Cyber AB Responds to CMMC Phase II Pause: The Work Isn't Stopping
The defense contracting community received unexpected news this month when the Department of War announced it would suspend CMMC Phase II requirements and launch a 60-day review of the program. Naturally, the announcement sparked questions across the Defense Industrial Base about what comes next.
In its official response, Cyber AB acknowledged that it was surprised and disappointed by the decision, especially given the amount of progress the CMMC program has made in a relatively short period of time. At the same time, the organization made it clear that it intends to work with the newly formed CMMC Reform Task Force and support efforts to improve the program where needed.
One theme stood out throughout Cyber AB’s statement: this is a pause in implementation, not a shutdown of the CMMC ecosystem. While Phase II requirements are being reviewed, the infrastructure supporting CMMC remains intact. Assessments, training programs, professional certifications, and practitioner services are all continuing as normal.
Below is the full response from Cyber AB.
Cyber AB also pointed to the significant momentum already built around the program. More than 1,000 Certified Assessors, 110 authorized C3PAOs, and nearly 2,000 contractors have invested in achieving CMMC Level 2 certification. From Cyber AB’s perspective, that level of participation demonstrates that the industry has already embraced the need for stronger cybersecurity and independent validation.
Perhaps the most important reminder for contractors is that cybersecurity requirements have not disappeared. NIST SP 800-171 and DFARS 252.204-7012 remain in effect, and organizations handling Controlled Unclassified Information (CUI) are still expected to protect that information appropriately. The Department may be reevaluating how CMMC is implemented, but it is not backing away from cybersecurity expectations across the Defense Industrial Base.
For companies that have been preparing for certification, Cyber AB’s message is essentially one of continuity. The organization continues to view third-party assessments as a critical component of supply chain security and believes the value of independent verification will remain evident throughout the review process.
At this point, the biggest takeaway isn’t that CMMC is going away. It’s that the Department is taking a closer look at how the program can best achieve its goals while reducing unnecessary burden on industry. As that review unfolds, Cyber AB remains confident in the progress that has been made and in the role CMMC will continue to play in strengthening the cybersecurity posture of the defense supply chain.





