
Loading summary
A
All right folks, it is July of 2026 and here is the big news. The upcoming November 2026 transition to phase two of CMMC implementation is officially suspended. That means that until further notice, the only CMMC status requirements that will appear in new DoD contracts and solicitations will be either CMMC level 1 self assessment or CMMC level 2 self assessment. All of the cyber requirements in the FAR and the DFARs for the protection of Controlled Information Cyber Incident Reporting are still in place and so is your liability for meeting them. Meanwhile, the DoD CIO Task Force will conduct a 60 day review of the CNMC program and the DoD wants your feedback on the program via an official request for information. So how does any of this actually impact your contracts moving forward? And what should you focus on first as we move ahead here? That's what we're going to talk about today. Jason this is all pretty straightforward. I mean despite all the noise and the chaos, this is all pretty straightforward. Pretty program reviews. Giving contractors more time before third party assessments is literally nothing that we haven't seen before in the story of CMMC. CMMC 2.0 was the result of the last program review that they did in 2021. And the requirements in DFARS 252, 204, 7012 and NIST SP 800171 literally haven't changed in 10 years.
B
Jacob to quote a great poet, Paula Abdul, two steps forward, two steps back, right? And apparently that's just been the theme of the program. Maybe it's up on like a live Laugh Love banner inside the walls of the Pentagon for Kristen Davies to walk by and see every day. Not quite sure. What I am sure of is that the only thing that this will produce is potential confusion and conflation with already existing requirements and not new things that have to exist. People are going to think, right, that this is just another 7012. Let me throw in a score so I can keep getting the contracts. And it's not exactly that we're not back to the old days, but we're back to the old days and maybe a customary review of things that haven't been reviewed for, I don't know, in the past, let's say decade is what is in order, right?
A
Yeah. CMMC self assessments are a lot more complicated and there's a lot more ways that you can mess them up compared to your self assessments that you were uploading in SPRs previously over the last few years. That's what we're going to talk about. Let's talk about the impact of contracts first. So like we said, the only CMMC status requirements that will appear in new DoD contracts and solicitations will be one of two things. Either CMMC level one self assessment if you're only dealing with Federal contract information, OR CMMC Level 2 Self Assessment if you're handling controlled unclassified information. If you have the data that triggers the requirements in FAR clause 5220421, you got to do a level one self assessment in order to prove it. If you have the data that triggers the requirements and DFARS clause 252, 204 7012, then you got to do the CMMC level 2 self assessment to prove that you're meeting those requirements. Those requirements haven't changed. You're just doing the self assessment now. Beyond that, active solicitations that might be out there that contain CMMC status level requirements of either Level 2 C3PAO or CMMC Level 3 DIBCAC will be amended to remove those requirements. So if you're out there and you're seeing contract solicitations that still say you need a C3 PAO verification of your level 2, that is going to be updated here shortly. Any existing contracts that have already been awarded that have those requirements, which there are not many, will have those contract will have those requirements removed via modification prior to the exercise of the next option period or during the next scheduled administrative modifications. So to be clear, the CMMC program is still in effect and the DoD themselves are very clear about that in their memos and statements and videos and interviews that were on this media blitz earlier this week. Here's one of the quotes. We'll link to all of them below. The CMMC program still requires pre award assessment of covered contractor information systems against the prescribed cybersecurity standards for safeguarding CUI and fci. Straight out of the words of the dod. Check out the memos and the press releases below if you'd like to read it for yourself. The only difference now is that you, the contractor, will continue to be responsible and liable for assessing your cyber posture for the time being, rather than the DOD allowing you to to go out and have a C3PO third party vouch for your cyber compliance. And that's going to be a big problem.
