The Department has done what the Defense Industrial Base has learned to expect whenever a cybersecurity compliance deadline begins to look real: it has changed the plan.
Again.
So, excuse us in advance, because we’re going to take our time, go rather deep in this report, and speculate a bit.
On July 13 th , 2026, the Hon. Kirsten A. Davies, DoW Chief Information Officer announced suspension of the next phase of mandatory third-party CMMC assessments while the Department takes 60 days to review the program’s cost, capacity and impact on small and nontraditional suppliers. Phase I self-assessments remain in place (are you confident in your SPRS score?). And contractors are still expected to protect Controlled Unclassified Information under DFARS and NIST SP 800-171.
So, no, CMMC has not disappeared. It’s not dead (not yet, anyway). It has gone back into the workshop, where government programs traditionally spend several months being renamed, reorganized and refitted with a new acronym.
What’s the reason?
In her announcement Davies was clear:
“To ensure we maintain robust security without the red tape…”
For DIB suppliers, the important message is simple: the certification process may change dramatically, but today’s contractual obligations have not.
First, the Good News:
The Assessment Traffic Jam Has Been Delayed
The current CMMC model was heading toward a fairly obvious capacity problem.
Roughly 100,000 or so companies could eventually require third party assessments, while the accredited assessor community remained far too small to handle that volume. For small and midsize businesses, the cost of preparing for certification could also be substantial—sometimes approaching the price of the contract they were hoping to win.
That is not exactly the streamlined pathway to innovation the Department has in mind.
The Hegseth team appears to have concluded that requiring every company handling CUI to join the same certification queue might slow acquisition, raise costs and push capable suppliers out of the market.
The likely response is a narrower, risk-based system. Third-party assessments may survive for suppliers handling highly sensitive information, supporting mission-critical programs or presenting elevated cyber risk. Other companies may rely on self assessments, automated tools, managed security providers, commercial certifications or government spot checks.
In short, the Department may stop inspecting every passenger’s luggage and focus more heavily on the bags that are ticking.
Now, the Less Exciting News:
DFARS Is Still Very Much Alive
The pause does not change DFARS 252.204-7012.
It does not change the requirement to safeguard covered defense information.
It does not change the requirement to report certain cyber incidents.
And it does not change the current reliance on NIST SP 800-171 Revision 2 as the security baseline for contractors that process, store or transmit CUI.
The same basic compliance package still matters:
- A current System Security Plan
- Implementation of the 110 NIST requirements
- Defensible Plans of Action and Milestones
- An accurate SPRS score
- Evidence showing that the controls described on paper exist in the real world
The government may have postponed the proctored exam. But it has not cancelled the class, changed the textbook or stopped collecting grades.
Prime Contractors Did Not Receive a Hall Pass Either
Prime contractors are still required to manage cybersecurity risk across their supply chains and flow down applicable DFARS clauses to subcontractors.
That matters because many DIB suppliers do not experience government policy directly. They experience it through a portal, questionnaire, spreadsheet or urgent email from a prime contractor.
Even if the Department delays Phase II, primes may continue asking suppliers for NIST assessments, SPRS scores, System Security Plans, POA&Ms, CMMC readiness evidence and contract-specific cybersecurity assurances.
Some primes may decide to relax their requirements. Others may decide that the policy uncertainty is a reason to ask for even more evidence.
Nothing says “simplification” quite like receiving three different compliance questionnaires from three different business units of the same prime.
Suppliers should ask their customers what requirements will apply to new awards, renewals, option exercises and continued access to CUI. A Department-wide pause does not automatically rewrite existing subcontract language or override a prime contractor’s internal risk policy.
The Legal Risk Has Not Taken a Vacation
The absence of a mandatory third-party assessment does not make an inaccurate self-assessment safer.
It may make it more dangerous.
When a supplier submits an SPRS score or represents that it meets contract cybersecurity requirements, the government is relying on that statement. If the score is inflated, unsupported or based on a creative interpretation of the word “implemented,” the company may face contract consequences, loss of eligibility or False Claims Act exposure.
The Department of Justice’s Civil Cyber-Fraud Initiative operates independently of CMMC Phase II. It does not need a C3PAO report to investigate whether a contractor made misleading cybersecurity claims.
Self-assessment therefore does not mean “give yourself the score that feels right.”
It means “be prepared to explain every point to someone who knows in detail what the NIST controls mean.”
Enter “Brilliant at the Basics”
The Department’s “Brilliant at the Basics” guidance offers the clearest clue about where the replacement model may be heading.
Its priorities include phishing-resistant multifactor authentication, accurate asset inventories, network segmentation, vulnerability management, secure AI use, immutable backups, workforce readiness, operational technology protection and supply-chain resilience.
Some of that sounds familiar because it maps directly to NIST SP 800-171. Identity management, access control, configuration management, monitoring and vulnerability remediation are already part of the existing framework.
But “Brilliant at the Basics” also reaches into areas that NIST SP 800-171 Revision 2 handles lightly—or not at all—including AI governance, secure software development, supply-chain risk, operational resilience and OT security.
That creates a very real possibility that the Department is not simply trying to shrink CMMC. It may be preparing to replace the current framework with a broader, more operational set of
cybersecurity outcomes.
The Worst Case: Welcome to “New NIST”
The most disruptive scenario is not that cybersecurity requirements disappear.
It is that the Cyber AB disappears, the C3PAO model is dismantled and the Department replaces the current NIST-based assessment structure with something new inspired by “Brilliant at the Basics.”
Call it “New NIST,” “NIST Plus,” “CMMC 3.0,” or, because history has a sense of humor, “CMMC Simplified.”
Under this scenario, it’s possible (though not necessarily likely) suppliers could spend the next year continuing to comply with DFARS and NIST SP 800-171 while the Department develops an entirely new framework. Changing the existing regulatory and contractual structure would not happen overnight. DFARS clauses, acquisition regulations, solicitations, prime-contractor processes and thousands of subcontracts all rely on the current model.
Indeed, formal change could require rulemaking, contract updates, implementation guidance and another transition schedule. That process could easily take a year or longer.
During that period, the DIB could face two overlapping expectations:
- Continue meeting the current DFARS and NIST requirements because they remain contractually binding.
- Begin preparing for a future framework that adds AI, OT, backup resilience, secure development and supply-chain visibility.
The signs would be obvious. However, this would be the compliance equivalent of rebuilding the aircraft while continuing to fly it, and being asked to submit monthly progress reports on the wing.
What “New NIST” Could Mean in Practice
What Suppliers Should Do Now
DIB suppliers should not try to predict the final acronym. They should invest in capabilities that survive every likely policy outcome.
That means validating NIST SP 800-171 assessments, correcting unsupported SPRS scores, closing high-risk POA&M items and maintaining strong evidence. The framework exists, and it’s still the standard to measure by.
It also means improving the areas most clearly signaled by “Brilliant at the Basics”: multifactor authentication, asset inventory, segmentation, vulnerability management, backups, incident response, OT security, AI governance and supply-chain risk.
Those investments will still matter whether the future includes CMMC, a reduced C3PAO model, government spot checks or “New NIST.”
The Bottom Line:
The Rules Are Still Here, but the Referee May Be Fired
The current requirements remain in force today. DFARS still applies. NIST SP 800-171 still applies. Primes are still flowing requirements down, and changing the regulatory and contractual ecosystem could take a year or more.
The likely outcome is a smaller, more targeted assessment model.
The worst-case outcome is a complete reset: the Cyber AB is eliminated, the third-party structure disappears and the Department builds a broader framework around “Brilliant at the Basics”—leaving suppliers to support the old requirements while preparing for the new ones.
They have, indeed, done it again.
The safest response is not to chase what could be. But doing nothing to wait and see rather than guess and do isn’t the best choice either.
Cybersecurity threats are real, especially from adversaries trying to obtain sensitive information.
The safest response is to build a cybersecurity program that protects CUI, produces defensible evidence and can adapt when Washington inevitably unveils the next simpler framework, complete with perhaps another 400-page implementation guide. Given the change, we hope simpler really means better.
FNI | Get Serious - Get Secure