CMMC Phase II Paused: What Every MSP Needs to Know episode artwork

EPISODE · Jul 20, 2026 · 1H 28M

CMMC Phase II Paused: What Every MSP Needs to Know

from The CyberCall Podcast · host Andrew Morgan

It's Thursday, July 16th, and three days ago the Department of War suspended CMMC Phase II, effective immediately. The third-party certification requirement that was set to hit on November 10th is gone for now, a reform task force has 60 days to review the entire program, and officials would not rule out scrapping it altogether.Here's the thing: if you were paying attention, you saw this coming. Back in March, CIO Kirsten Davies sat in front of the House Armed Services cyber subcommittee and told lawmakers she was looking at CMMC through the lens of Secretary Hegseth's push to reduce regulatory burden. Congressmen were quoting GAO findings that compliance costs could bankrupt small contractors, and Davies confirmed a dedicated review of the CMMC ecosystem was already underway. Monday was that review going public.But here's what did NOT change, and it's the reason this call exists. The Department's own release says this action "does not eliminate the requirement for companies to protect federal data." Self-assessments are still in force. DFARS 7012 didn't move. NIST 800-171 is still the standard. What got suspended is the referee, not the rules. And with self-attestation now the primary enforcement mechanism, the False Claims Act exposure for your clients arguably went up on Monday, not down.Your DIB clients are calling this week asking to pause projects and redirect budgets. Today we're giving you the answers for those calls.Joining me is the Mount Rushmore of CMMC: Jacob Horne, Scott Singer, Ryan Bonner, Andy Sauer and co-host Scott Edwards.Important: Legal considerations for MSPs working with the DIB is laid out in this blog by Eric Tilds.

Episode metadata supplied by the publisher feed · Published Jul 20, 2026

Embed this episode

It's Thursday, July 16th, and three days ago the Department of War suspended CMMC Phase II, effective immediately. The third-party certification requirement that was set to hit on November 10th is gone for now, a reform task force has 60 days to review the entire program, and officials would not rule out scrapping it altogether. Here's the thing: if you were paying attention, you saw this coming. Back in March, CIO Kirsten Davies sat in front of the House Armed Services cyber subcommittee and...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

CMMC Phase II Paused: What Every MSP Needs to Know

0:00 1:28:44

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The CyberCall Podcast?

This episode is 1 hour and 28 minutes long.

When was this The CyberCall Podcast episode published?

This episode was published on July 20, 2026.

Can I download this The CyberCall Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!