This special edition covers the Pentagon’s recent suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements and initiation of a 60-day review by the CMMC Reform Task Force, and is hosted by Yuan Zhou, Kate Growley, and Nkechi Kanu. Crowell & Moring’s “Fastest 5 Minutes” is a biweekly podcast that provides a brief summary of significant government contracts legal and regulatory developments that no government contracts lawyer or executive should be without.
Continue Reading Special Edition of the Fastest 5 Minutes: Suspension of CMMC Phase II RequirementsCMMC Phase II Suspension Requires Reconsideration of Such Requirements in Solicitations

As discussed in more detail here, the U.S. Department of War (DoW) recently issued a memorandum (Memo 26-P-1023, dated July 13, 2026) directing the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements (Level I and II self assessments are still permitted). Significantly, the memo directs that “all pending and future CMMC implementation milestones across DoW solicitations and contracts are held in abeyance until further notice.” Moreover, the DoW issued a memorandum on implementing these requirements (available here), directing agencies to issue amendments removing CMMC Level 2 and 3 requirements from active solicitations “as soon as practicable.” Contractors should monitor the government’s compliance with this requirement and should be prepared, if needed, to file a bid protest to protect their rights.
Continue Reading CMMC Phase II Suspension Requires Reconsideration of Such Requirements in SolicitationsCMMC Final Rule Includes M&A Trigger for New Assessment






As Crowell covered in a recent alert, the Department of Defense (DoD) on October 11, 2024 released a final rule (the “Final Program Rule”) formalizing the requirements, assessment processes, and related governance for its Cyber Maturity Model Certification Program (CMMC).
Continue Reading CMMC Final Rule Includes M&A Trigger for New AssessmentFastest 5 Minutes: CMMC Assessment Process, SBA final rule, Transactional Data Reporting, OCIs

This week’s episode covers the Cyber AB’s recently released pre-decisional draft CMMC Assessment Process, an SBA final rule that implements new methods for evaluating expanded sources of small business past performance, a GSA OIG Alert about the Transactional Data Reporting rule, and Senate passage of an amended version of the Preventing Organizational Conflicts of Interest…
Fastest 5 Minutes: CMMC, Bid Protests, NDAA

This week’s episode covers an update on the Cybersecurity Maturity Model Certification program, a GAO report on DHS’ controls to protect personally identifiable information, a Federal Circuit decision regarding prejudice in the bid protest context, and highlights from the National Defense Authorization Act for FY2022, and is hosted by Peter Eyre and Monica Sterling. Crowell …
Byte-Sized Q&A: What’s not in CMMC 2.0?
Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this episode, hosts Evan Wolff and Kate Growley talk through some key elements that are no longer expected under CMMC 2.0.
Listen: Crowell.com | PodBean | SoundCloud | Apple Podcasts
Byte-Sized Q&A: What can we expect under CMMC 2.0?
Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this episode, hosts Evan Wolff and Kate Growley talk through the fundamental changes that the DoD has announced will be made under “CMMC 2.0.”
Listen: Crowell.com | PodBean | SoundCloud | Apple
Byte-Sized Q&A: Part 3 – The CMMC Clause
Crowell & Moring’s “Byte-Sized Q&A” podcast takes the complex world of government contracts cybersecurity and breaks it down into byte-sized pieces. In this final episode of a three-part series, host Kate Growley digests the current state of DFARS clause 252.204-7021 and what contractors should know about the Cybersecurity Maturity Model Certification (or CMMC).
Listen: …
Crowell & Moring Achieves CMMC Registered Provider Organization Status to Help Defense Contractors Prepare for Upcoming DoD Cybersecurity Assessments
More than 300,000 companies within the Defense Department’s supply chain will need to meet new Cybersecurity Maturity Model Certification (CMMC) requirements and pass a third-party assessment to ensure they are adequately protecting sensitive information on their networks. Now, Crowell & Moring has become the first AmLaw 100 firm to achieve Registered Provider Organization (RPO) status…

