Moved, Not Removed: What the CMMC Phase II Suspension Actually Did
On July 13, the Department of Defense suspended CMMC Phase II, the third-party audits due in defense contracts this November. Most of the supply chain heard a reprieve. The rules say otherwise: NIST 800-171, DFARS 252.204-7012, SPRS scores, and the signed annual affirmation all remain enforceable. Twenty-five days before the suspension, the Justice Department settled a half-million-dollar False Claims Act allegations with a contractor over the gap between its attested compliance and its assessed score.
This session maps what was suspended, what survived, and where the risk went, because it didn’t disappear. It moved, and it moved toward the people who run these environments.
Certification is suspended. Prosecution is not. Join us and find out what those six words mean for your practice.
Speaker
Lewis Pope
Lewis started his career in the MSP channel, spending six years as a System Administrator, Manager of Service Delivery, and IR Lead with a break/fix operation that eventually matured to a full MSP. Lewis joined N‑able in 2018 as a Sales Engineer, and in 2021 became a member of the Head Nerds team.
As a Head Nerd at N‑able, Lewis is focused on cybersecurity, helping MSPs overcome security and operational challenges by providing education, training, and advocacy for implementation of practical security controls, proper risk management, and incident response. His primary goal is helping MSPs start the cybersecurity maturation process that is needed to contend with modern risks and the evolving threat landscape, as well as finding opportunities for growth.
In his downtime, you can find him hosting gameshows at sci-fi conventions, tinkering with microcontrollers that have way too many LEDs, or reading endless threat-intelligence feeds. He’s also very proud of his daughter, but if we got into all of the reasons for that we’d be here for quite a while.