Since the DoW announcement, my phone and inbox have been filled with the same question, asked in two ways. Defense contractors want to know, “Is CMMC dead? Can we stop?” Our MSP and channel partners are asking, “My clients have questions. What do I tell them?”
The honest answer to both is no, and we need to collectively take a breath and learn together what the most important next steps are.
On July 13, the Department of War paused the third-party assessment requirement for CMMC Level 2. That was the step set to start appearing in contracts on November 10. The Department also opened a 60-day review led by a new CMMC Reform Task Force. This is a real change to how compliance gets verified. It is not the end of the requirement to protect federal information, and it is not a permission slip to stand down.
What changed is narrow. What stayed the same is nearly everything.
These are all still in force today, exactly as they were on July 12. NIST SP 800-171 Rev 2. Your DFARS 252.204-7012 duty to safeguard covered defense information. Your Level 1 and Level 2 self-assessments, where Level 2 still requires a minimum SPRS score of 88 out of 110. The annual affirmation that a senior executive at your company signs into SPRS. And the government's authority to assess you directly. The Department was blunt about its own intent. As Under Secretary Michael Duffey put it, “We're not relaxing the standards by any means.” The cleanest way I've heard it said is this: the government is reviewing the mandatory verifier, not the obligation.
One piece deserves its own spotlight: the signature. A named company senior official still affirms compliance in SPRS every year, and that affirmation is a continuing legal representation to the federal government. So it is worth asking what your Affirming Official actually reviews before signing: a spreadsheet from IT and a verbal assurance, or real evidence mapped to each requirement. That question matters the same today, not less, because the enforcement behind a false or inflated self-assessment has not paused.
To the Defense Industrial Base, keep going. If you are mid-readiness, the work you have done retains its full value regardless of the outcome of this review. And here is a point that gets lost in the “dollar figure to comply” headlines. The majority of the expense is for implementing NIST 800-171: people, processes, and a hardened environment. The third-party audit is the smaller, recurring piece on top of it. Pausing your program saves very little, and it compresses the same work into a tighter runway later. Your primes, by the way, are not waiting for Washington. They are still setting their own subcontractor requirements.
To MSPs and our channel partners, you do not have to be the CMMC expert to be the calm, credible voice your clients need. You need to keep the relationship and the trust you have built. We have built a plain-English client briefing you can send under your own logo, and our team is glad to help you put it to work. You can find it by clicking this button.
On the mission, this is bigger than a compliance calendar. Protecting Controlled Unclassified Information across the Defense Industrial Base is how we protect the people who depend on it downstream. That responsibility did not pause on July 13, and neither did the adversaries it exists to stop.
Where CyberNINES and ControlCase stand: we moved fast, with daily coordination, and steady, factual client guidance. My colleague Scott Singer, CAPT USN (Ret), President of ControlCase Federal, Chair of the Cyber AB's C3PAO Advisory Council, founder of CyberNINES, A ControlCase Company, and a retired U.S. Navy Captain, is out in the industry helping contractors and partners read this accurately and helping shape what comes next. Scott recently joined Andrew Morgan's Right of Boom “CyberCall,” alongside Jacob Horne, Ryan B., Andy Sauer, and Scott Edwards for a special edition on exactly this topic. It is a sharp, no-spin panel for MSPs and their DIB clients, and I have linked the post and the full recording below.
Our recommendation is simple, and it is the same one we are giving our own clients. Continue protecting your information. Continue strengthening your cybersecurity. Continue preparing. The headlines changed. The mission did not.
If you want to talk, our team is at the ready with time to give and expert guidance available.
5 Downloads, keep reading and watch (links)
• DoW CIO “Brilliant at the Basics” resources: https://dowcio.war.gov/BrilliantBasics
• CyberNINES, A ControlCase Company's public statement: https://www.controlcase.com/cmmc-p2-pause
• Our deeper, fully sourced analysis of the review: https://www.linkedin.com/pulse/dow-cmmc-phase-ii-60-day-pause-cybernines-atdif/?trackingId=H0iNtHNssRzpj2UblA3cfA%3D%3D
• Right of Boom “CyberCall” LinkedIn post on the pause (Scott Singer and panel): https://www.linkedin.com/feed/update/urn:li:activity:7482792835436597248/
Watch the full CyberCall recording: https://www.youtube.com/live/BkuSqPH0FWs