CMMC Hit Pause, the FAR Council Hit Play

I was at XChange a couple weeks ago, and I kept asking the same question at our booth: "Does anybody here have defense contractor customers, and do you care about CMMC?"

The answers were pretty consistent:

  • "We had two clients pushing hard on it. Both of them went quiet after the news."

  • "My client's prime told them to keep going. Nobody knows who to listen to."

  • "Wait, it got paused? What does that mean?"

That last one came up more than once. And I get why. If you only read the headline on July 13, you'd walk away thinking the whole thing evaporated.

It didn't. And while everybody was busy reading the CMMC hyperbole, a different rule went out that has a much bigger blast radius. Let me walk you through both.

What actually happened on July 13

DoD suspended CMMC Phase 2. That's the phase where contract officers require third-party certification assessments for solicitations published after November 10, 2026. Under this "strategic pause," solicitations still include the CMMC provision and contracts still include the CMMC clause (DFARS 252.204-7021) for phase 1 with self-assessments.

A new CMMC Reform Task Force is running a top-to-bottom review of the program and reporting back to the CIO inside 60 days, doing some back-of-the-napkin math, that puts recommendations somewhere around September/October.

Can't stop, won't stop

Here's the part that got lost.

Phase 1 never stopped. Level 1 and Level 2 self-assessments still show up in applicable solicitations and contracts. They've been in force since November 2025. Solicitations still include the CMMC provision (DFARS 252.204-7025) and contracts still include the CMMC clause (DFARS 252.204-7021) using Level 1 and Level 2 "self-assessment."

SPRS scores still matter. Your client is still submitting a score. What changed is the enforcement, not the rule. A contract specifying Level 2 has always required at least 88 out of 110 points; Phase 1 just means someone's actually checking now.

DFARS 252.204-7012 didn't move. The obligation to safeguard CUI and report incidents inside 72 hours has been sitting in defense contracts since 2017. A memo pausing a certification phase does nothing to this contract clause.

Primes haven't stopped based on what the Pentagon announced. We've already seen prime contractors send supplier notices telling their subs to keep going. Your client's flowdown obligations come from their contract, not from a press release.

And the False Claims Act exposure arguably got worse. The combination of higher minimum scores, and a requirement for senior company officials to annually affirm the score's accuracy, means more opportunities to misrepresent compliance. Meanwhile the Department's own assessment teams (DIBCAC) are now cooperating directly with the Department of Justice on False Claims Act cases. No whistleblower required.

Put plainly: the certification tier is paused. Proving compliance is not.

Now here's the rule nobody covered, and it's gonna go FAR

Ten days before the CMMC announcement, on June 23, the FAR Council published its proposed CUI rule as part of the Revolutionary FAR Overhaul. The FAR council includes DoD. Meaning it's a level above DoD with a much wider reach.

Three things in it you should know about:

  1. It's not just defense anymore. The proposed clauses would apply to federal contractors on FAR-based contracts, not just the defense industrial base. If a contract involves CUI, the contracting officer completes a form identifying what CUI is involved and where it lives, and that form comes along with the contract. Civilian agencies never had a governmentwide clause for this. Every agency improvised. This closes that gap.

  2. The baseline moved to NIST 800-171 Revision 3. The January 2025 version of this rule pointed at Rev 2, the same baseline DFARS 252.204-7012 uses today. The June 2026 version points at Rev 3. That is not a citation cleanup. Rev 3 restructures and expands on the requirements. Meanwhile CMMC Level 2 is still tied to Rev 2. So for a while, a mixed defense and civilian contractor could be looking at two revisions of the same standard at the same time.
    Note: we think it likely that a CMMC move to Rev. 3 in 2027 will be an outcome of the pause to align both rules. Keep your eye out for that, it's important.

  3. 72-hour incident reporting, and it flows down to subcontractors. Which means it eventually lands on somebody's MSP.