B
Yeah, I think that people aren't looking as to how much that actually means or the impact of that statement right there itself. That means everything now falls back on you. It's your responsibility to report it. It's your responsibility for your organization to adhere to it. And if you're the person that puts that score in when the DOJ needs to ask questions or when DIBCAT comes and verifies things and they're not correct, it's you that they're going to talk to. And so organizations are thinking that there's this a deflection of responsibility, deflection of resources and etc. Etc. But don't realize the ramifications that lie underneath. Like I mentioned in the opening, this isn't just a back to 7012 back to the basics type situation. This is a situation where there are CMMC Level 2 self attestations that are required and and minimum thresholds to achieve those.
A
Yeah, absolutely. All right, so we're back to everybody doing self assessments. So this is the part that's probably the most important and I honestly am pretty disappointed that the DoD didn't point this out while they were making all this noise about the change because thanks to this DOD decision it is now extremely important. Please listen to what I am telling you. It is extremely important that you familiarize yourself with the level 2 self assessment portion of the CMMC regulation that is still in effect because now moving forward until we hear otherwise, everyone has to now go through this part of the regulation rather than allowing the C3PAO to do it for you. That's 32 CFR section 170.16. We will link that below. The only difference now as a result of this news, the only difference is who is running the assessment. The only difference between a C3PAO assessment and a self assessment is the person doing the assessment. The NIST requirements? The same. The verification criteria in 801 71A for those requirements? The same. The scoping guidance? The same. The minimum passing score of an 88 in order to have a status at all and not fail your assessment? The same. Which cyber requirements are allowed to be open findings and still pass with a conditional status? The same. Which or sorry, the requirement to conduct closeout assessments if you have any open Items which within 180 days the same. Maintaining six years of assessment evidence and artifact retention the same. If you self assess you are liable for all of that. You don't get the COVID of a third party vouching for you through the certification. So thanks to the DOD going back for yet another review of a program that has already been reviewed half a dozen times between the IG, GAO, DOD's internal tiger teams over the years, contractors are now maybe they don't realize it yet. More exposed than they otherwise would be for the assessment and attestation of their cyber posture.
B
While you, you know, motivate people to familiarize themselves with 32 CFR 1 170, section 170.16. Right. Which contains the self assessment criteria, the level assessment criteria, I also urge you to Familiarize yourself with 170.21 or 24, the one that lists the POAM criteria and what's acceptable and what's the closeout is there. And the reason why is because there is a minimum threshold that remains the same. There is a 180 day window that remains the same. But that doesn't mean any control that you need, it can just go on the pom window. And I got six months, but I still get the contract. Not the case. There's a qualifying list. So if you try to input that, let's say. And this is just feasibility, right Jacob? But let's just say I try to input a score and that score reflects a poem that has an item that's not on the limited deficiencies that's listed within the rule.
A
Guess what bud, flag on the play.
B
Yes sir. That's not correct. You actually just falsified to get a contract. I know that that's petty, but that's what we're dealing with at this point. And, and now instead of having somebody with expertise come in and validate that and maybe give you a little reassurance so you can sleep better at night, it's all on you, Mr. Affirming Official. Thanks DOD.
A
Well, let's talk about affirming officials because probably the second most important thing that people need to pay attention to, which still exists regardless of whether it's a third party or a self assessment, is the annual affirmation part of the CMMC regulation. So regardless of who conducts your assessment or when you're required to have the assessment, you are still on the hook for having a senior company official affirm the company's continuing compliance on an annual basis. None of that has changed. If that does not ring a bell to you, it is extremely important. Please listen to what I am telling you. It is extremely important that you go read section 170.22 of the CMMC regulation. We will link it directly below the liability is through the roof for people who conduct their self assessments. And a lot of people out there are rejoicing, being like hey, DOD's taking their foot off the gas for the third party assessment. So I don't have to pay 50 grand for a third party assessment. The companies that understand how liability works and they understand that the CMMC program is different than the other underlying requirements in their contracts are not happy.
B
If you are an organization that thinks the DoD is taking their foot off the gas because they're at a stop sign and everything is going to completely halt, you're going to quickly hear the deeping of the DOJ Brinks truck backing up to your organization.
