Linkedin
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Menu Categories
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Linkedin
Cart To use Cart please install WooCommerce plugin
"Select Government-Led Assessments" — The Three Words Everyone Skipped | Overwatch Tools
The Self-Assessment Era · Part 4 of 6

"Select Government-Led Assessments" — The Three Words Everyone Skipped

The Department didn't remove assessment. It removed the third party from assessment. And that changes what your documentation has to do.

Published July 27, 2026. This article reflects the Department of War announcement of July 13, 2026 and reporting available at the time of writing. The CMMC Reform Task Force is expected to deliver findings within 60 days — roughly mid-September 2026 — and guidance may change. We will update this article as the situation develops.

Two weeks after the Department of War suspended CMMC Phase II, the small-contractor community has mostly settled into one of two readings. The first — "CMMC is dead, I can stop" — is wrong, and we've already dismantled it. The second — "self-assessment is the only path now" — is right, and we covered why that's actually good news.

But there's a third piece of the announcement that almost nobody has stopped on. It's a single phrase describing how the Department will enforce NIST SP 800-171 Rev 2 during the interim period. The mechanism is self-assessments — and:

"select government-led assessments" — U.S. Department of War, July 13, 2026

Read that again, slowly, because those three words are the interim enforcement model — and they change the job your documentation has to do.

The headlines said the audits went away. That's not what happened. Assessment did not disappear. The third party did. What was suspended is the C3PAO pathway — the private, scheduled, hire-your-own-assessor model. What was retained, explicitly and in writing, is the government's own ability to assess you directly.

And a government-led assessment is a very different room to be in.

Three Words, Unpacked One at a Time

Regulatory language is chosen carefully. Each of these words is doing work.

"Select"

Not everyone. Not on a published schedule. Not something you apply for. The Department chooses — which contractors, which contracts, which timing. You don't get to decide whether you're in scope, and you likely won't get a long runway when you are. "Select" is the word that makes preparation a standing condition rather than an event you schedule.

"Government-led"

Not a C3PAO you hired. Not a consultant with an engagement letter and an incentive to see you succeed. The government already has this machinery — DFARS 252.204-7020 requires contractors to give the government access to facilities, systems, and personnel for exactly this kind of assessment, and DIBCAC has been running government assessments of contractor compliance for years. This isn't a new invention. It's an existing capability, now named as the interim enforcement backstop.

"Assessments"

Plural. Ongoing. Not a one-time sweep tied to a deadline that might move. As long as the interim period runs — and officials have been clear that everything is fluid until the Task Force reports — this mechanism stays live. It's also the mechanism that persists even in the status-quo-extends scenario, which makes it the most durable enforcement fact in the whole announcement.

Put the three words back together and the interim model becomes clear: you assess yourself, you attest to the result, and the government reserves the right to check your work directly.

What "Self-Assessment + Government-Led Assessment" Actually Means

Here's the shift most coverage missed. Under the old Phase II model, a Level 2 contractor would prepare for a C3PAO assessment — often with a consultant beside them, an assessor who walks through the binder with them, a scheduled date circled on the calendar, and months of runway to get the story straight.

A government-led assessment removes every one of those cushions. If you're selected:

  • There is no consultant beside you. Nobody is in the room to reframe a weak answer or promise a follow-up memo.
  • There is no assessor walking you through your binder. The government reviews what exists. It doesn't help you assemble it.
  • There is no negotiated timeline. "Select" means the schedule isn't yours.
  • Your self-assessment score is already on record in SPRS. The question isn't "are you compliant?" — it's "does the evidence support what you already attested to?"

⚠️ Your documentation is the only thing in the room

In a government-led assessment, your documentation stands alone. It represents you when you can't explain, contextualize, or promise to fix. Either the record shows your controls operating, or it doesn't. The bar for evidence quality didn't drop when the third-party audits were suspended. It went up.

This is worth sitting with, because it inverts the instinct most contractors had on July 13. The suspension felt like pressure coming off. For documentation, the pressure went the other direction. A C3PAO assessment was a conversation. A government-led assessment is a records review. And records reviews are won or lost long before anyone shows up.

"We are not reducing cybersecurity through this measure. We are reducing the red tape." — Katie Davies, Department of War, July 13, 2026

The Department has been consistent on this point. The security expectation stands. What changed is who verifies it — and "you, with the government checking select work directly" is a model that rewards exactly one thing: documentation that holds up without you in the room.

The Three-Layer Test: Policy → Procedure → Evidence

So what does documentation that holds up actually look like? Every practice — whether it's one of the 15 at Level 1 or the 110 at Level 2 — needs three layers, and most contractors have exactly one of them.

Layer 1 — Policy

What you require

The rule. "Access to company systems is limited to authorized users and reviewed quarterly." A policy proves intent — that you know what's supposed to happen.

↓
Layer 2 — Procedure

How it happens, who does it, when

The mechanism. "The owner reviews the user list on the first Monday of each quarter, removes departed staff, and records the review." A procedure proves the rule is operational — not just aspirational.

↓
Layer 3 — Evidence

Proof it actually happened

The record. The dated review log from April, January, October, and July — with names, decisions, and sign-offs. Evidence proves operation. It's the only layer that survives scrutiny on its own.

Here's the uncomfortable arithmetic: policies prove intent. Evidence proves operation. Only one of those survives scrutiny — and it's the layer most "completed" self-assessments don't have. What we see constantly in the field is a self-assessment that is, in substance, a spreadsheet of yes/no answers with a folder of downloaded, lightly edited policies behind it. Every "yes" is sincere. Almost none of them can be demonstrated.

That gap was survivable when nobody was checking. It is not the posture you want to hold while "select government-led assessments" is the enforcement mechanism of record.

What a Government Assessor Actually Asks For

The single best way to pressure-test your own documentation is to hear the difference between the question contractors prepare for and the question assessors actually ask.

The question you prepared for:

"Do you have an access control policy?"

The question you'll get:

"Show me your last four access reviews."

Notice what the second question does. It doesn't ask about your rules — it asks for dated, recurring operational records. It assumes the policy exists and skips straight to whether it runs. Four quarterly reviews means a year of demonstrated operation. You cannot produce that record retroactively, and an assessor knows it — which is exactly why it's the question.

Across the practices, the same pattern repeats. These are the recurring operational records that most small contractors never generate — not because they're hard, but because nobody told them these are the compliance:

Access Reviews

Recurring, dated reviews of who has access to what — with the departures actually removed and the decision recorded, not just discussed.

Training Completion Records

Per-person, dated records showing each user completed security awareness training — not a policy saying training is required.

Dated Configuration Evidence

Exports or captures showing your MFA, firewall, and system settings as of a date — refreshed on a cadence, not frozen at setup.

Media Disposal Logs

What was sanitized or destroyed, when, how, and by whom — every time a drive, laptop, or device leaves service.

Physical Access Records

Visitor logs, escort records, and the recurring confirmation that physical access to systems is actually controlled — not assumed.

Why last year's screenshot doesn't count

A common objection: "I have evidence — I screenshotted our settings when we set everything up." That's a start, but a single capture from last year proves one thing: that the control existed on one day. Ongoing evidence has three properties that a setup-day screenshot doesn't:

  • Dated — every record carries the date it was produced, so operation can be placed on a timeline.
  • Recurring — the record repeats at the cadence your procedure names. One review is an event; four quarterly reviews are a practice.
  • Attributable — the record shows who performed the action and who approved it. Anonymous evidence is weak evidence.

Dated, recurring, attributable. If a record has all three, it survives scrutiny without you. If it's missing any of them, it's a supporting detail, not proof.

Not sure which layers you're missing?

Book a free 30-minute consultation and we'll walk through your current documentation the way an assessor would — policy by policy, record by record — and show you exactly where the evidence layer is thin. No pressure, no scare tactics, just a clear-eyed read on where you stand.

Book a Free 30-Minute Consultation → Run the Free Assessment Tool

The Fix Isn't More Effort. It's Structure.

Here's the good news buried in all of this: the evidence layer is not technically difficult. A quarterly access review takes minutes. A disposal log takes one line per device. Training records generate themselves if the training is tracked. The reason most contractors don't have these records isn't capability — it's that nobody defined what to collect, how often, and where it goes.

That's the exact problem the Evidence Locker in our Turnkey L1 Package was built to solve. Every one of the 142 artifacts across the 15 Level 1 practices is defined in advance — what the record is, what cadence it recurs on, and what "done" looks like — so evidence lands in an organized structure as you operate, instead of being reconstructed in a panic later. Everything is date-stamped, current, and exportable: if a request ever comes, your documentation walks into that room organized, and it walks in alone with confidence.

The same discipline runs through the L2 CUI Enclave Package for contractors handling CUI: 110 practices mapped to 182 defined artifacts, with a pre-filled SSP, POAM framework, Risk Register, and an evidence checklist that tells you exactly which recurring records your enclave needs to generate — implementable part-time, with no Active Directory, no SIEM, and no enterprise IT.

⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

Will You Actually Be Selected? An Honest Answer.

We'd be doing exactly what we criticize in others if we ended this piece implying a government assessor is on their way to your office. So here's the straight version:

The honest odds

Nobody outside the Department knows how "select" will be applied — how many contractors, which criteria, what cadence. We won't invent statistics, and you should be skeptical of anyone who does. Being selected is not a certainty. It may never happen to you.

But "unlikely" is not a documentation strategy. Your self-assessment score sits in SPRS today. Your annual affirmation is a legal attestation today. Your prime can request your posture today. The government retained the right to check your work today. The evidence layer isn't insurance against a low-probability audit — it's what makes every one of those standing attestations true.

And that's the real point of the three words everyone skipped. They aren't a threat. They're a clarification of what kind of compliance the interim period rewards: not attested compliance, demonstrated compliance. The contractors who internalize that now — while their competitors are still celebrating the end of audits that didn't actually end — are the ones whose documentation will be an asset instead of a liability, in every scenario the Task Force could produce.

The Bottom Line

The Department suspended the third-party audit. It kept assessment — and named itself the assessor. In that model, your documentation doesn't get a spokesperson, a coach, or a scheduled date to be ready by. It stands alone, whenever it's asked to.

Policies prove intent. Evidence proves operation. Build the layer that survives the room.

See how the Evidence Locker organizes this

The Turnkey CMMC Level 1 Package: all 15 practices broken into 142 defined artifacts, platform-specific templates for Microsoft 365 or Google Workspace, all 8 device & network configuration guides, the Evidence Locker, and your SPRS documentation — organized, date-stamped, and defensible. Eight bi-weekly expert sessions keep you moving. Most clients complete their Level 1 assessment in 2–4 weeks.

$2,495/year — Save $500 (regular $2,995), limited time

Book a Free 30-Minute Consultation → Start with the Free Assessment

Sources & Further Reading

  • U.S. Department of War — "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements" (July 13, 2026)
  • DefenseScoop — "DOD halts cybersecurity requirements for CMMC Phase 2: 'The math just simply doesn't math'" (July 13, 2026)
  • National Defense Magazine — "BREAKING: Pentagon Suspends Phase 2 of CMMC Program" (July 13, 2026)
  • U.S. Small Business Administration — Statement on the CMMC Phase II Suspension (July 13, 2026)
  • NIST SP 800-171 Rev. 2

This article is provided for informational purposes and does not constitute legal advice. Contractors should review their specific contract terms and DFARS clauses with qualified counsel.

Share Post
  • Twitter
  • Facebook
  • Pinterest
  • Linkedin
L1/L2 Self-Assessment Is Now t...
L1/L2 Self-Assessment Is Now the Only Path — And It Was Never the Lesser One
Need a blog header image created for a blog on CMMC titled - Why "Free" Self-Assessment Costs $388,600
Why “Free” Self-As...

Comments are closed

Company Address

  • Overwatch Tools, Inc.
  • 300 Woodards Ford Road
  • Chesapeake Virginia 23322
  • E-Mail: info@overwatchtools.com
  • Outervision Capitol Company
  • Privacy Policy

,Copyright © 2025 Overwatch Tools, Inc.

Home
Shop
Contact us
More
More
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool