The Trooper Stopped for a Donut. The Speed Limit Didn't Change.

What the CMMC Phase II suspension changes, and what defense contractors still have to do.

Since the pause was announced, I've watched the relief roll through this space, and I understand it. Everybody's tired of the compliance spend, the deadlines, and the uncertainty. But that relief has started turning into something riskier, the quiet assumption that the whole thing went away.

The difference between paused and gone is why I'm writing this. The speed limit doesn't disappear because the trooper pulled off for a donut.

On July 13, the Department of War suspended the November 10 transition to CMMC Phase II and established a task force to conduct a top-to-bottom, 60-day review of the program. During the suspension, contracting activities may require Level 1 or Level 2 self-assessments, but they may not designate Level 2 C3PAO or Level 3 DIBCAC assessments. If you sit anywhere in the defense supply chain, you probably felt the room exhale.

What paused was the checkpoint. Not the rule.

What Actually Stopped, and What Didn't For most Level 2 contractors, the most significant change is that the required outside C3PAO assessment won't begin appearing in contracts this November as planned. The broader Phase II transition and Level 3 DIBCAC assessment designations are also on hold.

What remains in place:

The obligation under DFARS 252.204-7012 to protect controlled unclassified information and report cyber incidents. The requirement to implement NIST SP 800-171 Revision 2. Level 2 self-assessments and submission of the results in SPRS. The annual affirmation signed by an official who is attesting that the organization continues to comply. Select government-led assessments.

The Department has been clear that baseline compliance will continue to be enforced through self-assessments and selected government-led assessments. Level 2 self-assessments remain tied to the 110 requirements in NIST SP 800-171, with assessment results submitted in SPRS and an affirmation required annually.

The government paused one method of verifying compliance. It didn't suspend the underlying obligation to comply. The bar stayed where it was. The scheduled outside checkpoint moved.

Why Coasting Is the Expensive Read

Three things remain true.

First, cybersecurity compliance is still a contract requirement, and it still has teeth. A self-assessment score you knowingly can't support is more than a paperwork problem. Cybersecurity representations made to the government can become a False Claims Act problem, and the Department of Justice continues to resolve cases involving contractors that allegedly represented they were meeting requirements when they weren't, with recent settlements reaching into the millions of dollars. The C3PAO pause doesn't change that. A government-led assessment can still show up, and the records supporting your score still need to exist.

Second, this is a review, not a repeal. The task force was instructed to redesign the supply-chain cybersecurity approach, and what comes next may involve third-party assessments, government-led assessments, risk-based tiers, a scaled model for small businesses, or something else entirely. Nobody outside that task force knows the final answer yet. What we do know is that the Department is reviewing how compliance will be verified, not whether it still matters. Every gap you leave open now is one you may have to close later, on someone else's timeline instead of your own.

Third, the threat these controls were designed to address was never watching the compliance calendar. Whoever's after your CUI doesn't care whether your audit is scheduled. The controls aren't there for the certificate. They're there because the information has value and the risk is real.

Use the Gift for What It Is

Here's the useful way to read the pause. You were handed time, time to do the real work without an assessor's clock ticking and a hard date breathing down your neck.

As I sit here tonight, I'm 67 documents into a review nobody's making me do this week. I'm doing it because this is the window to close the kinds of gaps every honest compliance program carries, on my clock instead of an auditor's. That's what the pause is for.

Score yourself honestly, not aspirationally. Look at the controls you were quietly hoping the auditor wouldn't poke at, and go fix them. Work your POA&M like it matters, because it does. Make sure your SPRS score reflects what's implemented, operating, documented, and supported by evidence.

Do that, and you'll be ready for whatever verification model comes next, whether it's a C3PAO, DIBCAC, or something redesigned. Coast until the task force reports back, then start scrambling, and you'll pay for the quiet stretch with interest.

I've spent a long time translating this material out of regulation-speak for people who have real jobs to do and no patience for acronym soup. The line I keep coming back to is simple.

The requirement was never the certificate. It was always the security.

The trooper stopped for a donut. The limit stayed the same. Drive like it.

Previous
Previous

Turning On an AI Tool Is a Scoping Decision

Next
Next

What to Ask a Subcontractor About CMMC (and What Not To)