Key Takeaways:
- Phase II relief is limited. Contractors may no longer face an immediate Level 2 certification requirement, but their existing cybersecurity obligations remain in force.
- Self-assessments now matter even more. Contractors handling CUI must continue implementing NIST SP 800-171 controls, maintaining accurate documentation, submitting supportable assessments and making defensible compliance affirmations.
- Enforcement risk is shifting, not disappearing. With DoD relying more heavily on contractor self-representations, inaccurate compliance statements may create post-award False Claims Act and cyber-fraud enforcement exposure.
The Department of Defense (DoD) has announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program and has launched a comprehensive review of the certification framework. Importantly, this is not a suspension of the requirements for protecting Controlled Unclassified Information (CUI) under DFARS 252.204-7012.
Under the announcement, DoD will continue to enforce Phase I requirements, including self-assessments and annual affirmations of compliance, while evaluating whether and how the broader CMMC program should continue. For defense contractors, the suspension alleviates the near-term burden of obtaining third-party CMMC certifications but leaves in place the existing obligation to self-assess and report compliance. False statements in these reports will continue to expose contractors to...
Read Full Story:
https://news.google.com/rss/articles/CBMihAFBVV95cUxNVmwyR0FQRHJldnhPTnBpZXNP...