
Loading summary
A
All right, folks, it is July of 2026 and everybody is talking about what the DoD suspended private third party assessments as a condition of contract award. But almost nobody is talking about what they didn't suspend. Government led third party assessments for the most critical programs, technologies and controlled data. So yes, third party C3PAO assessments are currently paused, but DIBCAC, government led assessments, those are still very much alive. And that raises a fascinating question. If the department still believes that some contractors absolutely need independent verification, how do they decide who those contractors are? And more importantly, are you one of them? And that's what we're going to talk about today. Jason, it's very easy to read the headlines and just move on. Celebrate CMMC is suspended. Never give it another thought. But people really need to read the entire memo all the way to the bottom.
B
This doesn't usually apply for everything, but if you read from the back to the front, you get the most valuable knowledge. Right? It seems like anything DoD specific or Cybersecurity specific. Specific. That's the way that we go immediately when the headlines were released, Jacob, what happened where people ran to the streets? Enjoy. Right? Suspended. Phase two suspended. Nobody's going to come in and verify this. Let's go back to the era of negative NIST scores being reported and continuously rotating poams and they. I don't think, as we mentioned on last week's episode, I don't think people are really grasping what still remains and how the Dow still intends to seek out people who aren't compliant.
A
Yeah, absolutely. All right, so we're going to talk about two things here. First, contractors need to be aware that third party assessments are absolutely still happening. And second, the DoD should probably just go back to the original phased rollout plan under CMMC 1.0, because that's essentially what they're doing right now. All right, let's get into it. Here's the part that people missed. People hear, people heard phase two suspended and they assume that the DoD went back to only using self assessments at best. That's not what the entire memo or even the DoD is saying in their statements since the announcement last week. So from the DoD's CIO memo last week, at the very bottom, they say interim cyber posture. During this suspension, the DoD will continue enforcing baseline compliance with NIST SP 800, 171 Rev 2 through DIB self assessments and select government led assessments. Later last week, the DOD CIO gave an interview and in that interview, talking about the suspension, they said, we also have the ability at any time based on contractual regulations to step in and conduct in person assessments or documentation assessments of our defense industrial base. She's talking about good old DFARS 252-204-7020. That is the clause that lets the DoD show up with DIBCAC and just start asking about your cyber security posture. It's been the same since 2020. We did a whole episode about it. Check it out. We'll link it below. So recently we also covered the False Claims act settlement with Log Zone. The unique thing about that False Claims act settlement wasn't just that this company allegedly misrepresented their cyber security posture and then got paid for it on a government contract. There was no whistleblower in that case. DIBCAC called them and said, you have a perfect score. Tell us about your documentation. They couldn't. And now they're writing a check for 75% of the value of what they got paid for on those contracts. That's exactly what the DOD CIO is talking about in this interview. So like we talked about last week, you're still liable for all of your requirements and self assessment. But just because you don't need a third party assessment as a condition of award, that doesn't change any of this. They're still running these third party assessments.
B
Just you don't need third party assessment as a widespread general conditioners award right now. Right. But Jacob, I, I think that one of the things that people quickly glanced over is when third party assessments and the suspension of phase two went out the window, they didn't realize that even though DIBCAC is internal to the Department of Defense. Right. That it is still considered a third party that's coming into your organization and conducting an assessment. The Log Zone FCA was very timely because it kind of showed the impact and effects of these kind of situations. And, and if things aren't properly, you know, in place when DIBCAT comes a calling and this is the risk that's been placed on a lot of organizations. But the issue, Jacob, and I hope that you're going to help us determine this is the argument has always been there's not enough DIBCAC to go around.
A
Yeah. So let's get into how they decide here. Right. Because they don't have unlimited DIBCAC assessors. They've never had unlimited DIBCAC assessors, especially back in the day under CMMC 1.06 years ago when this originally started. There's a lot more DIBCAC assessors now, still very limited. So the big question here is like, okay, you still have the requirements, they won't make you prove it to get the award, but they're still going to show up afterwards and still conduct a third party assessment. Because there are still situations where they absolutely want assurance over programs, data contractors, that the requirements are being implemented. That's not everybody, but there's definitely a subset in the DIB where they care about that. That's really the reason why this program was created in the first place. That's another story. The question is how do they decide? How do they know? How do they pick where DIBCAC spends its limited resources? It's not a random lottery. The DoD very clear that they still want this assurance over certain programs and data. They don't have unlimited assessors, so clearly they prioritize this somehow. Okay, so like we were saying before, DIBCAC started hunting down suspiciously high self assessment scores once they had extra capacity to be able to do that, they're very, very limited capacity was not sent out randomly. The DIBCAC high assessments were targeted to critical technologies, critical programs and things like that. We even heard from the DoD back in the day, circa 2022 at various conferences, including CS2 for those of you that were around back then, that getting a DIBCAC high in person assessment was a great if unofficial indicator that you would Receive CMMC Level 3 requirements in the future because of your criticality or the criticality of the data that you handle, or your place in the supply chain. The department has always known what those things are. They've always known who those companies are, they've always known where those companies are. That's been true since before the first CMMC rule was ever written and it's still true today.
