DoD freezes third-party CMMC assessments for 60-day review
A program built to prove contractor discipline just admitted its own cost model may be undisciplined.
TL;DR
DoD suspended all Cybersecurity Maturity Model Certification third-party assessment requirements while it runs a 60-day review, Federal News Network reports. The review includes a request for information and listening sessions aimed at small business cost concerns. Contractors, subcontractors, C3PAOs and assessors now have stalled certification timelines, plus the more useful problem: DoD has finally stopped treating implementation pain as a communications issue.
DoD is pausing all third-party Cybersecurity Maturity Model Certification assessment requirements while it conducts a 60-day review of the program, according to Federal News Network. The review includes listening sessions across the country and a request for information, with DoD Chief Information Officer Kirsten Davies framing the move around cost and compliance burdens on small businesses.
That is not a minor scheduling adjustment. For contractors and subcontractors working toward CMMC certification, the assessment clock just stopped. For C3PAOs and assessors, the near-term pipeline just became provisional. For primes trying to keep qualified small suppliers inside their defense industrial base, the compliance conversation is now less about booking an assessment slot and more about guessing what DoD will still require when the review ends.
The notable part is not that DoD heard complaints about CMMC costs. Those complaints have been the background noise of the program for years. The notable part is that DoD suspended the third-party requirement rather than adding another clarification memo, webinar, or incremental adjustment. That signals the department is willing, at least for 60 days, to treat the structure of CMMC as reviewable rather than merely explainable.
The open question is what comes back. Federal News Network reports that officials have left room for outcomes ranging from small changes to a broader overhaul. Contractors should not read the pause as permission to stop implementing NIST SP 800-171 controls. They should read it as a warning that the certification path, assessment economics and timing for re-engaging third-party assessments are all now live questions.
Published ·Deep Fathom