What's Happening?
The Department of Defense has suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC), which required third-party assessments for defense contractors. Despite this suspension, contractors must still adhere to existing cybersecurity
requirements under DFARS 252.204-7012. The suspension is part of a 60-day review aimed at reforming the CMMC process. The government continues to emphasize the importance of cybersecurity, with new regulations under the FAR CUI framework mandating compliance with NIST SP 800-171 for systems handling controlled unclassified information.
Why It's Important?
The suspension of CMMC Phase II highlights the government's shift towards more flexible cybersecurity measures while maintaining stringent data protection standards. This move affects defense contractors who must continue to uphold cybersecurity practices despite the pause in third-party assessments. The ongoing emphasis on cybersecurity underscores its critical role in protecting American innovation and maintaining national security. Contractors must remain vigilant and prepared for potential changes in compliance requirements, as the government seeks to balance security with operational efficiency.
What's Next?
Defense contractors should monitor developments during the 60-day review period and prepare for potential changes in CMMC requirements. While the immediate pressure of third-party assessments is reduced, contractors must continue to prioritize cybersecurity to meet existing obligations. The government may introduce new guidelines that focus on scalable and resilient cybersecurity measures, emphasizing the need for contractors to maintain robust security postures. Contractors are advised to participate in webinars and stay informed about updates to ensure compliance and readiness for future requirements.













