The Pentagon paused CMMC Phase II, but cybersecurity requirements remain. Here's what the decision really means for defense contractors.

Top Pentagon officials said as currently executed, CMMC is too prohibitive and burdensome on the Defense Industrial Base.

The Defense Department will keep cybersecurity self-assessments, but will not require third-party certifications as planned.