AGP Picks
View all

FEDCON warns contractors to keep CMMC Level 1 in place as Level 2 pauses

Aug. 17, 2026
By AI, Created 13:00 UTC, Aug 17, 2026, AGP -

FEDCON says federal contractors should not treat the pause in CMMC Level 2 as a cybersecurity reset. The firm says Level 1 requirements remain mandatory for companies pursuing federal work, even as Washington reworks the rollout of tougher assessments.

Why it matters: - Federal contractors and subcontractors handling Federal Contract Information still need to meet CMMC Level 1 to stay eligible for awards and renewals. - The pause in CMMC Level 2 may delay tougher audits, but it does not remove basic cybersecurity obligations for defense and technology vendors. - Companies that assume the delay is a full reprieve risk compliance gaps and contract problems.

What happened: - FEDCON said the federal government has temporarily paused rollout of CMMC Level 2. - The update was shared Aug. 17, 2026, in Tampa, Florida. - FEDCON said the pause gives the government time to review assessment timelines, third-party assessor availability and industry readiness. - FEDCON also said the Level 2 delay does not change CMMC Level 1 requirements.

The details: - CMMC Level 2 requires third-party audits covering 110 security controls based on NIST rules. - FEDCON said the pause should help refine assessment standards, simplify paperwork and address implementation bottlenecks across the defense industry. - CMMC Level 1 applies to protecting Federal Contract Information with 17 basic cybersecurity practices. - Key Level 1 practices include access control management, regular system updates, basic network authentication and sanitization of removable media. - Federal procurement rules continue to require compliance with Level 1 standards for contractors and subcontractors handling FCI. - FEDCON advised contractors to keep annual CMMC Level 1 self-attestations current in the Supplier Performance Risk System, or SPRS. - FEDCON urged contractors to hold subcontractors to basic cyber hygiene standards, including strong passwords and updated software. - FEDCON recommended that companies preserve internal mapping against NIST SP 800-171 controls because Level 2 is expected to resume under updated implementation guidance after administrative reviews end.

Between the lines: - The pause appears aimed at making the Level 2 rollout more workable, not weaker. - The message to industry is clear: the government is slowing the process, but not lowering the baseline. - Contractors that keep Level 1 records, subcontractor oversight and Level 2 preparation in place are better positioned when the next phase resumes.

What's next: - FEDCON said it will watch federal rulemaking, Department of Defense changes and procurement updates. - The company said it will continue sharing timely guidance for federal contractors as the CMMC framework evolves. - Level 2 implementation is expected to restart under revised guidelines after the administrative review is complete.

The bottom line: - The CMMC Level 2 pause is temporary, but Level 1 compliance remains a live requirement for federal business.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Florida Political Journal

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Florida Political Journal

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.