08/18/2026
CMMC Phase II is paused. Contractor liability is not.
The temporary suspension of CMMC Phase II may have changed the certification timeline, but it did not eliminate contractors' cybersecurity obligations.
NIST SP 800-171 requirements still apply. Contractual cybersecurity requirements remain. And the potential for False Claims Act liability hasn't disappeared.
So what should defense contractors be doing now?
Our latest blog explains what the Phase II pause means, what hasn't changed, and why this is an opportunity to strengthen your cybersecurity posture before the next phase takes shape.
👉 Read the blog: https://www.smeinc.net/cmmc-phase-ii-is-paused-but-contractor-liability-is-not/