DoW Paused the Deadline. You Still Have to Comply with the Law.

Key Takeaways

Big news in the CMMC world this month: 

  • DoW hit pause on the Phase II certification deadline. 

Big Huntress news for CMMC this month: 

  • Huntress just increased from 37 of the 110 NIST SP 800-171 requirements to 55, thanks to Managed ISPM.

TL;DR: Nothing about your obligation to protect CUI got lighter this month. DoW bought suppliers' time, not an exemption. Huntress is using this moment to keep investing in coverage, not coast on it. And so should you. 

DoW Paused the Deadline. Your Compliance Work Isn't Paused.

The short version: the November certification deadline is paused, but NIST SP 800-171 self-assessments, DFARS 252.204-7012 obligations, and prime contractor expectations all remain in place; and complying with the False Claims Act is still your North Star. The FAR Council is also moving forward on a separate government-wide CUI rule. Stay the course in protecting your CUI to future-proof your DoW revenue.

The need to protect CUI and self-assess for L1, L2, and L3 doesn't go away. The only thing being suspended is the DoW requirement for a C3PAO or DIBCAC to certify you before November 2026. DoW still requires you to meet the 110 L2 requirements to protect CUI, and it reserves the right to audit your self-assessment at any time.

Read between the lines here: this is DoW admitting that suppliers aren't ready. For SMBs, that's a gift of extra time. Use it wisely. This is not an excuse to delay preparation. It's a chance to walk into your eventual assessment prepared, rather than scrambling.

Separately, the FAR Council proposed a rule on June 23 to make CUI incident reporting in under 72 hours a government-wide requirement, not just DoW. 

CUI protection isn't slowing down. It's expanding.

What actually changed

DFARS 252.204-7012 and NIST SP 800-171 Rev 2 are still in force. There's no change. You still have to do that. Full stop.

CMMC itself is suspended pending a 60-day review. In practice, that means CMMC Level 2 (C3PAO) and Level 3 (DIBCAC) can't be contractually required by DoW right now. Active solicitations that already carry that requirement are getting amended to remove it.

Prime contractors are the open question. Nothing stops a prime from requiring certification on their own, even while DoW backs off. If you're a sub, don't assume your prime is going to relax just because DoW did.

And C3PAOs haven't stopped working. We've confirmed assessments are continuing today for organizations that had them scheduled. Those who move forward with their assessments are future-proofing their funnel and their DoW revenue. Stay the course.

What this means for you

If you've got a Level 2 or Level 3 assessment underway or on the calendar, the November deadline pressure is gone. That's real relief. Don't waste it. Use the extra runway to close gaps properly instead of rushing a checklist exercise. But don't cancel your plans. Keep doing the work to protect CUI.

If you were hoping this suspension meant you could stop worrying about CUI, that's not what happened. NIST SP 800-171 Rev 2 self-assessment is still mandatory. DFARS 252.204-7012 still obligates you to safeguard covered defense information, certification status or not. DoW can still audit your self-assessment whenever it wants. And the FAR Council is actively building a government-wide CUI reporting rule that will apply well beyond DoW contracts. CUI protections are expanding, not going away.

Meanwhile, Huntress Just Got You Closer to Half the Controls

This month, Huntress added Managed Identity Security Posture Management (ISPM) to our CMMC documentation. That update takes Huntress support from 37 of the 110 NIST SP 800-171 requirements to 55, which is over half the controls a CMMC L2 assessment runs on. The updated mappings are now live in the Shared Responsibility Matrix available for download in our Trust Center.

A Shift Left to Prevention

Managed ISPM continuously enforces security controls across your Microsoft cloud attack surface. That's new ground for us. Until now, Huntress has earned its place in a CMMC scope mostly by catching attacks after they started. ISPM lets us configure and enforce Microsoft 365 settings against current attacker tradecraft before anything fires, which is why our supported requirement count moved from 37 to 55.

We refreshed the paperwork to match. The Shared Responsibility Matrix and the Operations Plan now live together, with a "How to Use" tab and a separate tab that maps 800-171 to Huntress products in plain terms. Partners and customers receive the latest guidance through the Trust Center, rather than chasing the latest version.

Where ISPM earns the new coverage

Identity and access. Before ISPM, Managed Identity Threat Detection and Response (ITDR) and Managed SIEM detected identity-based attacks and isolated the accounts involved. ISPM adds prevention through Security Controls and Managed Conditional Access Policies, so common attacker tradecraft gets blocked at the door. That's what pushes our coverage further into the Access Control (AC) and Identification and Authentication (IA) families.

Configuration and protocols. ISPM runs independently from Microsoft 365, so it tracks configuration drift, holds settings in a secure state, and keeps unauthorized changes from sticking. A lot of the current controls and managed policies exist to disable or block insecure protocols and services, which is what broadens our reach across Configuration Management (CM) and System and Communications Protection (SC).

Continuous monitoring. An assessor wants ongoing proof that a control still works, not a screenshot from the day it was switched on. ISPM dashboards show continuous enforcement of Security Controls next to Conditional Access Policies, both the ones Huntress manages and the ones your team creates. You can point to how long a configuration has held, and to the enforcement alert that fires when Continuous Enforcement reverts an unauthorized change. That's the evidence an assessment and/or audit both ask for.

Why the documentation update carries weight

Better security only helps in compliance when it's documented, enforced, and verifiable. Huntress already built its CMMC support around the Shared Responsibility Matrix, the Operations Plan, and the supplemental templates that help you document the work inside your own business. Those materials now reflect the wider scope ISPM opens up and the move from 37 requirements to 55.

For partners, MSPs, and DoD subcontractors, that's less guesswork mapping Huntress capabilities to requirements, and more confidence in a self-assessment or walking into a C3PAO assessment with the evidence already lined up.

Same Message, Two Fronts: We're Not Slowing Down. Neither Should You.

Notice the pattern. DoW hit pause on a deadline, and we ship, and map, more coverage, not less effort. The Shared Responsibility Matrix isn't a document we published once and shelved. It's one we keep updating as our platform picks up more of the 110 controls. And ISPM's jump from 37 to 55 is the latest proof of that.

That's the standard we'd point you toward, too. DoW admitting the industry isn't ready is not permission to stand still. It's extra runway. Use it to close real gaps, not to turn a blind eye and hope it goes away.

The Takeaway

Stay the course. You still have to protect CUI. You still have to self-assess. You can still be audited on that assessment. The certification gate moved, the obligation didn't, and Huntress isn't easing off either.

Treat this pause like extra time on a test you still have to take, not a reason to put the pencil down.

Ready to see what's new? Download the updated SRM + Ops guide and dig into the latest CMMC resources on the Trust Center.