Cybersecurity Pros Divided on Pentagon CMMC Pause
A new ISC2 survey reveals split sentiment among industry professionals regarding the suspension of CMMC phase two.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Should federal agencies maintain pauses in mandatory cybersecurity certification programs for contractors?
ISC2 has released survey results gauging expert opinion on the Pentagon's Cybersecurity Maturity Model Certification (CMMC) program. While a clear majority of professionals agree that a certification program is necessary, opinions remain divided on the recent phase two suspension.
Why it matters
The CMMC program is designed to standardize security requirements for defense contractors, and the uncertainty surrounding its rollout timing directly impacts the procurement pipeline for the U.S. military. This survey highlights the professional friction created by the current program status.
The survey shows that 76% of cybersecurity professionals believe the CMMC program is necessary for defense infrastructure security. However, sentiment regarding the phase two suspension is split, with 42% in opposition and 38% in favor of the current program pause.
The players
ISC2
An international nonprofit organization that provides professional certifications and training for the cybersecurity workforce.
Pentagon
The headquarters of the United States Department of Defense, responsible for setting security standards for defense contractors.
The details
The Cybersecurity Maturity Model Certification is a framework developed by the Department of Defense to protect sensitive unclassified information within the defense industrial base. The program requires contractors to demonstrate compliance with specific security standards through independent audits. By gathering feedback from industry experts, ISC2, an international nonprofit association for cybersecurity professionals, aimed to quantify how the phase two suspension affects the daily operations of contractors currently working toward compliance.
Timeline
September 2026: ISC2 released survey results regarding CMMC program status.
The Tech Race
The CMMC program represents a shift toward mandatory security verification across the defense supply chain. Industry sentiment serves as a barometer for how effectively this regulatory framework can be implemented without disrupting the national security industrial base.
Defense contractors and cybersecurity professionals must monitor official Pentagon guidance for updates on the phase two rollout. The current suspension creates a period of uncertainty for companies currently building their compliance workflows to meet the standard.
The takeaway
The split in professional opinion suggests that while the industry supports the necessity of security standards, the mechanics of the rollout remain a point of significant contention. Observers should track the next official Pentagon announcement regarding the reinstatement of phase two requirements.
Further reading
For broader trends in industry standards, visit the Cybersecurity section.
Live Poll
Should federal agencies maintain pauses in mandatory cybersecurity certification programs for contractors?









