TAKE NOTE (Insights and Emerging Technology)

The Department of War has immediately suspended Phase II of the Cybersecurity Maturity Model Certification program, which was scheduled to begin November 10, 2026, while it conducts a 60-day review of the program.
During the suspension, contracting activities may require only CMMC Level 1 or Level 2 self-assessments. They may not require Level 2 third-party certification or Level 3 government certification. Active solicitations containing those requirements are to be amended, and existing contracts are to have them removed before the next option exercise or scheduled administrative modification. Importantly, this is not an abandonment of contractor cybersecurity. NIST SP 800-171, DFARS 252.204-7012, annual affirmations, self-assessments, and selected government-led assessments remain in effect.
The CMMC regulation states that the Department “intends” to introduce third-party certification during Phase II and expressly gives it discretion to delay when certification becomes a condition of award. The regulation also states that the CMMC program creates no legally enforceable right or benefit against the United States. In my view, the stronger criticism is that the suspension may be inequitable, disruptive, and potentially challengeable in how it is implemented, particularly if the Government removes a contractual requirement without properly addressing costs that a contractor incurred to perform that requirement. The suspension itself does not appear facially unlawful, but individual solicitation amendments and contract modifications must still comply with federal procurement law and the terms of each contract.
My concern is that the Government spent years telling the defense industrial base that certification would become a condition of competing for substantial portions of defense work. Small businesses responded by purchasing compliant technology, hiring consultants, remediating systems, segregating networks, developing documentation, training employees, and paying for assessments. Some made those investments early not merely to satisfy a future mandate, but to demonstrate that they were more secure and responsible than their competitors. The suspension temporarily reduces the value of that differentiation while allowing companies that deferred the expense to compete under the same self-assessment framework. Large businesses will generally absorb this policy reversal more easily, while small businesses may have tied up scarce working capital that could otherwise have supported hiring, capture, product development, or contract performance. C3PAOs, managed service providers, consultants, and other companies built around the certification ecosystem may also experience an abrupt loss of expected demand.
There is currently no announced Government reimbursement program, and companies that invested voluntarily in anticipation of future opportunities are unlikely to have a direct legal right to a refund. The better possibility exists for a company that incurred documented costs because an active contract specifically required third-party certification and that requirement is now being removed. Such a contractor should examine the modification, preserve invoices and labor records, avoid signing an unrestricted release, and consider submitting a request for equitable adjustment under the contract’s Changes clause. If the contracting officer denies entitlement, a formal claim may be available under the Contract Disputes Act. In my view, the Department should also consider a targeted reimbursement, credit, grant, or transition program for small businesses that can demonstrate reasonable reliance on finalized regulations, contract language, or active solicitations. Without such relief, the Government risks penalizing the very companies that acted early and responsibly.
Over the next 60 days, businesses should not dismantle their cybersecurity environments or treat the announcement as permission to retreat from NIST SP 800-171. Companies should instead inventory every CMMC-related expenditure, identify which costs were tied to specific contracts or solicitations, review forthcoming amendments carefully, and submit evidence-based comments through the Department’s public information request. Certified businesses should continue positioning their investments as evidence of lower performance risk, stronger data protection, and readiness for whatever framework replaces or reforms Phase II. My view is that the Government now has an obligation to produce more than another revised compliance schedule. It must explain how it will preserve meaningful cybersecurity verification, recognize companies that invested in good faith, and avoid creating a future system in which waiting until the last possible moment becomes the most financially rational strategy.
Read original at DoW link below
Interested in learning more about RPA? Download our FREE White Paper on “Embracing the Future of Work”
UNDER DEVELOPMENT (Insights for Developers)
Moving SAP to the Cloud Is Easy. Modernizing the Business Is the Hard Part

Intro
As organizations continue their journey toward SAP S/4HANA, cloud adoption has become less of a question of if and more of when. Driven by the approaching end of mainstream maintenance for SAP ECC, increasing demands for agility, and the emergence of AI-powered business capabilities, enterprises across both the public and private sectors are accelerating their cloud strategies.
Yet despite billions of dollars invested in cloud migration initiatives, many organizations discover that moving SAP to the cloud does not automatically deliver the business transformation they expected.
Why?
Because migrating infrastructure and modernizing a business are two very different things.
Cloud migration is a technology initiative. Business modernization is an organizational transformation. While cloud provides the platform, modernization is what creates measurable value.
At IT Partners, we’ve found that organizations achieve the greatest return on their SAP investments when they treat cloud migration as the foundation for transformation rather than the transformation itself.
![]()
MIGRATION IS THE BEGINNING, NOT THE DESTINATION
For years, organizations measured success by whether an implementation finished on time and within budget. Today’s leaders are asking a different question:
“How does this make the business operate better?”
Moving an SAP landscape from an on-premises data center into a cloud-hosted environment certainly provides operational advantages:
- Improved scalability
- Reduced infrastructure management
- Greater resiliency
- Faster provisioning
- Better disaster recovery
- Simplified patching and lifecycle management
These are meaningful improvements. However, none of them necessarily improve procurement cycle times, increase financial visibility, streamline logistics, reduce audit findings, improve customer service, or enable better executive decision making.
Those business outcomes require much more than a hosting change. Simply relocating existing processes into the cloud without addressing decades of accumulated technical debt often results in what many organizations jokingly refer to as “the world’s most expensive lift and shift.”
![]()
THE HIDDEN COST OF CARRYING YESTERDAY INTO TOMORROW
Every mature SAP environment contains history.
- Years of enhancements.
- Custom reports.
- Legacy integrations.
- Department-specific workflows.
- Manual workarounds.
- Business rules that may no longer serve their original purpose.
Many organizations assume every customization represents critical business functionality. In reality, a significant percentage exists because the software could not support a requirement years ago that SAP now provides as standard functionality.

Carrying unnecessary customization into a cloud environment creates several long-term challenges:
- Increased implementation complexity
- Longer testing cycles
- More difficult upgrades
- Higher maintenance costs
- Greater cybersecurity exposure
- Reduced flexibility for future innovation
Cloud migration presents a rare opportunity to evaluate what should remain, what should be redesigned, and what should simply be retired. Organizations that use migration as an opportunity to simplify frequently realize greater long-term benefits than those that simply replicate their existing environment.
One of the most common mistakes organizations make during SAP transformation is…
– Dig Deeper –
The Power of decoupling migration & modernization
Q&A (Post your questions and get the answers you need)

Q. . My company is currently going through the CMMC process. From an employee perspective, what is CMMC, how do the different levels compare, and why is achieving the right level important to the business?
A. CMMC is essentially the Department of War’s way of verifying that companies in the defense industrial base are properly protecting sensitive government information. For us, this is more than an IT or cybersecurity exercise. It affects how we operate as a company, how we manage risk, and whether we remain eligible to compete for certain DoD contracts. That is why the process requires involvement from leadership, contracts, operations, human resources, facilities, and our technical teams.
The real question is no longer whether AI will transform enterprise operations. The question is whether organizations have built the operational and data foundations necessary to trust AI with increasingly important business decisions. Those that begin laying that groundwork today will be best positioned to leverage autonomous capabilities tomorrow and turn AI from an interesting technology into a measurable business advantage.
The three CMMC levels are based on the type and sensitivity of the information a company handles. Level 1 covers basic protection of Federal Contract Information and focuses on fundamental cybersecurity practices. Level 2 applies to companies that handle Controlled Unclassified Information and requires compliance with the 110 security requirements in NIST SP 800-171. Level 3 is intended for organizations supporting the most sensitive national security programs and adds stronger protections against advanced cyber threats.
From an executive perspective, the key point is that CMMC is not just about having the right policies or security tools in place. The company must be able to prove that its controls are working and that employees are consistently following the required procedures. That means understanding where sensitive information is stored, limiting access, maintaining documentation and evidence, managing subcontractor compliance, and correcting any gaps that are identified.
Ultimately, achieving the appropriate CMMC level protects both the government and the company. It reduces cybersecurity and operational risk, strengthens customer confidence, and helps preserve our ability to pursue and perform defense work. A company may have a strong technical solution and excellent past performance, but without the required CMMC status, it may not be eligible to compete for certain opportunities.
There is currently a pause affecting the implementation of CMMC Phase II. On July 13, 2026, the Department suspended the Phase II requirements that had been scheduled to begin on November 10, 2026, and initiated a 60-day review of the program. However, Phase I self-assessment requirements remain in place, and the Department has stated that it will continue enforcing NIST SP 800-171 compliance through self-assessments and selected government-led assessments.
In my opinion, and what we as a company are doing, is to view this as a pause in the implementation schedule, not a reason to stop preparing. Continuing the work protects government information, reduces our risk, strengthens customer confidence, and positions the company to meet whatever requirements emerge from the review.
Cheers!



