In Episode 12 of Winners Circle, host Pavle Majerle sits down with CMMC experts Don Costanzo (NexusTek vCIO and CMMC Registered Practitioner) and Dr. Yvette Burton (founding partner of Silent Partner Solutions and a CMMC Certified Assessor) to examine what the CMMC Phase 2 60-day suspension really means for defense contractors. They explain what changed, what didn’t, and why organizations should use the additional time to strengthen their cybersecurity posture instead of putting compliance efforts on hold.
On July 13th, the Department of War suspended plans to begin requiring third-party Cybersecurity Maturity Model Certification (CMMC) Level 2 assessments under Phase 2 for 60 days. There was a collective sigh of relief among defense contractors because it seemed like the pressure was off.
But was it?
In episode 12 of Winners Circle, host Pavle Majerle sat down with two NexusTek experts to explain what the delay really means. Their message was consistent: the assessment timeline has shifted, but the underlying cybersecurity requirements have not. Organizations should use this extra time to strengthen their security programs, not pause them.
Don Costanzo, a NexusTek vCIO and CMMC Registered Practitioner (RP), started by separating the headlines from the reality.
The original Phase 2 plan would have required many contracts to include third party CMMC Level 2 certification as a condition of award starting November 10th, 2026. The Department postponed that certification requirement while it continues reviewing the program.
Contractors are still responsible for protecting Controlled Unclassified Information (CUI) under NIST SP 800-171. SPRS scores still matter. Contracting officers can still evaluate cybersecurity risk, request documentation, and consider existing SPRS scores when awarding work. The certification requirement paused. The responsibility to secure CUI did not.
The panel discussed whether a good analogy to the CMMC delay was removing speed cameras while leaving the speed limit in place. You may not continue getting speeding ticket automatically, but you can still get stopped for speeding. In other words, the rule hasn’t changed, only how it’s enforced. Constanzo pointed out that an important difference is that cybersecurity isn't a single number like a speed limit. It's an ongoing operational discipline built from multiple factors gathered over time: access reviews, vulnerability remediation, employee training, incident records, and system logs.
You can organize documentation before an assessment. You can’t manufacture a year’s worth of security evidence over a weekend.
From Scheduled Exam to Pop Quiz
Dr. Yvette Burton, founding partner of Silent Partner Solutions and a CMMC Certified Assessor (CCA), described the change even more simply. Organizations have effectively gone from preparing for a scheduled exam to preparing for a pop-up quiz.
Without a fixed certification checkpoint, contracting officers may rely more heavily on due diligence to evaluate whether companies are adequately protecting sensitive information throughout their supply chains.
Dr. Burton also pointed out that organizations sometimes think that when you reduce external pressure it’s like getting permission to slow down. Companies that already invested time and resources into CMMC readiness, may feel frustrated by the delay. But whether a company started preparing or not, if they can see the delay as a strategic opportunity instead of a reason to pause, they can leverage the extra time to strengthen documentation, close security gaps, and prepare for anything that comes next.
Both experts emphasized practical security improvements that reduce real risk including.
When these capabilities are in place, businesses can build a practical environment that protects CUI while supporting the business.
Dr. Burton also shared why one of cybersecurity’s biggest blind spots is people. Even well-designed technical controls fail when an employee clicks the wrong link, for instance. And generic annual awareness training are often not enough because they’re not connected to an employee’s daily responsibilities. It isn’t realistic to expect someone to remember a policy months later or during a stressful moment. To build effective security training, build it into everyday workflows.
When asked which organizations will have the advantage when the next compliance phase begins, both experts agree. Companies should already know where their CUI resides, understand which systems and third parties are in scope, have documented control ownership, identified remaining gaps, and can produce evidence on demand. That means not starting over but continuing to improve on an existing security program. It’s also a leadership challenge. Companies succeed when leaders accept uncertainty as a normal part of doing business, keep teams focused, and use the extra time to strengthen their security posture instead of waiting for another deadline to act.
If you paused your compliance work when Phase 2 paused, the expert guidance is simple: unpause. If you never started, this window is the head start you may have missed before. NexusTek is partnering with Silent Partner Solutions to help defense contractors assess where they stand and get their system security plan (SSP) and controls on solid footing before the next checkpoint, whenever it lands.
Watch the full episode: CMMC Phase 2 is Paused. Your Obligations Aren’t. https://youtu.be/jIjX5mh8U6w
Explore: NexusTek CMMC 2.0 Compliance Services.