What happened
The US Department of Defense suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) requirements for defense contractors. Phase II is the stage where certification stops being voluntary and becomes a condition for contract awards, so a suspension there changes the timeline for thousands of suppliers in the defense industrial base.
Why this is a GRC story
CMMC matters beyond defense. It is the clearest example of a regulator making certification a contractual gate, and every compliance professional has been watching it as the model for what happens when a standard stops being advisory.
The compliance risk lesson. When a program like CMMC is suspended, organizations that already invested in Level 2 or Level 3 preparation are not harmed. They built real controls, and the controls remain valuable regardless of what the certification calendar says. The organizations that delayed investment because they hoped the requirement would soften are the ones now exposed. A suspension is not a waiver of the underlying security obligations. DFARS 7012 clauses still require contractors to implement NIST SP 800-171 controls, whether or not an assessment is currently being scheduled.
The roadmap lesson. Compliance roadmaps that hinge on a single external deadline are fragile. The better design treats the certification as a checkpoint in an ongoing control program, not the finish line. If the checkpoint moves, the program continues.
What GRC teams should take from this
Track regulatory pauses separately from control obligations. When a mandate is suspended, ask the question that matters: does the underlying contract clause still require the controls? In most cases it does. Continue the control work, keep the evidence current, and treat the certification as something you are ready for rather than something you are waiting on.
Attribution: Analysis based on Infosecurity Magazine's reporting and DoD program documentation. This article is original commentary, not a repost of the source material.