A
Well, well, let's talk about it. Because the DoD even says this in their memos and their press releases. DIBCAC and the Department of Justice, they don't use this word, but effectively they're still on the hunt. And now we're chumming the water for these guys. The days of simply conducting a self assessment and needing any score uploaded into the SPR SPRS database are over. Starting in 2020, you could have had a negative 200, you could have had a perfect 110, you could have had a zero, you could have. It didn't matter. You just had to have a score as a result of your self assessment uploaded into the system as a condition of contract award. Now you have to have a CMMC Level 2 status as a condition of award. And in order to do that you have one of two options. Achieving what's known as a final status or achieving what's known as a conditional status. You get a final status if your self assessment determines that every requirement is fully implemented and you therefore have a perfect score. If you have any open items and only some requirements qualify to be open items, you have what's known as a conditional status. You have an open plan of action that must be closed out with another assessment within 180 days to then move to final status showing that all of your requirements are fully implemented. If your open items as a result of your assessment result in a score of less than 88, you don't have a CMMC status. You have failed your assessment. It doesn't matter if you're doing the math or if the third party is doing the math, you have to cross that threshold. You didn't have to do that before cmmc. You could miss every single control and put them on a poem. You just had to have a score. So make sure that you are correct because this is the exact situation that DIBCAC and the DOJ specialize in in exposing. DIBCAT can call you or show up at your door at any moment and say prove what you just claimed. In this system we already know you have to maintain the artifact evidence. Two weeks ago we just did an an episode on a DOJ settlement for 75% of the value of the contracts that this contractor was awarded because they uploaded a perfect score and it turned out they had like a minus 170. All this is going to do is cause people to upload minimum threshold 88s, which is going to dramatically overstate the readiness of the ecosystem. And as soon as you do that, you have made a statement and a claim to the government that is in the system that they can go back and look at. All of these False Claims act settlements that we've been covering over the last two, three years are not about current status. They're about claims that people made a year or two or three years ago that they got paid for and now they're paying fines on. So be very, very, very careful. Familiarize yourself with what this regulation says, because you can't just enter whatever score you want to. If you find out you have a negative score and you have to have an 88 to achieve the status for you to win this contract, you think that they're going to, the leadership of your company is going to be like, guess we're going to skip the contract. We all know what they're going to do. They're going to tell you to put an 88 into that system. And that's how you end up with a whistleblower under the False Claims Act. This is a bad, bad situation. I mean, this is a recipe for disaster. And it's not sudden and it's not overnight and it's not something that'll happen tomorrow. But we're going to see this crop up over time as we move forward here. We've already seen this happen in the past. This is just setting more people up for the same thing.
B
What's happening or what is going to happen in some cases. And we, we can predict it now because we saw it in the days of the 800171 reporting is I've got the score of 88, the 80% minimum required for me to get there. All of these items on my POAM list are limited deficiencies. And then the six months ends and they're like, well, I still got the score of 88, but that poem list extended six more months. Right. I'm just going to re enter the score. That is one of the reasons why you're gonna have to retain all of your files, all your evidence, all your artifacts, everything that was used when that score was submitted. Because that retention period is when, like Jacob said, the DOJ is going to come back and Be like, hey, you put this and then you put that. How come it took you seven different, you know, contract cycles for you to implement MFA effectively or whatever it is? That was exactly. That's not a deficiency.
A
So I'll tell you exactly what dibcac's probably going to do. They're probably going to sit there and they're going to walk in in the morning and they're going to go, hey, Chat GPT, give me a list of all the poems that we're going to. All the conditional CMMC level 2 statuses that expired yesterday because of poem closeout. And they go, here you go. And they go, hello, your POAM closeout period ended yesterday and you didn't update your score. You want to send me all your documentation? Click. That's exactly what's going to happen. So familiarize yourself with what's going on. Do not be misled by the noise around this news and think that this
B
is a joke in the log zone. FCA case being unsealed when it did probably was the perfect timing because it relays that these are the ramifications associated with what's just been put on the plate for every single organization in the div. If you do this, this is what you're required to do. This is what they were required to do. If you do this incorrectly, this could be you.
