logo

CMMC’s Third-Party Assessments Are Paused. The Standard of Care Isn’t

ID: 0e36f28d-ca23-59cf-8c67-c0ad4e9d7b60

STIX ID: report--0e36f28d-ca23-59cf-8c67-c0ad4e9d7b60

Feed Name: Security Boulevard

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Denis Calderone

...
...

The article explains the Department of War's July 13 suspension of CMMC Phase 2 third‑party assessments, emphasizing that while the certification requirement is paused the underlying DFARS/NIST 800‑171 security obligations remain intact; contractors must continue to self‑assess, maintain SPRS scores, and manage risk. The author discusses capacity and cost issues that drove the pause, warns that primes and DOJ enforcement still preserve strong incentives to be accurate in attestations, and urges organizations to focus on tangible cyber hygiene and preparedness rather than treating the pause as a repeal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.