CMMC Phase II Is Suspended. Your Obligations Aren’t
On July 13th, the Department of War announced the immediate suspension of CMMC Phase II. If you’ve spent the last two years planning around the November 10 certification deadline, you’ve probably already seen the headlines. Here’s the plain read, because there’s a lot of noise around this one.
What didn’t change
A few things are easy to miss in the relief of a delayed deadline:
- Phase I self-assessment requirements remain firmly in place.
- NIST SP 800-171 Rev 2 is still enforced during this interim period, through self-assessments and select government-led assessments. The stated focus is tangible cyber hygiene, not administrative overhead.
- DFARS clause 252.204-7012 is untouched. Every defense contractor and subcontractor is still contractually obligated to safeguard covered defense information, and that obligation still flows down to subs.
Put simply: the certification gate moved. The underlying requirement to protect federal data did not.
Where the risk sits now
A C3PAO assessment meant a third party shared the risk with you. A self-attestation means you’re holding that risk alone, and that attestation is a representation you’re making directly to the government.
So, the question changes. It’s no longer “who certified us?” It’s “can we prove what we asserted, and when?”
If that proof lives in email threads and shared drives, it won’t hold up when someone asks you to produce it three years from now.
What this means going forward
An Azure GCC High environment with full traceability, backed by an immutable, time-stamped record of what you attested to and when, is what holds up when you’re asked to show receipts. That’s been the mission from the outset, and this announcement is exactly why it matters now.
Blog
How much is lost paperwork costing your company
Read more →
Webinar
SmartTalk with quality and fastener expert Carmen Vertullo
Read more →
Case Study
PENCOM gained 80 percent efficiency on internal cert processes with SmartCert
Read more →
Transforming Traceability with SmartCert
Download PDF →
Click here to schedule a demo and explore how SmartCert can reduce your risk and strengthen visibility into your supply chain.




