CMMC Compliance Pause Creates MSP Services Opportunity

Kiteworks says the CMMC assessment pause is creating opportunities for MSPs to deliver compliance, evidence collection, remediation, and monitoring.

Aug 27, 2026
4 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Kiteworks is urging MSPs, MSSPs, resellers, and compliance consultants not to mistake the temporary pause in CMMC 2.0 Phase II assessments for a slowdown in compliance demand, arguing instead that uncertainty around enforcement is creating a broader services opportunity for channel partners.

Kiteworks research finds a CMMC evidence gap

New research from the secure data exchange vendor found that 96% of surveyed defense contractors believe their self-attested compliance score would withstand review, but only 29% can support that confidence with both a current Supplier Performance Risk System submission and an audited platform. 

Kiteworks surveyed 273 defense contractors subject to an active CMMC 2.0 requirement following the government’s July suspension of Phase II third-party assessments.

“You know, I think it comes down to evidence,” Michael told Channel Insider. “It’s one thing to say you’re compliant, and especially when you’re self-attesting. But you need to be able to prove it.”

Michael said audit trails are particularly important because organizations ultimately need to prove that their controls and handling of controlled unclassified information are working as intended.

“If somebody comes — let’s say an audit or the DOW decides to come knocking on your door from a compliance standpoint — you need to have the evidence in place to prove that you’re compliant,” Michael said.

CMMC pause does not eliminate existing compliance requirements

The suspension only affects one component of the compliance process. DFARS 252.204-7012, NIST SP 800-171, Phase I self-assessments, and SPRS submissions remain in effect, according to Kiteworks. 

The company found that 98% of contractors took some action after the pause was announced, while just two percent did nothing.

Michael said partners should therefore continue approaching CMMC much as they did before the pause.

“I don’t think it’s any different than a month ago,” Michael said. “I think there’s a huge opportunity. There’s hundreds of thousands of businesses and companies that are going to need to at least meet that requirement.”

Advertisement

Many continue to move forward with compliance despite the pause

Kiteworks’ survey also suggests many contractors are unwilling to simply wait for regulatory clarity. 

Thirty-two percent are continuing with scheduled third-party assessments voluntarily even though those assessments are temporarily no longer required, while 89% are using or plan to adopt a FedRAMP-authorized platform within six months.

Michael said Kiteworks continues to see companies actively seeking CMMC-related solutions despite the pause.

“We’re still seeing customers calling saying we need to be compliant,” he said, adding that Kiteworks is seeing several inquiries a week from organizations of varying sizes. “We haven’t seen a huge dramatic slowdown.”

Evidence collection creates recurring services opportunity for MSPs

The immediate partner opportunity extends beyond helping customers pass an assessment. Kiteworks identified gap assessments, evidence collection, System Security Plan remediation, continuous monitoring, and managed compliance retainers as potential services attached to the gap between self-attestation and audit-ready proof.

That shift could allow partners to turn what might otherwise be a one-time CMMC project into an ongoing managed service.

“For us as MSPs, that also requires us to shift our thinking from audit support and compliance support to really providing that compliance day in and day out,” Corsica Technologies CEO Brian Harmison told us in June. “The businesses we work with are counting on that happening, whether we are [already] doing it or not.”

Kiteworks is positioning its own platform as one component of that partner-delivered model. The company said its Control Plane supports CMMC Level 2 requirements and is FedRAMP Moderate Authorized, while partners can layer assessment preparation, remediation, consulting, and ongoing monitoring on top of the technology.

Advertisement

CMMC expertise could support broader compliance practices

The opportunity may also extend beyond defense contractors. Michael said partners that build CMMC expertise can use the same consulting-led approach as customers face a growing number of cybersecurity, data protection, and privacy requirements.

“The compliance environment is not getting any easier,” Michael said. “It’s going to get more and more challenging for businesses as time goes on.”

READ MORE: We spoke with Fortreum Chief Strategy Officer Andrew Black about how partners can leverage AI and consultative practices to address the complexity faced by CMMC-compliant organizations.

That makes regulatory expertise itself a potential differentiator for MSPs and security partners, particularly those that can combine technical controls with independent advisory services.

“As long as that continues, that creates a lot of opportunity for everybody in this space, specifically for partners,” Michael said, pointing to firms that can provide an independent view, consult on best practices, and recommend appropriate technologies.

Victoria Durgin

Victoria Durgin is a technology communications professional and editorial leader specializing in channel technology, cloud marketplaces, managed service providers (MSPs), technology distribution, and partner ecosystems. As Managing Editor of Channel Insider, she oversees editorial strategy and content development focused on helping technology vendors, solution providers, and channel partners navigate an evolving IT landscape. With nearly a decade of experience spanning technology journalism, corporate communications, content strategy, and digital publishing, Victoria has developed deep expertise in the business side of technology. Her work includes creating executive thought leadership content, industry analysis, case studies, and channel-focused reporting that helps organizations better understand market trends, partner relationships, and technology buying decisions. Before leading Channel Insider, Victoria built experience across local journalism, business reporting, social media communications, and corporate marketing. She has worked closely with technology vendors, cloud providers, and managed service organizations to develop content that highlights industry innovation, business growth strategies, and successful channel partnerships. Her portfolio includes case studies featuring mid-sized MSPs across the United States, Canada, and Australia. Victoria's work has appeared in Channel Insider, The Valley Ledger, and Medium. She holds a Bachelor of Arts in Communications and Environmental Studies from Susquehanna University. Through her reporting and editorial leadership, she helps technology professionals stay informed about the trends, challenges, and opportunities shaping the global IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.