The Pentagon’s decision to suspend the mandatory third-party assessment requirement for CMMC Phase 2 has sent shockwaves through the defense industry, with many experts weighing in on the implications of this move. At its core, the suspension means that companies will no longer be required to undergo independent verification of their cybersecurity controls, but they will still be expected to self-assess and report their compliance.
The Department of War’s decision to pause CMMC Phase 2 was driven by concerns over the ability of third-party assessors to keep up with demand. With thousands of companies requiring assessments, the existing ecosystem simply couldn’t scale to meet the need. Additionally, the cost of compliance was seen as a significant barrier for small and mid-sized firms, potentially pricing them out of the defense industrial base altogether.
One thing that’s essential to understand is that the suspension only affects independent verification, while Phase 1 self-assessment obligations, SPRS score submissions, and the underlying DFARS 252.204-7012 requirement to protect controlled unclassified information (CUI) remain fully in effect. This means that companies will still be required to assess their own compliance against the 110 NIST 800-171 requirements, but they won’t have to undergo a separate third-party audit.
Industry professionals are broadly in agreement that the suspension of third-party audits raises concerns about False Claims Act exposure. As Abdie Mohamed, GRC Engineering Lead at NR Labs, pointed out, self-attestation without verification is a recipe for disaster. “If you report a perfect 110 score,” he warned, “but it turns out you never actually did the due diligence, that’s False Claims Act exposure. And DOJ has already settled cases like Aerojet Rocketdyne ($9M), Raytheon ($8.4M), Penn State ($1.25M), and MORSE Corp, which paid $4.6M over the gap between its self-reported score and what assessors actually found.”
Mohamed believes that the Department of War made the right call in suspending CMMC Phase 2, but is concerned about the interim period without independent verification. “Self-attestation on its own hasn’t been enough,” he said. “Having a third party audit you keeps you accountable, and every settlement I just listed started with a company attesting to its own compliance.”
Chris Nyhuis, CEO of Vigilant, took a more nuanced view, arguing that the suspension was overdue. “Speed done securely is a security requirement now, not a nice-to-have,” he said. “Our adversaries move in days. When it takes a small defense supplier a year and six figures to clear a third-party audit before it can even bid, we’re not protecting the mission, we’re slowing it down.”
While Nyhuis acknowledges that the requirements and controls remain the same, he worries about the potential consequences of self-attestation without verification. “The audits existed for a reason,” he said. “Sadly, in my experience over my career a lot of these companies skirt the rules, and that’s exactly why third-party validation showed up in the first place.”
In the end, the suspension of CMMC Phase 2 is a temporary reprieve, but it raises more questions than answers. What will happen next? Will the program be revised, or even scrapped altogether? One thing is certain: companies must still comply with the underlying DFARS requirements to protect CUI.
So what can companies do in the meantime? Firstly, they should continue to assess and report their compliance against the 110 NIST 800-171 requirements. Secondly, they should use this opportunity to review and refine their cybersecurity controls to ensure that they are meeting the required standards. And finally, they should be prepared for the possibility that the program may undergo significant changes in the coming months.
Source: SecurityWeek — 2026-07-17