Summary and dates.
The four phases — and where they stand
Practical reading
The suspension is a pause pending reform, not a repeal. The underlying safeguarding requirements — DFARS 252.204-7012, NIST SP 800-171, SPRS scoring, and Phase 1 self-assessments — all remain in force, and primes continue to flow them down.
Specific contract requirements vary by program office and prime-contractor flowdown. Contractors should not assume that the program pause means absence of cybersecurity language in the next solicitation — and a reformed certification program is expected to emerge from the review.
Sources and citations.
- DoD CIO — CMMC About / phased rollout
- DoD CIO — CMMC program page
- Federal Register — CMMC Program final rule
DBIT Defense does not interpret control intent or republish substantive control text. All claims above link to primary sources for verification.
Related insights.
CMMC 2.0 Final Rule: timeline and structure
The CMMC 2.0 Program rule (32 CFR Part 170) was published in the Federal Register in October 2024 and took effect in December 2024. The dates and document struc…
The C3PAO ecosystem: who they are, where they are
Authorized CMMC Third Party Assessment Organizations (C3PAOs) conduct Level 2 certification assessments. The Cyber-AB maintains the authoritative marketplace li…
NIST SP 800-171: Rev. 2 vs Rev. 3
NIST published Revision 3 of SP 800-171 in May 2024. The CMMC Program rule (32 CFR Part 170) currently references Revision 2 as the underlying control catalog. …
DFARS 252.204-7012: history and current applicability
DFARS 252.204-7012 — "Safeguarding Covered Defense Information and Cyber Incident Reporting" — has been in DoD contracts since 2015 and remains the underlying a…