The U.S. Department of Defense's Cybersecurity Maturity Model Certification (CMMC) Phase 2 rollout has been paused for review, but this does not negate contractors' existing cybersecurity obligations. The underlying requirements, mandated by DFARS 252.204-7012 and based on NIST Special Publication 800-171 Rev. 2, remain in effect. Contractors must continue to implement these security controls, as non-compliance can still lead to False Claims Act violations, and prime contractors may impose their own cybersecurity timelines on subcontractors. AI
RANK_REASON Opinion piece discussing the implications of a regulatory pause on existing obligations.
Read on Mastodon — mastodon.social →
- Cybersecurity Maturity Model Certification
- Defense Federal Acquisition Rules
- Department Of Justice United States
- DFARS 252.204-7012
- NIST
- Special Publication 800-171 Rev. 2
- Thomas Graham
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →