Overview
Steptoe's lead of the Cybersecurity & Incident Response practice Michael Gruden was quoted in SecurityWeek discussing how the Department of War has paused CMMC Phase 2's third‑party assessment requirement due to scalability and cost concerns, and is launching a 60‑day review while leaving underlying NIST 800‑171 controls, self‑assessments, and legal obligations unchanged. The article highlights feedback from various industry professionals, emphasizing that although the audits are halted, companies remain fully responsible for protecting Controlled Unclassified Information and face continued False Claims Act risk if they rely on unverified self‑attestation.
Michael shared that "The suspension highlights an ongoing tension between cybersecurity expectations and the financial and operational burdens many contractors face in implementing required controls. While those challenges are real, the fundamental objective of CMMC—to improve protection of CUI and other sensitive defense information throughout the supply chain—remains as important as ever. There is a balance to be struck between reducing compliance burdens and ensuring that government regulated data is adequately protected in support of national security and mission objectives."
Read more at SecurityWeek.