CMMC program operational despite phase-two pause, Cyber AB says
The pause is tactical, not strategic, but the task force's mandate to "drastically reduce costs" could reshape level two for small and non-traditional shops before anything becomes contractually mandatory.
TL;DR
CMMC's phase-two implementation timeline is on hold after DoD's July 13 pause and 60-day task-force review, but Cyber AB CEO Matthew Travis told a July 28 town hall that the program itself remains operational: C3PAOs are conducting level two certifications, DFARS 252.204-7012 compliance is still in force, and both CMMC portals remain open. Travis framed certification as "the best insurance policy against False Claims Act risk" and urged contractors to respond to DoD's RFI by the Aug. 14 deadline. The task force's authority to alter the rule's cost, scope, or timing remains undefined, and the Cyber AB hasn't been contacted for tier-four participation yet.

Any contractor waiting for the CMMC Reform Task Force to decide whether level two certifications still matter got a clear signal from the Cyber AB last week: keep certifying.
CEO Matthew Travis used a July 28 town hall to walk the defense industrial base through what the July 13 phase-two pause actually means. The pause suspends the timeline for level two requirements appearing in solicitations under the November 2025 rulemaking. It does not suspend the program infrastructure. C3PAOs are active, both DOD portals for processing certifications remain up, DFARS 252.204-7012 compliance obligations are unchanged, and 111 authorized C3PAOs with over 1,000 assessors are conducting certifications. "Nothing has changed in the program," Travis said. "It's only these fractional requirement phases that was suspended."
The message is designed to keep the assessment pipeline from freezing during a 60-day review. Travis wants contractors in the pipe, and he wants them flooding DoD's RFI with responses that defend CMMC rather than dismantle it. "If you believe in CMMC, defend it," he told attendees, while also urging them to "use those big brains of yours and come up with good ideas to improve CMMC." The RFI closes August 14.
What the task force can actually do
Travis disclosed the task force's four-tier structure: internal DoD personnel at tier one, interagency partners including SBA and CISA at tier two, defense-industrial-base CISOs at tier three, and CMMC stakeholders including the Cyber AB at tier four. But the Cyber AB hasn't been contacted yet about participation, it has only been told to "expect to be invited."
The undefined scope is the real open question. DoD CIO Kirsten Davies asked for "actionable policy changes or regulatory reforms" that "drastically reduce costs and barriers to entry for small, medium, and non-traditional businesses." That language is broad enough to encompass changes to level two assessment requirements themselves, not just the implementation timeline. Travis expects recommendations within 60 days, findings public after 15 days of review, landing shortly before the Cyber AB's CS5 East conference in October.
What the pause doesn't change
Travis pushed back on claims of assessor shortages, pointing to 1,082 assessors and declining assessment costs. He pressed contractors to treat certification as operational risk management now, not compliance to be deferred. "It's the best insurance policy against False Claims Act risk," he said, tying voluntary certification to the civil exposure that persists under 7012 regardless of CMMC timeline. That argument will land differently depending on a contractor's exposure: primes and large subs with existing CUI flows face FCA risk today; small shops without CUI may find the insurance premium hard to justify during a regulatory pause.
The sharpest tension in Travis's remarks was the shift between his two asks. He told the room to defend CMMC to the task force, and in the same breath to propose improvements. That dual message reflects the Cyber AB's position: it needs the pipeline to stay alive while also needing the task force's recommendations not to hollow out the level two requirement that fills it.
Published ·Updated ·Deep Fathom