Echelon Risk + Cyber, a cybersecurity consulting and managed security firm based in Pittsburgh, PA, has issued formal guidance to defense contractors following the recent suspension of CMMC Phase II requirements. Echelon Risk + Cyber’s position is direct: contractors should not pause their security programs. What did not change is everything that actually governs a contractor’s security obligations. Echelon Risk + Cyber has published a detailed breakdown of the suspension and its implications for contractors of all sizes. Defense contractors seeking guidance on CMMC readiness, NIST 800-171 implementation, or what the Phase II suspension means for their specific situation can contact Echelon Risk + Cyber directly to speak with a CMMC specialist.