Linkedin
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Menu Categories
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Linkedin
Cart To use Cart please install WooCommerce plugin
The Audit Went Away. The Obligation Didn't. What Still Binds Defense Contractors After the CMMC Suspension | Overwatch Tools
The Self-Assessment Era · Part 2 of 6

The Audit Went Away. The Obligation Didn't.

CMMC Phase II is suspended. Your legal and contractual duty to protect federal data is not. Here's the calm, plain-English list of everything still standing — because we'd rather you hear it from us than find out the hard way.

Published July 15, 2026. This article reflects the Department of War announcement of July 13, 2026 and the reporting available at the time of writing. The CMMC Reform Task Force is expected to deliver findings within 60 days — roughly mid-September 2026 — and guidance may change. We will update this article as the situation develops.

Since July 13, one reaction has spread faster than any other across the small-contractor community: "Great — CMMC is dead. I can stop."

We understand the relief behind it. For years, the third-party audit hung over small defense contractors like a bill they couldn't afford. So when the Department of War suspended the phase that would have required it, "I can stop" felt like the natural conclusion.

It's the wrong conclusion, and it's the kind of wrong that quietly costs contracts.

Here's the distinction almost nobody is drawing clearly right now: the Department suspended the verification mechanism — the third-party assessment — not the obligation underneath it. The obligation to protect federal data was never a CMMC invention. It predates CMMC, it sits in federal contract law and in your subcontracts, and it is exactly as binding today as it was on July 12. What changed is who checks your work.

This piece is a walk through everything that is still standing. No fear-mongering, no artificial deadlines — just the plain facts, so you can make decisions with your eyes open.

What Was Suspended vs. What Is Still Firmly In Place

This is the single most important distinction in the whole announcement, and most of the coverage has blurred it. Read both columns side by side.

❌ Suspended

  • The Phase II transition — the milestone scheduled for November 10, 2026
  • Third-party C3PAO assessments as a precondition of contract award
  • Phase III (Nov. 2027) and its DIBCAC-led Level 3 assessments
  • Pending and future CMMC implementation milestones across DoW solicitations and contracts

✅ Still Firmly In Place

  • Phase I self-assessment requirements — in the Department's own words, these "remain firmly in place"
  • DFARS 252.204-7012 — your contractual duty to safeguard covered defense information and report cyber incidents
  • NIST SP 800-171 Rev 2 — the standard the Department will continue to enforce during the interim
  • Select government-led assessments — the Department explicitly retained these

Look at the right-hand column again. Nothing on your side of the ledger changed on July 13. The paperwork you owe, the standard you're held to, and the data you're responsible for are all identical to what they were the day before. The only thing that moved was the person standing across the table when it's time to prove it.

"We are not reducing cybersecurity through this measure. We are reducing the red tape." — Kirsten Davies, Department of War Chief Information Officer

That sentence is the whole story in one line. The red tape — the third-party bottleneck — is what got suspended. The cybersecurity obligation stayed exactly where it was.

DFARS 252.204-7012, Explained Plainly

If you take one thing from this article, make it this: DFARS 252.204-7012 is not a CMMC artifact. It is a clause written into your contract, and it stands entirely on its own.

The clause predates CMMC by years. CMMC was designed as a verification layer on top of it — a way to confirm contractors were actually doing what 7012 already required. Suspending the verification layer does nothing to the clause underneath. The clause is still in your contract. It still binds you. It would still bind you even in the scenario where CMMC is cancelled outright.

📋 What the clause actually asks of you

In plain terms, DFARS 252.204-7012 requires a contractor that handles covered defense information to:

  • Provide adequate security on the systems that process, store, or transmit covered defense information — which, in practice, means implementing the security requirements in NIST SP 800-171.
  • Rapidly report cyber incidents to the Department (the clause sets a 72-hour window) and cooperate with any follow-up.
  • Flow these requirements down to subcontractors whose work involves covered defense information.

Notice what's on that list and what isn't. There is no mention of a C3PAO. No mention of a certificate. No mention of an assessment phase. The obligation to safeguard the data and report incidents lives entirely inside your contract — and a suspended rollout phase doesn't touch a word of it.

