“None of those requirements went away as part of this. The only thing that was paused was how it was going to be validated. The key message is: you need to continue to do what you were doing, and should have been doing, to protect the CUI within your environment and within your control.” — Doug Barbin
Department of War pause of CMMC Phase 2.0 (July 13, 2026)
On July 13, 2026 the Department of War (DoW) abruptly paused Phase 2.0 of the Cybersecurity Maturity Model Certification (CMMC) program. The DoW halted the third-party assessment requirements that had been scheduled to go live in November 2026, leaving the validation mechanism in suspension. That announcement surprised many in the defense industrial base and generated speculation that broader compliance activity might be put on hold.
Phase 1 self-assessments and False Claims Act exposure remain in force
Despite the DoW pause, several obligations did not change. Phase 1 self-assessment requirements are still due, and contractors continue to face False Claims Act exposure for inaccurate attestations. Those legal and administrative risks persist even while third-party validation is paused, meaning attestations made by contractors can still carry significant consequences if they are false or misleading.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildControlled Unclassified Information and NIST 800-171 obligations
The obligation to protect Controlled Unclassified Information (CUI) under NIST 800-171 remains fully in effect. Doug Barbin emphasized that the DoW action affected only how compliance would be validated, not the underlying security responsibilities: organizations “need to continue to do what you were doing, and should have been doing, to protect the CUI within your environment and within your control.” In short, the technical and procedural requirements tied to CUI protection remain operational.
Schellman, clients, and the practical challenge of tracking CUI
On the Government Technology Insider podcast, host Lucas Hunsicker spoke with Doug Barbin, President and National Managing Principal at Schellman, about the practical aftermath. Barbin said the DoW pause was abrupt but "wasn’t entirely unexpected" and pointed to a central, ongoing problem: identifying and tracking CUI as it moves from primes down through layers of subcontractors. That movement — and the difficulty of reliably mapping it — continues to be the biggest challenge facing organizations preparing for CMMC compliance. Barbin also told Hunsicker that the majority of Schellman’s clients are still moving forward with certification despite the pause.
DoW 60-day review and the Request for Information (RFI)
The DoW has launched a 60-day review as part of its pause, and Barbin highlighted the significance of responding to the Request for Information (RFI). Industry engagement through the RFI is positioned as a consequential input to the DoW’s review. How companies and other participants respond during that window may influence the DoW’s next steps on validation and program mechanics — even as baseline requirements and legal exposures remain unchanged.
What this means for primes, subcontractors, and small contractors
- Primes: Continue to identify and track CUI flowing through supply chains and maintain controls required under NIST 800-171; do not treat the pause as relief from reporting or attestation obligations.
- Subcontractors: Keep Phase 1 self-assessments on schedule and avoid inaccurate attestations that could trigger False Claims Act exposure; expect primes to insist on continued adherence to CUI protections.
- Small contractors: Watch for emerging solutions that may help shrink compliance footprints; Schellman reports that many clients — including smaller firms — are still pursuing certification despite the DoW pause.
The DoW’s pause narrowed the immediate battleground from requirements themselves to the means of validation, but it did not erase the obligations that sustain that battleground. The 60-day review and RFI responses are now the proximate milestones; until the DoW decides on how and when validation resumes, contractors face a simple operational reality recapitulated by Barbin: protect the CUI you control, meet your Phase 1 deadlines, and treat attestations with the gravity they carry under the False Claims Act.




