SMT007 Magazine

SMT007-Aug2026

Issue link: https://iconnect007.uberflip.com/i/1546025

Contents of this Issue

Navigation

Page 39 of 65

40 SMT007 MAGAZINE I AUGUST 2026 For companies that would miss the deadline This is a reprieve, not an exemption. You've bought time, but you're not off the hook. The 800-171 self- assessment baseline still applies, and a low or missing SPRS score is still a contractual and false- claims exposure. Use the runway to close your real gaps rather than treating the pause as a stand-down. Firms that mistake "Phase II suspended" for "cyber- security no longer required" are the ones most likely to get caught out when the reformed rule lands. Does 'reducing administrative overhead' mean a revamp of the certifications? Yes, most likely. It's a revamp of the certification mechanism, not an abandonment of the security requirement. The language in the memo (priori- tize "speed to capability," replace "third-party compliance models with scalable, realistic secu- rity measures," focus on "tangible cyber hygiene as opposed to administrative overhead") signals that DoD wants to keep the 800-171 substance but change how compliance is verified. This will likely lean more heavily on self-attestation, risk-tiering based on data sensitivity, and possibly automated or continuous validation, rather than the point- in-time, pay-a-C3PAO model. Read it as "same controls, lighter and cheaper proof," not "controls going away." The actual shape won't be known until the task force reports and a new rule goes through rulemaking, which realistically takes many months. Advice for EMS Suppliers Don't stop going on controls, but pause discre- tionary spend on the certification event. Maintain and improve your NIST 800-171r2 implementation and keep your SPRS score current and honest. Don't cancel remediation, segmentation, MFA, logging, or SSP/POA&M work. Those are enforceable cyber hygiene. Hold off booking a C3PAO assessment or signing long-term compliance-tooling contracts until the target is defined. Preserve documentation so you can move fast when the new framework drops, and keep flowing requirements to your subcontractors. DFARS 7012 supply-chain obligations did not pause. Above all, don't forget the False Claims Act; the suspension does not dismiss honesty in reporting the SPRS score. SMT007 Divyash Patel is CEO of MX2 Technology Table 1: What the memo says Only self-assessments allowed During the suspension the only permitted designations are CMMC Level 1 (Self) or Level 2 (Self). Level 2 (C3PAO) and Level 3 (DIBCAC) designations are prohibited. Level 2 substance survives Level 2 (Self) remains aligned to the full NIST SP 800-171 Rev. 2 control set. For CUI-handling suppliers, "suspended" does not mean dropping to the light Level 1 FCI baseline. Full Level 2 can still be required, just self-attested. Baseline stays in force DFARS 252.204-7012 remains fully in effect. Contract relief mechanism Where a solicitation or contract already carries a C3PAO or DIBCAC requirement, program managers must amend it out with active solicitations "as soon as practicable," existing contracts by modification before the next option exercise or administrative mode. No waivers No waivers will be granted during the review. Further guidance follows the 60-day review. False Claims Act exposure unchanged Your SPRS score must be accurate and defensible on the evidence, backed by a real System Security Plan and honest POA&Ms. "Phase II is suspended" is never a defense to certifying a number you cannot support.

Articles in this issue

Archives of this issue

view archives of SMT007 Magazine - SMT007-Aug2026