It's Thursday, July 16th, and three days ago the Department of War suspended CMMC Phase II, effective immediately. The third-party certification requirement that was set to hit on November 10th is gone for now, a reform task force has 60 days to review the entire program, and officials would not rule out scrapping it altogether.

Here's the thing: if you were paying attention, you saw this coming. Back in March, CIO Kirsten Davies sat in front of the House Armed Services cyber subcommittee and told lawmakers she was looking at CMMC through the lens of Secretary Hegseth's push to reduce regulatory burden. Congressmen were quoting GAO findings that compliance costs could bankrupt small contractors, and Davies confirmed a dedicated review of the CMMC ecosystem was already underway. Monday was that review going public.

But here's what did NOT change, and it's the reason this call exists. The Department's own release says this action "does not eliminate the requirement for companies to protect federal data." Self-assessments are still in force. DFARS 7012 didn't move. NIST 800-171 is still the standard. What got suspended is the referee, not the rules. And with self-attestation now the primary enforcement mechanism, the False Claims Act exposure for your clients arguably went up on Monday, not down.

Your DIB clients are calling this week asking to pause projects and redirect budgets. Today we're giving you the answers for those calls.

Joining me is the Mount Rushmore of CMMC: Jacob Horne, Scott Singer, Ryan Bonner, Andy Sauer and co-host Scott Edwards.

Important: Legal considerations for MSPs working with the DIB is laid out in this blog by Eric Tilds.

Podden och tillhörande omslagsbild på den här sidan tillhör Andrew Morgan. Innehållet i podden är skapat av Andrew Morgan och inte av, eller tillsammans med, Poddtoppen.