The Department of Defense's (DoD) Chief Information Officer (CIO), which has recently adopted the secondary title "Department of War (DoW)" in certain communications, recently announced a pause in the implementation of Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program while the Department conducts a 60-day review. The announcement has generated significant discussion across the government contracting community, particularly among organizations preparing for upcoming CMMC certification requirements.
While the review may affect the timing of certain certification requirements, contractors should not interpret this announcement as a reduction in cybersecurity obligations. The key message is straightforward:
The CMMC program’s phased implementation timeline has shifted, but the requirements have not.
What Happened?
Defense leadership has paused implementation of CMMC Phase 2, which would have enabled contracting officers to require a final Level 2 third-party assessment conducted by an authorized C3PAO as part of contract awards and solicitations. The Department will use this pause to evaluate the program and gather feedback from industry stakeholders.
The review has prompted questions about the future of CMMC and what it means for contractors currently working toward certification. However, the announcement does not eliminate existing cybersecurity requirements or change contractors' responsibilities for protecting sensitive government information.
What Has Not Changed?
Organizations that handle Controlled Unclassified Information (CUI) or other sensitive government data remain responsible for meeting existing cybersecurity requirements. Contractors are still expected to:
- Maintain compliance with NIST SP 800-171 requirements
- Complete required self-assessments
- Maintain Supplier Performance Risk System (SPRS) submissions
- Meet applicable Defense Federal Acquisition Regulation Supplement (DFARS) obligations
- Protect controlled information throughout the supply chain
Importantly, the underlying regulations that govern these requirements, including provisions codified in federal regulations, remain in effect. As a result, organizations should continue their compliance efforts and avoid delaying cybersecurity initiatives based on the current review.
Why This Matters
Many contractors and subcontractors are seeking clarity on whether the announcement signals a broader rollback of CMMC requirements. At this time, that is not the case. Although the certification process is being reviewed, the underlying laws, regulations and cybersecurity expectations designed to safeguard government information remain unchanged.
For defense contractors, the pause may provide additional time to strengthen security programs, address compliance gaps and improve readiness. However, organizations should continue working toward cybersecurity compliance and remain prepared for future requirements as additional guidance emerges from the Department.
Our Perspective
Cherry Bekaert's guidance is simple: use this additional time to strengthen your cybersecurity posture — not to delay compliance efforts. Organizations should remain focused on protecting sensitive information, documenting compliance activities, and preparing for future certification or assessment requirements.
Our CMMC, cybersecurity, and government contracting professionals are actively monitoring developments, engaging with industry stakeholders and evaluating the potential implications of the Department's review. We are helping contractors understand what has changed, what has not, and how to navigate the evolving compliance landscape.
How Cherry Bekaert Can Help
Whether your organization is assessing its current cybersecurity posture, preparing for future CMMC requirements, or evaluating the impact of the Department's announcement on existing contracts, our team can help.
We can assist with:
- CMMC readiness and gap assessments
- NIST SP 800-171 compliance evaluations
- DFARS cybersecurity compliance
- SPRS submission support
- Cybersecurity program development and remediation planning
- Strategic guidance on evolving defense contracting requirements
Questions about how this announcement impacts your organization? Connect with Cherry Bekaert's CMMC and Government Contracting professionals to discuss your next steps and build a plan that supports both compliance and business objectives.