Full Report
DoW paused the CMMC Phase II deadline in July, but the underlying compliance obligations didn't move. Meanwhile, Huntress Managed ISPM pushes our NIST SP 800-171 coverage to 55 of 110 requirements. Here's what changed, what didn't, and why we're not slowing down.
Analysis Summary
# Regulation/Compliance: CMMC Phase II & NIST SP 800-171 Obligations
## Overview
This compliance update addresses the Department of Defense (DoD) decision to pause the Cybersecurity Maturity Model Certification (CMMC) Phase II certification deadline. While the formal third-party certification requirement is temporarily suspended, the underlying legal obligations to protect Controlled Unclassified Information (CUI) under existing DFARS clauses and NIST standards remain mandatory and enforceable.
## Key Details
- **Issuing Authority:** Department of Defense (DoD) / FAR Council
- **Effective Date:** Immediate (Pause announced July 2026); NIST/DFARS requirements are currently in effect.
- **Jurisdiction:** Defense Industrial Base (DIB) and federal contractors handling CUI.
- **Status:** CMMC Level 2/3 Certification: **Proposed/Paused** | NIST 800-171 & DFARS 252.204-7012: **Final/In Effect**.
## Requirements
### Mandatory Requirements
1. **NIST SP 800-171 Rev 2:** Compliance with all 110 security controls is still required for contractors handling CUI.
2. **DFARS 252.204-7012:** Mandatory safeguarding of covered defense information and cyber incident reporting.
3. **Self-Assessments:** Organizations must continue to perform and report self-assessments for CMMC Levels 1, 2, and 3.
4. **False Claims Act (FCA) Compliance:** Representations of security posture must be accurate to avoid litigation.
5. **Incident Reporting:** Proposed FAR rule requires reporting CUI incidents within **72 hours** (government-wide).
### Recommended Practices
1. **Maintain Assessment Schedules:** Organizations with C3PAO assessments already scheduled should proceed to "future-proof" revenue.
2. **Managed ISPM:** Implement Identity Security Posture Management to automate control enforcement across Microsoft 365 environments.
3. **Shared Responsibility Matrix:** Use vendor-provided matrices to identify which controls are managed by software vs. the organization.
## Affected Organizations
- **Industries:** All DoD contractors and subcontractors; expanding to all federal contractors under proposed FAR rules.
- **Organization Size:** All sizes, including Small to Medium-Sized Businesses (SMBs) in the supply chain.
- **Geographic Scope:** Global (any entity handling U.S. DoD CUI).
## Compliance Timeline
- **June 23 (Year Prior):** FAR Council proposed government-wide CUI reporting rule.
- **July 2026:** DoD pauses CMMC Phase II (Level 2/3) certification deadline for a 60-day review.
- **November 2026:** Original CMMC certification deadline (Currently paused, but self-assessment obligations remain).
- **Ongoing:** DFARS 252.204-7012 and NIST SP 800-171 compliance is currently required for active contracts.
## Implementation Guidance
### Assessment Phase
- **Gap Analysis:** Evaluate current environment against the 110 controls of NIST SP 800-171.
- **Identify CUI:** Locate where Controlled Unclassified Information resides within the network and cloud apps.
### Implementation Phase
- **Control Remediation:** Address failed controls; leverage tools like Huntress to cover identity-related requirements (e.g., Managed ISPM).
- **Documentation:** Update System Security Plans (SSP) and Plans of Action and Milestones (POA&M).
### Validation Phase
- **Self-Assessment:** Upload scores to the Supplier Performance Risk System (SPRS).
- **Internal Audit:** Conduct mock audits to ensure controls are "sticky" and consistently applied.
## Technical Requirements
- **Identity Security:** Continuous monitoring and enforcement of Microsoft 365 configurations (Managed ISPM).
- **Access Control:** Restricting CUI access to authorized users only.
- **Audit & Accountability:** Maintaining logs sufficient to meet the 72-hour incident reporting window.
## Penalties & Enforcement
- **Fines:** Significant penalties under the **False Claims Act** for misrepresenting compliance status.
- **Other Consequences:** Loss of current DoD contracts, removal from active solicitations, and damage to "Prime" contractor relationships.
- **Enforcement:** The DoD reserves the right to audit self-assessments via DIBCAC at any time, despite the CMMC certification pause.
## Related Standards
- **NIST SP 800-171:** The foundational framework for CMMC Level 2.
- **FAR (Federal Acquisition Regulation):** Moving toward a unified CUI rule for all federal agencies, not just the DoD.
## Resources
- **Official Documentation:** [NIST SP 800-171](https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final)
- **Guidance Documents:** [Huntress Trust Center / Shared Responsibility Matrix](https://trust.huntress.com/)
- **Tools:** Huntress Managed ISPM (Covers 55 of 110 NIST controls).
## Practical Recommendations
- **Do not cancel C3PAO plans:** The pause is a window of opportunity to finalize compliance without the pressure of a hard deadline.
- **Verify Subcontractors:** Prime contractors may still require certification regardless of the DoD pause to mitigate their own risk.
- **Focus on Identity:** Since identity is a primary attack vector, prioritize the 55 controls related to identity and cloud configuration.