A
It's been encouraging. I mean, last 48, 72 hours, companies that understand how liability works have all called us up and be like, well, we might not need a third party assessment, but we still got to implement all this stuff. It's been wonderful. A lot of the companies that are the smallest who can least afford a run in with DIBCAC and the DOJ are the first ones that are like, we don't really know what this means, so we're going to stop our implementation. Bad idea, folks. Bad idea.
B
If anything, the uncertainty of if a contract is going to drop or if a prime requirement is going to be sent to you by November 10th of this year relieved some of the oh my God. That was happening. We talked about it in the episodes where there wasn't enough assessment capacity that it wasn't the case. It was the fact that there was wasn't people ready to be assessed. The implementation wasn't going the way it was. Now a lot of those people are breathing the sigh of relief.
A
Yeah, we all know the reason why they're over here doing a program review. It's to buy time for people that weren't ready. So anyways, talking about the program Review. Don't have a lot of details on this. We don't know who or how many people are on this task force that's supposed to conduct a 60 day review of the program. Let's go way back in not so distant history, everybody. How did we go from CMMC 1.0 to CMMC 2.0? In March of 2021, they announced they were going to do a comprehensive program review of CMMC. And then it took them nine months to come up with CMMC 2.0. And what did CMMC 2.0 do? Did it change any of your requirements? Nope. Did it actually change any of the things that you have to implement? Sure didn't. It made a bunch of superficial changes. We went from five levels to three levels. We renamed practices the requirements, we got rid of a bunch of controls and just directly aligned with NIST so that there's zero other things that we can cut out. We made some changes to scoping guidance to make things even easier so you can have assets inside of your authorization boundary that you just tell people not to worry about. I mean they spent a long time going through everything and the changes that came out really didn't change anything for people that have to comply with DFAR7012 because they're different things. The program is different from the requirements. So I don't know what they expect to find in 60 days, but there's not really that much left to review. And 60 days is not a lot of time for whoever is on this task force to learn all of that stuff that they already went through back in the day.
B
Well, what I hope in that 60 days of what they learn and what they find is that this needs to align with NIST 800171 revision 3 To harmonize with other federal regulations within the government. I hope that they come out of that 60 day deep dark Aaron Rodgers Ayahuasca that they're in. Right. They're trying to figure out what's wrong with the CMMC program. And the one thing that they come up with above anything else is that there the second thing, if they're going to come up with something and I don't know what they're going to come up with because like I said, in the past 10 years almost everything's been reviewed, small business, large business, medium size, whatever, right? But the second thing is more flexibility. You want to create flexible, resilient systems to combat today's threat. But in this case the inflexibility of point in time assessments that require 100% significant change. Don't allow for that type of innovation in technology in systems to combat today's threats. So if we're going to do that, let's make that part a little bit more easier to limit some of the burden associated. When I'm evaluating risk of whether to implement a new technology to combat a threat, I don't have to add an extra $30,000 assessment cost that I just occurred six months ago.
