trade-press
DoD suspends CMMC third-party assessments indefinitely
Small-business cost pressure has stopped the verification model DoD built after deciding self-attestation was failing.
Federal News Network reports that DoD has suspended Cybersecurity Maturity Model Certification (CMMC) third-party assessment requirements indefinitely and opened a 60-day program review, with recommendations expected by late September. Primes and subcontractors face frozen certification pathways, while CMMC Third-Party Assessment Organizations (C3PAOs) lose near-term assessment revenue. DoD is reopening the verification model it built because contractor self-attestation did not work.