July 23, 2026
Key takeaways
  • Prompt injection attacks manipulate AI guardrails using natural language, exploiting the semantic gap to get models to ignore developer instructions.
  • AI social engineering scales faster and lowers attacker skill barriers, enabling automated, targeted campaigns like deepfakes and credential theft.
  • Primary harms include data exfiltration, unauthorized transactions, and malicious or biased outputs that damage reputation and operations.
  • Defenses are immature; require layered controls: human in the loop, prompt firewalls, input sanitization, least privilege, fuzz testing, patching, and user training.

Last Updated on July 28, 2026

The July 13, 2026 Department of War (DoW) announcement to suspend its impending Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirement for mandatory third-party audits buys defense contractors more time to bring their cybersecurity programs up to speed. But will it significantly reduce overall compliance cost or effort—especially for SMBs that handle controlled unclassified information (CUI)?

This article examines that question for business and technical leaders in the defense industrial base (DIB). 

Key takeaways

  • The recent DoW announcement pauses upcoming CMMC Phase 2 requirements for third-party assessments pending a 60-day review. All current requirements remain in force.
  • Implementing NIST SP 800-171 controls and assessment objectives is by far the largest cyber compliance cost factor for DIB firms that handle CUI. Pausing CMMC Phase 2 assessment requirements does not directly impact these costs.
  • The NIST SP 800-171 compliance mandate is encoded in law and will not change through the current review process. 
  • Rather than stopping or scaling back their cybersecurity programs, DIB orgs that handle CUI should view the CMMC Phase 2 pause as giving them additional time to identify the right compliance partners and implement the mandated NIST SP 800-171 controls and assessment objectives. 

What did the DoW announce on July 13, 2026?

The recent DoW announcement represents a major shift in its cybersecurity policy. The key changes are:

  • Immediate suspension of CMMC Phase 2 rollout requirements that were scheduled to take effect on November 10, 2026. The subsequent Phase 3 and Phase 4 milestones are also suspended. This delays the requirement for defense suppliers that handle CUI to pass a third-party CMMC Level 2 certification assessment as a precondition of contract award.
  • Formation of a CMMC Reform Task Force to perform a 60-day review of the entire CMMC program with a goal of delivering actionable recommendations to reduce CMMC compliance costs and bureaucratic hurdles for DIB SMBs. 
  • A mandate to align CMMC with recent DoW Acquisition Transformation System (ATS) goals to lower barriers for SMB and non-traditional suppliers looking to enter or stay in the DIB.

 

What the CMMC pause does not change are the current DoW cybersecurity obligations, most of which have been in place since 2016. These include compliance with the DFARS 7012 clause in current contracts mandating implementation of the 110 controls and 320 assessment objectives defined in NIST SP 800-171 Revision 2, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.”

Also still in force are current CMMC Phase 1 requirements for annual self-assessments with senior leadership affirmation, backed up by a compliance score and supporting evidence in the DoW’s Supplier Performance Risk System (SPRS) database. 

Why did the DoW suspend CMMC Phase 2?

The DoW’s decision to suspend CMMC Phase 2 reflects pressure from the US Small Business Administration and DIB SMB stakeholders. It reflects concerns that the current CMMC framework imposes onerous costs and bureaucratic red tape on small contractors that are essential to innovation and program execution across the defense supply chain. 

 

Following this latest review of the CMMC program, the DoW hopes to revamp CMMC in a manner that supports robust cybersecurity across the DIB while lowering regulatory hurdles. 

 

Pausing the requirement for third-party certification also serves to reduce the likelihood of inflated assessment costs driven by a C3PAO demand bottleneck. It may also reduce assessment delays that could lock compliant suppliers out of contract award processes, leading to reduced competition and lower supply chain efficiency. 

 

CMMC Level 2 assessments with C3PAOs are ongoing during the review process, as is the onboarding of new C3PAOs and qualified assessors. Also ongoing is the DoW’s authority to require third-party assessments in specific cases.

What are the cost factors for achieving DoW cyber compliance?

