The Department of War recently announced a pause in the implementation of CMMC Phase 2 certification audits, creating questions and uncertainty across the Defense Industrial Base. While the third-party certification process is being delayed, one thing remains clear: the underlying cybersecurity and compliance requirements have not changed.
For defense contractors handling Controlled Unclassified Information (CUI), this announcement should not be interpreted as a reduction in compliance obligations. Requirements including DFARS 252.204-7012, NIST SP 800-171, SPRS score reporting, annual affirmations, and cyber incident reporting remain fully in effect.


