trade-press
DoD CMMC pause leaves NIST SP 800-171 burden intact
The audit calendar moved; the control stack and executive signature risk did not, which is the part contractors actually pay for.
Federal News Network reports DoD paused Phase 2 third-party Cybersecurity Maturity Model Certification reviews, but defense contractors still must implement NIST SP 800-171 under DFARS 252.204-7012 and provide senior-official affirmations. Primes, subs and certified third-party assessment organizations get timeline uncertainty, not a compliance holiday. The expensive work remains the 110-plus controls, with False Claims Act and whistleblower exposure waiting for contractors that read “pause” as “stop.”