CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CMMC Hit Pause, the FAR Council Hit Play

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5597

As cited

Copy frozen at (site build).

regulatory

CMMC Hit Pause, the FAR Council Hit Play

The Cybersecurity Maturity Model Certification (CMMC) Phase 2 implementation has been paused, but the Federal Acquisition Regulation (FAR) Council's new rule on Controlled Unclassified Information (CUI) extends NIST SP 800-171 requirements beyond traditional defense contractors. The rule includes 32 non-deferrable requirements that contractors must address regardless of CMMC timeline delays.

Why it matters: Defense contractors and suppliers working with federal agencies must understand which NIST 800-171 controls are mandatory now under the FAR CUI rule, since CMMC delays do not eliminate underlying compliance obligations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

regulatory

CMMC Hit Pause, the FAR Council Hit Play

The Cybersecurity Maturity Model Certification (CMMC) Phase 2 implementation has been paused, but the Federal Acquisition Regulation (FAR) Council's new rule on Controlled Unclassified Information (CUI) extends NIST SP 800-171 requirements beyond traditional defense contractors. The rule includes 32 non-deferrable requirements that contractors must address regardless of CMMC timeline delays.

Why it matters: Defense contractors and suppliers working with federal agencies must understand which NIST 800-171 controls are mandatory now under the FAR CUI rule, since CMMC delays do not eliminate underlying compliance obligations.

Actorsplay
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary