Episode 151

CMMC Suspension Explained: What Changed and What Comes Next

Has CMMC been suspended, and do defense contractors still need to comply with NIST 800-171?

In this episode of CyberSound, Jason Pufahl and Mark Jennings explain what the DoD’s CMMC Phase 2 suspension actually means for defense contractors. They discuss why the November Level 2 third-party certification was paused, the 60-day program review behind it, what still applies under DFARS 252.204-7012, NIST SP 800-171, SPRS self-assessments, DIBCAC audits, and the False Claims Act, and why organizations should continue preparing for CMMC rather than putting compliance on hold. Whether you’re planning a C3PAO assessment or wondering if the pause changes your obligations, this episode explains what changed, what didn’t, and what comes next.

Episode Transcript

Speaker 1 00:02

This is CyberSound, your simplified and fundamentals-focused source for all things cybersecurity.

 

Jason Pufahl 00:11

Welcome to CyberSound. I’m your host, Jason Pufahl, today joined by Mark Jennings, part of the Vancord team, and one of our resident experts on CMMC, which is our topic today.
Welcome, Mark.

 

Mark Jennings 00:24

Thank you. Welcome.

 

Jason Pufahl 00:25

So this feels a little bit like here we are again, July 13th. We had basically a rollback of CMMC requirements where that looming assessment date was put on pause. And so everybody who had been planning for assessments with the C3PAOs that are out there, I guess the positives, I will say, h

Episode Details

Host
Guests
Mark Jennings
Categories
CyberSound