CMMC Phase 2 Paused, Contractors Must Still Meet Data Security Obligations
Key Takeaways The Department of Defense has temporarily halted Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) rollout. This pause does not relieve defense contractors of their...
Key Takeaways
- The Department of Defense has temporarily halted Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) rollout.
- This pause does not relieve defense contractors of their ongoing obligations to secure Controlled Unclassified Information (CUI).
- Contractors should leverage this period to enhance their cybersecurity postures and prepare for future CMMC compliance.
- The core mission of strengthening the Defense Industrial Base’s cybersecurity remains paramount.
The Department of Defense (DoD) has announced a temporary suspension of Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program. This pause, however, does not diminish the critical responsibility of defense contractors to safeguard sensitive data.
Table Of Content
CMMC Phase 2 Halted, Data Security Mandates Remain
While the CMMC Phase 2 implementation is on hold, the fundamental requirement for defense contractors to protect Controlled Unclassified Information (CUI) persists. Contractors must continue to adhere to existing data security regulations and standards, regardless of the CMMC timeline adjustments.
Industry experts emphasize that this period should be viewed as an opportunity for strategic improvement rather than a delay in compliance efforts. Organizations within the Defense Industrial Base (DIB) are encouraged to utilize this time to strengthen their cybersecurity frameworks, mitigate risks, and build robust security foundations. These foundational improvements will be crucial for long-term resilience, independent of specific compliance deadlines.
The overarching goal of CMMC has always been to elevate cybersecurity across the DIB, not merely to serve as a singular compliance checkpoint. This mission remains as vital today as it was prior to the recent pause. The ongoing threat landscape necessitates continuous vigilance and proactive security measures from all entities engaged with the DoD supply chain.
As John Grancarich, Executive Vice President and Head of Defense & Intelligence at Fortra, notes, understanding the evolving data security challenges in mission environments is key. His work focuses on assisting organizations in protecting sensitive information as it traverses various systems, organizations, supply chains, and increasingly, AI-driven workflows. Grancarich, a recognized authority in data security, advocates for data classification as a primary security control and for security policies that are inherently linked to the data itself. He frequently discusses topics such as data-centric security, Zero Trust architectures, coalition operations, allied information sharing, and the enduring strength of security strategies within national security contexts.
Grancarich previously served as Fortra’s Chief Strategy Officer, where he played a pivotal role in transforming the company into a specialized cybersecurity provider with data security at its core. Earlier in his career, he founded Product Fuse and held senior positions in cybersecurity, digital forensics, and legal technology. He is also a co-author of Internet Fraud Casebook: The Worldwide Web of Deceit.
What You Should Do
- Maintain Vigilance: Continue to prioritize and implement robust cybersecurity measures for all Controlled Unclassified Information (CUI).
- Assess Current Posture: Conduct thorough internal assessments of your current security controls against existing DoD regulations and best practices.
- Invest in Training: Ensure all personnel are regularly trained on data handling protocols, threat awareness, and compliance requirements.
- Strengthen Supply Chain Security: Work with your own supply chain to ensure their adherence to data security standards, recognizing that your security is intertwined with theirs.
- Prepare for Future CMMC: Use this pause to refine documentation, implement necessary technical controls, and address any identified gaps in anticipation of CMMC’s eventual full implementation.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.