90% of Government Contractors Use AI. CMMC Phase II Is Suspended. Your CUI Obligations Are Not.
Executive Summary
- On July 13, 2026, the Department of War suspended CMMC Phase II, scheduled to begin November 10, 2026, putting third party certification assessments on hold. DFARS clause 252.204-7012 was not suspended, amended, or paused. Contractors and subcontractors subject to it that process, store, or transmit covered defense information must still implement the 110 NIST SP 800-171 Revision 2 requirements it specifies.
- Deltek’s 17th annual Clarity study of 917 government contractors found 90 percent now use AI in some capacity and 92 percent use generative AI, while 73 percent remain in the early stages of AI governance maturity.
- An external cloud service that handles covered defense information must meet FedRAMP Moderate requirements or documented equivalency. A cloud hosted AI service falls inside that rule whenever it actually handles that information, and the Department’s CMMC FAQ confirms encrypting the data first creates no exception.
- The same week it suspended Phase II, the DoW Chief Information Officer published guidance telling defense industrial base partners to explicitly prohibit putting sensitive Department data into public commercial AI systems.
- With assessments paused, the False Claims Act became a leading enforcement route, alongside contract remedies, adverse government assessments, and debarment risk. In June 2026, an Alabama defense contractor paid $507,144 to resolve allegations it failed to implement NIST SP 800-171 controls on two Navy contracts.
In this article
- What the CMMC Phase II Suspension Actually Did
- Why 90 Percent AI Adoption Just Became a CUI Problem
- The Rule Nobody Suspended: DFARS 252.204-7012 and Your AI Vendor
- Encryption Does Not Save You
- Your CMMC Scope Now Has an AI Shaped Hole
- What the DoW CIO Published About AI, and What It Is Not
- Why False Claims Act Exposure Rises When Audits Pause
- The Overmarking Problem: When You Cannot Tell What Is CUI
- A 60 Day AI Governance Plan for a Small Defense Contractor
- What Happens When the Task Force Reports
1. What the CMMC Phase II Suspension Actually Did
The July 13, 2026 suspension paused third party certification assessments and every future CMMC implementation milestone. It did not remove a single cybersecurity obligation from a single contract.
One terminology note, because it trips people up. The Department of Defense has used Department of War as a secondary title since Executive Order 14347, signed September 5, 2025, and its public site now sits at war.gov. Only Congress can change a department’s statutory name, so Department of Defense remains the legal name while legislation moves through the annual defense authorization process. Same Department, two names. This article uses whichever term the source document uses.
The Department of War announcement is short and unusually clear about this. Phase II was scheduled to begin November 10, 2026. It is now suspended, along with all pending and future CMMC implementation milestones across Department solicitations and contracts. Phase I self assessment requirements remain firmly in place. The Department will enforce compliance with the NIST SP 800-171 Revision 2 standard through self assessments and select government led assessments during the interim period.
Then comes the sentence that most contractors skipped. The Department states that this action does not eliminate the requirement for companies to protect federal data, and that all defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012.
Be precise about that distinction when you brief your team. CMMC is suspended is not the same statement as our cybersecurity obligations are suspended.
The CMMC Phase II suspension is a pause on who checks your work, not on the work itself. The Department of War suspended CMMC Phase II on July 13, 2026, indefinitely deferring the third party certification assessments that were set to begin November 10, 2026. DFARS clause 252.204-7012, the 110 security requirements of NIST SP 800-171 Revision 2, and the annual CMMC Level 2 self assessment and affirmation obligations that took effect November 10, 2025 all remain in full force.
I spent fifteen years inside federal cybersecurity at the Department of State, the Department of Defense, and the Department of Homeland Security, and I have watched this pattern several times. A deadline slips, the trade press writes about relief, small firms quietly stand down their remediation. Two years later the deadline returns with a shorter runway and those firms are further behind than when they started.
The numbers explain why the relief feels real. In the 32 CFR Part 170 final rule, published October 15, 2024 and effective December 16, 2024, the Department estimated a Level 2 certification assessment and affirmation for a small entity at $101,752, three year cost $104,670, including a C3PAO engagement of 120 hours at $260.28 per hour, or $31,234. A Level 2 self assessment and affirmation for the same small entity was estimated at $34,277, three year cost $37,196.
