Most Recent News From the DoD Regarding CMMC: Why the Pause Just Made Self-Assessment Riskier

If you assumed the July 13 pause on CMMC Phase 2 bought you slack, the opposite is closer to the truth. DoD has not touched DFARS 252.204-7012 or your obligation to implement all 110 NIST 800-171 controls. What has changed is where the government’s enforcement attention now sits: on the accuracy of the SPRS score you already signed. With third-party audits frozen, your self-attestation is doing more legal work than it was three months ago, not less.

What Actually Changed (and What Didn’t) Since July 13

Contractors keep asking us the same question: does the pause mean CMMC is dead. It doesn’t. Here’s the current state as of early August 2026:

That last point matters more than most coverage of this story has explained. Nothing about the pause reduces your compliance requirement. It just removes, for now, the outside auditor who would have caught a gap before it became a contract problem.

The Real Reason Behind the Pause

DoD’s own numbers explain the decision better than the press release did. Two data points are driving the reform push:

  1. Cost. DoD’s CIO cited Small Business Administration estimates that fully scaled CMMC phases could cost small and midsize contractors more than $7 billion a year in aggregate.
  2. Capacity. Roughly 100,000 companies in the Defense Industrial Base need a Level 2 assessment. Fewer than 100 authorized C3PAOs currently exist to perform them.

Those two facts, not political appetite, are why a CMMC Reform Task Force now reports to the DoD CIO with recommendations due around mid-September 2026, and why a public Request for Information on reducing compliance burden closes August 14, 2026. Officials have not ruled out restructuring the program significantly. They also have not ruled out ending the third-party model altogether in favor of an expanded self-attestation framework. Either outcome still requires the underlying 110 controls to be in place.

Why Your SPRS Score Just Got More Dangerous

Here’s the framework we’re walking clients through right now.

Step 1: Treat your SPRS score as a legal representation, not a form field. A signed affirmation in the Supplier Performance Risk System is a statement to the federal government about your actual security posture. With C3PAO validation paused, DoD has more reason, not less, to scrutinize that number after the fact through audits, investigations, or False Claims Act exposure if a breach later reveals the score was inflated.

Step 2: Re-run your gap assessment against NIST 800-171 Rev 2, not what you think you scored last year. Controls drift. Staff turnover, new vendors, and cloud migrations all change your actual posture between affirmations. If your last honest gap assessment was more than six months old, the number in SPRS may no longer reflect reality.

Step 3: Document your evidence trail now, while there’s no external deadline pressure. System Security Plans, Plans of Action and Milestones, and audit logs that support your affirmation should exist before anyone asks for them; not assembled after a contracting officer or DoD Office of Inspector General inquiry.

Step 4: Watch three dates. August 14 (RFI comment window closes), mid-September (Reform Task Force report to the DoD CIO), and November 10 (the date Phase 2 was originally scheduled to begin, now the natural marker for what DoD does next).

Not sure your SPRS score would survive a closer look? Our CMMC Readiness Checklist walks you through exactly what a gap assessment should cover before you sign another affirmation. Download the checklist.

A Pacific Northwest Example

Consider a 90-person aerospace machining supplier outside Everett, Washington, holding two active DoD subcontracts that require CMMC Level 2 self-assessment. The company scored itself at 92 out of 110 in SPRS last November, ahead of a new contract award.

Since then, they’ve onboarded a new ERP vendor with access to controlled unclassified information and haven’t updated their System Security Plan to reflect it. Under the old assumption that a C3PAO audit was coming in November 2026, that gap might have surfaced during third-party review. With Phase 2 paused, no outside party is scheduled to catch it. The exposure doesn’t disappear. It just moves from “audit finding” to “undisclosed misrepresentation” if a prime contractor, DoD IG, or breach investigation ever pulls the thread.

This is a representative scenario built from common patterns we see across aerospace and manufacturing subcontractors in the region. It isn’t a specific client engagement.

What to Watch Before September

A few dates worth putting on your calendar beyond the federal ones:

The Bottom Line for Defense Contractors

CMMC’s certification mechanism is under review. Your obligation to protect controlled unclassified information under DFARS 252.204-7012 is not, regardless of which phase, task, or reform recommendation comes next. Contractors who use this pause to tighten their actual security posture and the accuracy of their SPRS score will be positioned well no matter what DoD decides in September. Contractors who read the pause as permission to wait will be exposed either way, audit or no audit.

inTech Consulting works exclusively with aerospace, DoD supply chain, and manufacturing clients across Washington, Oregon, and Idaho on CMMC compliance and the broader compliance and risk requirements tied to DFARS 252.204-7012. Our team supports aerospace and Department of Defense suppliers with SPRS score validation, gap assessments, and 24/7 SOC monitoring built around NIST 800-171 Rev 2.

Want a second set of eyes on your SPRS score before the Reform Task Force reports in September? Book a free 30-minute readiness call with Raj to review where your self-assessment might not hold up. Schedule your call. Serving defense contractors across Washington, Oregon, and Idaho.