The Department of War (DoW) recently announced a 60-day review of the Cybersecurity Maturity Model Certification (CMMC) Phase II program. Unsurprisingly, the announcement has raised questions across the Defense Industrial Base (DIB):
- Does this mean CMMC is going away entirely?
- Should we pause our compliance efforts?
- Do we still need to protect Controlled Unclassified Information (CUI)?
- Is a secure enclave still worth the investment?
The short answer is: CMMC is not going away. You still need to protect CUI and ensure your organization remains competitive for winning government contracts. While the path to CMMC certification is changing, the obligation to secure sensitive government information has not.
CMMC Level 2: What has changed?
The DOW has suspended CMMC Phase II certification while it conducts a 60-day review of the program. This means that only CMMC Level 1 or Level 2 Self-Assessments will be required in some procurement requests and documents.
Rather than requiring a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO) before contract award, contractors may now be required to complete a Level 2 Self-Assessment and submit their score to the Supplier Performance Risk System (SPRS).
While this changes how compliance is demonstrated, it does not change the need to ensure CUI remains secure.
CMMC Level 2: What Didn’t Change?
The DOW memo states: “All other contractual cybersecurity clauses in contracts remain intact.”
That means several foundational requirements continue to apply.
- NIST SP 800-171 Rev. 2 remains the standard and organizations handling CUI must still implement the 110 security controls defined in NIST SP 800-171 Rev. 2.
- DFARS 252.204-7012 Is Still Enforceable
- Contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012.
- In other words: A self-assessment is the score you sign. Your cybersecurity environment is the evidence behind it.
Why a Secure Enclave Matters More Than Ever
This policy change doesn’t reduce the importance of cybersecurity. If anything, it increases the importance of maintaining a secure, well-documented environment that supports your self-assessment. Rather than preparing for a single certification event, a secure enclave helps organizations build an ongoing security program around the controls that continue to matter.
A secure enclave can help you:
- Protect Controlled Unclassified Information (CUI) using NIST SP 800-171 Rev. 2
- Reduce the scope and complexity of your cybersecurity environment
- Centralize CUI into a purpose-built, managed environment
- Maintain documented security controls and operational evidence
- Continuously monitor and manage your cybersecurity posture
- Support accurate, truthful, and defensible self-assessments
Whether certification requirements evolve or return in a different form, the work required to secure CUI remains valuable.
Why Staying Ahead of Changing Compliance Requirements is Important
Some DIB contractors may be tempted to pause cybersecurity investments while the program is under review.
For most organizations, that’s a risky assumption. Maintaining a secure enclave today helps you:
- Continue meeting existing contractual cybersecurity obligations
- Protect sensitive government information from active cyber threats
- Support self-assessments with documented technical evidence
- Reduce operational complexity for your internal IT team
- Avoid scrambling if CMMC Level 2 certification requirements are reinstated
- Build a cybersecurity foundation aligned with the interim enforcement standard
Cyber threats aren’t waiting for regulatory certainty. Neither should your cybersecurity strategy.
At Rimstorm, we believe cybersecurity should reduce operational burden, not create more of it.
Our secure enclave provides government contractors with a managed environment designed to protect CUI, support NIST SP 800-171 requirements, and strengthen overall cybersecurity posture.
The current changes to CMMC may create uncertainty, but they don’t have to create confusion. Our team is actively monitoring guidance from the Department of War and helping government contractors understand what has changed and how those changes impact their business. Whether you’re evaluating your current cybersecurity posture or determining the best path forward for protecting CUI, we’ll help you make informed decisions about how to secure contracts by strengthening your cybersecurity posture.
As the CMMC program evolves, we’ll continue monitoring developments and sharing practical guidance to help our customers make informed decisions. If you have questions about how these changes affect your organization, or whether a secure enclave is the right fit for your business, our team is here to help.
Because while the certification process may change, the responsibility to protect CUI remains.

