Did the Department of Defense just put CMMC on hold? Not exactly.

The Department of Defense recently announced a pause on one of the most significant upcoming requirements of the Cybersecurity Maturity Model Certification (CMMC) program, creating confusion across the defense industrial base. Does this mean contractors can slow down their cybersecurity efforts—or does it simply change how compliance will be evaluated?

In this episode of Stay Sharp in Digital Engineering, hosts Juliann Grant and Jonathan Scott welcome back Steve Nichols, Razorleaf's government solutions expert, to explain exactly what changed, what didn't, and what defense contractors should be doing during this temporary pause.

Steve breaks down the July announcement, explains why companies are not off the hook for CMMC compliance, and discusses why maintaining strong cybersecurity practices remains essential regardless of how future certification requirements evolve.

In this episode, you'll learn:

  • Why the government paused third-party CMMC Level 2 assessments
  • What requirements still remain in effect
  • The difference between self-certification and third-party certification
  • The real costs of preparing for a CMMC assessment
  • Why good cybersecurity hygiene is still critical
  • How organizations should prioritize the 110 security controls
  • What the government may change after the public comment period
  • How small businesses could be affected
  • Why waiting for final guidance may be a risky strategy
  • How AI could eventually play a role in cybersecurity assessments

Key Takeaways

The current pause affects only the third-party assessment requirement for CMMC Level 2 certification. Organizations are still responsible for meeting applicable cybersecurity controls and certifying compliance where required. Companies should continue improving their security posture rather than assuming requirements will disappear.

Steve also explains that cybersecurity compliance should be viewed as an ongoing business process—not a one-time audit. Organizations that continue improving their IT environment today will be in a much stronger position regardless of how the government ultimately adjusts the CMMC program.

Featured Guest

Steve Nichols leads Razorleaf Government Solutions practice, helping defense contractors navigate digital transformation, cybersecurity requirements, PLM strategy, and government compliance initiatives. His experience spans startups, commercial software companies, and federal programs, making him a trusted advisor for organizations operating within the defense industrial base.

If your organization works with the Department of Defense or plans to enter the defense supply chain, this conversation will help you understand what today's changes mean—and how to prepare for what's next.

🔔 Subscribe for more conversations about digital engineering, PLM, cybersecurity, manufacturing, AI, and digital transformation.

Music is considered “royalty-free” and discovered on Story Blocks.
Technical Podcast Support by Jon Keur at Wayfare Recording Co.
© 2026 Razorleaf Corp. All Rights Reserved.

Podden och tillhörande omslagsbild på den här sidan tillhör Razorleaf Corp.. Innehållet i podden är skapat av Razorleaf Corp. och inte av, eller tillsammans med, Poddtoppen.