Navigating Compliance During the CMMC Pause with FutureFeed 

Daniel Akridge and FutureFeed tackle audience‑driven questions about navigating compliance during the CMMC pause. Their webinar discussed unchanged DFARS/NIST obligations, prime‑driven expectations, and the lasting value of prior readiness, offering contractors practical guidance in an uncertain landscape.

Summary
During FutureFeed’s audience‑driven webinar, Daniel Akridge joined experts to clarify compliance during the CMMC pause. Key takeaways: DFARS/NIST obligations remain, primes still expect readiness, and prior work retains value. Implementation outweighs assessment costs, and delaying increases risk. Early action positions organizations ahead when certification resumes.

In FutureFeed’s recent Explorers webinar session, I sat down with Mikkie Dorsey, Partner Manager, and Tiffiney Groce, Director of Engagement and Compliance at FutureFeed. We used our time to answer audience questions and discuss the complexities of navigating compliance during the Cybersecurity Maturity Model Certification (CMMC) pause. 

FutureFeed’s poll found that 89% of respondents are still moving forward with CMMC. 64% are very confident in their current compliance posture, and 59% still want to know what actually changed. In an uncertain landscape, even those who choose to move forward with compliance are confused. 

The Pause Didn’t Change the Fundamentals 

The first and most important thing to note is that you must still follow the controls and report incidents. DFARS 7012 and NIST 800-171 requirements are still in full force, even though third-party assessment obligation is paused. Where applicable, contracts still require Level 1 and Level 2 self‑attestation with a minimum Supplier Performance Risk System (SPRS) score of 88/110. The only part of CMMC that’s on pause is the third-party assessment requirement. 

Second, remember that suspension is not cancellation. The controls and enforcement mechanisms that matter are still active, and the risks tied to them remain unchanged. That reality shaped nearly every question raised during the session. 

Should I get a CMMC Level 2 Certification or self-attestation during the suspension? 

Consult your prime contractor to determine if they require CMMC Level 2 self-attestation or certification is right for your subcontracting work. Though a Level 2 certification isn’t a current government contract requirement, primes can use their own criteria to determine who they want to do business with. 

Because primes continue to carry the burden of risk, many are still insisting on certification or strong evidence of readiness. More than half of FutureFeed’s webinar poll respondents indicated that their primes are still requiring CMMC preparation, even today. 

This creates a scenario where subcontractors must be proactive by asking the prime directly what they prefer and expect.  When reaching out to your prime, ask which level applies, whether they still expect third-party certification, and when they expect compliance. 

Previous Compliance Work Isn’t Wasted 

Previous CMMC readiness efforts and certifications still “count,” even with the third-party certification requirement suspended. 

During the Department of War (DoW) CMMC Listening Session at Blackhat, the Chief Information Officer (CIO) said that the department intends to adjust bid scoring to prioritize those who are certified, even though certification is not a current requirement. Even if your prime doesn’t require your third-party assessment, your certification can still win you more contracts than your non-certified competitors. 

CMMC Pathfinder Tool - Find Your Path to CMMC in 5 Minutes

Additionally, implementing your controls puts you ahead of the curve for FAR CUI compliance. The upcoming Federal Acquisition Regulation for Controlled Unclassified Information (FAR) CUI Rule and the shift toward NIST 800‑171 Rev 3 will demand stronger, clearer, and more consistently applied controls. Organizations that have already aligned to NIST 800-171 Rev 2 will be significantly closer to meeting Rev 3’s increased number of assessment objectives and the new Organization-Defined Parameters (ODPs). 

Organizations that have implemented controls, built documentation, reduced risk, improved governance, or established repeatable cybersecurity processes have created lasting value.

In short, if you’re ahead now, you’ll keep the advantage. 

CMMC Assessment Cost Concerns Need Clear Context 

The cost of the assessment itself inhibiting meaningful security investment is a long-standing industry myth. This framing is misleading. DFARS 7012 and NIST 800‑171 implementation create the majority of the financial burden tied to compliance, not the third-party assessment itself. 

For many small businesses, the total cost of establishing a compliant enclave, implementing secure identity systems, managing logging, protecting data, and establishing governance exceed the cost of the assessment many times over. The assessment is usually a small percentage of total compliance cost over a three-year cycle. 

Contractors should be careful to get multiple quotes, validate the assessment scope, and avoid inflated pricing, but the more meaningful cost consideration is the cost of delaying implementation. Organizations that wait for perfect clarity, for the FAR rule to finalize, or for the CMMC pause to lift will face higher demand, limited assessor availability and consulting partners, and higher pricing due to industry backlog. The economics of delay are far more concerning than the cost of an assessment. 

When will the CMMC suspension end? 


When the suspension will end is becoming a difficult question to answer. We expected the DoW’s reform task report was within 60 days of the pause announcement, but two months passed without public release. Until the findings are published, contracting officers cannot include Level 2 or Level 3 certification requirements in new awards. 

Because rulemaking changes typically take years, most signs point toward certification resuming with adjustments rather than a full redesign. Once the DoW resumes the program, demand for assessors and compliance partners will likely spike. That means higher cost and longer wait times for contractors who hold.

Early action is still the safest position, especially with timelines slipping and future requirements trending toward more complexity, not less. 

Watch the Full Webinar: 

Watch the full webinar to hear the other topics we touched on, including: 

  • CUI scoping and handling 
  • The complexities of incident reporting 
  • FutureFeed’s Rev 2 → Rev 3 mapping project 

Reach out to a Summit 7 expert to learn about your organization’s path to NIST SP 800-171 compliance. 

Have Questions? We're Here to Help!

Scroll to Top