The suspension therefore moves a small contractor from a $104,670 three year path to a $37,196 three year path. That roughly $67,000 of avoided cost is genuine, and it is also the entire benefit. The underlying 110 requirements, the system security plan, the annual affirmation, and the flow down obligations did not move at all.
| Obligation | Status after July 13, 2026 | Source |
|---|---|---|
| C3PAO Level 2 certification assessment | Suspended indefinitely | DoW release, July 13, 2026 |
| Level 3 DIBCAC assessment | Suspended indefinitely | DoW release, July 13, 2026 |
| CMMC Level 1 and Level 2 self assessment | In force since November 10, 2025 | DoW CIO CMMC FAQ, A-A1 and B-A2 |
| DFARS 252.204-7012 safeguarding and reporting | Unchanged | DoW release, July 13, 2026 |
| NIST SP 800-171 Rev 2, 110 requirements | Unchanged and actively enforced | DoW release, July 13, 2026 |
| FedRAMP Moderate requirement for cloud handling CUI | Unchanged | DoW CIO CMMC FAQ, E-A1 |
| Annual affirmation by the Affirming Official | Unchanged | DoW CIO CMMC FAQ, C-A1 |
| False Claims Act exposure for false attestation | Increasing | DOJ settlement, June 18, 2026 |
2. Why 90 Percent AI Adoption Just Became a CUI Problem
Nearly every government contractor now runs AI tools, and almost none of them have governed those tools inside their CMMC assessment scope. That gap is where CUI leaves the building.
Deltek’s 17th annual Clarity GovCon study, based on a survey of 917 government contractors, reports that as many as 90 percent of firms now use AI in some capacity and 92 percent are leveraging generative AI tools. The same study found that 73 percent of firms remain in the early stages of AI governance. Deltek’s own analysis notes that overall adoption roughly doubled from the 45 percent reported the prior year.
Read those two figures as answers to two different survey questions rather than slices of one pie. Deltek hedges the first with the words as many as, and a firm can report generative AI use without calling itself an AI adopter in the broader question. The number that carries this article is the third one, and it is not ambiguous. Adoption is close to universal and governance is not.
Adoption at 90 percent with governance maturity at 27 percent is not a technology story. It is a data spillage story with a three year lag before anyone looks.
Consider what a 40 person subcontractor does with these tools. A proposal manager pastes a statement of work into a chatbot to tighten the language. An engineer uploads a technical drawing to summarize tolerances. A contracts administrator drops a subcontract into an AI assistant to extract flow down clauses. A program lead runs an AI notetaker on a system design review call.
Every one of those transmits data to a third party system. If any of it is covered defense information, the firm just used an unauthorized external cloud service to process it, with no system security plan entry, no security impact analysis, and no provider contract meeting DFARS requirements.
Nobody involved intended to break a rule. The tool was already in the browser, already in the Microsoft or Google tenant, in many cases switched on by the vendor in an update nobody read. This is the same dynamic we covered for manufacturers facing Tier 1 customer AI questionnaires, except here the customer is the United States government and the remedy is not a lost purchase order.
GOVERNANCE INSIGHT
The suspension bought you time, not absolution.
The three year CMMC assessment cycle means a certification assessment conducted in 2029 will evaluate whether changes to your environment between now and then were managed according to the security requirements and performed as stated in your system security plan. Every AI tool you adopt in the interim is a change that assessment will look at. Undocumented adoption today becomes a failed assessment later.
3. The Rule Nobody Suspended: DFARS 252.204-7012 and Your AI Vendor
DFARS 252.204-7012 requires that an external cloud service provider used to store, process, or transmit covered defense information meet security requirements equivalent to the FedRAMP Moderate baseline. A cloud hosted AI service can be exactly that kind of provider.
Whether a given AI tool falls inside the clause is a question about data flow, not product category. It turns on the deployment model, your contract with the vendor, where the data actually goes, and whether the information is covered defense information handled in performance of a Department contract. The same vendor’s tool can be in scope on one workflow and out of scope on the next.
The clause text defines a covered contractor information system as an unclassified system owned, or operated by or for, a contractor that processes, stores, or transmits covered defense information, and defines that information by reference to the CUI Registry. It requires implementation of NIST SP 800-171, rapid reporting of cyber incidents within 72 hours of discovery, preservation of images of all known affected systems for at least 90 days from the incident report, and inclusion of the clause in subcontracts involving covered defense information.
