CMMC Phase II Suspended: What MSPs Need to Know
Key Points The Department of War suspended CMMC Phase II requirements, but organizations must still comply with NIST SP 800-171, DFARS, and other existing federal security obligations. The suspension pauses C3PAO certification requirements but does not eliminate self-assessments, SPRS score reporting, annual affirmations, or Controlled Unclassified Information (CUI) protection requirements. MSPs should continue remediation efforts, […]

