Read the News Again, Carefully
On July 13, 2026, the Pentagon suspended CMMC Phase 2 — the third-party certification assessments scheduled to begin with the November 10, 2026 transition — and stood up a reform task force to conduct a 60-day, top-to-bottom review of the program, citing compliance costs and bureaucratic burden on the industrial base. An accompanying request for information invited industry comment, and the task force’s final report is due in mid-September 2026.
If you run a small defense subcontractor, you may have read that news with relief. Read it again.
The suspension removed the auditor. It did not remove a single obligation.
What’s Still in Force
Every contract clause that actually binds you survived the suspension intact:
- DFARS 252.204-7012 still requires you to implement NIST SP 800-171 to safeguard Controlled Unclassified Information — and to report cyber incidents to the Department through DIBNet within 72 hours of discovery.
- DFARS 252.204-7019 and -7020 still require a current NIST SP 800-171 self-assessment score posted in the Supplier Performance Risk System (SPRS), and the Government’s right to conduct higher-level assessments.
- CMMC Phase 1 self-assessments continue under existing terms, with an annual affirmation of compliance signed by a senior company official.
- Flow-down obligations to your own subcontractors are unchanged. If you pass CUI down, you pass the clause down with it.
Here is what actually changed, and it matters more than most coverage acknowledges: with third-party assessments on hold, your self-assessment is now the entire compliance record.
Think about what a C3PAO assessment would have done for you, apart from creating work. It would have validated your score. It would have caught the honest mistake — the control your MSP told you was implemented and is not, the requirement your team read differently than an assessor would. It would have distributed responsibility for the resulting number across an accredited third party and a formal methodology.
None of that exists right now. The affirmation your senior official signs in SPRS is a representation to the federal government, made without an independent check, about the state of controls that official probably cannot personally verify. That is precisely the fact pattern the Department of Justice has pursued under the False Claims Act through its Civil Cyber-Fraud Initiative — cases built not on breaches, but on the gap between what a contractor certified and what was actually running. Several of those matters have resolved for seven-figure sums against companies far smaller than the prime contractors people picture.
The suspension did not lower your exposure. It concentrated it.
What the Pause Did and Didn’t Do
- Paused: Phase 2 third-party (C3PAO) assessments and the November 10, 2026 transition milestone.
- Not paused: DFARS 7012 implementation of NIST SP 800-171 and 72-hour DIBNet incident reporting.
- Not paused: SPRS scores, annual senior-official affirmations, and flow-down to your subcontractors.
- Not paused: False Claims Act liability for a score that does not match reality.
- Pending: The reform task force’s report, due mid-September 2026. Some form of verification is coming back.
The Three Requirement Families a Small Firm Cannot Staff
Most of NIST SP 800-171’s 110 requirements are things a competent MSP can configure once and maintain: access control, encryption in transit and at rest, patching cadence, media protection, physical security. They are checkable states. Someone sets them, someone verifies them, they stay set.
But three families are not configurations. They are operations — ongoing activities that assume someone is watching, every day, including the days nobody is in the office.
3.3 — Audit and Accountability
You must create audit logs, retain them, protect them from unauthorized modification, correlate them enough to support investigation, and — this is the part that fails in self-assessments — review them. Requirement 3.3.5 expects audit record review, analysis, and reporting processes that support the investigation of suspicious activity. A folder of unread logs is evidence of the control’s absence, not its presence. Retention alone satisfies nothing; the requirement is about the reviewing.
3.6 — Incident Response
You need an operational incident-handling capability spanning preparation, detection, analysis, containment, recovery, and user response activities — and you need to test it. This family is what feeds the 72-hour DIBNet clock in 7012. The clock starts at discovery, which is a word doing enormous work: you cannot report an incident within 72 hours of discovery if nothing in your environment is positioned to discover it. A contractor with no detection capability does not have a 72-hour problem. It has an indefinite one, ending whenever a customer or a federal agency tells them.
3.14 — System and Information Integrity
You must identify and correct flaws, protect against malicious code, monitor your systems — including inbound and outbound communications traffic — to detect attacks and indicators of potential attacks, and act on alerts and advisories in a timely manner. “We have an EDR that generates alerts” satisfies the tooling half. Someone dispositioning those alerts satisfies the requirement.
The Arithmetic Behind the Gap
For a 10- or 20-person engineering, machining, or consulting firm, the honest math is unforgiving.
Continuous monitoring is a 24/7/365 function. Covering it with people means roughly three to five full-time analysts once you account for shifts, coverage, holidays, and turnover — more than most small subcontractors spend on their entire IT function, and a hiring problem in a labor market where cleared or experienced analysts are competing for defense-prime salaries.
So the pattern repeats across the industrial base. The firm buys tooling, because tooling is purchasable. The tooling generates alerts into a console. The console is checked when someone remembers, or when something breaks. The controls get scored as implemented in SPRS on the strength of the tool being installed — which is not a lie anyone tells cynically; it is what “implemented” feels like when you have bought the thing the requirement names. And the operational half of the requirement — the reviewing, the dispositioning, the investigating, the timely acting — goes unperformed.
That gap has a specific way of surfacing. It surfaces after an incident, when investigators reconstruct the timeline and establish what your logs showed, when they showed it, and that nobody looked. At that point the question stops being technical and becomes a question about the accuracy of a signed affirmation.
Two Ways to Score 3.3.5 as “Implemented”
- The way that fails: Logging is enabled across endpoints and the domain. Retention is 90 days. Nobody has opened the log console since it was configured. The requirement is scored implemented because the capability exists.