The Department’s own CMMC frequently asked questions document, updated July 13, 2026 to reflect the suspension, answers this directly at E-Q1. A contractor using a cloud service provider to store, process, or transmit CUI in performance of a contract shall require and ensure the provider meets requirements equivalent to the FedRAMP Moderate baseline. That is satisfied by a FedRAMP Moderate authorized service, or by a provider meeting the equivalency requirements in the Department’s December 2023 memorandum.
Equivalency is not a paperwork exercise. As Baker Tilly’s analysis of the memorandum explains, the Department requires 100 percent compliance with the FedRAMP Moderate control baseline, validated by a FedRAMP recognized third party assessment organization, supported by a body of evidence including a system security plan, security assessment report, customer responsibility matrix, and closed out plan of action and milestones. The contractor, not the vendor, carries the obligation to verify and maintain that status.
Now apply that to the AI tools in your environment. The question is not whether the vendor’s marketing page says secure, SOC 2 compliant, or enterprise grade. It is whether that specific offering, at the tier and cloud region you are licensed for, carries FedRAMP Moderate authorization or an equivalency body of evidence you have actually read.
For most commercial AI assistants in a standard commercial tenant, the answer today is no. Vendors do publish government offerings that sit in accredited environments, and those authorizations change as products move through the FedRAMP process. That is precisely why you check the FedRAMP Marketplace listing for the exact offering rather than trusting a vendor blog post or a reseller.
State the standard the way an assessor would. Before covered defense information goes into a third party cloud AI service, you should be able to produce documentation of FedRAMP Moderate authorization, or DoD recognized equivalency, for that exact service environment. If you cannot, you still have two legitimate paths: build the equivalency evidence, or confine the tool to an approved architecture where it never receives the controlled data. What you do not have is the option to assume it is probably fine.
4. Encryption Does Not Save You
Three answers in the Department’s CMMC FAQ close every workaround a technically minded small contractor tends to reach for first. Encrypting CUI before it goes into an unauthorized AI tool does not remove the tool from scope.
The first is B-Q8. Under 32 CFR Part 2002, CUI remains controlled until formally decontrolled, and encrypted CUI retains the control designation of its plain text counterpart. The Department accepts that some transmission risks are tolerable for cipher text that would not be tolerable for plain text, but is explicit that this decontrols nothing.
The second is E-Q2, added in November 2025 because contractors kept asking. Can a cloud service offering that is not FedRAMP Moderate store encrypted CUI? The answer is one word. No. A provider storing encrypted CUI in performance of a Department contract must still meet FedRAMP Moderate equivalent requirements.
The third is F-Q3. Encryption alone cannot create logical separation within a CMMC assessment scope. Logical separation occurs when data transfer between physically connected assets is prevented by non physical means such as firewalls, routers, VPNs, or VLANs. Encryption provides confidentiality, but does not by itself prevent transfer or enforce a boundary.
Put those three together and the practical consequence is clear. Encryption does not decontrol anything, and you cannot argue that because the AI vendor does not retain your prompts the data never really left. The control designation follows the information.
Redaction is the one path that can genuinely change the analysis. If a document is properly redacted or de identified so that no controlled information remains, what is left is not covered defense information and the constraint falls away with it. The catch is that this is a determination you have to make deliberately, document, and be willing to defend. Partial redaction that leaves controlled technical detail in place changes nothing, and where the markings are unclear you want the contracting officer’s view in writing before you rely on your own.
The FAQ does describe an architecture that can work, at F-Q1 and F-Q2. Treat it as a worked example rather than a guaranteed exemption, because the outcome turns on configuration. A properly configured virtual desktop infrastructure can keep an endpoint out of scope if the server side blocks copy and paste, file transfers, screenshots, printing, and any data exchange across the session, if the session transmits only video, keyboard, and mouse data, and if multifactor authentication to the server is separate from the unmanaged client. The FAQ is explicit that the client configuration must be verified. If your AI capability lives inside an accredited enclave reached under those conditions, you have a design you can defend. If it lives in a browser tab on a laptop that also opens CUI, you do not.
