WASHINGTON — Despite the pause of third-party audits in a Defense Department program for contractors, the Pentagon will likely have to return to some kind of review regime to ensure there are no unlocked virtual doors for adversary hackers to walk through, according to industry officials and experts.

Leaders in the Department of Defense and Small Business Administration announced Monday that they are taking a pause on Phase II of the Cybersecurity Maturity Model Certification (CMMC) program, which requires companies working with the DoD to undergo third-party assessments to ensure they’re compliant with cybersecurity standards.

CMMC does not set the standards; those come from NIST SP 800-171 Rev 2, which outlines 110 cybersecurity requirements to protect controlled unclassified information (CUI). CMMC, rather, is focused on ensuring any contractor bidding for a certain capability complies with said standards.

Through the pause, the Pentagon said it will continue to enforce baseline cybersecurity compliance through self-assessments, which the department says will focus on tangible cyber hygiene as opposed to administrative overhead.

The CMMC Phase II pause “shouldn’t be a shocker to anybody,” according to Katie Arrington, thought of as the creator of CMMC. But, she said in a video posted to LinkedIn, at the end of the day the Pentagon is likely to come back around to where it is now, realizing “that there really is no other way to get compliance.”