The Cyber AB's Response to the CMMC Pause Tells You Everything About Who Actually Benefits From Phase II 

Andrew Hennigan

The Cyber AB published its statement on July 15th, two days after DoW suspended CMMC Phase II. I read it a couple times and the thing that stands out isn’t what it says about the program. It’s what it says about the Cyber AB. 

“Surprised and disappointed” is the tell. 

Read that opening line again. The Cyber AB is the Department’s “sole official non-governmental partner” for administering the entire CMMC ecosystem, and they’re telling us they were surprised by this. If you’re the official partner and a decision this size lands on you with no warning, that’s not a neutral fact to disclose, that’s an admission about how much influence you actually have inside the building. I’d have expected a partner organization to at least see this coming. The fact that they didn’t is more informative than anything else in the release. 

Their own stats undercut their own argument. 

The Cyber AB lists its progress: 110 C3PAOs, over 1,000 assessors, nearly 2,000 companies certified at Level 2. They’re presenting that as evidence the program is working and shouldn’t be paused. Held up against the headline number, over 100,000 DIB companies eventually needing third-party assessment, against roughly 100 organizations authorized to do it, that looks like a capacity problem. But that comparison assumes all 100,000 companies need certification by the same date, and they don’t. Phase II is a phased rollout, not a single deadline; the “eventually needing” figure is a ceiling for the whole rollout period, not a headcount due by November. Measured against the pace the rollout actually requires rather than the full universe of eventual flier, 110 C3PAOs may be closer to adequate rather than the raw ratio suggests. Where the Cyber AB’s numbers still cut against them, though, is the certified-to-date count: two thousand certified out of a hundred thousand, eight months into the final rule, is a real date point on throughput so far, phased rollout or not, and it’s their own number to explain. 

“All program elements remain operational” is true and also beside the point. 

The Cyber AB is right that C3PAO assessments, CCP exams, and Registered Practitioner services haven’t gone anywhere. You can still go get Level 2 certified today if you want to. What that framing skips past is why a rational contractor would do that voluntarily right now. One real answer: the underlying SPRS scoring obligation didn’t pause along with Phase II, and a company that self-attests a score it can’t back up is still exposed to False Claims Act liability and DOJ enforcement. That’s a genuine reason to move ahead regardless of the certification timeline. But it’s a narrower, more specific case than “the program is working, don’t pause it,” and the Cyber AB’s statement doesn’t make the case, it just gestures at continuity.  The government just told you the condition-of-award requirement that would have forced the decision is paused for at least 60 days, possibly longer, possibly redesigned entirely. “You can still buy this” isn’t the same claim as “you should still buy this,” and the statement quietly slides from one to the other without ever landing on the actual reason someone might still need to act. 

For a clear, beginner‑friendly walkthrough of what CMMC certification actually involves, you can read our step‑by‑step guide here.

Where I actually agree with them. 

The DFARS 7012 and NIST 800-171 point is correct and worth repeating to clients regardless of who’s saying it. The underlying safeguarding obligation hasn’t moved—only the third-party verification layer has. An organization being self-interested doesn’t make everything it says wrong. It just means you shouldn’t rely on that organization alone to confirm its own claims. You need to verify them against an independent source, like the actual regulation text or the agency’s own statement.  

Need help figuring out your required CMMC level? Start here.

What it means if you’re advising clients through this pause 

Don’t hand a client the Cyber AB’s statement as your analysis. It’s a trade association’s press release protecting a certification pipeline it operates, not an independent read on regulatory risk. Use the parts that are independently verifiable, DFARS 7012 didn’t change, NIST 800-171 didn’t change, and set aside the parts that are advocacy, the False Claim Act liability insurance framing, the “prove itself indispensable” language. Then go read the actual DoW memo and RFI questions, because that’s where the real signal on what happens after the 60 days is going to come from, not from the accreditation body whose seat at the table just got smaller. 

Source: The Cyber AB, “Statement on the Department of War’s Suspension of CMMC Phase II Requirements,” July 15, 2026. 
 
https://cyberab.org/Portals/0/Documents/CyberABStatementOnDoWPhaseIISuspension-15JUL2026.pdf 

About the Author
Andrew Hennigan