Bottom line: The CMMC Phase II halt affects C3PAO assessments, but NIST SP 800-171 requirements remain in force for contractors.
What's happening: The US Department of Defense (DoD) has suspended CMMC Phase II, which included the planned third-party assessment requirement for C3PAO, impacting over 300,000 contractors and approximately $1.4 trillion in DoD spending.
What to do: Contractors must continue to implement and maintain NIST SP 800-171 controls, with the DoD providing a 60-day grace period for contractors to ensure compliance before assessing their cybersecurity posture.