July 14, 2026
CMMC Phase One Extended
Well, well, well, interesting times indeed! Yesterday DoD/DoW announced that the C3PAO certifications required in Phase II are being postponed indefinitely. A lot of folks stopped reading after the first sentence, and missed the next one:
All Phase I self-assessment requirements remain firmly in place.
So, everyone still needs to be working on their compliance requirements, completing self-assessments and affirmations for both L1 and L2.
The press release says a priority is "lowering barriers for small, medium, and non-traditional businesses." Well, I like the sound of that, actually! But how small is small? How big is medium? What exactly is a non-traditional business?
A CMMC Reform Task Force is being formed, with orders to report back to the CIO within 60 days. "[T]he team will recommend realistic, scalable security measures that prioritize speed to capability and lower barriers for small and non-traditional businesses." That sounds good in theory, but in reality, how will they make these changes without more rulemaking?
"During this interim period, the Department will enforce cybersecurity compliance with the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments" -- so this is definitely not a signal for contractors to back off their security programs. "It is critical to note that this action does not eliminate the requirement for companies to protect federal data. " (And don't forget that the Dept of Justice continues to prosecute FCA cases like this one.)
This quote seems pretty clear:
“I want to be clear across the Department of War and our defense industrial base, investing in and dynamically maintaining robust cybersecurity remains a critical non-negotiable priority. This action does not eliminate the legal requirement for our industry partners to protect federal data.” Davies added later, “We are not reducing cybersecurity through this measure. We are reducing the red tape.”
Let's not forget one very important thing: prime contractors. They have been the driving force up to now. I'll be very interested to see whether they back off or continue pushing their supply chains to comply.
What's my primary takeaway? For now, stay the course. If you have FCI, you need to meet the requirements of the FAR Basic Safeguarding Rule, self-assess CMMC L1 and record your self-assessment in SPRS. If you have CUI, you need to fully implement 800-171, do a self-assessment and record the results in SPRS. Protect that export-controlled data according to its needs. Don't forget, the FAR CUI rule is coming soon and will extend the CUI protection requirements across all federal agencies and their contractors. And if you are already preparing for official CMMC L2 assessment, there's no need to stop. C3PAOs will continue to perform, and I do believe it will still be a market differentiator.
Wanna chat? Reach out.
Sincerely,
Glenda R. Snodgrass, CCP/CCA/Lead CCA
grs@theneteffect.com
The Net Effect, LLC
www.theneteffect.com
251-433-0196 x107

