CMMC Phase 2 Is Suspended… So Why Is the DoD Still Assessing Contractors?

Jacob and Jason push back on the July 2026 celebration over CMMC Phase 2 being suspended. Their core point: private C3PAO assessments as a condition of award are paused, but government-led DIBCAC assessments never stopped — and if you’re on a critical program, you’re still a target.

Key takeaways:

  • Suspended ≠ off the hook. The DoD CIO memo (read the bottom) says they’ll keep enforcing NIST 800-171 Rev 2 through DIB self-assessments and select government-led assessments. Your requirements and liability are unchanged.
  • DFARS 7012 is the standing authority. That clause has let DIBCAC show up since 2020 — internal to DoD, but still a third party walking into your environment.
  • The LOGZONE case shows the teeth. No whistleblower needed: DIBCAC called on a “perfect” SPRS score, the documentation wasn’t there (score dropped to -170), and the company paid back ~75% of what it was awarded.
  • Targeting isn’t random. Limited DIBCAC capacity goes to implausibly high self-scores, critical technologies/programs (OSD R&E’s list — AI, quantum, hypersonics, etc.), sensitive CUI, and key supply-chain roles. The DoD already knows these companies.
  • It’s basically CMMC 1.0 again. The original 2020 rollout hand-selected critical contracts via the deputy secretary / USD(A&S) — the same selective model the suspension quietly returns to, just renamed. The mechanics and logo change; the philosophy is consistent.
  • If they “want to reduce your burden,” you may be the target. Ironically, the innovative small critical firms are exactly who DIBCAC is most likely to visit — so stay assessment-ready.

Transcript

Jacob: All right, folks. It is July of 2026, and everybody is talking about what the DoD suspended: private third-party assessments as a condition of contract award. But almost nobody is talking about what they didn’t suspend — government-led third-party assessments for the most critical programs, technologies, and controlled data. So yes, third-party C3PAO assessments are currently paused, but DIBCAC government-led assessments? Those are still very much alive. And that raises a fascinating question: if the department still believes that some contractors absolutely need independent verification, how do they decide who those contractors are? And more importantly — are you one of them? That’s what we’re going to talk about today. Jason,

Jason: It’s very easy to read the headlines and just move on. Celebrate. “CMMC is suspended,” never give it another thought. But people really need to read the entire memo, all the way to the bottom. This doesn’t usually apply for everything, but if you read from the back to the front, you get the most valuable knowledge, right? It seems like anything DoD-specific or cybersecurity-specific, that’s the way we go. Immediately when the headlines were released, Jacob, what happened? People ran to the streets in joy, right? “Suspended, phase two suspended, nobody’s going to come in and verify this. Let’s go back to the era of negative SPRS scores being reported and continuously rotating POA&Ms.” And — I don’t think, as we mentioned on last week’s episode, I don’t think people are really grasping what still remains, and how the DoD still intends to seek out people who aren’t complying.

Jacob: Yeah, absolutely. All right, so we’re going to talk about two things here. First, contractors need to be aware that third-party assessments are absolutely still happening. And second, the DoD should probably just go back to the original phased rollout plan under CMMC 1.0 — because that’s essentially what they’re doing right now. All right, let’s get into it.

Here’s the part that people missed. People heard “phase 2 suspended” and assumed the DoD went back to only using self-assessments, at best. That’s not what the entire memo — or even the DoD — is saying in their statements since the announcement last week. So, from the DoD’s CIO memo last week, at the very bottom, they say: interim cyber posture during this suspension — the DoD will continue enforcing baseline compliance with NIST SP 800-171 Rev 2 through DIB self-assessments and select government-led assessments. Later last week, the DoD CIO gave an interview, and in that interview, talking about the suspension, they said, “We also have the ability at any time, based on contractual regulations, to step in and conduct in-person assessments or documentation assessments of our defense industrial base.” She’s talking about good old DFARS 252.204-7012. That is the clause that lets the DoD show up with DIBCAC and just start asking about your cybersecurity posture. It’s been the same since 2020. We did a whole episode about it — check it out, we’ll link it below.

So, recently we also covered the False Claims Act settlement with LOGZONE. The unique thing about that settlement wasn’t just that this company allegedly misrepresented their cybersecurity posture and then got paid for it on a government contract. There was no whistleblower in that case. DIBCAC called them and said, “You have a perfect score. Tell us about your documentation.” They couldn’t. And now they’re writing a check for 75% of the value of what they got paid on those contracts. That’s exactly what the DoD CIO is talking about in this interview. So, like we talked about last week, you’re still liable for all of your requirements in self-assessment. Just because you don’t need a third-party assessment as a condition of award, that doesn’t change any of this. They’re still running these third-party assessments.

