In Stay Sharp Episode 146, CMMC Paused, Not Cancelled: Why Contractors Shouldn’t Stop Now, co-hosts Juliann Grant and Jonathan Scott welcome returning guest Steve Nichols, the head of Razorleaf Government Solutions. The podcast has covered the Cybersecurity Maturity Model Certification (CMMC) in past episodes, Understanding the Cybersecurity Maturity Model and How SMBs Can Break into the Defense Industrial Base (DIB), and this week’s topic is the recent CMMC pause and what organizations should do about it.
CMMC Updates
The CMMC process, which has been in place for more than five years, is fundamentally “focused on IT security, good IT hygiene, good IT practices,” Steve says.

Steve Nichols, Vice President, Razorleaf Government Solutions
For the last year and a half or more, DIB contractors have been required to not only self-certify that they meet requirements for their level—or have a plan to meet them—but also to have certification from a third-party auditor. Then, on July 13, 2026, the government paused that third-party audit requirement and put out an RFI asking for comment on how to go forward with the IT hygiene requirements.
Steve reiterates that the pause does not change the requirements or the need to self-certify, it’s simply about the third-party certification. “We know that the administration has looked at, Hey, some of this is onerous and it’s causing us problems,” Jonathan says. “We don’t get people in the DIB because it’s too hard to be in the DIB. So we try to loosen things up, but we’re finding this middle ground. That’s what this seems like the pause is about.”
For the moment, this is good news for small- and medium-sized businesses (SMBs), because the audits are extremely resource intensive. First, it’s expensive to hire the auditors, and companies are likely also paying an outside consultant helping you prepare. Plus there’s the cost of internal resources that need to support the process. Steve explains, “One of the things I’ve heard is assume for a small company it’s going to take about a week to review all the documentation, review all the processes. And then you’ve got a couple weeks to fix any findings.”
What SMBs Should be Doing Now
Rather than thinking they’ve got a break to stop the work they’re doing to be compliant, Steve says government contractors/suppliers need to keep working on those requirements or “controls,” especially because there are so many of them. While he admits it’s possible some of them could be tweaked as a result of the public comment and review, they aren’t going away. “Most of those controls are just really good IT policy. And I think you should do your best to adhere to them if at all possible,” he says. “You still have to figure out how to meet the requirements. I’m assuming that some of those requirements will change and evolve, but what if it’s 10% out of all the requirements? You still should be moving towards it and then adjust the requirement changes when they come out.”
Looking Ahead
Even though the government’s RFI period is 60 days, Steve cautions we shouldn’t expect an answer for some time, likely after another couple rounds of requested input. SMBs should be ready to review what the changes are when they’re finally settled and evaluate them against their own plans and processes, as well as against how the government will want you to certify your compliance. Jonathan suggests that with this pause, some companies may wonder if they’re spending money they don’t need to be spending to chase those 110 requirements, but Steve is confident the list of requirements will remain very similar before and after this adjustment.

While the government potentially seeks a middle ground between onerous requirements and a looser approach, Steve advises taking a commonsense approach during this pause. He says, “I expect there’s going to be some relaxation in some of these time frames, but I just don’t expect there’s going to be a huge relaxation in the requirements across the board. And the truth is going to be somewhere in the middle.” Jonathan agrees, adding, “You could keep going full bore, but you got to do what’s right for your business and recognize that it’s not like the hundred and ten controls are a bunch of superfluous stuff. You’re probably going to need to get there anyway, it’s just a question of when.”
Learn More About the CMMC Pause
The full podcast contains more discussion and details on a variety of topics, including how AI could potentially play a role in CMMC audits or approvals, why it’s a good pause even if you shouldn’t stop working, if CMMC is likely to cost you $30,000 or $100,000+, and more.
Be sure to check out Stay Sharp Episode 146: Stay Sharp Episode 146: CMMC Paused, Not Cancelled: Why Contractors Shouldn’t Stop Now and join us each week for a new podcast.



