Secure Talk podcast | by Strike Graph

CMMC Phase 2 SUSPENDED: What DOD Just Did, What It Really Means, and Why Little Changed

Written by Strike Graph Team | Jul 17, 2026 8:48:58 PM

The Pentagon paused CMMC Phase 2 with zero warning — and half the defense industrial base is celebrating for the wrong reason.

The Pentagon paused CMMC Phase 2 with zero warning — and half the defense industrial base is celebrating for the wrong reason.
Description:
When the Department of War suspended CMMC Phase 2 rollout with no notice, panic spread fast across the defense contractor community — but the requirement to secure CUI never went away. In this special roundtable, host Justin Beals brings together three CMMC insiders — Logan Therrien (C3PAO Chief Strategy Officer, retired Navy submariner), Lance Arnold (30-year industry veteran, just completed his own CMMC Level 2 journey), and Brian Hubbard (President, Evolved Cyber Solutions, CMMC assessor since 2015) — to separate what actually changed from what didn't.
They break down the difference between the assessment requirement (paused) and the security implementation requirement (still very much alive under NIST 800-171), why "self-assessment" doesn't mean "no requirement," and what small businesses and primes should do right now instead of waiting for clarity that may not come for months.

Sources referenced

DFARS 252.204-7021 (CMMC assessment clause)
DFARS 252.204-7012 (NIST 800-171 compliance clause)
DFARS 252.204-7019 (SPRS scoring requirement)
32 CFR Part 170 (CMMC Program Rule)
32 CFR Part 48
NIST SP 800-171 / NIST SP 800-172

#CMMCPhase2, #CMMCsuspended, #DFARS7021, #CMMC2025update, #CMMCcompliance, #defense #contractor #cybersecurity #NIST800-171 #C3PAO, #CMMC #self-assessment #DIB #cybersecurity