B
So what you're telling me is, is that when the Dow came out and said we don't really know how deep the supply chain is, or our defense industrial base is part of the part or part of the defense industrial base that was excluded from that comment was the part that they're well versed in the critical functions, the critical activities, the really crucial contracts. Right?
A
Yeah. And so they said it, but they kind of downplayed it. Which is strange to me.
B
Even if, you know, like downplaying, I'm sure that they know there's risk attached to it and things of that nature. Even, even if one of the things that I just thought about to consider is that as a prime contractor you're responsible for reporting up all the UIDs associated with the contract. So you're actually delivering on a platter to The Dow. These are all the organizations working in here. This is our supply chain. If you're looking for people to, to assess based off of this contract and the risk attached to it. Here you go.
A
Your and the DOD has never known the entirety of the dip. They've never had visibility into the entirety of the dip. They haven't had visibility into the entire. They've been talking about this since the 1970s. Right. They just don't know. However, they do know specific supply chains in the DIB very, very well. Right. That is a thing that they've established for a long, long time. We don't know exactly how they select what's critical and what's not. The Undersecretary of Defense for research and engineering, OSDR&E has a public list of critical technology areas. This is stuff like applied AI biomanufacturing, contested logistics technologies, anything related to quantum battlefield information dominance, scaled directed energy weapons, scaled hypersonic systems, things like that have pretty big supply chains. Those are the kinds of things that the department absolutely understands the supply chains for. And more importantly are the kinds of things that they absolutely want proof that you are protecting the data when it flows into your non federal environment. Is that everybody in the dib? No. Was everybody in the DIB working on the submarine launched hypersonic anti ship cruise missile known as Sea Dragon that was compromised by the Chinese Ministry of mss, Ministry of State Security? No, but some were and they got compromised as a result. And that's why we're all having this conversation several years later. So they know who these people are, they know what they want. The assurance over that hasn't changed. It clearly hasn't changed based on Deity's own suspension memo and follow up interviews after the memo. And that gets us to a bigger idea here. Well one, you might know who you are based off that initial list. But the bigger picture here is isn't this exactly what they did under CMMC 1.0? Do you guys remember CMMC 1.0 in the original 1.0 phased rollout?
B
Oh, you're right. If you're on one of these critical programs, we might select to have your assurance verif. Wait a minute.
A
Yeah, so you know, stick with me here. Everybody, let's let's history lesson. The original CMC 1.0 had a phased rollout just like 2.0 has a phase rollout. But it was very different. It was much more selective. So for a period of five years from 2020 to 2025, the only contracts that would have CMMC third party assessment requirements in them were those that were hand selected by the Deputy Secretary of Defense because they were related to Critical Technologies programs, data and contractors. The rule back in 2020, I know a lot of people didn't read it back then, said in order to implement the phased rollout of cmmc, the inclusion of a CMMC requirement in a solicitation during this five year time period must be approved by the Office of the Undersecretary of of Defense for Acquisition and Sustainment at the direction of the Deputy Secretary of Defense. And only after five years of time would CMMC apply to all relevant contracts. The DoD went on in their rulemaking to say that it was specifically designed as hand selected according to Critical Technologies. Exactly what we're currently talking about in the memos and the interviews around the suspension was specifically designed to reduce disruptions and burdens on the dib. Exactly what we're still talking about now. The DoD said the rollout is intended to minimize the financial impacts to the industrial base, especially small entities, and disruption to the existing DoD supply chain. They went on to say that they considered other alternatives to the development of the rule in order to reduce the burden on small entities and still meet the objectives that Congress gave to the Department. Department, which included implementing a phased rollout that stipulated that the inclusion of CMMC requirements in new contracts must be approved by the Undersecretary of Defense for acquisition and Sustainment. And it would not show up unless that was done. They know who the contractors are, they know who the contracts, what the contracts are, they know the data, they know the supply chain. They had the plan in 2020. It got delayed through rulemaking. Sounds to me based off the memo DIBCAC activity, the statements from the DoD that we're essentially back in the CMMC 1.0 phased rollout, even though that's not what they're saying.
