The Department of Defense's temporary pause on CMMC third-party assessments has left many contractors wondering what comes next. Cybersecurity expert Don Maclean explains why the delay doesn't change the law, and why organizations that continue investing in compliance today will be better positioned to protect sensitive data and compete for future defense contracts.
When the Department of Defense announced it was suspending third-party CMMC assessments while it evaluates the program, many defense contractors wondered whether they could hit the pause button on their own compliance efforts.
According to CMMC Certified Assessor and independent consultant Don Maclean, that's the wrong conclusion.
While assessment timelines may shift, the underlying legal requirements for protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) haven't changed. Companies that use the delay as an opportunity to strengthen their cybersecurity program will be far better positioned than those that stop investing altogether.
For Don, CMMC has never been about checking a box. It's about building a sustainable security program that protects sensitive information and enables organizations to compete for defense contracts over the long term. As he puts it, “the law still applies.” That simple reminder serves as the foundation for every decision organizations should make while the Department of Defense reevaluates the assessment timeline.
News of the CMMC assessment suspension generated understandable questions throughout the Defense Industrial Base. If assessments are temporarily paused, should companies continue spending time and money preparing?
Don believes the answer is unequivocally: Yes.
While many observers expect assessment deadlines to move, the laws governing the protection of sensitive defense information remain in force. Contractors are still expected to safeguard CUI and FCI, and organizations that falsely attest to compliance continue to face significant legal and financial consequences.
As Don explains, certification requirements and legal obligations are related—but they aren't the same thing. A delayed assessment doesn't eliminate the responsibility to protect sensitive information, it simply changes when an independent assessor may verify that you're doing so.
For organizations hoping the announcement means compliance can wait, Don offers a practical reality check: Companies still need compliant security controls, accurate documentation, and evidence that those controls are operating effectively. Waiting only compresses the timeline later down the line.
Organizations often focus on the visible part of compliance while overlooking the work that actually determines success. Don compares the assessment itself to the tip of an iceberg: Most organizations notice the third-party assessment because it's highly visible and carries a defined cost, but that's only a small portion of the overall effort.
The real investment lies beneath the surface:
“The biggest part is putting all the security apparatus in place and validating it and documenting it. That's where most of the effort, time, resources, et cetera, go. That's what's below the [tip] of the iceberg.”
— Don Maclean
Successful organizations recognize that compliance isn't something an assessor creates; the assessor simply verifies what already exists. That means the real work happens months—or even years—before assessment day through planning, implementation, governance, documentation, and continuous operational discipline. Companies that understand this distinction tend to build stronger cybersecurity programs regardless of when assessments occur.
Don's first recommendation is also his simplest: Don't confuse changes to the assessment process with changes to federal requirements.
Organizations handling CUI are still responsible for protecting that information. Existing contractual obligations haven't disappeared simply because assessment schedules may shift. Instead of asking whether compliance is still necessary, organizations should ask whether they're prepared to demonstrate compliance whenever the assessment eventually occurs.
This mindset prevents unnecessary delays and avoids the expensive scramble that often accompanies shifting deadlines.
If there's one technical recommendation Don has, it's scoping. In his view, nearly every major CMMC decision flows from accurately defining what systems, users, and assets actually need to be included within the compliance boundary. A smaller, well-defined scope reduces costs, simplifies documentation, and limits operational complexity—but only if it's accurate.
“The CMMC scope is the number one thing. Everything revolves around that.”
— Don Maclean
An improperly scoped environment creates downstream problems everywhere else:
Conversely, organizations that carefully identify only the people and systems requiring access to CUI create compliance programs that are easier to manage and less expensive to maintain. For Don, effective scoping isn't about shrinking the environment at all costs, it's about making it “as small as possible but also accurate and correct.”
Technology plays an important role in any modern CMMC program, but Don cautions organizations against expecting software to solve a governance problem.
One approach he recommends is using a dedicated enclave environment. By isolating systems that handle CUI, organizations can significantly reduce the size of their compliance boundary while leveraging cloud providers and managed environments that already understand CMMC expectations.
