Read the News Again, Carefully

On July 13, 2026, the Pentagon suspended CMMC Phase 2 — the third-party certification assessments scheduled to begin with the November 10, 2026 transition — and stood up a reform task force to conduct a 60-day, top-to-bottom review of the program, citing compliance costs and bureaucratic burden on the industrial base. An accompanying request for information invited industry comment, and the task force’s final report is due in mid-September 2026.

If you run a small defense subcontractor, you may have read that news with relief. Read it again.

The suspension removed the auditor. It did not remove a single obligation.

What’s Still in Force

Every contract clause that actually binds you survived the suspension intact:

Here is what actually changed, and it matters more than most coverage acknowledges: with third-party assessments on hold, your self-assessment is now the entire compliance record.

Think about what a C3PAO assessment would have done for you, apart from creating work. It would have validated your score. It would have caught the honest mistake — the control your MSP told you was implemented and is not, the requirement your team read differently than an assessor would. It would have distributed responsibility for the resulting number across an accredited third party and a formal methodology.

None of that exists right now. The affirmation your senior official signs in SPRS is a representation to the federal government, made without an independent check, about the state of controls that official probably cannot personally verify. That is precisely the fact pattern the Department of Justice has pursued under the False Claims Act through its Civil Cyber-Fraud Initiative — cases built not on breaches, but on the gap between what a contractor certified and what was actually running. Several of those matters have resolved for seven-figure sums against companies far smaller than the prime contractors people picture.

The suspension did not lower your exposure. It concentrated it.

What the Pause Did and Didn’t Do

  • Paused: Phase 2 third-party (C3PAO) assessments and the November 10, 2026 transition milestone.
  • Not paused: DFARS 7012 implementation of NIST SP 800-171 and 72-hour DIBNet incident reporting.
  • Not paused: SPRS scores, annual senior-official affirmations, and flow-down to your subcontractors.
  • Not paused: False Claims Act liability for a score that does not match reality.
  • Pending: The reform task force’s report, due mid-September 2026. Some form of verification is coming back.

The Three Requirement Families a Small Firm Cannot Staff

Most of NIST SP 800-171’s 110 requirements are things a competent MSP can configure once and maintain: access control, encryption in transit and at rest, patching cadence, media protection, physical security. They are checkable states. Someone sets them, someone verifies them, they stay set.

But three families are not configurations. They are operations — ongoing activities that assume someone is watching, every day, including the days nobody is in the office.

3.3 — Audit and Accountability

You must create audit logs, retain them, protect them from unauthorized modification, correlate them enough to support investigation, and — this is the part that fails in self-assessments — review them. Requirement 3.3.5 expects audit record review, analysis, and reporting processes that support the investigation of suspicious activity. A folder of unread logs is evidence of the control’s absence, not its presence. Retention alone satisfies nothing; the requirement is about the reviewing.

3.6 — Incident Response

You need an operational incident-handling capability spanning preparation, detection, analysis, containment, recovery, and user response activities — and you need to test it. This family is what feeds the 72-hour DIBNet clock in 7012. The clock starts at discovery, which is a word doing enormous work: you cannot report an incident within 72 hours of discovery if nothing in your environment is positioned to discover it. A contractor with no detection capability does not have a 72-hour problem. It has an indefinite one, ending whenever a customer or a federal agency tells them.

3.14 — System and Information Integrity

You must identify and correct flaws, protect against malicious code, monitor your systems — including inbound and outbound communications traffic — to detect attacks and indicators of potential attacks, and act on alerts and advisories in a timely manner. “We have an EDR that generates alerts” satisfies the tooling half. Someone dispositioning those alerts satisfies the requirement.

The Arithmetic Behind the Gap

For a 10- or 20-person engineering, machining, or consulting firm, the honest math is unforgiving.

Continuous monitoring is a 24/7/365 function. Covering it with people means roughly three to five full-time analysts once you account for shifts, coverage, holidays, and turnover — more than most small subcontractors spend on their entire IT function, and a hiring problem in a labor market where cleared or experienced analysts are competing for defense-prime salaries.

