DoD pauses CMMC Phase II, security obligations for contractors remain
The U.S. Department of Defense has suspended the certification requirement for Phase II of the Cybersecurity Maturity Model Certification (CMMC). The pause applies only to the C3PAO certification checkpoint; all underlying federal security obligations stay in force. Contractors in the Defense Industrial Base must continue to meet the NIST SP 800‑171 controls, honor DFARS clauses, submit accurate SPRS scores, make annual affirmations, and protect Controlled Unclassified Information (CUI).
Managed service providers (MSPs) serving these contractors face the same duties: maintaining remediation work, validating SPRS submissions, and preserving defensible audit evidence. While the certification timeline is delayed, the security risk does not diminish, and postponing compliance improvements could increase contractual and operational exposure.
Analysts note that the regulatory ambiguity is prompting interest in AI‑driven compliance tools, but the core compliance burden remains unchanged for organizations handling defense contracts.
Entities: Cybersecurity Maturity Model Certification (CMMC) · Defense Federal Acquisition Regulation Supplement (DFARS) · Defense Industrial Base · National Institute of Standards and Technology (NIST) SP 800‑171 · U.S. Department of Defense