The actual cost of achieving, maintaining, and validating a DoW compliant cybersecurity posture involves a range of factors:

 

  • Upfront technology investments. These include deploying new cybersecurity tools and services, upgrading or replacing legacy systems, and integrating current solutions. These investments can be a stretch, especially for SMBs already operating on lean budgets.
  • Assessment and certification costs. These costs vary based on business size/complexity, the presence of CUI in the environment, and whether the audit is performed internally or by an independent assessor. The expense and effort involved is ongoing and likely to be significant for smaller firms. 
  • Resource allocation. Attaining and maintaining DoW cyber compliance requires dedicated resources, often including both internal and external staff with specialized expertise. DIB orgs may need to train, hire, and/or outsource new skill sets, which can substantially increase operational costs.  
  • Ongoing compliance costs. Maintaining compliance with DoW regulations is a continuous process that involves ongoing expenses associated with monitoring, risk assessment, periodic gap assessments, control updates, etc. 
  • Indirect costs. Indirect DoW cyber compliance costs include opportunity costs associated with diverting time and effort toward cybersecurity that might otherwise go towards direct revenue generation or product development, temporary operational disruptions due to IT changes, and productivity impacts from assigning additional tasks to current staff.

 

When analyzing cost factors for your own business, keep in mind that technology and process implementation expenses are “durable” investments that remain in place and deliver ongoing return by mitigating cybersecurity and compliance risks and associated financial, reputational, and legal impacts. The cost of a single data breach often vastly exceeds the total cost of NIST SP 800-171 control implementation. A verifiably robust cybersecurity posture also confers competitive advantage with the DoW and its prime contractors.

How does pausing CMMC Phase 2 change the DIB cyber compliance cost picture?

Notwithstanding short-term relief and an opportunity to develop a more efficient strategy and/or spread expenses out over time, many cyber compliance costs are not directly impacted by delaying CMMC Phase 2. 

 

These are key cost considerations now for DIB SMBs that handle CUI:

  • Per the DFARS 7012 clause in current contracts, the requirement to achieve and maintain compliance with the NIST SP 800-171 framework that CMMC is based on does not change. 
  • Requirements for self-assessment, maintaining a current compliance score in SPRS, maintaining evidence to validate that score, and executive affirmation of compliance status do not change.
  • While the DoW has paused the requirement for independent assessments for DIB orgs that store, process, or transmit CUI, it has not eliminated those costs. Whether this is a temporary or permanent reprieve for some or all contractors that handle CUI remains to be seen.
  • The current 60-day review period creates uncertainty for DIB orgs about whether the DoW will restructure CMMC Level 2 audit requirements, how that might look, and how long the associated rulemaking or policy development will ultimately take. Consulting and outsourcing expenses could persist or even increase as companies attempt to make business decisions based on shifting guidelines.

 

For nearly every defense contractor, the largest cost vector by far in DoW cyber compliance is the technical controls implementation, IT changes, staff augmentation, policy and documentation updates, and continuous monitoring required to meet current DoW contract obligations around protecting CUI. All the NIST SP 800-171 controls must remain active to avoid violating contract terms and risking contract revocation, Small Claims Act prosecution, and/or revenue repayment.

Consequently, cybersecurity and DoW compliance costs are unlikely to drop significantly for DIB orgs during the current CMMC review period. Whether costs drop going forward depends on the nature of any CMMC program reforms—but these are likely to impact only the DoW’s compliance assessment regime. 

 

For example, the DoW could institute a more streamlined certification scheme for some SMBs based on the sensitivity of the CUI they handle. The Capability Maturity Model Integration (CMMI) offers a possible model for greater flexibility in CMMC assessment obligations or compliance scoring.

 

One factor that will not change is the mandate to protect CUI via NIST SP 800-171 control requirements, which is encoded in law. The only legally possible shift in that regard is a change from NIST SP 800-171 Revision 2 to NIST SP 800-171 Revision 3 controls. The latter consolidates some controls to reduce the overall count from 110 to 97, but increases the number of assessment objectives significantly, from 320 to over 420—not exactly a reprieve for DIB orgs.

 

The DoW has stressed that a robust cybersecurity posture capable of protecting CUI in today’s threat environment remains a fundamental priority across the defense supply chain. Scaling back or halting cybersecurity investments now could leave DIB orgs unable to address new or reinstated requirements or meet compliance deadlines.

What’s next?

Is your business in compliance with the DoW cybersecurity requirements your current or prospective contracts specify? Are you able to post, justify, and attest to a competitive compliance score in SPRS?

CBIZ Pivot Point Security offers a full slate of advisory and consulting services for DIB companies. Our assessment, implementation, and remediation support will ensure you efficiently meet all cyber compliance obligations to participate in DoW contracts.

Contact us today to schedule a conversation with a defense industry cybersecurity and compliance expert.

Back to Blog