DoD CMMC pause leaves NIST SP 800-171 burden intact
The audit calendar moved; the control stack and executive signature risk did not, which is the part contractors actually pay for.
TL;DR
Federal News Network reports DoD paused Phase 2 third-party Cybersecurity Maturity Model Certification reviews, but defense contractors still must implement NIST SP 800-171 under DFARS 252.204-7012 and provide senior-official affirmations. Primes, subs and certified third-party assessment organizations get timeline uncertainty, not a compliance holiday. The expensive work remains the 110-plus controls, with False Claims Act and whistleblower exposure waiting for contractors that read “pause” as “stop.”
For practitioners, the CMMC news is narrower than the headline panic. DoD paused Phase 2 third-party Cybersecurity Maturity Model Certification activity while it reviews the program, according to Federal News Network. That affects the timing and scope of C3PAO reviews. It does not repeal the underlying DFARS 252.204-7012 obligation to protect controlled unclassified information using NIST SP 800-171 controls, and it does not make senior-official affirmations harmless paperwork.
That is the dangerous misread. Contractors heard “pause” and some apparently converted it into “wait on security spend.” Eric Crusius of Hunton Andrews Kurth told FNN he has heard anecdotal accounts of companies doing exactly that. His point is the same one compliance counsel should be making in capital letters: CMMC is the certification layer. The control requirement is the substrate. If the substrate is missing, the absence of a near-term third-party audit is not a defense; it may just mean the contractor signed its own exhibit for a later False Claims Act theory.
The risk shift is counterintuitive but real. A clean third-party assessment can operate like evidence that the contractor took the requirement seriously, even if it is not absolute protection. Self-certification puts more weight on the contractor’s own scoping, evidence, plan of action and executive affirmation. DFARS 252.204-7021 also ties CMMC status to affirmations of continuous compliance by an affirming official, as reflected in the current Acquisition.gov clause text (https://www.acquisition.gov/dfars/252.204-7021-contractor-compliance-cybersecurity-maturity-model-certification-level-requirements.).
The operational instruction is boring because the law often is: keep implementing the controls, keep evidence current, and do not let a program review become the reason a senior executive signs a statement the system cannot support. The open question is how DoD will treat noncompliance discovered during this pause, especially conduct that predates the review. The safer assumption is that a procedural pause in CMMC does not pause contract clauses, whistleblowers or DOJ’s appetite for cyber-fraud cases.
Published ·Deep Fathom