B
So essentially where we sit in this suspension is that at the program management level, the determination was made whether to include it in the contracts.
A
Right.
B
You're saying now it goes up a higher tier of authorization. Instead of the individual programs making the determination on risk, it's the overseer of all programs that makes that determination.
A
Instead of individual program manager saying I need a CMMC Level 2 certification as a condition of award. The Deputy Secretary of Defense says this critical area matters to us. Hey, under Secretary of Defense for Acquisition and Sustainment, that contract people need proof that they are implementing their requirements.
B
Is that more of a measure to prevent exclusion in necessary areas or just to promote inclusion in all the necessary areas? That's what remains to be seen. Right.
A
They said in their rulemaking in 2020 that if they were to just shotgun out the requirement onto everybody that it would impact the div, it would cost money, it would affect small businesses, blah, blah, blah. And it wouldn't really, I mean it would get the critical contractors, but it would get a bunch of other people in collateral damage too. And they were going to give them five years to get ready for the other people to prove it. But immediately SeaDragon, applied AI hypersonics, quantum nukes, stuff like that. We need proof now that you guys are doing these things because you are the ones that matter the most. That's still what the DoD is saying right now. They're saying we're not going to require third party assessment as a condition of award for most people in the dib. But we're still running government led assessments. We still can run government led assessments. They clearly still are running government led assessments. That's the phase, that's the CMMC 1.0
B
phased rollout, just by a different name and maybe, possibly. And then this is just all speculatory. Right. But maybe there is still the element of discretion where a program manager can say that the risk on this data is higher, can we have these requirements attached to it? But that baseline of the ones that it necessarily needs to be attached to the high dollar whiz bang things that some people would like to say. Right. Those are the things in which the Dow is now obviously completely visual about and can go in and hey, we want to make sure that this is in place.
A
Yeah. So wrapping up here, just that everybody knows, be very aware, third party assessments still absolutely happening. If you're one of those innovative, small, critical companies that they ironically want to reduce the burden on, you're probably the ones that they're going to show up to still run the third party assessment on. And the bigger question from there is, isn't the CMC 1.0 phase rollout exactly what we're doing right now? Maybe after this review the DoD should just return to the original phased rollout plan where they hand select the most critical contracts and contractors that obviously demand assurance. So regardless, for six years the department has consistently treated subcontracts, contractors and data as deserving of independent verification. Everybody agrees on that. We've changed the mechanics several times, we've changed the name several times, we've changed the color of the logo several times, the number of levels. But the underlying philosophy is remarkably consistent. So the next question is figuring out how those questions are made and probably just doing the CMMC1 1.0 phase rollout all over again, ironically. Don't you love it, everybody? Isn't that great? Isn't that fun?
B
Isn't it ironic, man?
A
Well, tune in next week because there's plenty more to talk about on the, on the, the. This little suspension project that we're doing here. We got brilliant at the basics. We got to talk about, we got the RFI we got to talk about, we got maybe what's going to come out. But for now, just know third party assessment still exists. Your liability still exists. Check out that episode below. Like and subscribe. We'll see. See you next week.
B
See you next week.
Episode Title: CMMC Phase 2 Is Suspended... So Why Is the DoD Still Assessing Contractors?
Date: July 23, 2026
Host: Summit 7
This episode dissects the recent suspension of private third-party CMMC (Cybersecurity Maturity Model Certification) assessments as a condition of Department of Defense (DoD) contract awards. While the headline news is about a “pause” in these assessments, the hosts dive into what has not been suspended: selective, government-led assessments (specifically DIBCAC), especially for contractors handling critical technologies and data. The discussion illuminates the continuity in how DoD manages cyber assurance over sensitive programs, arguing that—despite the branding—the current approach mirrors the original CMMC 1.0 phased rollout.
For deeper dives mentioned in the episode—including past coverage of the DFARS clause, DIBCAC enforcement, and False Claims Act cases—refer to previously linked episodes from the Sum IT Up podcast archive.
Tune in next week for more on the ongoing evolution (and recursion) of CMMC compliance in the defense industry!