Many enclave providers also offer shared responsibility matrices that clearly define which security responsibilities belong to the provider and which remain with the contractor. This helps organizations focus their resources where they add the most value.
Technology, however, is only part of the equation. Tools can simplify implementation; they can't replace operational accountability.
One of the biggest misconceptions Don sees is the belief that compliance ends once an organization earns its CMMC certification. In reality, certification marks the beginning of an ongoing operational commitment.
Organizations must continue reviewing logs, conducting tabletop exercises, documenting security activities, and demonstrating that controls remain effective throughout the certification period.
Too many companies invest heavily to prepare for the assessment, only to relax their efforts afterward. But passing an assessment doesn't eliminate cybersecurity risk. If anything, maintaining compliance becomes the real challenge because organizations must consistently execute the policies, reviews, and governance practices they documented during the assessment process.
That means:
Compliance isn't something organizations achieve once, it's something they must demonstrate continuously.
Although cybersecurity teams often lead CMMC initiatives, Don encourages organizations to frame compliance as a business decision rather than simply a technical project.
For executive leadership, the key question isn't whether security controls are valuable, it's whether the investment aligns with the organization's business objectives.
Don encourages companies to examine:
For organizations whose revenue depends heavily on defense contracts, the answer is straightforward: Maintaining compliance protects existing business.
For organizations considering entering the defense market, the calculation becomes more strategic: Certification opens the door to opportunities—but only if the market justifies the investment. As Don explains, organizations should balance known revenue with realistic projections for future work before deciding how aggressively to pursue certification.
Don addresses a misconception he frequently hears from organizations beginning their compliance journey. Some assume that earning CMMC certification automatically leads to new contracts—that's not how the process works. Certification makes an organization eligible to compete, but winning business still depends on proposal quality, pricing, technical capability, customer relationships, and execution.
As Don puts it:
“It gives you the hunting license. It's legitimate for you to hunt, but it's not going to guarantee that you'll actually catch anything.”
— Don Maclean
Organizations shouldn't view compliance as a revenue guarantee. Instead, they should see it as a business enabler—one that removes a barrier to entry and allows them to compete for opportunities that would otherwise be unavailable. For many companies, especially those serving the Defense Industrial Base, that access alone justifies the investment.
Don's guidance succeeds because it shifts the conversation away from deadlines and toward long-term operational excellence. Organizations that continue investing in cybersecurity despite uncertainty gain several advantages:
Perhaps most importantly, they recognize that cybersecurity isn't a project with a finish line; it's an ongoing business capability.
By focusing on sustainable compliance instead of short-term certification, organizations create programs that remain effective regardless of regulatory changes.
Does the Department of Defense's pause on CMMC assessments mean companies can stop preparing?
No. As Don Maclean explains, while third-party assessments may be temporarily suspended, the legal requirements for protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) remain in place. Organizations should continue building and maintaining their compliance programs.
What is the most important first step in preparing for CMMC?
According to Don, proper scoping is the foundation of every successful CMMC effort. Clearly identifying which systems, users, and assets require protection helps organizations reduce costs, simplify documentation, and implement the appropriate security controls.
How can organizations reduce the complexity of CMMC compliance?
One strategy Don recommends is using a dedicated enclave solution. By isolating systems that handle sensitive information, organizations can reduce the size of their compliance boundary while leveraging technology providers that understand CMMC requirements and shared security responsibilities.
Does earning CMMC certification guarantee defense contracts?
No. Certification allows organizations to compete for contracts that require CMMC compliance, but it doesn't guarantee they will win business. Contract awards still depend on factors such as technical capabilities, pricing, proposal quality, and customer needs.
Is CMMC compliance primarily an IT responsibility?
While IT and cybersecurity teams play a critical role, Don emphasizes that CMMC is ultimately a business decision. Leadership should evaluate how compliance protects existing defense revenue, supports future growth opportunities, and aligns with the organization's long-term strategy.
What happens after a company earns CMMC certification?
Certification is only the beginning. Organizations must continue performing ongoing security activities such as log reviews, tabletop exercises, policy reviews, evidence collection, and documentation updates to demonstrate that their cybersecurity program remains effective throughout the certification period.