CMMC Phase II pause leaves audits likely to return
Schedule relief is real, but the verification problem that created CMMC is still sitting on DoD’s desk.
TL;DR
Breaking Defense reports that Katie Arrington and other industry voices expect DoD’s CMMC Phase II pause to be temporary, with cybersecurity audits likely to return. Defense contractors preparing for assessments get schedule relief, but no exit from compliance. The hard part remains verification: DoD still needs a way to know whether suppliers actually meet the requirements.
Breaking Defense’s follow-up on the CMMC Phase II pause is useful because it strips away the performative surprise. Katie Arrington, widely associated with the creation of Cybersecurity Maturity Model Certification, told the outlet the pause “shouldn’t be a shocker to anybody,” and argued the Pentagon is likely to come back to audits because “there really is no other way to get compliance.” That is the important distinction for contractors: the mandate calendar may move, while the verification problem stays put.
DoD’s own acquisition text points in the same direction. DFARS Subpart 204.75 describes CMMC as a framework under 32 CFR part 170 for assessing a contractor’s information security protections, and applies it to unclassified contractor information systems (https://www.acquisition.gov/dfars/subpart-204.75-cybersecurity-maturity-model-certification). If the department wants the CMMC requirement to carry weight beyond the contract file, someone eventually has to test the environment.
The harder implementation problem also survives the pause. GAO said in March that DoD relies on 200,000 private companies and had not systematically documented external factors that could affect CMMC implementation, including whether the private sector would have enough certified assessors (https://www.gao.gov/products/gao-26-107955). If audits come back, that capacity problem comes back with them. If they do not, DoD still has to explain what replaces them.
For practitioners, the Monday answer is dull and expensive: keep treating CMMC preparation as live. Use the pause to clean up system boundaries, evidence, and remediation plans. The worst reading is that cybersecurity work can wait for the next DoD announcement. That is how a reprieve becomes an assessment failure with better calendar management.
Published ·Deep Fathom