720-891-1663

The The CMMC Pause: A Compliance Break, or a Trust Fall Without a Net?

In July 2026, the Department of War paused the third-party verification requirement at the heart of CMMC Phase 2. The stated reason: assessment costs were eating up money and time small contractors could otherwise spend on real security. In its place, DoD rolled out “Brilliant at the Basics,” a voluntary top-10 list of security practices, and promised to keep enforcing standards through self-assessment. This voluntary standard has no legal effect on reducing the existing CMMC controls that contractors have to comply with. In fact, it adds 20 new controls, many of which are extremely difficult and expensive to implement. On paper, nothing about the underlying legal requirements changed. In practice, the mechanism that made those requirements mean anything just went away.

We already ran this experiment

Self-attestation without verification isn’t a new idea — it’s the old one. DFARS 252.204-7012 has required NIST 800-171 compliance since 2017 on an honor-system basis. CMMC exists because that honor system didn’t work: a DoD Inspector General review found contractors were claiming compliance they hadn’t implemented. Removing third-party checks now doesn’t fix that problem. It recreates it.

The “basics” aren’t basic, and nobody’s built to do them

Several items on DoD’s new list — particularly for operational technology like factory-floor machinery — actually exceed current NIST 800-171 requirements. Segmenting or upgrading legacy industrial equipment is expensive, specialized work. Most of the roughly 100,000+ small manufacturers this applies to don’t have an in-house IT person, let alone an OT security specialist. Their outsourced IT provider, if they have one, is rarely trained on industrial control systems. Asking this population to voluntarily fund and execute upgrades with no one checking, no funding offered, and no consequence for skipping it is asking a lot on hope alone.

The legal exposure didn’t pause

Contractors who scale back now are making a bet, not getting relief. NIST 800-171 and the 7012 clause remain legally binding regardless of what DoD chooses to verify. A gap between what a company attests in SPRS and its actual posture is False Claims Act exposure — and the Department of Justice has already brought and settled cases on exactly this theory. A competitor or former employee doesn’t need DoD to enforce anything; they can act as a whistleblower directly. “No one’s checking” is not the same as “no one can sue.”

AI has quietly raised the stakes

The threat model behind CMMC’s original 2019 legislative mandate assumed patient, well-resourced nation-state actors. That’s no longer the whole picture. AI tools have already been used to let unsophisticated attackers scan, penetrate, and exfiltrate from networks at a scale and speed that used to require a dedicated team. A small, unverified subcontractor is a more attractive and more reachable target today than it was when CMMC was first conceived — not less. With U.S. forces currently engaged in active operations where soft-target casualties have already made headlines, the cost of a supply-chain breach isn’t abstract.

What’s likely next

DoD’s own Reform Task Force is due to report in October 2026. But Congress doesn’t have to wait for it. The same bipartisan, security-focused members who wrote CMMC’s original mandate into the FY2020 NDAA have every incentive to write sharper, harder-to-sidestep language into the FY2027 NDAA before that report ever lands. Treating this pause as a settled, permanent state of affairs is likely to be a short-lived assumption.

The bottom line

Nothing about your actual legal obligations has changed, only who’s checking. The companies best positioned when verification returns — and it likely will, in some form — are the ones that kept building real security and evidence of it during the pause, rather than treating a quiet enforcement window as a green light to stop.

Further Reading

Facebooktwitterredditlinkedinmailby feather

Leave a Reply

Your email address will not be published. Required fields are marked *