CMMC Audits Paused, but DoD Still Needs Cyber Assurance

The Department of Defense paused Phase II of the Cybersecurity Maturity Model Certification (CMMC) program, requiring third-party cybersecurity assessments for contractors, but industry experts believe some form of review will return. The DoD will continue to enforce baseline cybersecurity through self-assessments, focusing on practical cyber hygiene.
However, leaders acknowledge the weakness of relying on self-reporting, a problem identified seven years ago by the DoD Inspector General. Industry figures point out that while the pause may not lower cybersecurity expectations, it creates uncertainty in verifying contractor compliance.
Without independent validation, the Pentagon risks increased reliance on potentially unsubstantiated claims and heightened False Claims Act risk. The debate centers on finding a balance between rigorous certification and manageable requirements, particularly for smaller contractors. The DoD has 60 days to develop a framework that addresses security objectives while reducing complexity, potentially shifting towards a risk-based model with stronger assessment for high-risk work.
Surfaced by the Solutions lens — one of the vital signs ovr.news reads.
How we evaluated this
AI summary
read the original for the full story — Read on breakingdefense.com . How we work →