A
Yeah, well, we'll see if we'll see what they come up with with the guidance out of the 60 days. But for now you guys still have all the same liability and whatever they come up with out of days, you're still going to have the same requirements in the far and the DFARs for what you have to actually implement. Alrighty, last pit here. Let's talk about the rfi. We're going to do a separate show on this, so make sure that you like and subscribe. Almost 150,000 of you have liked and subscribed so far, so thanks for that. The RFI, the Request for Information DoD wants your feedback on the CMMC program. Comments are due by August 14th and it can't be longer than 10 pages, everybody, so tell your LLMs to chill out. Will link to the official RFI down below. We're going to talk about it in detail in an upcoming episode because there are some very interesting implications about what the current group of people at DOD think CMMC is. I'm not so sure that they have a firm grasp of what this program is actually doing because they just got here. Anyways, let's wrap this show up. There is a lot of noise around the announcement to suspend Phase two, but whether or not you think this is a big deal really depends on three things. Your understanding of the relationship between the CMMC program and the underlying independent requirements that it's supposed to verify. How much context you have around the cyber policy problem that CMMC is supposed to solve, not relying on self assessments, pro tip dodge, and how much liability you had all along. While the DoD occasionally makes these superficial changes to the front cover of the CMMC program documents, all that stuff is going to really determine whether you think that this is an opportunity to pause what you're doing or an opportunity to use this extra time to get your house in order. So still lots of stuff to talk about with the rfi. Still lots of stuff to talk about with a couple of the things that were said and some of these statements from the DoD that boggle my mind. Like and subscribe. There'll be a whole series, probably for the rest of the month. A couple weeks coming up, and we'll see you next week.
B
Happy birthday, Mom. See you next week.
Sum IT Up: CMMC News Roundup
Episode: CMMC Phase 2 Is Suspended... But Contractor Liability Just Went UP
Date: July 16, 2026
Host: Summit 7
This episode discusses the Department of Defense’s (DoD) unexpected announcement: the planned Phase 2 transition for the Cybersecurity Maturity Model Certification (CMMC), scheduled for November 2026, is now officially suspended. Despite appearances, the hosts clarify that the core cybersecurity requirements for defense contractors have not been relaxed, and—if anything—contractor liability has increased. The hosts, A and B (Jacob and Jason), dig into what this suspension really means, the continuing obligation for self-assessment, and the rising compliance risks for defense contractors.
[00:00-02:39]
[02:39–06:25]
“The only difference now is that you, the contractor, will continue to be responsible and liable for assessing your cyber posture…” – A [04:35]
[05:36–11:21]
“If you’re the person that puts that score in... when the DOJ needs to ask questions or when DIBCAC comes and verifies things and they’re not correct, it’s you that they’re going to talk to.” – B [05:43]
[08:55–11:21]
A: “You actually just falsified to get a contract. I know that’s petty, but that’s what we’re dealing with at this point.” [09:45]
B: “Yes sir. And now... it’s all on you, Mr. Affirming Official. Thanks, DoD.” [09:47]
[10:05–11:21]
“The liability is through the roof for people who conduct their self-assessments… The companies that understand how liability works … are not happy.” – A [10:47]
[11:21–16:31]
"[DIBCAC’s] probably going to sit there … ‘Hey, ChatGPT, give me a list of all the conditional CMMC Level 2 statuses that expired yesterday because of POAM closeout.’ And then they’ll call… ‘You want to send me all your documentation?’ That’s exactly what’s going to happen.” – A [16:31]
[18:12–21:05]
[21:05–End]
On the DoD’s reliability:
“Two steps forward, two steps back, right? Apparently that’s just been the theme of the program.” – B [01:46]
On contractor risk:
“The days of simply conducting a self-assessment and needing any score uploaded into the SPRS database are over.” – A [11:34]
On CMMC review cycles:
“They spent a long time going through everything and the changes that came out really didn’t change anything for people that have to comply with DFARS 7012 because they’re different things.” – A [18:59]
On contractor misconception:
“If you are an organization that thinks the DoD is taking their foot off the gas ... you’re going to quickly hear the beeping of the DOJ Brinks truck backing up to your organization.” – B [11:21]
On future compliance traps:
“This is just setting more people up for the same thing.” – A [14:50]
In summary: The suspension buys time, but not relief—contractors are more exposed than ever, and misunderstanding the rules could cost you dearly. Use this pause wisely: get compliant, keep documentation, and don’t underestimate the risk.