Cybersecurity Professionals Divided Over CMMC Pause

A new ISC2 survey shows split sentiment regarding the status of the Pentagon’s CMMC program.

Updated on Sept. 21, 2026 in Cybersecurity

Bold flat-color editorial illustration of a heavy circular steel vault door, symbolizing secure federal infrastructure.
A recent ISC2 survey reveals a sharp divide among cybersecurity professionals regarding the Pentagon's ongoing pause of its CMMC certification program. AI Illustration. Upload story photo >

Live Poll

Should federal agencies maintain pauses in mandatory cybersecurity certification programs for contractors?

ISC2 recently released survey results revealing that cybersecurity professionals are sharply divided on the ongoing phase two suspension of the Pentagon's Cybersecurity Maturity Model Certification (CMMC) program. While a vast majority of those surveyed believe such a program is necessary, opinions remain split on the impact of the current pause.

Why it matters

Understanding professional sentiment toward the CMMC is critical as the defense industry navigates the complexities of federal security standards. The survey highlights the ongoing tension between maintaining rigorous cybersecurity protocols and managing the practical challenges faced by contractors.

Data indicates 76% of surveyed professionals see the CMMC program as necessary. Meanwhile, 42% of respondents oppose the current phase two suspension, compared to 38% who support the move.

The players

ISC2

This international nonprofit association provides professional certifications and training for cybersecurity experts.

Pentagon

The United States Department of Defense oversees national security policies and the implementation of federal contractor requirements.

The details

The ISC2 study gauged the reactions of industry experts to the program's current status and its influence on defense contracting. Respondents provided feedback on their experiences with the program suspension, reflecting the sector's struggle to find consensus on regulatory timing.

Timeline

  1. September 2026: ISC2 released survey results regarding CMMC program status.

The Tech Race

The survey results provide a pulse check on the Cybersecurity Maturity Model Certification as it evolves within the defense sector. This data tracks the industry's attempt to standardize security protocols against the historical challenges of implementing large-scale government compliance frameworks.

The program's status directly influences the compliance burdens and operational requirements for those working with the defense industrial base. Professionals in the field must stay informed as shifts in federal policy dictate new security protocols for daily operations.

The takeaway

The lack of industry consensus suggests that federal regulators face a difficult path in finalizing the certification framework. Stakeholders should prioritize internal audit preparedness regardless of current program pauses to ensure readiness for future requirements.

Further reading

For more information on national security technology standards, visit the United States Cybersecurity section.

Live Poll

Should federal agencies maintain pauses in mandatory cybersecurity certification programs for contractors?