CMMC Phase II halt puts C3PAO assessments on hold, but leaves NIST SP 800-171 obligations in force for contractors

CMMC Phase II halt puts C3PAO assessments on hold, but leaves NIST SP 800-171 obligations in force for contractors

The US Department of Defense (DoD) has suspended CMMC Phase II, which included the planned third-party assessment requirement for C3PAO.

Bottom line: The CMMC Phase II halt affects C3PAO assessments, but NIST SP 800-171 requirements remain in force for contractors.

What's happening: The US Department of Defense (DoD) has suspended CMMC Phase II, which included the planned third-party assessment requirement for C3PAO, impacting over 300,000 contractors and approximately $1.4 trillion in DoD spending.

What to do: Contractors must continue to implement and maintain NIST SP 800-171 controls, with the DoD providing a 60-day grace period for contractors to ensure compliance before assessing their cybersecurity posture.

Source: Industrial Cyber