Everyone saw the headline that CMMC Phase 2 was suspended.

Almost nobody read the part that says government-led assessments are still happening.

In this episode we look at what the DoD actually said, how DIBCAC decides who gets assessed, why the LogZone False Claims Act case matters, and why today's approach looks surprisingly similar to the original CMMC 1.0 phased rollout.

If you think the suspension means nobody is verifying cybersecurity anymore, you may want to read the Phase 2 suspension memo one more time.

Phase 2 Suspension: https://youtu.be/TfdwAc5tdMA?si=H8Dtz6Z1UbG_aYpX

LogZone FCA: https://youtu.be/T5wJYnQzWws?si=ME3p2C8Sx_jhXTGJ

DFARS 7020: https://youtu.be/D4JLkfvB-Ws?si=rG-4enAdaj0InsfY

DoD Critical Tech: https://www.cto.mil/osc/critical-technologies/

CIO Interview: https://defensescoop.com/2026/07/17/pentagon-task-force-to-review-cmmc-hits-the-ground-running/

Suspension Memo (PDF): https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf

Podden och tillhörande omslagsbild på den här sidan tillhör Summit 7. Innehållet i podden är skapat av Summit 7 och inte av, eller tillsammans med, Poddtoppen.