- Prompt injection attacks manipulate AI guardrails using natural language, exploiting the semantic gap to get models to ignore developer instructions.
- AI social engineering scales faster and lowers attacker skill barriers, enabling automated, targeted campaigns like deepfakes and credential theft.
- Primary harms include data exfiltration, unauthorized transactions, and malicious or biased outputs that damage reputation and operations.
- Defenses are immature; require layered controls: human in the loop, prompt firewalls, input sanitization, least privilege, fuzz testing, patching, and user training.
Last Updated on August 7, 2026
Many clients in the defense sector are asking about changes to Cybersecurity Maturity Model Certification (CMMC) Level 2 compliance and assessment requirements during and after the CMMC Phase 2 suspension.
What should DIB orgs with controlled unclassified information (CUI) do now to maintain compliance, honor current contracts, and stay on track for what’s next?
This post gives business and technical decision-makers a quick overview of what is most important now and going forward for US Department of War (DoW) compliance if you handle CUI.
Key takeaways
- You remain obligated to implement the 110 controls in NIST SP 800-171 Rev. 2 per the DFARS 252.204-7012 clause in current contracts.
- The DoW still requires you to maintain a valid, defensible, up-to-date NIST SP 800-171 self-assessment compliance score and associated executive attestation in the Supplier Performance Risk System (SPRS) database.
- Many prime contractors (including the five largest) may still require CMMC Level 2 compliance or certification as part of their flow-down requirements to protect the CUI they share with subcontractors.
- Only third-party audit mandates are on hold.
What has and has not changed with the CMMC Phase 2 suspension?
On July 13, 2026, the DoW paused the CMMC Phase 2 rollout pending a 60-day program review. CMMC Phase 2 would have required third-party certification of CMMC Level 2 compliance for most contractors that handle CUI, effective November 10, 2026.
What has changed is the requirement for an independent certification assessment to validate your compliance with DoW cybersecurity mandates.
What has not changed are your critical obligations to protect CUI. Still fully in force are:
- Contract agreements under DFARS 7012 to implement the 110 controls and 320 assessment objectives in NIST SP 800-171 Rev. 2.
- The requirement to maintain a valid, current (less than 3 years old) NIST SP 800-171 compliance self-assessment score and substantiating evidence (e.g., a current System Security Plan, historical logs) in SPRS.
- The requirement for an annual assignation by a senior leader that your SPRS self-assessment score is valid.
- The US Department of Justice (DoJ) Civil Cyber-Fraud Initiative, which exposes your business and its executives to prosecution the under the False Claims Act if your SPRS score does not withstand scrutiny.
DoW paused CMMC Phase 2 to release resistance and bottlenecks associated with third-party audit costs and timelines. The longstanding obligation to protect CUI on non-government systems remains.
According to Under Secretary of War Michael Duffey, the reason for suspending CMMC Phase 2 was to “maintain a strict security baseline while removing paralyzing costs.”
What are essential next steps for DIB orgs that handle CUI?
Even if your cybersecurity program already complies fully with NIST SP 800-171 and you have posted a perfect 110 score and associated documentation in SPRS, you still need to sustain compliance as your environment continuously changes and threats advance.
If you have documented Plans of Action & Milestones (POA&Ms) in SPRS, you need to continue resolving those and moving toward full compliance. This is essential to maintain your good standing with the DoW and prime contractors, demonstrate a commitment to protecting sensitive data to stakeholders, and avoid negative competitive impacts for weak cybersecurity or data breach exposure.
If your cybersecurity program does not yet conform to DoW requirements, you should not lose momentum but use this extra time to keep following through on your NIST SP 800-171 compliance roadmap and close remaining gaps. Threat actors are targeting your organization, and a cyber incident could bring not just competitive losses but also audit scrutiny, legal impacts, and reputational damage even outside your defense business.
The government’s 60-day review period is to evaluate streamlining CMMC, not scaling back CUI protections in the face of escalating threats. Keep an eye out for news and updates on CMMC reforms and DoW recommendations during the review period, which ends in mid-September 2026.
What is the real risk from overstating NIST SP 800-171 compliance?
Above all, do not inflate or falsify your self-attestations, as is this is a federal crime and False Claims Act prosecution remains aggressive with financial penalties up to triple the contact value. Self-attested compliance scores that you cannot support are also cause for loss of DoW contracts and disqualification from participation in future contracts.
If you think your organization can risk overstating its NIST SP 800-171 compliance score in SPRS because your chances of facing a government-lead audit are low, consider that a high percentage of False Claims Act prosecutions result from whistleblower claims lodged by internal staff, third-party consultants, and others. Under the law, whistleblowers receive 15% to 30% of the total funds the DoJ recovers from a successful lawsuit or settlement.
What’s next?
Is your business in compliance with the DoW cybersecurity requirements in your current or prospective contracts? Are you able to post, justify, and attest to a strong compliance score in SPRS?
CBIZ Pivot Point Security offers a full slate of advisory and consulting services for DIB companies. Our assessment, implementation, and remediation support will ensure you efficiently meet all cyber compliance obligations to participate in DoW contracts.
Contact us today to schedule a conversation with a defense industry cybersecurity and compliance expert.