This is why we keep saying DFARS 7012 is the durable anchor. Every plausible outcome of the 60-day review — CMMC returns streamlined, CMMC is replaced, CMMC is cancelled, or the status quo simply extends — leaves 7012 exactly where it is. There is no version of September that rewrites your contract for you.

A rough analogy: think of the obligation to protect the data as the speed limit, and think of the third-party audit as a speed camera on that stretch of road. On July 13, the Department switched off the camera. The speed limit didn't change. The law you're driving under is identical — the only difference is how, and by whom, it might get checked. Nobody reads "the camera is off" as "there is no longer a limit." The same logic applies here.

Phase I Self-Assessments Are Still Required Where Your Contract Requires Them

The Department's language on this was unusually direct: Phase I self-assessment requirements "remain firmly in place."

Here's the part that gets lost. Phase I — which began in November 2025 — is the phase that put the self-assessment requirement into effect, and it covered required self-assessments under both CMMC Level 1 and Level 2. Phase II was the phase that would have layered a third-party assessment on top for certain Level 2 contractors. So the piece that's suspended is the third-party layer. The self-assessment obligation you may already carry is not.

If your contract requires a Level 1 or Level 2 self-assessment and an annual affirmation, that requirement did not evaporate on July 13. And the annual affirmation is the part worth pausing on: it isn't a box you tick once. It's a recurring attestation that your security posture is what you say it is — which brings us to the two points contractors most often overlook.

The Point Most Contractors Haven't Thought Through: Flow-Down

If you're a subcontractor, your obligations don't come only from the Department of War. A large share of them come from your prime.

When a prime contractor wins work that involves covered defense information, it is contractually required to flow the relevant clauses — including DFARS 252.204-7012 — down to the subcontractors doing that work. Those flow-downs become part of your agreement with the prime. They are a contract between you and them.

💡 The Department suspending a phase does not amend your subcontract

This is the whole point, and it's the one that surprises people. A regulatory rollout getting paused at the federal level does nothing to the private contract you already signed with your prime. If your subcontract says you'll safeguard covered defense information, implement NIST SP 800-171, and affirm your posture — those terms are still binding, word for word, until the two of you agree otherwise in writing. The prime is still on the hook to the government, which means the prime still has every reason to hold you to what you signed.

So before you conclude that anything changed for your business, the honest first step isn't to read the news — it's to read your contracts. Your obligations are whatever your contract and your prime's flow-downs actually say, and no press release rewrites those for you.

The False Claims Act Point: The Real Risk Never Moved

Here's the risk that was always the sharpest one, long before the suspension and long after it: attesting to a security posture you don't actually have.

Every self-assessment score you submit, every affirmation you sign, every representation you make about your compliance in a proposal — those are statements the government relies on. When a company certifies a posture it hasn't actually implemented, that can create exposure under the False Claims Act. That exposure is not a CMMC mechanism, and nothing about July 13 reduced it.

If anything, the suspension raises the stakes on getting your attestations right, because the number you affirm now carries more weight, not less. When the third-party check is paused, your own attestation is the primary signal the government and your primes are relying on. Affirming a posture you can't back up with evidence was always the real danger. It still is.

⚠️ Three words worth circling: "select government-led assessments"

The Department didn't remove assessment. It removed the third party from assessment and kept the right to look for itself. If you're selected for a government-led assessment, there's no consultant beside you and no assessor walking you through your binder — your documentation is the only thing in the room. That's a bigger topic than we can do justice here, and it's the subject of Part 4 in this series. For now, just know the bar for evidence quality went up, not down.

Not sure what your contracts actually require now?

That's the right question to be asking this month. Book a free 30-minute consultation and we'll walk through your DFARS clauses, your prime's flow-downs, and what a defensible self-assessment looks like for a business your size. No pressure, no six-figure quotes.

Book a Free 30-Minute Consultation →

The Reframe: What Actually Changed Is Who Checks Your Work

Let's put the whole announcement into one honest sentence.

