Cybersecurity professionals are no strangers to navigating regulatory change. In ISC2’s 2025 Cybersecurity Workforce Study, nearly a third (32%) of respondents identified keeping up with changing regulatory requirements as the biggest challenge they faced in the previous year. Looking ahead, the same proportion (32%) expect it to be the top challenge they will face over the next two years.

The U.S. Department of Defense (DoD) suspending implementation of the Cyber Maturity Model Certification (CMMC) is the latest reminder of how shifting regulatory requirements can create uncertainty for cybersecurity professionals.

Top Cybersecurity Challenges

On July 13, 2026, the U.S. DoD announced the suspension of CMMC Phase II requirements. The CMMC is a framework created by the DoD to verify that contractors and subcontractors in the Defense Industrial Base (DIB) securely handle controlled unclassified information (CUI). Phase II would have required the DIB to undergo third party audits to demonstrate compliance with NIST standards for any government provided CUI. The organizations impacted by this framework prior to the suspension, many of which were small and medium-sized businesses, needed to begin proving compliance in late 2025 and were working towards Phase II audit requirements when the suspension was announced.

To better understand the impacts of CMMC preparation and the recent suspension, ISC2 surveyed 219 cybersecurity professionals in the U.S. who have been involved in CMMC-related activities or preparation efforts within their organizations over the past 12 months. We heard from professionals working at organizations of all sizes and have provided results by organization size to highlight the disproportionate burden that regulatory requirements can impose on smaller organizations. Please note the sample sizes are small and should be interpreted as directional rather than representative of all organizations within each category.

Reactions to the CMMC Phase II Suspension

The cybersecurity professionals we surveyed largely agree (76%) on the need for a CMMC program to ensure that cybersecurity standards are being met. However, opinions on the CMMC Phase II suspension are nearly evenly split, with 38% supporting the pause and 42% opposing it.

These mixed views may reflect the significant amount of time and financial investment needed for some organizations and employees to comply with CMMC requirements. For example, over the past year, nearly a third (32%) of respondents said that they have spent less time on their cybersecurity responsibilities due to CMMC.

With that context in mind, the aim here is to examine these tradeoffs—specifically how CMMC requirements have affected cybersecurity professionals’ workloads, how the suspension changed those demands, along with the long-term impact to professional development and career plans.

Reactions to CMMC Phase 2 Suspension

Time Spent on CMMC-Related Work

ISC2 asked respondents how much time they spent per week on CMMC-related work over the past year. While the largest share (43%) reported spending anywhere from 1-5 hours per week on CMMC-related work, many respondents dedicated significant portions of their workweeks to complying with CMMC requirements in addition to their existing cybersecurity responsibilities. Over a third (36%) of respondents spent between 6-20 hours on CMMC-related tasks, while 21% spent 20 hours or more.

Time Spent on CMMC Work in the Past 12 Months

Examining these numbers further—specifically whether the time required for CMMC compliance varied across different groups of cybersecurity professionals—we found that respondents from smaller organizations experienced a greater individual time burden from CMMC-related work. Among respondents from organizations with 1–99 employees, over a third (35%) reported spending more than 20 hours per week on CMMC-related work, significantly higher than respondents at organizations with 100–499 employees (19%), 500–9,999 employees (17%) and 10,000 or more employees (15%). On the other hand, respondents at larger organizations were more likely to have spent 1-5 hours on CMMC-related tasks. This may reflect that larger organizations tend to have dedicated compliance teams whereas small and medium sized businesses necessitate reallocating time from other projects to complete compliance exercises.

Time Spent on CMMC Work in the Past 12 Months by Org Size

CMMC-Related Impacts to Security Workloads

Our research shows that in complying with CMMC requirements, cybersecurity professionals are absorbing additional work into their existing responsibilities—and this can come at a cost. Two-thirds of respondents (66%) said that CMMC preparation has increased their workload and 62% reported increased documentation requirements and expanded job responsibilities. This was broadly the same when also looked at by organization size.

Two in five respondents (42%) said that CMMC preparation has delayed other projects or responsibilities, while a quarter (25%) reported spending less time on cybersecurity-focused responsibilities.

