{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Secure Talk Podcast","title":"Special Episode: CMMC Phase 2 SUSPENDED: What DOD Just Did, What It Really Means, and Why Little Changed","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/43ab6091\"></iframe>","width":"100%","height":180,"duration":2798,"description":"The Pentagon paused CMMC Phase 2 with zero warning — and half the defense industrial base is celebrating for the wrong reason.\nWhen the Department of War suspended CMMC Phase 2 rollout with no notice, panic spread fast across the defense contractor community — but the requirement to secure CUI never went away. In this special roundtable, host Justin Beals brings together three CMMC insiders — Logan Therrien (C3PAO Chief Strategy Officer, retired Navy submariner), Lance Arnold (30-year industry veteran, just completed his own CMMC Level 2 journey), and Brian Hubbard (President, Evolved Cyber Solutions, CMMC assessor since 2015) — to separate what actually changed from what didn't.They break down the difference between the assessment requirement (paused) and the security implementation requirement (still very much alive under NIST 800-171), why \"self-assessment\" doesn't mean \"no requirement,\" and what small businesses and primes should do right now instead of waiting for clarity that may not come for months.\nSources Referenced: \nDFARS 252.204-7021 (CMMC assessment clause)DFARS 252.204-7012 (NIST 800-171 compliance clause)DFARS 252.204-7019 (SPRS scoring requirement)32 CFR Part 170 (CMMC Program Rule)32 CFR Part 48NIST SP 800-171 / NIST SP 800-172","thumbnail_url":"https://img.transistorcdn.com/FI5U-V5f7xdITFyeJIbD7DHq2VtWIj7V7SxzbEqbbTM/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81NzRj/MTkwYWEwN2IzMjIw/ZjRhZTE0MGJiYjhi/N2YxMS5qcGc.webp","thumbnail_width":300,"thumbnail_height":300}