification

Dive deeper into these critical CMMC changes, what they really mean, and exactly what's still required of you. Our CMMC and cybersecurity experts will answer the questions creating the most confusion right now—so you walk away with a clear understanding of where things stand, what to do next, and the confidence to move forward through an uncertain landscape.

Featuring a full panel of cybersecurity experts:

  • Chat Adams, Consultant, Technology & Security at Impact
  • Chase Deatherage, Virtual Compliance Manager, DOT Security
  • Jeremiah School, President, DOT Security
  • Cory Carnes, Chief Revenue Officer, DOT Security

Use the form above to register for the event and join us live on August 27th! 

Tags

CybersecurityMitigate Cyber RisksCompliance

Share

Impact Insights

Sign up for The Edge newsletter to receive our latest insights, articles, and videos delivered straight to your inbox.

More From Impact

View all Insights