Secure Talk podcast | by Strike Graph

CMMC After the 60-Day Review: What DOD Decided, What It Didn’t, and What to Do Now

Written by Strike Graph Team | Oct 6, 2026, 2:35:39 PM

CMMC wasn't suspended. Only one piece of it was, and the defense contractors acting like the whole program went away are the ones taking on the most risk.Eighty days after the DoD CIO paused CMMC Phase 2, the 60-day review has closed, a class deviation has written the pause into contracts, and the Reform Task Force's recommendations are still not public. Contracting officers and primes aren't waiting. Some solicitations now require a posted SPRS score before you can even open the RFP.

In this SecureTalk panel, host Justin Beals sits down with three NIST SP 800-171 practitioners (a C3PAO strategist, a lead CCA and instructor, and a former Navy cryptologist turned enclave provider) to separate what DoD actually decided from what the internet decided for it.

WHO THIS IS FOR
Defense contractors and subcontractors, compliance and IT leaders preparing Level 1 or Level 2 self-assessments, MSPs and MSSPs serving the DIB, and anyone trying to make sense of CMMC after the Phase 2 pause.

TIMESTAMPS
00:00 Why this episode is a panel
00:39 Meet the guests
04:11 "We're NIST 800-171 experts, not CMMC experts"
05:16 80 days after the pause: where things stand
07:21 What hasn't changed: Level 1 and Level 2 self-assessments
08:26 Myth: "CMMC was suspended"
11:33 No SPRS score, no RFP documents
14:08 CMMC is a floor, not a ceiling
14:26 The FAR overhaul and retired clauses still in contracts
18:29 Myth: "CMMC got pushed to November 2028"
22:02 The class deviation most people misread
24:14 What a defensible self-assessment looks like
29:06 Reddit, Discord and the misinformation problem
33:30 Myth: "My MSSP handles CMMC for me"
36:40 Myth: "Our policies prove we're compliant"
40:32 Myth: "We bought an enclave, so we're done"
44:07 Where the real risk lies now
51:13 How to choose outside help

SOURCES REFERENCED
- DoD CIO memo suspending CMMC Phase 2 (July 13, 2026), via Federal News Network: https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/
- Sept. 3 acquisition memo codifying the pause, via MeriTalk: https://www.meritalk.com/articles/dod-codifies-pause-of-cmmc-phase-2-dod-cio-says-more-work-needed-on-cmmc/
- 32 CFR Part 170, the CMMC Program rule (phased rollout in §170.3): https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
- NIST SP 800-171 Rev. 2: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final
- NIST SP 800-171A, the assessment methodology: https://csrc.nist.gov/pubs/sp/800/171/a/final
- CMMC Program Final Rule: https://www.federalregister.gov/d/2024-22905/p-1876-

- Free executive level class: https://www.evolvedcyberacademy.com/courses/Rev3LeadershipWHAT

- CMMC Level 2 Self- Assessment: Step-by-step with Templates: https://www.strikegraph.com/blog/conduct-cmmc-level-2-self-assessment

YOU'LL LEARN
The requirement never moved. The pause hit third-party C3PAO assessments, not NIST SP 800-171 compliance and not Level 1 or Level 2 self-assessments. Brian Hubbard sets the bar at a self-assessment you could defend "if the DIBCAC walked in the next day after you posted your score."

November 2028 is not a new deadline. Logan Therrien explains it has always been the end of CMMC's four-year phased rollout. Reading it as a two-year reprieve is one of the costliest misreadings in the market.

The market is moving faster than the policy. Vince Scott compares it to oil moving through the Strait of Hormuz: there are months of supply in the system before anyone feels the change. Primes are already asking to see SSPs and SPRS scores.

GUESTS
Logan Therrien, Chief Strategy Officer, Kieri Solutions (C3PAO); 24-year military veteran
Brian Hubbard, President, Evolve Cyber; Lead CCA and CMMC instructor; 40+ years in cybersecurity
Vince Scott, CEO, Defense Cybersecurity Group; retired Navy cryptologist

HOST
Justin Beals, founder of Strike Graph and host of SecureTalk, a podcast focused on security news, innovation, and excellence.

🔔 Subscribe for conversations where cybersecurity, compliance and national security meet.

#CMMC #NIST800171 #DefenseIndustrialBase