The Defense Department’s decision to pause the next phase of Cybersecurity Maturity Model Certification (CMMC) implementation has added another layer of uncertainty for defense contractors.
But while assessment timelines may have shifted, the need for cybersecurity preparation has not—creating a growing opportunity for managed service providers, security consultants, and compliance specialists to help customers navigate evolving federal requirements.
CMMC Phase 2 pause does not remove current obligations
The compliance landscape shifted again in July when the Defense Department suspended the planned November 2026 transition to Phase 2 of CMMC implementation. The move temporarily holds back the broader use of third-party Level 2 certification requirements while the department conducts a review of the program.
The suspension does not eliminate CMMC or give defense contractors permission to put cybersecurity preparation on hold. Phase 1 self-assessment requirements remain in place, and organizations handling controlled unclassified information must still meet applicable NIST SP 800-171 and DFARS safeguarding obligations.
For MSPs and consultants, the change may provide customers with more time to prepare, but it also introduces another layer of uncertainty around assessment timelines and contractual requirements.
Contractors face confusion over CMMC scope and readiness
Organizations selling into the federal market may already be managing requirements tied to individual agencies, government contracts, data types, and system classification levels.
Andrew Black, the chief strategy officer at Fortreum, told Channel Insider that companies entering the defense industrial base sometimes assume an existing commercial certification, such as ISO or SOC compliance, will translate directly into CMMC readiness. However, the required security architecture, system boundaries, and protection mechanisms may differ.
Confusion also persists around the distinctions between federal contract information and controlled unclassified information, as well as which CMMC level applies to a particular contract.
That uncertainty creates an opening for consultants and service providers that can interpret requirements, define appropriate boundaries, and prevent customers from building unnecessarily expensive compliance environments.
AI can accelerate compliance work but not replace experts
Compliance programs have long depended on spreadsheets, documentation, and manual evidence collection, making assessments both time-consuming and labor-intensive.
“People are turning to AI because we bring leverage to that… not just workflow orchestration or workflow automation, actually contributing to the work product itself,” Black said. “We’re actually able to analyze, assess, write, generate so that the human expertise can get more output with the inputs that we have.”
That efficiency could help MSPs and compliance consultants serve more customers without proportionally increasing headcount, particularly as demand for CMMC readiness grows.
Black cautioned, however, that organizations should resist the temptation to treat large language models as a replacement for experienced compliance professionals.
“There is a false narrative out there that AI is going to do this,” he said. “The whole job can just be given to an LLM, and we’re good. Horrible idea.”
Instead, he said AI should function as a copilot that accelerates documentation, analysis, and evidence preparation while humans continue making architectural decisions, validating findings, and ultimately assuming responsibility for the assessment.
“The signature [on the assessment] is still a human signature. It’s not an AI signature,” Black said.
MSPs can help customers contain compliance costs
Cost remains one of the largest barriers for smaller contractors and suppliers. Organizations may need new technology, consulting support, documentation, assessments, and continuous monitoring—all without having budgeted for those expenses.
“That’s why we built this company,” Black said about Fortreum. “You shouldn’t have to come up with an extra $200,000 as a small business that’s been providing great value.”
Black said partners should help customers determine the level of protection they actually need and narrow the compliance scope wherever possible. That can reduce the number of systems, users, and security tools included in the assessed environment.
The long-term goal, he said, should be to direct more resources toward security itself rather than the documentation surrounding it.
“The world’s not getting safer, so we’ve got to get this right. It just can’t cost as much as it did in the past. That’s where we come in and help,” Black said.





