CMMC Is Paused. Your CUI Obligations Aren't.
By Kenio Shirley · · 8 min read
A program pause is not a control pause. The contract clauses kept running while the certification scheme caught its breath.
On July 13, 2026, the Department of War suspended Phase II of the CMMC rollout — the phase that would have made third-party certification a condition of award for a large share of defense contracts — pending a 60-day Reform Task Force review. Skadden, DoW Suspends CMMC Phase II Within weeks, the FAR Council moved the other direction, proposing a government-wide rule for safeguarding and reporting on Controlled Unclassified Information that would reach nearly every federal contractor, defense or not. McDermott, FAR Council Speeds Up CUI Rules While DoW Slows Down
One program slowed down. A bigger one sped up. And underneath both, the obligation that was already in your contracts — DFARS 252.204-7012, with its NIST SP 800-171 safeguarding requirement and its 72-hour incident-reporting clock — never paused for a single day. DoD CIO, CMMC Program
Certification is a program. Safeguarding CUI is a contract. The program got paused. The contract did not.
What actually paused
Be precise about what July 13 changed, because the headline and the substance are different things. What paused is the phase-in of certification requirements in new solicitations — the mechanism that was going to make a C3PAO assessment a gate on contract award. What did not pause: the underlying cybersecurity clauses already in force in existing contracts, the obligation to maintain a System Security Plan and POA&M against 800-171, the requirement to report covered incidents within 72 hours, and the government’s ability to assess your self-reported SPRS score against reality.
That last point deserves emphasis. Every contractor in the defense industrial base has a self-attested score sitting in SPRS right now. Those scores were made under a certification-threatened environment. They are still live representations to the government, and the False Claims Act exposure attached to an inflated score does not depend on CMMC phasing at all. If your SPRS score says 110 and your environment says 70, the suspension bought you nothing.
What is speeding up
The FAR Council’s proposed CUI rule is the more consequential document, and it is getting a fraction of the attention. Where CMMC reaches the defense industrial base, a FAR-level CUI safeguarding and incident-reporting rule reaches the federal contractor base — civilian agencies, research institutions, SaaS platforms holding government data. The divergence is the story: while the market fixated on the suspension, the center of gravity of federal CUI enforcement started moving from a certification scheme to the contract-clause layer, which is broader, older and already signed.
If you are a SaaS or platform company selling anywhere near the federal market, this is the trend line to watch — not the task force.
The governance failure mode this creates
I have seen this exact pattern in every regime that announces and then slips a deadline, and it goes like this. The compliance program was funded against a date. The date moves. The budget conversation turns into “can we slow down too?” — and the people saying yes are not wrong about the program, they are wrong about what the program was for.
An 800-171 implementation was never a CMMC deliverable. It is the difference between a company that can demonstrate how it handles federal information and a company that cannot. The assessment was only ever the forcing function. When the forcing function pauses and the work pauses with it, what you have learned about your program is uncomfortable: it existed to pass an assessment, not to protect anything. That is the same failure I wrote about in the ITGC context — a control that exists to produce the audit rather than survive it is the first casualty of any schedule slip.
What to keep doing regardless of the task force
- Keep the SSP and POA&M living documents. Whatever CMMC looks like after the review, and whatever the FAR CUI rule finalizes as, both roads run through an accurate System Security Plan and a POA&M that reflects real remediation velocity. Stale versions of either are the easiest findings in any assessment.
- Treat your SPRS score as a representation, because it is one. Re-baseline it against your actual environment now, while there is no assessment pressure, and remediate toward the score you published — or correct the score. Either is defensible. A gap between them is not.
- Rehearse the 72-hour incident clock. The 7012 reporting obligation is in force today, suspension or not. Most companies have never run the drill: who detects, who determines “covered,” who has the DoD-approved medium assurance certificate to actually submit the report. Finding out during an incident is a finding.
- Map where CUI actually lives. The FAR rule’s breadth means the scoping question — which systems, which enclaves, which subcontractors touch covered information — is about to be asked of a much larger population of companies. The answer that survives is the one drawn from architecture and data flow, not from contract optimism. This is the FedRAMP boundary discipline applied one market over.
- Watch the FAR rulemaking, not just the CMMC news. Comment periods and final-rule language in the FAR CUI track will define your obligations more durably than whatever Phase II becomes.
The useful way to read July 2026
The suspension is real, and if your program was drowning in assessment logistics, the breathing room is legitimate — use it to fix the environment instead of rehearsing for the assessor. But read the two July events together and the direction of travel is unmistakable: federal information-security obligations are moving from certification events to continuous contractual reality. That is the same move FedRAMP is making with 20x, and the same move SOC 2 auditors made years ago. The regimes are converging on a single expectation — your controls are running, your evidence is system-generated, and neither depends on whether someone is scheduled to come look.
Build for the contract, not the calendar. The calendar just proved, again, that it moves.