Skip to main content

The CMMC Pause Does Not Pause the Threat

The Department of War's review of the Cybersecurity Maturity Model Certification (CMMC) program does not reduce the obligation for defense contractors to protect controlled unclassified information. The threat has not paused — and neither should your security posture.

Jul 22, 2026

·

Blog

·

Secure Communications

The Department of War's decision to review the CMMC Phase 2 assessment requirements reflects a genuine tension at the heart of defense contracting: cybersecurity frameworks must strengthen the defense industrial base, not price smaller suppliers out of it. That tension is legitimate. Third-party assessment capacity, cost barriers, and implementation complexity have slowed participation. A review was warranted.

The review changes the compliance timeline, not the threat environment. Adversaries are still targeting defense contractor networks, executive communications, and mobile workflows. CUI and FCI remain exposed wherever contractors rely on unmanaged tools, unsecured channels, or commercial messaging platforms that were never designed for national security use cases.

For defense contractors, the immediate issue is not whether CMMC certification is active on a specific date. It is whether the organization could show a defensible, documented security posture if scrutinized today. That posture depends on what happens in real time across the devices and channels the workforce uses.

What the CMMC Pause Actually Means for Defense Contractors

The DoW review of CMMC Phase 2 does not remove existing obligations. Contractors still operate under DFARS 252.204–7012, which requires adequate security measures for covered defense information. NIST SP 800–171 remains the baseline. What changes is the timing of third-party certification, not the duty to protect sensitive information.

Organizations that treat the pause as permission to delay security investments may be exposed operationally and contractually when the framework resumes. They also remain vulnerable now to the adversaries CMMC was designed to address.

The defense industrial base is a high-value target. Nation-state actors and sophisticated cybercriminal organizations routinely probe contractor networks looking for access to sensitive program data, supply chain information, and mission-related communications.

Where Sensitive Information Is Most Vulnerable

Security frameworks tend to focus on network perimeters and IT infrastructure. That focus is necessary, but it is not sufficient. Sensitive defense information moves through email threads, mobile messaging applications, voice calls, file-sharing platforms, and distributed collaboration tools.

This is where exposure is often highest. Commercial messaging platforms such as WhatsApp, Telegram, and standard SMS lack centralized policy control, continuous identity verification, and metadata protection for mission-critical communications.

Metadata is an underappreciated risk. Even when message content is encrypted, timestamps, call logs, participant identities, and behavioral patterns can reveal sensitive operational information. For defense contractors coordinating with government agencies, that exposure matters.

Secure-by-design communications, certified to government-grade standards and deployed with full organizational control, address these vulnerabilities directly.

What a Defensible Security Posture Looks Like During the Pause

A defensible security posture does not require CMMC certification to be in place today. It does require documented security practices, practical safeguards across operational workflows, and communication tools that reduce risk rather than introduce it.

For defense contractors, the current environment should be evaluated across several dimensions.

Identity Verification: Every participant in a sensitive communication should be explicitly authorized and continuously verified. Consumer applications authenticate users by phone number, not by organizational identity.

Encrypted Communications Across All Channels: End-to-end encryption for voice, messaging, and file sharing is a baseline expectation for any tool handling CUI or FCI. Encryption that covers only part of a communication chain leaves gaps that adversaries will find.

Zero Metadata Exposure: A secure communications platform should shield metadata, preventing adversaries from mapping organizational behavior, personnel relationships, and operational patterns.

Centralized Policy Control and Compliance Visibility: Unlike consumer-grade alternatives, a government-grade secure communications platform gives security teams centralized oversight, configurable data retention, and auditable records. These capabilities support defensible self-assessments and reduce the burden of compliance documentation.

Deployment Flexibility: Not all contractor environments are the same. Some require cloud-hosted solutions. Others require on-premises deployment or air-gapped environments with no external infrastructure. Support for multiple deployment models helps contractors align communications security with their operational and contractual requirements.

Why Secure Communications Should Be Part of the CMMC Baseline

The CMMC review gives policymakers and contractors a chance to make cybersecurity requirements more workable. A framework that prices smaller suppliers out of the defense industrial base defeats its own purpose. Workability, however, cannot mean weaker security. It should lead to controls that are easier to deploy, easier to verify, and harder for adversaries to bypass.

Secure communications fits that test. A certified, encrypted communications solution gives contractors a governed environment for sensitive conversations, file exchanges, and coordination activities on channels that meet government-grade security standards.

That is the kind of practical, scalable control the defense industrial base needs. BlackBerry® Secure Communications supports a risk-based approach to protecting high-value communications without adding unnecessary friction to daily operations. Security for national security use cases must be strong enough to trust and simple enough to adopt across large, mixed, and mobile workforces.

Certified and validated by FIPS, Common Criteria, FedRAMP Class D (High), and NATO Restricted standards, BlackBerry Secure Communications delivers the level of assurance that defense-sensitive environments require. Contractors working across classified and unclassified boundaries, or coordinating with multiple agencies and subcontractors, need a solution built specifically for that complexity.

Defense supply chains are only as secure as their most vulnerable participant. Large prime contractors may have mature security programs. Smaller subcontractors and nontraditional suppliers often do not, yet they frequently exchange sensitive information with primes and government agencies.

That vulnerability is exactly what CMMC was designed to address, and it does not disappear during a review period. Adversaries know smaller contractors may be less protected. They also know that communication channels between contractors and government customers are valuable targets.

Protecting those channels requires more than perimeter security. It requires secure-by-design communications that work across organizational boundaries, support interoperability between agencies and contractors, and maintain consistent security standards no matter who starts the conversation.

A solution that encrypts communications end-to-end, verifies the identity of every participant, protects metadata, and supports deployment configurations ranging from cloud to fully air-gapped environments addresses this requirement at the supply chain level, not just the individual contractor level.

Turning the Pause into Progress

During the CMMC review, every defense contractor should be able to answer one question: what does our security posture look like today, regardless of which certification requirements are formally active?

Organizations that use this period to strengthen operational security, document their practices, and deploy practical safeguards will be better positioned when Phase 2 requirements resume. Organizations that treat the pause as a reason to wait will find themselves catching up on security and compliance simultaneously, under greater time pressure, in a threat environment that has continued to evolve.

The CMMC framework, at its core, exists because the threat is real. The review is a signal that the path to compliance needs to be more achievable. Defense contractors should take this signal seriously: strengthen security now and engage with the compliance process as it evolves.

Secure communications is a practical place to start. It addresses a real operational vulnerability, is applicable across diverse contractor environments, and is aligned with the documented security practices that a defensible self-assessment requires.

Get updates about the latest in-depth knowledge for secure communications.

The New Standard

Watch the Webinar: The Case for Mission-Critical Communications

Join us for a 45-minute webinar where our experts explore the technical and operational framework to ensure mission-certified secure communications across encryption, architecture, sovereign control, independent validation, and mission orchestration.

Watch now