Ryan Burnette, a special counsel with Covington & Burling LLP focused on government contracts and technology, was quoted in Law360 in an article examining the Pentagon's decision to halt the next phase of its Cybersecurity Maturity Model Certification (CMMC) program for defense contractors. Law360 reported that while it was unclear what the CMMC reform task force would recommend at the end of its 60-day review, the DOD made sure to reiterate its commitment to the underlying cybersecurity requirements when it announced the Phase 2 suspension, according to Ryan.
"I think the real question is, how does DOD strike the balance of meaningful assurance of cybersecurity without excluding companies from the defense market, and I think that's the problem they're working with now," Ryan said.
Law360 reported that while the Phase 2 requirements were halted and the program's future remained in flux, Ryan said contractors should not stop their compliance efforts.
"The underlying controls have not been changed or delayed or paused in any way. And in some ways, there is even more need for companies to focus on their compliance at the moment because if they don't already have a CMMC certificate, if a deficiency is identified or is known by someone within the company at the time they make a self attestation to the government, there will not be an excuse of having disclosed that deficiency to an assessor," Ryan said.