cmmctrade-pressNewsThe Broadside1 min read

Contractors continue CMMC assessments through DoD pause

A paused mandate still leaves contractors choosing between preserving sunk C3PAO spend and betting against whatever regime follows.


TL;DR

Federal News Network reports that Professional Services Council President Stephanie Kostro says PSC members already midway through Cybersecurity Maturity Model Certification (CMMC) assessments are staying with Certified Third Party Assessment Organizations (C3PAOs) despite DoD’s suspension. PSC has 400 member companies, about 40% with Defense Department work. The lesson is operational: companies have sunk assessment costs, protected government information to secure and no evidence that contractor cybersecurity requirements are disappearing.

Federal News Network’s interview with Stephanie Kostro, president of the Professional Services Council, is useful because it separates the CMMC press-cycle drama from the contractor decision. DoD has paused CMMC third-party assessment requirements while it reviews the program. Kostro said PSC companies already in the Certified Third Party Assessment Organization process are, in her conversations, continuing. Her sample does not cover the whole market, but it is a clean signal from companies with money already committed and Defense Department work to protect.

The broader PSC point was that contractors are making business decisions while cybersecurity regulations, AI clauses and acquisition policies are still taking shape. CMMC is the cleanest example because the spend is already in motion. The logic is straightforward: companies have already spent money, they expect some contractor cybersecurity regime to survive, and the protected-information problem did not pause with the rulemaking. Kostro said members told her they want to finish assessments they have already funded.

The awkward middle is DoD’s 60-day review and the Aug. 14 request-for-information deadline. Terry Gerton framed the immediate issue correctly: the Pentagon has not said companies need less cybersecurity; it is reviewing whether self-attestation remains enough or third-party validation should be required. For practitioners, the sane answer is narrow: keep closing control gaps, preserve assessment evidence and treat C3PAO spending as a contract-risk decision tied to actual Defense Department work.


Published ·Deep Fathom