Key takeaways
- CMMC certification was paused because it was too expensive, too slow, too chaotic, and too manual.
- The pause changed who verifies compliance, not what is required.
- AIC CMMC Complete™ is a standardized, integrated kit to deploy, operate, and audit CMMC at Level 1, Level 2, and Level 3.
On July 13, 2026, the Department of War (DoW) stopped the clock on Cybersecurity Maturity Model Certification (CMMC). It suspended Phase 2, which would have required third-party certification starting November 10, 2026, and put Phases 3 and 4 on hold. A CMMC Reform Task Force began a 60-day review.
This post explains why the Department did it, in its own words and in the Small Business Administration's (SBA's), and what solves the underlying problem.
Why the Department stopped the clock
The Department's announcement said the program "has created prohibitive compliance costs and bureaucratic burdens," and that CMMC compliance "is forcing innovative companies out of the Defense Industrial Base." Under Secretary of War Michael Duffey spoke of "removing paralyzing costs." SBA Administrator Kelly Loeffler said CMMC "was becoming an untenable barrier pushing them out of the Defense Industrial Base."
Behind those statements are four crises.
1. Too expensive
The SBA estimated that total compliance costs can reach about $593,800 per certification for a small firm that needs a third-party assessment, and about $388,600 for a firm that can self-assess. The SBA said more than 120,000 small businesses in the defense industrial base would have been affected.
The Department's own rule estimated about $101,752 for a small company's first Level 2 third-party assessment. That figure covers only the assessment and assumes the security controls are already built.
2. Too slow
The SBA said Phase 2 would have pushed those businesses through "a cost-prohibitive system supported by only about 100 approved assessors." Industry reporting from the May 2026 CMMC accreditation body town hall put final Level 2 certifications at about 1,391, which is less than 2 percent of the roughly 76,598 organizations the Department estimated would need one. Before the pause, assessors were commonly booked 6 to 9 months out.
3. Too chaotic
There is no standard way to build a CMMC environment. Every company picks its own mix of products, its own network design, and its own way of meeting each of the 110 requirements. Every assessment starts with the assessor learning a one-off system. Every prime contractor faces a supply chain of hundreds of different environments.
4. Too manual
Evidence is still gathered by hand: screenshots, spreadsheets, shared drives, and email. The Department's own cost estimate for a small company's Level 2 assessment includes about 94 hours of preparation before the assessor arrives. Much of that time goes to collecting and organizing evidence.
The pause does not solve any of these
The suspension changed who verifies compliance and when. It did not change what is required. DFARS 252.204-7012 still requires the 110 requirements of NIST SP 800-171. Contractors still post a self-assessment score in the Supplier Performance Risk System (SPRS), and a senior official still signs an affirmation. The Department still conducts selected assessments. Many primes still require certification from their suppliers.
The cost, the delay, the chaos, and the manual work are all still there. A pause cannot fix them. Only a different way of doing the work can.
What actually fixes it
The fix is a standardized model for three things: how CMMC is deployed, how it is operated, and how it is audited. It has to work for companies of every size.
| Crisis | What a standardized model changes |
|---|---|
| Too expensive | One pre-built kit replaces a custom build from many separate products, with one roster, one audit trail, and one evidence package. |
| Too slow | A pre-built, standardized environment, and an assessor who sees the same design every time, remove the one-off build and the one-off review. |
| Too chaotic | Every contractor runs the same enclave, the same controls, and the same evidence format. Primes and MSPs can use one playbook. |
| Too manual | Evidence is created by the systems as they work and assembled automatically, instead of collected by hand before each assessment. |
Until now, contractors have not had a standardized deployment, operation, and auditing model, especially at Level 2 and Level 3, where the requirements are hardest.
AIC CMMC Complete™
Analog Informatics Corporation (AIC) built AIC CMMC Complete™ as a standardized, complete kit designed to overcome all four of the crises that led the Department to halt certification.
Standardized deployment. The kit launches from the Microsoft Azure Commercial Marketplace into the contractor's own Azure subscription. It comes as a pre-configured enclave with an isolated network, a secure gateway, and access control. Every contractor gets the same design, at Level 1, Level 2, or Level 3.
Standardized operation. The following are built in and work together:
- Privileged Identity Management (PIM)
- Privileged Access Management (PAM)
- Privileged User Management (PUM)
- Session recording on Level 3
- Training and attestation
- A document sharing vault for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)
Current State Compliance rescans controls and records drift. A Managed Service Provider (MSP) can run the same playbook for every customer.
Standardized auditing. The Assessment Binder assembles evidence created by the systems as they work. The organization, its MSP, and its assessor share it. Assessors see the same layout every time.
Low cost, with the control where it belongs. Contractors pay for cloud usage instead of buying hardware. A prime contractor can pay for its subcontractors through Microsoft, using existing cloud commitments where the offer is eligible. We are starting with Azure private offers for our first customers. The subcontractor keeps exclusive control of its own keys, identities, and access rules. It can give an MSP temporary access in line with government requirements.
AIC is a member of the Microsoft AI Cloud Partner Program. Membership reflects a cooperative relationship. It is not an endorsement by Microsoft.
What to do while the clock is stopped
- Keep your NIST SP 800-171 work moving. Your duty and your SPRS affirmation did not pause.
- Stop building one-off environments. Every custom build you add now is one more thing to explain to an assessor later.
- Standardize now. When certification resumes, the contractors with a standard, documented environment will be ready first.
- Primes: standardize your supply chain. Give your suppliers one environment instead of a questionnaire.
An assessment organization, and in some cases the government, decides whether an organization meets CMMC. The kit gives you the tools, the training, and the records to do the work and to show it.
Get started
- See it working. Take the product screenshot tour. No sign-up needed.
- Try it for 30 days. Start AIC CMMC Complete™ with a 30-day trial license, launched from the Microsoft Azure Marketplace. Cloud usage is billed by Microsoft.
- Learn for free. Training from Analog Informatics is free.
- Primes and MSPs. Ask about Azure private offers that cover your suppliers.
Learn more
- AIC CMMC Complete™ kits for Level 1, Level 2, and Level 3
- AIC CMMC Complete™ for defense contractors and their suppliers
- Continuous compliance
- Product screenshots
- Read next: Your SPRS score is a sworn statement
Sources
- Department of War, Department of War Suspends CMMC Phase II Requirements, July 13, 2026
- Small Business Administration, SBA Commends U.S. Department of War's Suspension of CMMC Phase II for Small Defense Contractors, July 13, 2026
- Center for Strategic and International Studies, What the CMMC Pause Means for the Defense Industrial Base
- Final CMMC Program rule, 89 FR 83092, October 15, 2024
- PolicyCortex, C3PAO Backlog 2026 (May 2026 certification counts)
- Secureframe, Why Are Less Than 2% of Level 2 Organizations Certified?
- Microsoft Learn, Azure consumption commitment and private offers
