You may have seen recent news that the Department of Defense has suspended the planned rollout of CMMC Phase II requirements and launched a 60-day review of the program.
While this is a significant development, many articles and social media posts are talking about it I wanted to make sure our clients had good information.
The cybersecurity requirements themselves have not been suspended.
What has primarily been suspended is the planned expansion of mandatory third-party C3PAO assessments.
Reference: https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf
What Changed
The DoD has directed acquisition personnel to suspend the transition to CMMC Phase II and pause future CMMC implementation milestones while a comprehensive review is conducted.
During this period, contracting activities are only authorized to require CMMC L1 and L2 Self Assessments.
Contracting activities may not designate CMMC Level 2 (C3PAO) or CMMC Level 3 (DIBCAC) assessments during the suspension period.
What Did Not Change
DFARS 252.204-7012 remains in effect.
Contractors and subcontractors are still contractually obligated to protect Covered Defense Information (CDI) and Controlled Unclassified Information (CUI), implement required security controls, and report cyber incidents as required by contract.
NIST SP 800-171 Rev. 2 remains the current standard for protecting CUI, and the recent CMMC announcement does not change that. The DoD has stated it will continue enforcing cybersecurity requirements through self-assessments and select government-led assessments.
We are actively preparing for NIST SP 800-171 Rev. 3. Although contractors are not currently being assessed against Rev. 3, we believe organizations that begin aligning their security programs now will be better positioned for future regulatory and contractual changes.
Understanding the Current Holding Pattern
For companies handling only Federal Contract Information (FCI):
- FAR 52.204-21 remains the governing safeguard requirement.
- CMMC Level 1 Self-Assessments remain applicable.
For companies handling Controlled Unclassified Information (CUI):
- DFARS 252.204-7012 remains the primary cybersecurity requirement.
- NIST SP 800-171 remains the security standard.
- Level 2 Self-Assessments remain the currently authorized assessment mechanism.
- For organizations previously preparing for C3PAO certification:
- The requirement to secure CUI has not changed.
- The immediate requirement to obtain third-party certification has been suspended pending further DoD guidance.
How the Clauses Fit Together
I know most of you already know this but just wanted to lay it out again:
- Security Requirements: If your organization handles CUI, DFARS 252.204-7012 (RFO Change: No substantive change) requires you to protect that information. To meet that requirement, organizations typically implement the security controls found in NIST SP 800-171.
- Assessment Requirements: DFARS 252.204-7019 (RFO Change: Removed) and DFARS 252.204-7020 (RFO Change: Renumbered to DFARS 252.240-7997) establish how the government can assess and validate your implementation of NIST SP 800-171. This includes SPRS scoring and government assessment authority.
- Contract Award Requirements: DFARS 252.204-7025 (RFO Change: No substantive change) identifies the required CMMC level within a solicitation, while DFARS 252.204-7021 (RFO Change: No substantive change) establishes the CMMC status required at the time of contract award.
What We Recommend
Organizations should not stop their cybersecurity efforts.
If your organization handles CUI, you should continue to:
- Maintain and update your System Security Plan (SSP)
- Maintain and manage your POA&M
- Continue implementing NIST SP 800-171 controls
- Maintain required SPRS submissions where applicable
- Ensure incident reporting processes remain operational
- Continue improving your overall security posture
- Conduct a Self-Assessment (We do that for you as part of Compliance Assistance Service)
We expect additional guidance following the completion of the DoD’s 60-day review and will continue monitoring developments closely.