Jason: Just — you don’t need a third-party assessment as a widespread, general condition of award right now, right? But Jacob, I think one of the things people quickly glanced over is that when third-party assessments and the suspension of phase two went out the window, they didn’t realize that even though DIBCAC is internal to the Department of Defense, it is still considered a third party that’s coming into your organization and conducting an assessment. The LOGZONE FCA was very timely, because it kind of showed the impact and effects of these situations if things aren’t properly in place when DIBCAC comes calling. And this is the risk that’s been placed on a lot of organizations. But the issue, Jacob — and I hope you’re going to help us determine this — the argument has always been: there’s not enough DIBCAC to go around.

Jacob: Yeah. So let’s get into how they decide here, right? Because they don’t have unlimited DIBCAC assessors. They’ve never had unlimited DIBCAC assessors, especially back in the day under CMMC 1.0, six years ago when this originally started. There are a lot more DIBCAC assessors now — still very limited. So the big question is: okay, you still have the requirements. They won’t make you prove it to get the award, but they’re still going to show up afterwards and conduct a third-party assessment, because there are still situations where they absolutely want assurance — over programs, data, and contractors — that the requirements are being implemented. That’s not everybody, but there’s definitely a subset in the DIB where they care about that. That’s really the reason this program was created in the first place — that’s another story. The question is, how do they decide? How do they know? How do they pick where DIBCAC spends its limited resources? It’s not a random lottery. The DoD is very clear that they still want this assurance over certain programs and data. They don’t have unlimited assessors. So clearly they prioritize this somehow.

Okay, so like we were saying before — DIBCAC started hunting down suspiciously high self-assessment scores once they had extra capacity to do that. Their very limited capacity was not sent out randomly. The DIBCAC High assessments were targeted to critical technologies, critical programs, and things like that. We even heard from the DoD back in the day — circa 2022, at various conferences, including CS2 for those of you who were around back then — that getting a DIBCAC High in-person assessment was a great, if unofficial, indicator that you would receive CMMC Level 3 requirements in the future, because of your criticality, or the criticality of the data you handle, or your place in the supply chain. The department has always known what those things are. They’ve always known who those companies are. They’ve always known where those companies are. That’s been true since before the first CMMC rule was ever written, and it’s still true today.

Jason: So what you’re telling me is that when the DoD came out and said, “We don’t really know how deep the supply chain, or our defense industrial base, is” — part of the defense industrial base that was excluded from that comment was the part that they’re well-versed in: the critical functions, the critical activities, the really crucial contracts, right?

Jacob: Yeah.

Jason: And so they said it, but they kind of downplayed it, which is strange to me. Even — well, “downplaying” — I’m sure they know there’s risk attached to it and things of that nature. One of the things I just thought about, to consider, is that as a prime contractor, you’re responsible for reporting up all the UIDs associated with the contract. So you’re actually delivering on a platter to the DoD: “These are all the organizations working in here. This is our supply chain. If you’re looking for people to assess based off this contract and the risk attached to it — here you go, here’s your solution.”

Jacob: Yes. And the DoD has never known the entirety of the DIB. They’ve never had visibility into the entirety of the DIB — they’ve been talking about this since the 1970s, right? They just don’t know. However, they do know specific supply chains in the DIB very, very well. That is a thing they’ve established for a long, long time. We don’t know exactly how they select what’s critical and what’s not. The Under Secretary of Defense for Research and Engineering — OSD R&E — has a public list of critical technology areas. This is stuff like applied AI, biomanufacturing, contested logistics technologies, anything related to quantum, battlefield information dominance, scaled directed energy weapons, scaled hypersonic systems — things like that have pretty big supply chains. Those are the kinds of things that the department absolutely understands the supply chains for, and, more importantly, are the kinds of things that they absolutely want proof that you are protecting the data when it flows into your non-federal environment.

Is that everybody in the DIB? No. Was everybody in the DIB working on the submarine-launched anti-ship cruise missile known as Sea Dragon, that was compromised by the Chinese MSS — the Ministry of State Security? No. But some were, and they got compromised as a result, and that’s why we’re all having this conversation several years later. So they know who these people are. They know what they want the assurance over. That hasn’t changed. It clearly hasn’t changed, based on the DoD’s own suspension memo and follow-up interviews.

And that gets us to a bigger idea here. One, you might know who you are based off that initial list. But the bigger picture is: isn’t this exactly what they did under CMMC 1.0? Do you guys remember CMMC 1.0 — the original 1.0 phased rollout?

Jason: Oh, you’re right. If you’re on one of these critical programs, “we might select to have your assurance verified.” Wait a minute.

Jacob: Yeah. So, stick with me here, everybody. Let’s do a history lesson. The original CMMC 1.0 had a phased rollout, just like 2.0 has a phased rollout, but it was very different. It was much more selective. For a period of five years, from 2020 to 2025, the only contracts that would have CMMC third-party assessment requirements in them were those that were hand-selected by the deputy secretary of defense, because they were related to critical technologies, programs, data, and contractors. The rule back in 2020 — I know a lot of people didn’t read it back then — said that in order to implement the phased rollout of CMMC, the inclusion of a CMMC requirement in a solicitation during this five-year time period must be approved by the Office of the Under Secretary of Defense for Acquisition and Sustainment, at the direction of the deputy secretary of defense. And only after five years would CMMC apply to all relevant contracts.

The DoD went on in their rulemaking to say that this was specifically designed — this hand-selection according to critical technologies, exactly what we’re currently talking about in the memos and interviews around the suspension — specifically designed to reduce disruptions and burdens. It did exactly what we’re still talking about now. The DoD said the rollout is intended to minimize the financial impacts to the industrial base, especially small entities, and disruption to the existing DoD supply chain. They went on to say that they considered other alternatives to the development of the rule in order to reduce the burden on small entities and still meet the objectives that Congress gave to the department — which included implementing a phased rollout that stipulated that the inclusion of CMMC requirements in new contracts must be approved by the under secretary of defense for acquisition and sustainment, and it would not show up unless that was done.

They know who the contractors are. They know what the contracts are. They know the data. They know the supply chain. They had the plan in 2020. It got delayed through rulemaking. Sounds to me, based off the memo, the DIBCAC activity, and the statements from the DoD, that we’re essentially back in the CMMC 1.0 phased rollout — even though that’s not what they’re saying.

Jason: So essentially where we sit in this suspension is that, at the program management level, the determination was made whether to include it in the contracts. You’re saying now it goes up a higher tier of authorization, instead of the individual programs making the determination on risk — it’s the overseer of all programs that makes that determination.

Jacob: Instead of an individual program manager saying, “I need a CMMC Level 2 certification as a condition of award,” the deputy secretary of defense says, “This critical area matters to us. Hey, under secretary of defense for acquisition and sustainment — the contract people — they need proof that they are implementing their requirements.”

Jason: Is that more of a measure to prevent exclusion in necessary areas, or just to promote inclusion in all the necessary areas? That’s what remains to be seen.

Jacob: Right. They said in their rulemaking in 2020 that if they were to just shotgun out the requirement onto everybody, it would impact the DIB, it would cost money, it would affect small businesses, blah blah blah — and it wouldn’t really… I mean, it would get the critical contractors, but it would get a bunch of other people in collateral damage too. And they were going to give them five years to get ready, for the other people to prove it. But immediately — Sea Dragon, applied AI, hypersonics, quantum, nukes, stuff like that — “we need proof now that you guys are doing these things, because you are the ones that matter the most.” That’s still what the DoD is saying right now. They’re saying, “We’re not going to require third-party assessment as a condition of award for most people in the DIB, but we’re still running government-led assessments. We still can run government assessments.” They clearly still are running government assessments. That’s the phase — that’s the CMMC 1.0 phased rollout, just by a different name.

Jason: And maybe, possibly — and this is all speculatory, right? — but maybe there is still the element of discretion where a program manager can say the risk on this data is higher, “can we have these requirements attached to it?” But that baseline of the ones it necessarily needs to be attached to — the high-dollar, whiz-bang things, as some people would like to say — those are the things the DoD is now obviously completely visual about, and can go in and say, “Hey, we want to make sure this is in place.”

Jacob: Yeah. So, wrapping up here, just so everybody knows: be very aware, third-party assessments are still absolutely happening. If you’re one of those innovative, small, critical companies that they ironically want to reduce the burden on — you’re probably the ones they’re going to show up to and still run the third-party assessment on. And the bigger question from there is: isn’t the CMMC 1.0 phased rollout exactly what we’re doing right now? Maybe after this review, the DoD should just return to the original phased rollout plan, where they hand-select the most critical contracts and contractors that obviously demand assurance.

So, regardless — for six years, the department has consistently treated certain contractors, contracts, and data as deserving of independent verification. Everybody agrees on that. We’ve changed the mechanics several times. We’ve changed the name several times. We’ve changed the color of the logo several times, the number of levels — but the underlying philosophy is remarkably consistent. So the next question is figuring out how those decisions are made, and probably just doing the CMMC 1.0 phased rollout all over again, ironically. Don’t you love it, everybody? Isn’t that great? Isn’t that fun?

Jason: Isn’t it ironic, man?

Jacob: Well, tune in next week, because there’s plenty more to talk about on this little suspension project we’re doing here. We’ve got “brilliant at the basics” to talk about. We’ve got the RFI to talk about. We’ve got maybe what’s going to come out. But for now, just know: third-party assessment still exists, your liability still exists. Check out that episode below. Like and subscribe. We’ll see you next week.

Jason: See you next week.

Contact

Speak With Our Team

Scroll to Top