
With all the confusion around DoW's July 13th announcement that Phase II of the CMMC Program was suspended for 60 days while the Program is under review, its time to set the record straight and present the facts of where we are right now and what our current requirements are.
Here is a step by step break down of “the facts:”
- All CMMC program elements remain operational and available, to include C3PAO Level 2 certification assessments, CAICO-sanctioned training courses, CMMC professional exams, Registered Practitioner support services, and the DIBCAC’s assessment of C3PAOs and candidate C3PAOs.
- DoW suspended the start of the CMMC Program Phase 2 rollout, which would have introduced “the requirement for CMMC Status of Level 2 (C3PAO) for applicable DoD solicitations and contracts as a condition of contract award” on 10 November.
- Consequently, DoW suspended the inclusion of the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7021, “Compliance with the Cybersecurity Maturity Model Certification Level Requirements,” for CMMC Level 2 Certifications by a CMMC 3rd Party Assessment Organization (C3PAO) and for Level 3 assessments by the Defense Industrial Base Cybersecurity Assurance Center (DIBCAC).
- The suspension of CMMC Program Phase 2 rollout is ONLY applicable to contracts awarded between DoW and the awarded contractor.
- The suspension of CMMC Program Phase 2 does not negate any contractual requirements from your primes if they require your organization to be CMMC Level 2 certified.
- The following DFARS Clauses are still in full effect for awarded contracts and related flow downs to suppliers:
- 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting
- 252.204-7019: Notice of NIST SP 800-171 DoD Assessment Requirements
- 252.204-7020: NIST SP 800-171DoD Assessment Requirements
- 252.204-7021: Cybersecurity Maturity Model Certification Requirements
- 252.204-7024: Notice on the Use of the Supplier Performance Risk System
- 252.204-7025: Notice of Cybersecurity Maturity Model Certification Level Requirements
- DIB companies will still see DFARS Clause 252.204-7021 requiring your organization to self-affirm your protections around CMMC Level 1 for Federal Contract Information (FCI) and CMMC Level 2 for Controlled Unclassified Information (CUI).
- This will further delay changes requiring your organization to migrate to NIST SP 800-171 Revision 3, at least until the new Federal Acquisition Regulation (FAR) CUI begins to show up next year.
- Given that DIBCAC has ceased efforts to begin CMMC Level 3 Assessments, DoW will likely use this increased availability to step up its non-voluntary DFARS Clause 252.204-7012 audits by DIBCAC during this period.
- There is no correlation of DOW’s CMMC Program Phase 2 date does not correlate to a suspension of “PHASE 2 - Assess Conformity To Security Requirements” under the CMMC Assessment Process (CAP) version 2.0.
- Regarding CMMC 3rd Party Assessment Organization (C3PAO) conducting CMMC Level 2 Certification Assessments:
- The DoW has not directed any changes to The Cyber AB for program elements under its purview.
- C3PAOs continue conducting CMMC Level 2 Mock and Certification Assessments in support of CMMC Phase 2 being restarted and prime contractor requirements.
- The Supplier Performance Risk System (SPRS) and CMMC Enterprise Mission Assurance Support Service (eMASS) remain open for C3PAOs to submit organization Certification Assessment results.
- Organizations that have a CMMC Level 2 Certification from a C3PAO will retain competitive advantage over their peers within the prime’s supply chains.
- Organizations that have a CMMC Level 2 Certification from a C3PAO have increased protections against False Claims Act (FCA) charges by demonstrating due diligence.
Remember that that Phase II of CMMC is the MANDATORY insertion of the CMMC Certification Clause into new contracts. Your Customer can still make any demands of you, and put ANY requirement into your T’s&C’s.
Talk to your Customers about how they are handling this news. They may determine to delay insertion of CMMC Certification into their contracts, they may determine not to.
What CMMC Level 2 Certification does is provide 3rd Party validation that you have in fact implemented the NIST 800-171 controls to protect CUI. Your Customer is making a risk-based decision to flow this data to you at the moment. Certification decreases that risk. Customers consider this when both writing and awarding contracts.
CompliancyIT is a cybersecurity consulting firm providing compliant helpdesk, compliant infrastructure, and compliance management services to defense contractor across the United States. You can reach out to us with questions or for help at: compliance@complianyit.io or 724.235.8750.








