Search
Close this search box.

For Cybersecurity Certification, a Pause is Not a Pass

Until July, contractors across the U.S. defense industry had circled Nov. 10 as a watershed date marking the planned start of Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) rollout.

CMMC is a Department of Defense (DoD) initiative intended to validate that contractors have implemented the security requirements in the National Institute of Standards and Technology’s (NIST) Special Publication 800-171 Rev. 2.

For Contractors who store, process and/or transmit controlled unclassified information, implementation is not optional. Defense Federal Acquisition Rules (DFARS) 252.204-7012 makes it a contractual obligation since Dec. 31, 2017. NIST SP 800-171 Rev. 2 is the set of 110 security requirements that are required, and CMMC is the mechanism used to verify that contractors have actually met them.

Phase 2 of the CMMC program rollout would have added a layer of independent third-party verification on top of the contractor’s own self-assessment. The DoD paused Phase 2 on July 13 and initiated a 60-day review of the CMMC program. For contractors racing toward a completed assessment by the original enforcement date, the obvious question becomes: does that mean we can stop?

The government’s implementation timeline may be under review, but the underlying cybersecurity obligations, contractual requirements and business pressures facing the defense industry have not disappeared.

CMMC is the DoD’s verification layer, not the source of the underlying obligation. Regulatory shifts do not make security gaps disappear. It simply gives organizations additional time to address them deliberately before being contractually obligated to verify them.

Contractors are still on the hook

Contractors have been required to implement the NIST SP 800-171 controls under DFARS 252.204-7012 since 2015, more than three years before CMMC 1.0 was announced in 2019. DFARS is the set of rules used by the DoD when purchasing goods and services and covers a variety of topics. CMMC came along afterwards as a way to check whether contractors were actually meeting a standard that had already been mandatory for years, and after the Defense Contract Management Agency identified gaps in contractor implementation.

The Phase 1 self-assessment requirements remain in place, and the department said it will continue enforcing NIST SP 800-171 Rev. 2 implementation through self-assessments and select government-led assessments during the pause. Additionally, the Department of Justice will pursue any organization identified as having submitted false claims pursuant to the False Claims Act.

Contractors subject to DFARS 252.204-7012 also remain responsible for providing adequate security for covered defense information, independent of anything happening on the CMMC calendar.

Cybersecurity expectations are still real

Even before the pause, many in the defense industry misunderstood Nov. 10 as a universal deadline. A contractor’s actual timeline has always depended on the contracts it holds or wants to pursue, the information it handles and the requirements of its customers.

For subcontractors in particular, that means the pressure may be coming from prime contractors.

Primes can establish cybersecurity expectations for their supply chains on timelines that do not necessarily mirror the government’s phased implementation schedule. In April, for example, L3 Harris sent a memo to its supplier base requesting Level 2 certification months before Phase 2 was originally scheduled to begin.

Those requirements can have real business consequences. A subcontractor that cannot meet a Prime’s timeline may find itself excluded from teaming arrangements, less competitive for future opportunities or at risk of losing existing work. The Phase 2 pause does not automatically erase those expectations. If your Prime’s CMMC Certification clock is still running, that is the clock that matters most to your business.

Contractors should look beyond the CMMC phase calendar and understand the requirements in their existing contracts, upcoming solicitations, option years and period-of-performance extensions, as well as the expectations being communicated by their primes and customers.

What companies should be doing right now

For contractors that slowed or stopped their CMMC efforts after July 13, they should start with the requirements that exist today.

They should review contracts and applicable DFARS clauses. And they should understand whether they handle controlled unclassified information or federal contract information, where that information lives and who has access to it.

They should validate the implementation of NIST SP 800-171 and ensure that the Supplier Performance Risk System score – the DoD database where contractors submit and store their self-assessment and independent assessment score – is accurate.

They should confirm that evidence would hold up against the NIST SP 800-171A objectives, the companion document that identifies how to properly assess the NIST SP 800-171 Rev. 2 requirements (and has to be followed for even self-assessments). They should talk to prime contractors and customers about what they expect from their suppliers during the pause.

Accurately defining the systems, people and processes that touch controlled unclassified information is both a security requirement and a cost-control measure. A well-scoped environment can reduce the complexity and expense of protecting sensitive information regardless of what ultimately changes within CMMC.

CMMC represents something more fundamental than compliance. Our adversaries have learned that the fastest path to sensitive defense information often runs not through prime contractors, but through less defended members of their supply chains. Every organization that fails to meet its cybersecurity obligations creates a vulnerability that can extend to the prime, the department and ultimately national security.

Phase 2 was never a deadline; it is a milestone. The target has never been a date on the calendar. The target has always been protecting data and American ingenuity.

 

Share This Article

Facebook
Twitter
LinkedIn
Email

Also in Defense Opinion