
The Department of War’s decision to pause the implementation timeline for CMMC Phase II has created questions across the Defense Industrial Base. It’s important to understand that this is not a pause in your cybersecurity and contractual obligations.
The requirements that matter today remain unchanged:
- DFARS 252.204-7012, 252.204-7019, and 252.204-7020 and 32 CFR remain in effect. (Requirements to protect CUI )
- SPRS score submissions and Phase I self-assessments, and C3PAO assessments continue where required by contract and Primes.
- DIBCAC continues to pursue non-voluntary audits of NIST 800-171 implementations for the DIB. The Department of Justice continues to enforce unsupported cybersecurity attestations under the False Claims Act.
Our recommendation is simple: continue moving forward.
Organizations that complete their CMMC Level 2 assessment now validate their cybersecurity program, identify and address gaps before they become contractual issues, strengthen customer confidence, and position themselves to respond immediately when Phase II resumes. Waiting for additional guidance may delay certification, but it does not reduce your existing legal liabilities or contractual obligations.
At Provincia Government Solutions, we are continuing to conduct CMMC Level 2 assessments for a majority of our clients. Completing your assessment now puts you in the strongest position for whatever comes next.



No comment yet, add your voice below!