The Department of Defense has suspended Cybersecurity Maturity Model Certification Phase II requirements that were scheduled to take effect Nov. 10 while a reform task force reviews the program.
CMMC Phase I remains in effect, including self-assessment requirements. The Department also said it will continue enforcing National Institute of Standards and Technology Special Publication 800-171 Revision 2 through contractor self-assessments and selected government-led assessments.
For defense contractors, the suspension changes the timing of certain third-party assessments but does not eliminate the need to maintain CMMC readiness, according to Bill Osborne, vice president of Defense Sector Services at Magna5.
“Some contractors may hear ‘pause’ and think they can postpone the program and their obligations,” Osborne said. “The Department has given the Defense Industrial Base more time to prepare, not permission to stop protecting the information their contracts require them to safeguard.”
CMMC Assessment Requirements Remain
Level 1 self-assessments continue to cover 15 safeguarding requirements from Federal Acquisition Regulation clause 52.204-21 and are conducted annually.
Level 2 self-assessments continue to measure implementation of the 110 security requirements in NIST SP 800-171 Rev. 2. These assessments are conducted every three years with annual affirmation and results entered into the Supplier Performance Risk System (SPRS).
For contracts covered by Defense Federal Acquisition Regulation Supplement clause 252.204-7012, contracting officers must verify that a current NIST SP 800-171 DoD Assessment score is available in SPRS before certain awards, contract extensions or option exercises.
“The assessment schedule changed. The underlying requirement to safeguard Controlled Unclassified Information (CUI) did not,” Osborne said. “Level 2 still measures the contractor against all 110 requirements, even if a third-party assessment is no longer arriving on the original timeline.”
Contractors Can Use Pause to Address Readiness Gaps
The suspension may affect when contractors engage a CMMC Third-Party Assessment Organization (C3PAO). Companies that are not already scheduled and fully prepared for an assessment may choose to wait while the Department reviews the program, Osborne said.
During the interim period, contractors can verify current SPRS scores and supporting evidence, confirm that System Security Plans reflect their current environments, resolve CUI boundary questions and review subcontractor requirements and flow-down obligations.
Contractors can also identify work that can continue while the Phase II timeline remains under review.
“This may be a reason to delay the assessment, not the readiness work,” Osborne said. “If the documentation, score or scope is wrong today, contractors should use this window to fix it before those gaps show up in a contract requirement or assessment.”
The press release also notes that organizations should continue maintaining evidence, assigning responsibility, addressing gaps and budgeting for future assessment needs because contract and data-protection responsibilities remain.
Contractors are also expected to monitor how NIST SP 800-171 Rev. 3 enters future federal contracting requirements. The DoD continues to use Rev. 2 for current CMMC obligations while an upcoming FAR clause could require Rev. 3 for other federal contracts.
“The Defense Industrial Base has already seen multiple pauses and updates,” Osborne said. “When the program moves again, contractors should expect it to move quickly. The companies that keep their scope, evidence, and reporting current will be ready; the ones that wait for another deadline will always be rebuilding under pressure.”