Comments closed July 23. There's no final rule yet, so nothing here is live contract language today. Don't go rewriting anybody's security program off a proposed rule.

But read the room. This is an administration that spent a year pulling clauses out of the FAR under an executive order literally about restoring common sense to procurement. Almost nothing got added in that process. This got added.

About that "we'll just POA&M it" plan

This is where I want to spend a minute, because it's the most common misconception I run into, and it's the one that costs people money.

A lot of folks treat the plan of action and milestones like a hall pass. Score's a little low, no big deal, we'll write a POA&M and sort it out later.

Read 32 CFR 170.21 and that falls apart fast.

  • Level 1 self-assessments get no POA&M. Ever. Not a narrow exception. Zero.

  • At Level 2, you need a score of at least 88 out of 110 before a POA&M is even on the table.

  • Only 1-point requirements can go on it. Every requirement is worth 1, 3, or 5 points. Every 3-point and 5-point requirement has to be fully met going in. There's exactly one carve-out: CUI encryption can ride a POA&M at 3 points if you're already encrypting but the module isn't FIPS-validated. That's it.

  • Six specific requirements can never be deferred, even though they're only worth a point each. External connections, control of public information, your system security plan, and three physical access requirements around escorting visitors, access logs, and managing access devices.

  • You get 180 days. Miss the closeout and your conditional status expires.

So the POA&M isn't a strategy. It's a small budget for residual gaps you find during the assessment, not a place to park work you already know you haven't done.

32 of our 55

Here's why this matters for anyone using Huntress as part of a compliance story.

Our team and the folks at DEFCERT went through the requirements you cannot skip under Level 2, even on the self-assessment path. Of the 55 NIST 800-171 requirements Huntress currently helps you support, 32 of them fall into that non-negotiable bucket.

Not "nice to have by the assessment." Not "we'll get to it." Has to be done.

That's a little over half of what we cover landing squarely in the category where a POA&M won't save you. Which is a decent argument for why "compliance is paused" is the wrong way to read the last month, and a very good argument for looking at what your clients already have deployed versus what they think they need to buy.

Keep in mind: That 32-of-55 analysis is built on Rev 2 and CMMC Level 2 scoring, which is where the DoD program sits today. If the FAR CUI rule finalizes on Rev 3, some of that mapping shifts. We're working the upgrade path with DEFCERT already and we'll publish the crosswalk when it's solid, not before.

And to be clear about what we do and don't do: Huntress supports these requirements. We don't certify anybody. Nobody's product does. Your client's SSP and their signature are still their SSP and their signature.

What to actually do this week

You don't need a compliance program by Friday. You need better questions. Three of them, for your next client conversation:

  1. Do you hold any federal contracts, prime or sub? Including grants, including the odd one-off. A lot of clients have one and never thought to mention it.

  2. Who reads the clauses? If the answer is "our lawyer, sometimes," you've found your gap. MSPs don't review contracts. Somebody has to.

  3. Where does government data actually live right now? Not on the org chart. In the environment. Which endpoints, which mailboxes, which file shares.

If you've got higher ed, healthcare, state and local, or financial services clients, run those questions there too. Those sectors sit on FAR-based contracts more often than people expect, and the CUI categories they handle are exactly the kind this rule is built around.

Where we're at

CMMC didn't get easier. The next phase got paused while the underlying requirements got wider and, on the FAR side, a revision harder.

We're tracking this and we'll keep publishing as the task force report lands in September and as the final rule shows up. When we're wrong about something, we'll say so and fix it.

If you want the requirement-level detail, the CMMC kit and the coverage documentation live in our Trust Center. And remember, there's no upcharge to get the benefits of CMMC compliance with Huntress, just a support request to enable Sensitive Data Mode and download and use the Shared Responsibility Matrix and free preparation documentation we've created for you in our Trust Center, free of charge.


This post covers a proposed rule that is not final. Nothing here is legal advice, and you/your client's contract is the only thing that actually binds them. Talk to their contracts attorney.