- The way that holds: Every alert the environment produces is triaged, analyzed, and dispositioned with recorded reasoning. The record shows what was reviewed, when, what was concluded, and what was escalated — continuously, with dates. The requirement is scored implemented because the activity happened and can be produced on request.
- The difference at assessment time: One of these is a screenshot of a settings page. The other is an evidence package.
Small Subcontractors Are Not Low-Value Targets
There is a persistent assumption in the lower tiers of the defense supply chain that nobody is interested in a 15-person shop. The targeting record says otherwise, and the logic is straightforward: adversaries interested in a weapons program do not attack the prime with the mature security organization. They attack the sub that machines a component, holds the drawings, and shares an email thread with the prime’s engineering team.
CUI concentrates in exactly those places — technical data packages, specifications, test results, delivery schedules — and it sits in environments defended by a firm whose competitive advantage is precision manufacturing, not intrusion detection. State-sponsored campaigns against defense-adjacent industry have repeatedly favored long, quiet residency over fast smash-and-grab operations, which is a strategy that only works against organizations where nobody reviews activity logs. We have written about that pattern in the context of five-year dwell times inside US critical infrastructure, and the structural failure is identical: the alerts fired, and the investigation never happened.
The 72-hour DIBNet clock exists because the Department knows this. It is not a paperwork requirement. It is an attempt to compress the time between compromise and awareness across a supply chain where that interval has historically been measured in months.
What Intruex Does About It
Intruex is an AI security operations platform: a coordinated team of specialist AI analysts that connects to the security tooling you already run — leading SIEM and EDR platforms, or nearly any log source via a standards-based REST interface — and investigates every alert your environment produces.
Mapped to the requirements above:
- Every alert investigated, every verdict explained (3.3, 3.14). Each alert is triaged, enriched with threat intelligence, and dispositioned with a confidence level and plain-language reasoning. Nothing sits unread. The platform’s audit trail — who or what acted on each alert, when, and why, with the full investigation record preserved — is itself the documented, reviewable record 3.3 expects you to produce, and the “timely action on alerts” that 3.14 asks for.
- Detection that feeds your 72-hour clock (3.6, DFARS 7012). Genuine threats are escalated to your team with a complete investigation package: what happened, what is affected, what the evidence shows, and what the recommended response is. That is the input your incident-response process — and your DIBNet report — needs, in minutes rather than whenever someone next checks a queue.
- Compliance-aware reporting. Intruex maps monitoring activity to major control frameworks, including NIST alignment, through a unified control catalog that spans frameworks rather than requiring a separate mapping exercise per standard. Demonstrating that log review and system monitoring actually happen becomes a report you pull, not a scramble you perform before an assessment.
- Deployment that matches defense work. The platform runs in Intruex’s cloud, self-hosted in an environment you control — including AWS GovCloud — or on an air-gap-capable architecture using local model inference with no external LLM calls. Your alert data can stay inside a boundary you define, which is often the first question a subcontractor handling CUI asks about any new platform.
- Humans stay in charge. Response actions are recommendation-first and approval-gated. The one autonomous behavior — closing high-confidence benign alerts — is opt-in, threshold-controlled, and fully audited. For a compliance posture built on individual accountability and signed affirmations, that design is the point rather than a limitation.
What to Do Before the Task Force Reports
- Re-score 3.3, 3.6, and 3.14 honestly. For each, write down the name of the person who performs the activity and the date it last happened. Where you cannot, you have found a scoring error while you still have time to fix it rather than explain it.
- Update your SPRS score if the honest re-score changes it. A corrected score you fixed voluntarily is a fundamentally different fact than an overstated score discovered later.
- Confirm your System Security Plan and POA&M reflect reality, with dated remediation milestones you are actually working.
- Test the DIBNet path before you need it. Confirm you have a medium assurance certificate, know who reports, and know what information the report requires. Discovering that at hour 60 of a 72-hour window is its own incident.
- Check what your MSP contract actually covers. Most managed IT agreements cover availability and patching, not alert investigation. Read the SOW rather than assuming.
- Verify your own flow-downs. Your subcontractors’ obligations are your exposure too.
The Window Is the Opportunity
The reform review will conclude, and some form of external verification will return — the Department has framed the review as reducing burden, not abandoning assurance. When it does, the subcontractors in the best position will be the ones whose self-assessment scores were true all along: firms that can show a working audit-review practice, a monitored environment, and an incident-response capability that has actually operated on a real alert.
If your SPRS score currently claims 3.3, 3.6, and 3.14 on the strength of installed tools and good intentions, this window is the cheapest time you will ever have to make those claims true. Right now the gap is a project. After an incident, or after an assessment regime returns, it is a finding.
The Core Question
Your senior official signs an annual affirmation that your NIST SP 800-171 implementation is accurately represented. For requirements 3.3.5, 3.6.1, and 3.14.6 — audit review, incident handling, and system monitoring — what evidence would that official point to if asked to substantiate the signature this afternoon? If the answer is a list of installed products rather than a record of activity performed, the affirmation is describing a capability the firm owns rather than one it operates.
Sources: DoD memoranda of July 13, 2026 suspending CMMC Phase 2 implementation deadlines and establishing a 60-day reform review, with the task force report due mid-September 2026, as reported by Federal News Network, Washington Technology, and analyses from Greenberg Traurig, Crowell & Moring, and Holland & Knight. DFARS 252.204-7012, -7019, and -7020. NIST SP 800-171 requirement families 3.3, 3.6, and 3.14. DOJ Civil Cyber-Fraud Initiative. Program status was accurate as of publication on August 9, 2026 and is subject to change as the review concludes. This article is informational and is not legal advice.