MSPs: Don’t waste this CMMC Level 2 pause

Turn the Cybersecurity Maturity Model Certification pause into stronger client security and recurring revenue.

CMMC-Level-2-Pause

Defense contractors got a reprieve this summer when the Department of Defense paused CMMC (Cybersecurity Maturity Model Certification) Level 2, suspending the requirement indefinitely while it reviews how the program should work. Many contractors read that as good news, and in one narrow sense it is. But if your MSP practice serves defense-adjacent clients, the wrong lesson to take from this pause is “we can put CMMC on the shelf for a while.” The better one is much closer to the opposite.

What changed and what didn’t

Formal certification by a third-party assessor is on hold. Contractors are still expected to self-attest that they’re meeting NIST 800-171 standards; that obligation has not moved. Certification got “easier” only in the sense that it isn’t happening for anyone right now. Self-attestation became more difficult, though, since clients are the ones signing their names to it without anyone necessarily standing behind them.

Under the certification path that was supposed to take effect by now, a company would typically work with a Registered Provider Organization to get ready, then go through a Certified Third-Party Assessment Organization to get certified. While that isn’t cheap, the structure puts two parties between the contractor and the government, with each one providing documentation and, frankly, some cover if a claim gets questioned later. Remove that path and self-attestation is what remains. Clients have to gather the evidence themselves and make the claim themselves…and then answer for it themselves if a contracting officer or auditor comes asking how they know it’s true.

That’s a longer way of saying that framing this delay as “easier” misses what’s actually happening beneath the surface. There’s no requirement to bring in outside help anymore, so skipping that step can look like savings on paper, but liability doesn’t disappear just because paperwork got simpler. A contractor who tells the government MFA is enforced, or that backups are tested and recoverable, has to be able to prove it when someone asks. Unsupported cybersecurity claims carry real exposure under the False Claims Act (certification pause or not), and self-attestation without evidence behind it is a signature on a promise nobody can back up.

Where MSPs come in

Your clients, or prospective clients, who were bracing for a formal certification process have some breathing room, and plenty of them are going to spend time kicking up their proverbial heels. Complacency with pushed-out mandates is an easy trap, but it’s also an opening MSPs don’t get very often. Whoever shows up now with the tools and documentation to make self-attestation defensible rather than aspirational is going to look a lot more valuable when the certification requirement resumes.

The path there treats controls that self-attestation depends on as the priority, not an afterthought. With backup management, for example, a job running last night doesn’t really tell anyone much on its own. The important part is whether the recovery truly works when it’s tested. Similarly, multi-factor authentication only counts if it’s enforced across the client’s entire user base, rather than being switched on for a handful of admin accounts and then considered done. Additionally, encryption reporting has to confirm coverage because assuming a policy is being followed is far from the same as knowing it is. The work isn’t necessarily complex, but it must automatically produce an audit trail, so a client signing off on a self-attestation is backing it with something more solid than a gut feeling. (It also should go without saying, but these controls hold their value independent of CMMC. A client running consistent MFA and locked-down data access controls and risk-response automation and layered encryption are far better protected against any incident…).

Documentation matters just as much as the controls themselves. Your clients can have every technical safeguard in place and still struggle to answer a straightforward question about how they know it’s working or who’s responsible for keeping it that way. Self-attestation runs on records just as much as it runs on tools, and clients who produce a clear evidence trail on demand are in a fundamentally different position than clients who are hoping nobody asks too many follow-up questions.

Building trust now, while the pressure is “off”

MSPs who can walk into that conversation now, while CMMC Level 2 certification pressure is temporarily off, can build something more durable than a single project: trust. And the more trust, the stickier the client. Use this opportunity to lock in revenue operational habits that will carry a client through whatever the requirement eventually looks like once DoD’s review wraps up. If anything, the review points toward more scrutiny down the line. The mechanism for verifying compliance is under revision, but the underlying bar isn’t going anywhere.

I know plenty of MSPs will let these client discussions go quiet until the next deadline forces the issue again, but that shouldn’t be you. If you take a path of sitting on your hands now, you’ll be leaving clients scrambling when Phase 2 resumes. So spend the next several months getting clients’ self-attestation evidence in order so they’ll have something real to show for it when the pressure comes back. It’s a conversation to have now, before the deadline comes back around and the window for getting ahead of it closes.


×