Impact of CMMC Preparation

We then investigated the specific CMMC-related activities that respondents are involved in and found a notable focus on more administrative tasks such as documentation (81%) and participation in CMMC-related meetings (78%). Given the known requirements needed to demonstrate compliance and accuracy, the workload overhead reported by respondents is both expected and illustrative of the pressures CMMC places on organizations and teams.

CMMC Related Activities

CMMC Workforce Development Needs

Beyond its impact on cybersecurity professionals’ workloads, CMMC preparation appears to be creating additional workforce development needs—especially at smaller organizations. Over half of respondents (55%) said that CMMC preparation has increased the need for them to obtain additional credentials, training or expertise and nearly half (46%) reported a similar need among other employees within their organizations.

Respondents at small and medium-sized organizations were significantly more likely to report needing additional credentials, training or expertise due to CMMC preparation than those at larger organizations. Training and skills needs can carry potentially significant cost and personnel challenges for these smaller organizations. The need for others within their organizations to obtain additional workforce development did not vary significantly by organization size.

Has CMMC Preparation Increased Training Needs?

The top expenses incurred for these additional development needs are on training courses or education materials (59%); certification maintenance or renewal fees (52%); certification exam fees, professional membership fees, and continuing professional education (CPE) expenses (tied at 42%).

Expenses Incurred for CMMC Preparation

Obtaining additional workforce development requires both time and financial investment. Among respondents who pursued additional credentials, training or expertise, the largest share (33%) estimated that the cost of their individual development expenses amounted to $5,000 or more. One in 5 (20%) estimated training expenses to be in the $3,000-$4,999 range, one-quarter (25%) in the $1,000-$2,999 range and the remaining 22% said their expenses were less than $1,000.

Cost of CMMC Preparation

While organizations are more likely to provide funding for additional CMMC-related development, the costs are not always borne entirely by employers. Close to half (44%) of respondents who pursued additional development said their organization covered the cost, 28% said they paid out-of-pocket and 21% said the expenses were shared between themselves and their employer.

Who Paid for CMMC Preparation

CMMC Suspension and Impact on Work

Despite the uncertainty of how the CMMC Phase II suspension will impact respondents’ future work plans and career decisions, the majority (68%) continue to work on CMMC-related tasks.

At the same time, many respondents have also reported changes in their work since the suspension. Over a third of respondents have reallocated their time to other projects or priorities (34%), and others report delayed or canceled assessment preparation (26%), paused or postponed training activities (16%) or delayed credentialing (13%). Some have even reported longer-term impacts: 15% of respondents say the suspension has changed their professional development or career plans.

Impact of CMMC Suspension

Conclusion

The CMMC Phase II suspension may ease near-term pressure, but it does not remove the underlying need for strong cybersecurity practices, defensible documentation and readiness for future regulatory change. For many cybersecurity professionals, particularly those in smaller organizations, the preparation process has already required substantial time, shifted workloads, and created new development needs. The pause should therefore be treated not as a reason to step back, but as an opportunity to reassess priorities and strengthen long-term resilience.

Impacted organizations and cybersecurity teams within them should use this period to review where compliance activity has displaced core security work, identify gaps in skills or capacity, while ensuring training investments are aligned with both current requirements and likely future expectations. Professionals can also use the pause to build expertise in risk management, evidence collection, governance and frameworks such as NIST SP 800-171; while employers should consider how to fund and protect time for continuing professional development.

Next steps should include maintaining existing self-assessment discipline, keeping compliance records current, monitoring the outcome of the DoD’s review and preparing to adapt quickly when revised requirements emerge. Most importantly, organizations should use this moment to balance compliance readiness with practical security outcomes, ensuring that regulatory preparation supports— rather than distracts from— the mission of protecting sensitive information.

Methodology

In August 2026, ISC2 surveyed 219 U.S.-based cybersecurity professionals involved in CMMC-related activities or preparation efforts within the past 12 months. Respondents represent organizations of varying sizes, including 1-99 employees (25%), 100-499 employees (17%), 500-9,999 employees (29%) and 10,000+ employees (28%). The top industries that respondents work in are IT services (18%), aerospace (12%), consulting (11%) and the military (11%). Respondents also represent a variety of professional levels, including nonmanagerial mid- or advanced-level staff (35%), managers (28%), directors (19%), C-suite executives (12%), and independent contractors (5%).