DoD Suspends CMMC Phase 2 Requirements – Launches 60 Day Reform Review

Requirement | IT-X Managed Services

DoD Suspends CMMC Phase 2 Requirements – Launches 60 Day Reform Review

DoD Suspends CMMC Phase 2 Requirements – Launches 60 Day Reform Review 1376 768 GladiusIT

We wanted to make you aware of an important announcement from the Department of Defense regarding the Cybersecurity Maturity Model Certification (CMMC) program.

The DoD has announced an immediate suspension of the planned Phase II rollout requiring mandatory third-party CMMC (C3PAO) assessments while it conducts a review of the program.

While this is a significant development, it is important to understand what has and has not changed.

What has changed:

  • The planned rollout of mandatory third-party CMMC assessments has been paused.
  • The DoD will be reviewing the current program before determining the next steps.

What has NOT changed:

  • The requirement to protect Controlled Unclassified Information (CUI).
  • Compliance with NIST SP 800-171 for organizations handling CUI.
  • Existing DFARS cybersecurity obligations included in applicable contracts.
  • The need to implement required security controls, maintain documentation, and continuously improve your cybersecurity posture.

It is also worth noting that this is not the first time the Department of Defense has adjusted or delayed implementation of the CMMC program. Previous versions of CMMC experienced delays and revisions before moving forward. While the assessment requirements and timelines may evolve, the underlying expectation that defense contractors adequately protect CUI has remained consistent throughout the program’s evolution.

Organizations that continued implementing NIST SP 800-171 during previous delays were ultimately in a much stronger position when new guidance was released. We believe that remains the best approach today.

For customers currently working with GladiusIT on:

  • NIST SP 800-171 implementation
  • System Security Plans (SSPs)
  • Plans of Action & Milestones (POA&Ms)
  • Policy development
  • Security awareness training
  • Technical remediation

Our recommendation is to continue moving forward as planned. Compliance with NIST SP 800-171 remains a contractual obligation for organizations handling CUI and serves as the foundation for CMMC. Continuing your implementation efforts will not only prepare your organization for future CMMC requirements but will also improve your overall cybersecurity posture and help ensure you meet your current contractual responsibilities.

As the DoD releases additional guidance, we will continue monitoring the situation closely and provide updates along with recommendations on any changes that may affect your compliance roadmap.

If you have questions about how this announcement impacts your organization or your current compliance efforts, please don’t hesitate to reach out to your GladiusIT team. We’re here to help you navigate these changes and ensure you remain prepared for whatever comes next.