On July 13, the Department of War hit pause on one of the most consequential compliance regimes in the defense industrial base. In Episode 14 of The GIST of Govt IT, Brian and Sean break down the suspension of CMMC Phase II — the third-party assessment requirement that was set to take effect November 10 — and what it actually means for the thousands of contractors caught in the middle. Sean's message is blunt: this is a pause, not a repeal. The requirement to protect controlled unclassified information isn't going anywhere, and the smart move is to keep marching toward NIST SP 800-171 compliance regardless of what the 60-day CMMC Reform Task Force recommends. The conversation digs into the real economics that triggered the review, the False Claims Act lawsuits already settling in the six-to-eight-figure range for contractors who attested to compliance they didn't have, why ISO 27001 is the closest on-ramp for commercial companies new to the space, and a clear Monday-morning playbook. Plus, CISA Director Nick Andersen's hacker name (hint: he's a Matrix fan).
Resources Mentioned in This Episode
The Core Story
- Department of War release: "Forging the Arsenal of Freedom: DoW Suspends CMMC Phase II Requirements" (July 13)
- Office of Industrial Base Growth version of the announcement
- Federal News Network coverage
- The CMMC Reform Task Force RFI (responses due 12:00 PM ET, Friday, August 14) — posted on SAM.gov
Legal & Advisory Analysis
- Morgan Lewis — "Cybersecurity Obligations Remain"
- Crowell & Moring — DFARS obligations & contractor action steps
- Greenberg Traurig — the July 13 memoranda explained
Standards & Frameworks Referenced
- NIST SP 800-171 Rev. 2 (protecting Controlled Unclassified Information)
- NIST SP 800-171 Rev. 3
- CMMC Program overview (DoD CIO)
- ISO/IEC 27001 (the commercial on-ramp Sean recommends)
- DFARS 252.204-7012 (safeguarding covered defense information)
- FIPS 140 validated encryption
Compliance & Assessment Concepts
- SPRS (Supplier Performance Risk System) — where self-assessments are posted
- DIBCAC (Defense Industrial Base Cybersecurity Assessment Center)
- C3PAO (CMMC Third-Party Assessment Organizations) via the Cyber AB
The False Claims Act Angle
The Hosts & Show