5. Your CMMC Scope Now Has an AI Shaped Hole
Adding an AI tool to an environment that handles CUI is a change to your CMMC assessment scope, and the Department has told you exactly which security requirements govern that change. Most small contractors have documented none of it.
The FAQ at C-Q5 contains a sentence that deserves to be printed and taped to a wall. Offerors must identify every CMMC unique identifier in the proposal that will be used to process, store, or transmit federal contract information or CUI in performance of the contract, and any company information systems not represented by those identifiers are considered non compliant and cannot be used to process, store, or transmit that information during contract performance.
Apply that carefully. It does not turn every AI tool in your company into a compliance problem. It means an AI service outside the identified assessment boundary must not process, store, or transmit federal contract information or CUI in performance of the contract unless you have documented a compliant scope and architecture covering it. A public chatbot on public marketing copy is not implicated. The same chatbot pointed at a marked technical data package is, and it does not matter that it is convenient or that no assessor is scheduled to look.
The FAQ at C-Q12 lists the security requirements that address changes: control CUI flow through the environment (AC.L2-3.1.3), actively manage changes (CM.L2-3.4.3), perform security impact analysis (CM.L2-3.4.4), conduct risk assessments (RA.L2-3.11.1), utilize plans of action (CA.L2-3.12.2), monitor controls continuously (CA.L2-3.12.3), and update the system security plan (CA.L2-3.12.4).
That last one carries a specific penalty. Per the FAQ at C-Q10, marking CA.L2-3.12.4 as not met produces no score at all in the Supplier Performance Risk System, because the absence of an up to date system security plan yields a finding that the assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012. A firm also gets no status if its score divided by the total Level 2 requirements falls below 0.8, or if it places any of the six requirements prohibited under 32 CFR 170.21 on a plan of action and milestones.
The decision about whether an AI deployment is a significant change requiring reassessment falls to your Affirming Official, who the Department states bears the legal and contractual risk of continued compliance. In a 40 person firm that is usually the owner or the president. If nobody in your company holds that title formally, that is the first gap to close.
| AI use case | Likely data type | Requirement triggered | Risk level |
|---|---|---|---|
| Public chatbot used to polish marketing copy | Public | Written AI use policy only | Lower |
| AI assistant summarizing a solicitation from SAM.gov | Public, but often overmarked | Verify markings before use | Medium |
| AI notetaker on a program status call | Frequently CUI | DFARS 252.204-7012 cloud requirement | High |
| AI code assistant on a repository that holds CUI | CUI | FedRAMP Moderate or equivalency | High |
| AI contract review on a subcontract with 7012 flow down | CUI | Scope, SSP entry, security impact analysis | High |
| AI summarizing controlled technical information or drawings | CUI, possibly export controlled | 7012 plus export control review | High |
6. What the DoW CIO Published About AI, and What It Is Not
The Department of War Chief Information Officer published voluntary AI guidance for the defense industrial base at the same moment it suspended Phase II, and practice number eight tells firms to prohibit sensitive Department data in public commercial AI systems. It is best practice guidance, not a contract clause.
The suspension release pointed contractors to Brilliant at the Basics, a DoW CIO initiative for small, mid sized, and non traditional companies, which publishes a top 10 list of IT cybersecurity best practices. Item eight, Secure AI Adoption and Data Protection, is the closest thing the Department has issued to plain language AI guidance for small contractors.
It recommends that firms establish clear policies and technical guardrails governing the use of artificial intelligence and automation tools across the workforce, explicitly prohibit the input of sensitive Department data into public commercial AI systems, and implement content filtering, endpoint controls, and approved enterprise AI environments so that accidental data exposure is prevented while safe adoption continues.
Be clear about its status before you cite it. It is published by the DoW CIO and addressed to defense industrial base partners, and it is expressly educational: the document carries a disclaimer that the information is for educational and informational purposes only, that implementing it guarantees no immunity, and that practices must be tailored to your organization. It says sensitive Department data rather than the defined terms CUI or covered defense information, so it changes the scope of nothing in your contract. It is the Department telling you what good looks like, not what you owe. What you owe is in DFARS 252.204-7012.
Notice the structure. It is not an AI ban. It has three parts: a written policy, technical enforcement, and a sanctioned alternative. Publish a policy without an approved environment and usage goes underground. Block tools without offering a sanctioned path and you lose proposal throughput to competitors who did the work.
None of that makes it safe to ignore. When an assessor, a contracting officer, or a Justice Department attorney later asks what your firm did about AI in 2026, having done nothing after the Department published this in July is not a comfortable position. It is also the cheapest control on the list. A written AI use policy, a data classification rule, and a tenant level restriction cost a fraction of a certification assessment.
Getting your AI governance in order
Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001.
7. Why False Claims Act Exposure Rises When Audits Pause
With third party assessments suspended, the False Claims Act becomes one of the most consequential enforcement paths for cybersecurity noncompliance, and the Justice Department is actively using it against small defense contractors.
It is not the only one. Contract remedies, a poor government assessment score sitting in the Supplier Performance Risk System where contracting officers can see it, cure notices, termination, and suspension or debarment risk all remain available and all bite. What makes the False Claims Act distinctive in a self attestation regime is that treble damages and per claim penalties attach to representations you made in order to get paid, and a competitor or a departing employee can start the case without waiting for the government to notice.
On June 18, 2026, the Justice Department announced that LOGZONE Inc. of Huntsville, Alabama agreed to pay $507,144 to resolve False Claims Act liability for knowingly failing to comply with cybersecurity requirements in Department of the Navy contracts. From May 2021 to March 2025, the government alleged, LOGZONE failed to implement certain NIST SP 800-171 controls that, if not implemented, could lead to significant exploitation of the system or exfiltration of sensitive defense information.
The number that should hold your attention is the score. When the Defense Contract Management Agency assessed LOGZONE’s implementation, the firm received a score of negative 170, at the low end of a possible range running from negative 203 to 110. Practitioner analyses of the settlement, including Foley and Lardner’s, report that the company had earlier self assessed at a perfect 110.
That is the risk profile of a self attestation regime in one data point. A self reported score sits in the Supplier Performance Risk System, a contracting officer relies on it, payments flow, and years later a government assessment produces a very different number. The claims were allegations only with no determination of liability, but the referral path is instructive: the Justice Department resolved it through coordination among the Civil Division Fraud Section, the U.S. Attorney’s Office for the Northern District of Alabama, Navy counsel, NCIS, Army criminal investigators, and the DCMA Defense Industrial Base Cybersecurity Assessment Center.
Connect this to AI directly. Your annual affirmation states that your firm continues to comply with the security requirements for your CMMC status. If, during the affirmation year, your staff routed CUI through an AI service that sits outside your assessed boundary and carries no FedRAMP authorization, that affirmation is inaccurate. The suspension of Phase II did not suspend the affirmation, and it did not suspend 31 U.S.C. 3729.
GOVERNANCE INSIGHT
The Affirming Official is now your highest risk role.
The Department states that the Affirming Official bears the legal and contractual risk of continued compliance. In a small firm that person is usually the owner. Before the next annual affirmation, that person needs a written inventory of every AI tool in the environment and a documented determination of whether each one touches CUI. Signing without that inventory is signing blind.
8. The Overmarking Problem: When You Cannot Tell What Is CUI
A large share of small contractors genuinely cannot tell which of their data is CUI, because the government and prime contractors mark inconsistently. That ambiguity makes AI governance harder, and it is not an excuse a court will accept.
On August 19, 2026, Federal News Network reported that the Department’s inconsistent and unclear process for identifying and marking CUI is driving up costs and creating confusion across the CMMC program. Industry groups told the reform effort that the Department and prime contractors frequently overmark CUI, apply blanket CMMC requirements to subcontractors who do not handle sensitive data, and in some instances have treated publicly available information as CUI.
The SBA Office of Advocacy, quoted in that reporting, said small businesses expressed numerous times that CUI is being overmarked, inconsistently marked, or improperly flowed down, and that the resulting uncertainty has downstream consequences.
For AI governance, overmarking cuts in a specific and awkward direction. If a prime marks an entire solicitation package CUI when three quarters of it came from a public website, your team cannot use any AI tool on any of it without either an accredited environment or a documented determination that specific portions are not CUI. Most small firms have neither, so they either freeze or, far more commonly, quietly use the tools anyway.
