Summit 7 notes that the DoD began working on a revision to move the CMMC program to 171 revision 3 immediately after the 2024 CMMC final rule.
Public source
Publisher name
Public post
The cyber requirements mismatch problem that DoD successfully avoided in 2024 is back on the menu thanks to the CMMC Phase 2 suspension. 📺 Watch here: https://lnkd.in/g…
Company
Summit 7
Protecting The American Dream.
- Industry
- IT Services and IT Consulting
- Location
- Huntsville, US
- Company size
- 201–500 employees
About Summit 7
Summit 7 is the #1 Managed Services (MSP) and Managed Security Services (MSSP) provider for DoD contractors. Summit 7's greatest efforts are currently helping businesses configure, and manage their cloud environments to CMMC 2.0, NIST 800-171, and DFARS security and compliance requirements.
See moreLatest activity
Latest activity from Summit 7
9 signals
Presence & Recognition
Summit 7 launched a new partner short series breaking down cybersecurity and compliance in bite-sized pieces, featuring Michelle Andersen from DEFCERT on the first episode.
Presence & Recognition
Summit 7 announced that Jacob Horne, Daniel Akridge, and Scott Edwards explained CMMC Level 2 - DFARS 7012 and ITAR for Manufacturers on the CUI Hotline.
Research & Knowledge
Summit 7 published an episode detailing how DoW got to CMMC Phase 2, the options for fixing it, and why CMMC reform could make the problem even more complicated.
Discover more
Similar signals
Similar public activity from other companies.
Legal & Regulatory
Kieri Solutions | Authorized C3PAO
Kieri Solutions | Authorized C3PAO noted that NIST 800-171 Revision 3 is already published and the federal acquisition rule for civilian agencies is being built on it.
Legal & Regulatory
IP Consulting, Inc.
IP Consulting, Inc. notes that CMMC Phase 2 was suspended on July 13, 2026, and the Reform Task Force's recommendations are expected around September 13.
Legal & Regulatory
A-LIGN
A-LIGN notes that CMMC did not create the requirement to protect CUI using NIST 800-171, with DFARS and 32 CFR Part 170 using the 110 requirements of NIST 800-171 Rev. 2 as the Level 2 baseline.
Legal & Regulatory
Telarus
Telarus VP of Cybersecurity Sumera Riaz highlights that CMMC Phase 2 may be paused, but requirements haven’t gone anywhere, with defense contractors still needing to meet Phase 1 compliance.
Legal & Regulatory
Vigilant