CMMC Phase 2 is suspended but the requirements are not

Gettyimages.com/bixpicture

Find opportunities — and win them.

Contractors supporting the department’s most sensitive missions still must be prepared to prove their cybersecurity posture, writes Jason Sproesser of Summit 7.

Everyone is talking about the Defense Department’s decision to suspend CMMC third-party assessments as a condition of contract award. But far less attention has been paid to what the department hasn’t suspended.

Government-led third-party assessments remain in place for the department’s most critical programs, technologies, and controlled data. C3PAO assessments are paused, but assessments conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) are still very much alive.

This raises an important question for every defense contractor. If the department still believes that some contractors require independent verification, how does it decide which ones they are? More importantly, could your company be one of them?

Read the Memo All the Way to the Bottom

When the DOD’s memo was released on July 13, much of the industrial base saw “Phase 2 suspended” and assumed the department had returned to relying primarily on self-assessments. But that isn’t what the entire memo actually says, or how department officials have explained it since.

The relevant language appears at the very end, under Interim Cyber Posture: “During this suspension, the Department will continue enforcing baseline compliance with NIST SP 800-171 Rev. 2 through DIB self-assessments and select government-led assessments…”

In a follow-up interview, DOD CIO Kirsten Davies was even more direct. The department has the authority at any time to conduct in-person or documentation-based assessments of defense contractors.

What Davies was describing is DFARS 252.204-7020. It is the clause that allows the department to show up with DIBCAC and evaluate your cybersecurity posture, and it has remained unchanged since 2020.

While contractors no longer need a C3PAO assessment as a condition of contract award, they remain responsible for meeting the same cybersecurity requirements and for the accuracy of the compliance information they report. The recent LOGZONE settlement is a reminder that DIBCAC can initiate assessments on its own, without waiting for a whistleblower.

How DIBCAC Decides Where to Spend Limited Resources

The practical constraint is that there just isn’t enough DIBCAC to go around. Since it doesn’t have the capacity to assess every contractor in the defense industrial base (DIB), how does it decide which companies to target?

While the department has never published a formal methodology for selecting assessment targets, its actions over the past several years point to a consistent set of risk indicators:

  • Self-assessment scores that appear implausibly high relative to the organization and warrant additional scrutiny.
  • Participation in critical technologies or strategically important defense programs.
  • Responsibility for particularly sensitive controlled unclassified information (CUI).
  • A critical role within the defense supply chain.

DIBCAC is not selecting contractors at random. It relies on a risk-based approach, directing its limited assessment resources toward organizations where the consequences of inadequate cybersecurity would have the greatest impact on national security.

The Department Knows These Supply Chains

While the DOD has never had visibility into every corner of the DIB, it has extensive visibility into the supply chains supporting its highest-priority missions. It knows the critical functions, the critical activities, and the contracts that support them.

The Under Secretary of Defense for Research and Engineering maintains a public list of critical technology areas, including applied AI, biomanufacturing, contested logistics technologies, quantum, battlefield information dominance, scaled directed energy weapons, and scaled hypersonic systems. These programs are where the department wants assurance that its data remains protected after it leaves government networks.

There is another factor that smaller contractors often overlook. Prime contractors are responsible for reporting the unique identifiers associated with their contracts. As a result, the department already has a detailed map of the organizations supporting a given program and the level of risk associated with that work. If the department is deciding where to send assessors, much of that map already exists.

A Familiar Model

What’s striking is how closely today’s approach resembles the department's original vision for CMMC.

CMMC 1.0 was envisioned as a phased rollout with a selective criteria. It called for third-party assessments to begin with carefully selected contracts involving critical technologies, sensitive data, and strategically important programs before eventually expanding more broadly. This phased approach was intended to minimize disruption to the industrial base while obtaining the highest level of assurance where it mattered most.

Today’s implementation follows a similar philosophy. Rather than allowing individual programs to require third-party certification as a condition of award, the department is deciding where independent verification is most important and directing its limited assessment resources accordingly.

For contractors, the distinction is significant. Instead of a requirement that simply applies to your contract, you may be selected because of the work you perform. This is a targeted, risk-based model, and it closely resembles the one the department envisioned in 2020.

What Contractors Should Do Now

If your company supports critical technologies, handles sensitive CUI, or plays an important role in a priority defense program, you should assume a DIBCAC assessment remains a realistic possibility.

Third-party assessments still exist, and so does your liability.

Before DIBCAC asks the questions, make sure you can answer them:

  • Could we produce evidence supporting every NIST SP 800-171 control we’ve implemented?
  • Are our supplier performance risk system (SPRS) score and compliance assertions fully supported by documentation?
  • If DIBCAC contacted us tomorrow, could we demonstrate compliance rather than simply claim it?

The mechanics may change, but the expectation remains the same: contractors supporting the department’s most sensitive missions must be prepared to prove their cybersecurity posture. That means implementing NIST SP 800-171, maintaining documentation that substantiates compliance, and ensuring written policies match operational reality.