The workable answer is a data classification step before the AI step, not after. Keep a short written record for each contract stating what the customer marked, what your firm assessed, and who made the call. Use the right reference for the right question: the CUI Registry maintained by the National Archives is the governmentwide authority on categories and handling, because NARA is the CUI Executive Agent under 32 CFR Part 2002, while the DoD CUI Program site holds the Department specific implementation material. When a marking looks wrong, ask the contracting officer in writing and keep the answer. That correspondence turns a judgment call into a defensible one.
9. A 60 Day AI Governance Plan for a Small Defense Contractor
A firm under 100 people can establish a credible AI governance baseline in about 60 days using existing staff, and the work maps directly onto the NIST SP 800-171 controls an assessor will eventually examine.
Set the expectation honestly before you start. Sixty days gets you a defensible position on AI specifically: what tools exist, what data they reach, which ones are authorized, and the documentation to show it. It does not remediate a broader NIST SP 800-171 gap. If your self assessment score is well short of 110, closing that is a longer program on its own timeline, and this plan runs alongside it rather than instead of it.
Days 1 through 10: inventory. Produce a written list of every AI capability in the environment: standalone tools, AI features in your productivity suite, features your ERP or CAD vendor enabled in an update, browser extensions, AI notetakers on your meeting platform, and code assistants. Check identity provider logs and expense reports, not just what people tell you. This feeds directly into your system security plan.
Days 11 through 20: classify. For each tool, record what data it can reach and whether that data includes federal contract information or CUI. Be specific about the pathway. An AI assistant with access to a SharePoint site that holds a marked technical data package is a different risk than one that only sees a public marketing folder.
Days 21 through 30: verify authorization. For every tool that can reach CUI, obtain evidence of FedRAMP Moderate authorization or documented equivalency. Ask the vendor in writing for the specific offering, tier, and cloud region, and check the listing yourself rather than accepting a claim. Where the evidence does not exist, disconnect the tool from CUI systems or move the CUI.
Days 31 through 40: write the policy. Four pages is enough. Define approved tools, prohibited tools, what data may never be entered, the approval path for new tools, consequences of violation, and the named owner. State plainly that Department data may not go into public commercial AI systems, mirroring the DoW CIO guidance. Have every employee acknowledge it in writing.
Days 41 through 50: enforce technically. Policy without enforcement is a document that proves you knew. Use tenant level controls to block unapproved AI services, apply data loss prevention rules to CUI repositories, restrict browser extension installation, and disable AI features you have not approved in the platforms that keep enabling them by default.
Days 51 through 60: document the change. This is the step small firms skip and the step assessors look for. Perform a security impact analysis per CM.L2-3.4.4. Assess effects on CUI flow per AC.L2-3.1.3. Record the change in your change management process per CM.L2-3.4.3. Update the system security plan per CA.L2-3.12.4. Review the result with your Affirming Official before the next annual affirmation.
If you want a framework rather than a checklist, the NIST AI Risk Management Framework, published as NIST AI 100-1 in January 2023, organizes the work around four functions: govern, map, measure, and manage. It is voluntary and free, and it comes from NIST, the same agency behind the 800 series your contracts already cite. Keep the two straight in your documentation, because they do different jobs. NIST SP 800-171 is a federal information security publication your contracts incorporate by reference and an assessor scores you against. The AI RMF is voluntary risk guidance with nothing to score. ISO/IEC 42001 is the certifiable option when a customer asks for third party evidence of an AI management system.
10. What Happens When the Task Force Reports
The CMMC Reform Task Force owes its recommendations to the DoW Chief Information Officer roughly 60 days from July 13, 2026, which puts the report in mid September 2026, with formal decisions likely later.
The release established the task force as the central hub for synthesizing industry feedback from a public request for information on compliance challenges, which closed at noon Eastern on August 14, 2026. The task force was directed to recommend realistic, scalable security measures prioritizing speed to capability and lower barriers for small and non traditional businesses, and to report to the DoW CIO within 60 days.
Nobody outside the Department knows what the recommendations will say. The plausible outcomes range from a tiered model that exempts more small subcontractors from third party assessment, to a narrower CUI definition that shrinks scope, to a revived Phase II on a longer runway. Morgan Lewis noted in its client alert that the underlying contractual cybersecurity obligations survive regardless of what the program review concludes.
