Search
Recent Posts
Blog Categories
CMMC Phase 2 Is Paused. Your Obligations Are Not.
On July 13, the Department of War suspended CMMC Phase 2. The third-party audits that were set to become requirements in November are on hold while a new CMMC Reform Task Force reviews the program, with recommendations due back in 60 days.
Plenty of contractors read that news as breathing room. We read it as a warning.
The signature just got heavier
Nothing about the pause touches the annual affirmation. A senior official at your company still signs it every year, attesting that you meet all 110 requirements of NIST SP 800-171. What changed is that no third-party auditor stands behind that signature anymore. Your own self-assessment is the only thing under it.
The Department has said plainly that it is not relaxing standards. And the False Claims Act enforcement that produced multiple DOJ settlements over inaccurate self-attestations is exactly where it was in June. The pause removed the deadline. It did not remove the exposure.
Everything else is still in force
NIST SP 800-171 remains the standard for protecting Controlled Unclassified Information. DFARS 252.204-7012 remains in every applicable contract you hold. Level 1 and Level 2 self-assessments are still required, along with a current SPRS score. And primes can still make compliance a condition of award, whatever the Department does with its own timeline.
Don’t coast through the review
The task force is reviewing how compliance gets verified. The standard it verifies against comes from DFARS and NIST 800-171, and nothing in the review suspends it. Whatever model emerges in September will sit on top of the same 110 requirements, and a company that lets its posture slide carries legal exposure the whole time it waits to find out.
If you already have a C3PAO audit scheduled, it’s a good idea to keep it. A completed audit is independently verifiable proof of your posture at a moment when most of the Defense Industrial Base is self-attesting, and that carries weight with contracting officers and teaming partners alike.
Put your two cents in by August 14
Alongside the suspension, the Department issued a Request for Information asking contractors what CMMC actually costs, where the administrative burden sits, and which controls deliver real security instead of paperwork. The task force will build its recommendations partly from those responses. If the
current model has been pricing you out or burying your team in documentation, this is your chance to say so on the record and help the process. Responses are due August 14.
Keep two things current
The affirmation your leadership signs covers the whole year, so two things need to hold up year-round. The first is security operations, the monitoring, detection, and response that satisfy Level 2 requirements on an ordinary Tuesday, not just in the weeks before an assessment. The second is documentation. Your System Security Plan, your POA&M, and the evidence behind them are what give the person signing something defensible to stand on.
Where Guard Street fits
Guard Street has helped the Defense Industrial Base meet Department of War cyber requirements since 2020. We have watched frameworks pause, restart, and change shape, and our mission does not move: protect the systems.
For a clear read on where your posture stands before the task force reports, reach out at https//guardstreet.com/connect