So the pattern repeats across the industrial base. The firm buys tooling, because tooling is purchasable. The tooling generates alerts into a console. The console is checked when someone remembers, or when something breaks. The controls get scored as implemented in SPRS on the strength of the tool being installed — which is not a lie anyone tells cynically; it is what “implemented” feels like when you have bought the thing the requirement names. And the operational half of the requirement — the reviewing, the dispositioning, the investigating, the timely acting — goes unperformed.

That gap has a specific way of surfacing. It surfaces after an incident, when investigators reconstruct the timeline and establish what your logs showed, when they showed it, and that nobody looked. At that point the question stops being technical and becomes a question about the accuracy of a signed affirmation.

Two Ways to Score 3.3.5 as “Implemented”

  • The way that fails: Logging is enabled across endpoints and the domain. Retention is 90 days. Nobody has opened the log console since it was configured. The requirement is scored implemented because the capability exists.
  • The way that holds: Every alert the environment produces is triaged, analyzed, and dispositioned with recorded reasoning. The record shows what was reviewed, when, what was concluded, and what was escalated — continuously, with dates. The requirement is scored implemented because the activity happened and can be produced on request.
  • The difference at assessment time: One of these is a screenshot of a settings page. The other is an evidence package.

Small Subcontractors Are Not Low-Value Targets

There is a persistent assumption in the lower tiers of the defense supply chain that nobody is interested in a 15-person shop. The targeting record says otherwise, and the logic is straightforward: adversaries interested in a weapons program do not attack the prime with the mature security organization. They attack the sub that machines a component, holds the drawings, and shares an email thread with the prime’s engineering team.

CUI concentrates in exactly those places — technical data packages, specifications, test results, delivery schedules — and it sits in environments defended by a firm whose competitive advantage is precision manufacturing, not intrusion detection. State-sponsored campaigns against defense-adjacent industry have repeatedly favored long, quiet residency over fast smash-and-grab operations, which is a strategy that only works against organizations where nobody reviews activity logs. We have written about that pattern in the context of five-year dwell times inside US critical infrastructure, and the structural failure is identical: the alerts fired, and the investigation never happened.

The 72-hour DIBNet clock exists because the Department knows this. It is not a paperwork requirement. It is an attempt to compress the time between compromise and awareness across a supply chain where that interval has historically been measured in months.

What Intruex Does About It

Intruex is an AI security operations platform: a coordinated team of specialist AI analysts that connects to the security tooling you already run — leading SIEM and EDR platforms, or nearly any log source via a standards-based REST interface — and investigates every alert your environment produces.

Mapped to the requirements above:

What to Do Before the Task Force Reports

The Window Is the Opportunity

The reform review will conclude, and some form of external verification will return — the Department has framed the review as reducing burden, not abandoning assurance. When it does, the subcontractors in the best position will be the ones whose self-assessment scores were true all along: firms that can show a working audit-review practice, a monitored environment, and an incident-response capability that has actually operated on a real alert.

If your SPRS score currently claims 3.3, 3.6, and 3.14 on the strength of installed tools and good intentions, this window is the cheapest time you will ever have to make those claims true. Right now the gap is a project. After an incident, or after an assessment regime returns, it is a finding.

The Core Question

Your senior official signs an annual affirmation that your NIST SP 800-171 implementation is accurately represented. For requirements 3.3.5, 3.6.1, and 3.14.6 — audit review, incident handling, and system monitoring — what evidence would that official point to if asked to substantiate the signature this afternoon? If the answer is a list of installed products rather than a record of activity performed, the affirmation is describing a capability the firm owns rather than one it operates.

Sources: DoD memoranda of July 13, 2026 suspending CMMC Phase 2 implementation deadlines and establishing a 60-day reform review, with the task force report due mid-September 2026, as reported by Federal News Network, Washington Technology, and analyses from Greenberg Traurig, Crowell & Moring, and Holland & Knight. DFARS 252.204-7012, -7019, and -7020. NIST SP 800-171 requirement families 3.3, 3.6, and 3.14. DOJ Civil Cyber-Fraud Initiative. Program status was accurate as of publication on August 9, 2026 and is subject to change as the review concludes. This article is informational and is not legal advice.