The Department of War’s July 13 decision to suspend CMMC Phase II implementation changes the near-term opportunity for Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs) and Value-Added Resellers (VARs) serving the defense industrial base. It does not, however, eliminate the underlying demand for cybersecurity maturity among defense contractors.
The suspension changes the timing and structure of third-party certification requirements while the department conducts a 60-day review of the program. Existing requirements around protecting Federal Contract Information and Controlled Unclassified Information (CUI) remain relevant, including NIST SP 800-171 requirements and the assessment framework incorporated into DFARS. CMMC Phase I self-assessment requirements also remain in effect.

For MSPs, the pause creates an opportunity to turn CMMC from a time-bound compliance sale into a longer-term customer relationship – exactly what MSPAlliance President Charles Weaver advised during the August 2026 Office Hours session titled, “Sales & Marketing for MSPs.” He recommended providers “sell the motion, not the SKU,” leveraging compliance as the buying trigger. And it’s true: there’s a real opportunity to make the client journey start with readiness and extend into remediation, managed security and ongoing compliance. It becomes a matter of your go-to-market (GTM) approach.
From deadline-driven demand to durable demand
CMMC created an unusually visible catalyst for cybersecurity investment. As implementation timelines shifted, however, some buyers moved from immediate certification activity toward evaluating what is required now versus what can wait – which is understandable. The current pause is not the same as eliminating the broader cybersecurity requirements or customer need that CMMC brought into sharper focus. And, more importantly, a delay in compliance effort will only hinder your client’s ability to properly safeguard their CUI, potentially exposing them to operational failures, data breaches, supply chain damage and more.
As their trusted technology advisor, it’s up to you to move the conversation beyond the certification deadline to protect their business. This gives you greater durability in your positioning while you help defense contractors improve their security posture and readiness, irrespective of the final shape of CMMC.
What MSP leaders should do over the next 90 days
Reframe your offering. Rather than create another CMMC-branded service page, brochure or social post, consider packaging an assessment or readiness engagement that produces a clear picture of your client’s current position, material gaps and recommended priorities for both pre- and post-CMMC compliance. This exercise can help your clients and prospects better visualize how your expertise – as Weaver says, “your advice, not your RMM, is what they’re buying” – will not only defend their enterprise, but enable focus so they can preserve their competitive advantage free of threatening diversions.
“The goal is to make CMMC the catalyst for a broader advisory relationship rather than the endpoint of a transaction.”
Change the conversation. Review your current CMMC messaging, sales calls and consulting engagements and determine whether they are overly dependent on certification timing or a particular product or service. A stronger proposition will help clients understand their current posture, prioritize remediation and maintain readiness as requirements evolve.
Apply outcomes to differentiate. A competitive market means mature buyers are unlikely to be persuaded by another claim of “CMMC expertise.” MSPAlliance noted findings from Kaseya’s Datto Global State of MSP that 35% of MSPs name competition as their top challenge, and it’s easy to see why when the same claims are so widely promoted. But your documented outcomes, such as improved assessment scores, completed remediation programs, reduced security gaps or successful preparation for external assessment can provide substantially more useful proof that will strengthen credibility and cultivate confidence in buying decisions.
Align marketing, sales and consulting around the regulatory uncertainty. Sales teams should have a consistent answer to the question, “What does the pause mean for us?” that clearly distinguishes what has changed from what remains uncertain. Marketing should translate those developments into relevant content that addresses customer questions, supports the sales conversation and reinforces your firm’s skillset. Technical teams should be equipped to assess gaps and recommend solutions based on each client’s needs, priorities and timeline. The objective is not identical messaging across every function, but a shared understanding of who the firm serves, what problems it solves, how it delivers value and what evidence supports its claims.

Refine and adapt over time. The September review should be treated as a potential market catalyst, not simply a regulatory announcement. Build scenario-based campaign and sales-enablement plans now so you can respond quickly to changes in regulation without rebuilding positioning from scratch.
Build the GTM around the customer, not the regulation
The CMMC pause may ultimately prove less important to MSPs than the broader market it helped create. Defense contractors have spent several years becoming more conscious of cybersecurity requirements, CUI handling and the commercial implications of their security posture. Those investments don’t disappear because a certification milestone moves.
For MSP, MSSP and VAR leaders, the opportunity is to build on that awareness and urgency without anchoring the business to a single regulatory timetable, and that requires “repeatable motion,” as Weaver noted. By taking the time to re-build your go-to-market around your trusted advisor role, as reflected in a well-crafted CMMC offering, value proposition, messaging, expertise and actual outcomes, you’ll be on your way to support a more sustainable pipeline that survives what MSPAlliance warns when “referrals run dry.”
Assess your positioning gap
If you’re not sure whether your current CMMC positioning is deadline-driven or durable, or whether your GTM motion has the cadence to sustain it past September, Towers Fractional Marketing works with IT services firms to turn regulatory uncertainty into a repeatable pipeline motion. Reach out to benchmark where your firm lands and build the 90-day plan to move it by booking a call today.