The CMMC Phase II pause “shouldn’t be a shocker to anybody,” according to Katie Arrington, thought of as the creator of CMMC. But, she said, at the end of the day the Pentagon is likely to come back around to where it is now, realizing “that there really is no other way to get compliance.”

Top Pentagon officials said as currently executed, CMMC is too prohibitive and burdensome on the Defense Industrial Base.

The Defense Department will keep cybersecurity self-assessments, but will not require third-party certifications as planned.