Before July 13, the plan was that a paid third-party assessor would verify your compliance. After July 13, that verification is suspended — and the responsibility for confirming your posture shifted back onto you, with the government reserving the right to inspect.

That's it. That's the change. Not the obligation, not the standard, not the data you're responsible for. Who checks your work. And the answer is now you.

Why this is actually good news — if you understand it

The thing that was breaking small businesses — the six-figure audit, the assessor bottleneck, the sheer cost of proving compliance to a third party — is the thing that got removed. What stayed is the part you can genuinely complete on your own: a documented, defensible self-assessment. The barrier between you and a solid compliance posture is no longer money or assessor capacity. It's just documentation. And documentation is a solvable problem.

The contractors who read this moment correctly won't slow down. They'll use the window to get their self-assessment genuinely defensible while half their competition sits still waiting for September. Because when a contracting officer or a prime asks "can you prove you protect our data?", the right answer has always been the same — "yes, and here's the documentation." That answer wins bids in every scenario the Task Force could hand down.

Where This Leaves You: A Calm Five-Point Check

None of this calls for panic. It calls for a clear head and a short list. Here's what a well-run small contractor should confirm this month.

  1. Read your contracts, not the headlines. Pull your DFARS clauses and your prime's flow-downs and confirm what you actually agreed to. That document, not a press release, defines your obligations.
  2. Confirm whether a self-assessment and affirmation are required of you. If your contract calls for a Level 1 or Level 2 self-assessment and an annual affirmation, that requirement is still live.
  3. Know your real baseline honestly. Not a spreadsheet of yes/no answers — an actual gap analysis against the 15 Level 1 practices (and NIST SP 800-171 if you handle CUI). If the answer you'd affirm doesn't match reality, that's the gap to close first.
  4. Fix your evidence, not just your policies. A policy shows intent; evidence shows the control actually runs. In a government-led assessment, only the second one is in the room with you.
  5. Keep bidding. Primes still need subs, solicitations still need suppliers, and a contractor who can prove its posture stands out in a market where much of the competition is frozen.

Notice that not one of those five steps depends on what the Task Force decides in September. That's the point. The work in front of you is the same work regardless of the outcome — which is exactly why it's worth doing now rather than waiting.

Find out exactly where your self-assessment stands.

Our free CMMC Assessment Tool evaluates all 15 Level 1 practices and returns an instant gap analysis with a prioritized remediation roadmap. No credit card. Results in under 30 minutes.

Run the Free Assessment → Book a Consultation

The Self-Assessment Era — a 6-part series

Part 1: CMMC Phase II Is Suspended: What Actually Changed — and the Opportunity It Creates

Part 2 (you're here): The Audit Went Away. The Obligation Didn't.

Part 3 (next): Self-Assessment Is Now the Only Path — what that means for L1 and L2 contractors alike.

Sources & Further Reading

  • U.S. Department of War — "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements" (July 13, 2026)
  • DefenseScoop — "DOD halts cybersecurity requirements for CMMC Phase 2: 'The math just simply doesn't math'" (July 13, 2026)
  • National Defense Magazine — "BREAKING: Pentagon Suspends Phase 2 of CMMC Program" (July 13, 2026)
  • NIST SP 800-171 Rev. 2

This article is provided for informational purposes only and does not constitute legal advice. We are not attorneys. The obligations that apply to your business depend on your specific contract terms, DFARS clauses, and prime flow-downs, which you should review with qualified counsel.

Share Post
  • Twitter
  • Facebook
  • Pinterest
  • Linkedin
The 3rd Party Audit Went Away....
The Audit Went Away. The Obligation Didn't.
L1/L2 Self-Assessment Is Now the Only Path — And It Was Never the Lesser One
L1/L2 Self-Assessment Is Now t...

Comments are closed

Company Address

  • Overwatch Tools, Inc.
  • 300 Woodards Ford Road
  • Chesapeake Virginia 23322
  • E-Mail: info@overwatchtools.com
  • Outervision Capitol Company
  • Privacy Policy

,Copyright © 2025 Overwatch Tools, Inc.

Home
Shop
Contact us
More
More
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool