CMMC Phase 2 Suspension: Industry Reactions
The Department of War has suspended CMMC Phase 2's mandatory third-party assessment requirement, citing concerns that the assessor ecosystem couldn't scale to meet demand and that compliance costs were pushing small and mid-sized firms out of the defense industrial base.
A newly formed CMMC Reform Task Force will spend 60 days reviewing the program, gathering industry feedback, and reporting recommendations by mid-September. Crucially, the pause only affects independent verification, with Phase 1 self-assessment obligations, SPRS score submissions, and the underlying DFARS 252.204-7012 requirement to protect controlled unclassified information (CUI) remaining fully in effect.
Industry Professionals' Reactions
Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI, warning that self-attestation without verification raises False Claims Act exposure.
Phase 1 is still in place. If you handle CUI, you're still self-assessing against all 110 NIST 800-171 requirements and posting that score to SPRS. DFARS 252.204-7012 is still in your contracts. And if you report a perfect 110, the government audits you down the road, and it turns out you never did the due diligence, that's False Claims Act exposure. - Abdie Mohamed, GRC Engineering Lead, NR Labs
Experts are split on whether the fix should be to scope assessments down, automate them, or preserve them largely as-is. Chris Nyhuis, CEO of Vigilant, believes that suspending CMMC Phase II is the right call, and it's overdue.
This may not be popular, however, suspending CMMC Phase II is the right call, and it's overdue. Speed done securely is a security requirement now, not a nice-to-have. Our adversaries move in days. When it takes a small defense supplier a year and six figures to clear a third-party audit before it can even bid, we're not protecting the mission, we're slowing it down. - Chris Nyhuis, CEO, Vigilant
Fixing the Problem
Ned Butler, Manager of CMMC Services and Lead Assessor at Redspin, argues that the right fix isn't to weaken third-party assessment, but to shrink its scope dramatically.
Robert Teague, VP of CMMC Services and Lead CCA at Redspin, suggests that small and mid-sized contractors are already succeeding, and the narrative that CMMC is unattainable for small businesses is not reflected in their assessment experience.
Building Organizational Resilience
Chetrice Romero, Senior Cybersecurity Advisor at Ice Miller, advises organizations to recognize that CMMC is not simply another compliance exercise, but about building organizational resilience.
As the Department of War continues implementing the Cybersecurity Maturity Model Certification (CMMC), much of the conversation has centered on assessment requirements, technical controls, and certification timelines. Those are certainly important. But the organizations that will be most successful are the ones that recognize CMMC is not simply another compliance exercise. At its core, CMMC is about building organizational resilience. - Chetrice Romero, Senior Cybersecurity Advisor, Ice Miller
Emil Sayegh, CEO of CyberSheath, emphasizes that the Pentagon didn't repeal a law with a press conference, and while third-party CMMC assessments are paused during the 60-day review, the underlying cybersecurity obligations have not changed.
Source: SecurityWeek