If your organization holds a CMMC Level 2 certification, or is in the process of pursuing one, you’ve likely seen the headlines from the past week. On July 13, the Department of War suspended CMMC Phase II, the third-party certification requirement that was scheduled to take effect this November. A 60-day Reform Task Force is now reviewing the program.

What that suspension changes, and what it doesn’t, has been widely misreported. C3PAOs remain fully authorized. Certifications are still being issued. The underlying obligation to protect Controlled Unclassified Information hasn’t moved. But the questions organizations are asking, whether to pause an assessment, whether self-attestation is now sufficient, whether this changes competitive standing with primes, deserve a straight answer.

Join Insight Assurance on July 29th, at 1:00 PM ET, for a practical conversation on what changed, what the suspension means for organizations at every stage of the certification process, and how to think about the months ahead.

Topics We’ll Explore

  • What the July 13 suspension actually changed, and what it left untouched
  • What Cyber AB’s July 15 statement confirmed about C3PAO operations and ongoing certifications
  • The real risk profile of self-attestation during the review period, including False Claims Act exposure
  • What organizations already underway should do, and what the small-business relief under review actually covers
  • What to expect as the 60-day Reform Task Force reports back in September

Who Should Attend

This session is designed for security leaders, compliance managers, and risk professionals at organizations that hold or are pursuing CMMC Level 2 certification, particularly those reassessing timing or strategy in light of the recent announcement.