Two things are near certain in every scenario. NIST SP 800-171 is not going away: the Department has said in its FAQ that it will incorporate Revision 3 through future rulemaking, and issued a class deviation keeping Revision 2 as the assessment standard meanwhile. Whatever CMMC becomes, it will be measured against the 800 series. And AI usage will be higher when the next assessment regime arrives than it is today. Firms that documented their tooling in 2026 will pass. Firms that did not will be reconstructing two years of undocumented change from memory.
The pattern rhymes with what small SaaS companies faced when Brussels deferred the EU AI Act high risk deadlines while leaving transparency obligations on the original clock, which we covered in our analysis of the Digital Omnibus. A headline about delay is not a headline about repeal, and the obligations that were never deferred are the ones that get enforced in the gap. For the wider federal AI picture sitting on top of all this, including the GSA acquisition clause work and the FAR overhaul, we mapped it in The 2026 Federal AI Procurement Rules Decoded. CMMC is one layer, the AI procurement stack is another, and they are converging.
Talk to Ross about your AI governance needs
Every business has different AI governance requirements. Let us talk about yours.
Frequently Asked Questions
Does the CMMC suspension mean I can stop working on NIST SP 800-171?
No. The Department of War suspended CMMC Phase II on July 13, 2026, which paused third party certification assessments, but its announcement states that all defense contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS clause 252.204-7012. The Department also said it will continue enforcing the NIST SP 800-171 Revision 2 standard through self assessments and select government led assessments during the interim period.
Can my team use ChatGPT or Copilot if we handle CUI?
Only if the specific service offering meets FedRAMP Moderate baseline requirements or documented DoD recognized equivalency. DFARS 252.204-7012 requires a contractor using an external cloud service provider to store, process, or transmit covered defense information to require and ensure the provider meets those requirements. Whether a given AI tool is covered depends on whether it actually receives that information. Most commercial AI services in a standard commercial tenant hold no such authorization, and vendor government cloud offerings vary by product, tier, and region, so verify the exact service environment before any controlled data touches it.
What if we encrypt the CUI before putting it into an AI tool?
Encryption does not remove the obligation. The Department’s CMMC FAQ states at E-Q2 that a cloud service offering that is not FedRAMP Moderate cannot store encrypted CUI, and at B-Q8 that encrypted CUI retains the control designation of its plain text counterpart until formally decontrolled under 32 CFR Part 2002. The FAQ also states at F-Q3 that encryption alone does not create logical separation within a CMMC assessment scope.
What are the penalties if we get this wrong?
The realistic exposure is the False Claims Act rather than a failed audit. On June 18, 2026, the Justice Department announced that LOGZONE Inc. of Huntsville, Alabama agreed to pay $507,144 to resolve allegations it failed to implement required NIST SP 800-171 controls on two Navy contracts between May 2021 and March 2025. A Defense Contract Management Agency assessment scored the company at negative 170 on a scale running from negative 203 to 110.
When will CMMC Phase II come back?
No date has been announced. The Department established a CMMC Reform Task Force to review the program and deliver a final report to the DoW Chief Information Officer within 60 days of the July 13, 2026 announcement, which places the report in mid September 2026. The supporting request for information closed at noon Eastern on August 14, 2026. Formal program decisions are expected to follow the report rather than accompany it.
Does any of this apply to a subcontractor that never signed a contract with the government?
Yes. DFARS 252.204-7012 flows down through subcontracts involving covered defense information, and the Department’s CMMC FAQ confirms at B-Q6 that CMMC requirements flow down to subcontractors under 32 CFR 170.23 based on whether federal contract information or CUI is processed, stored, or transmitted on the subcontractor’s systems. A firm three tiers down the supply chain that receives marked CUI carries the safeguarding obligation.
About the author
Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.
Related articles
- The 2026 Federal AI Procurement Rules Decoded: A Survival Guide for Small Contractors and Subcontractors
- Only 12% of Manufacturers Think They Could Pass an AI Audit. Your Customers Are Starting to Run One.
- August 2 Did Not Get Cancelled: What the Digital Omnibus Delayed and What Small US SaaS Companies Still Owe
- Illinois SB 315 Explained: The First State AI Audit Law and What It Means for Your Business
This article is provided for general informational purposes and reflects the state of the law as of August 2026. It is not legal advice. Regulations in this area are changing quickly. Confirm current requirements and consult qualified counsel before making decisions for your organization.