- Prompt injection attacks manipulate AI guardrails using natural language, exploiting the semantic gap to get models to ignore developer instructions.
- AI social engineering scales faster and lowers attacker skill barriers, enabling automated, targeted campaigns like deepfakes and credential theft.
- Primary harms include data exfiltration, unauthorized transactions, and malicious or biased outputs that damage reputation and operations.
- Defenses are immature; require layered controls: human in the loop, prompt firewalls, input sanitization, least privilege, fuzz testing, patching, and user training.
Last Updated on August 7, 2026
The Department of Defense (DoD) developed the Cybersecurity Maturity Model Certification (CMMC) 2.0 program to protect sensitive information and enforce compliance across the defense supply chain. However, the Department of War (DoW) suspended CMMC Phase 2 requirements on July 13, 2026, sparking confusion across the defense industrial base sector. Cut through the uncertainty with this guide and learn how to leverage this review period for your competitive advantage.
Is CMMC Canceled or Just Paused?
The CMMC cybersecurity program remains active. The DoW has temporarily paused Phase 2 third-party assessments for sixty days to streamline the program and reduce barriers for small businesses. While the third-party assessment requirement is suspended, all other legal obligations remain in place.
What Does the CMMC Phase 2 Suspension Mean for Your Business?
If you’re wondering why you still need to comply with the CMMC cybersecurity program if Phase 2 was suspended, think of it as an adjustment in process, not a reduction in responsibility. The DoD continues to expect contractors to maintain strong cybersecurity practices. Your obligations to protect Controlled Unclassified Information (CUI) remain unchanged.
What Are Your Legal Obligations During the Review Period?
While the DoD evaluates the third-party assessment process, your underlying responsibility to protect controlled data remains firmly in place. These obligations are clear and enforceable:
- Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 compliance: The foundational requirements of the DFARS 7012 clause remain in full effect.
- National Institute of Standards and Technology (NIST) SP 800-171 controls: All applicable NIST SP 800-171 security requirements still apply for protecting CUI within your environment.
- Mandatory self-assessments: CMMC Level 1 and 2 self-assessments must be actively performed and documented.
- False Claims Act accountability: Avoid liability under the False Claims Act by maintaining an accurate, defensible cybersecurity posture.
Do You Still Need to Submit SPRS Scores After the CMMC Pause?
A current and accurate SPRS score is required for bidding on and winning DoD contracts involving CUI. It is essential for maintaining your eligibility.
Is It Safe to Pause Your CMMC Compliance Work?
Leverage the sixty-day review period to strengthen your compliance posture and enhance your competitive edge:
- Build organizational resilience: Protect data from persistent cyber threats and safeguard your reputation.
- Ensure contract eligibility: Maintain legal confidence and protect your revenue stream.
- Capture market share: Position your company for success when assessments resume.
What Should You Do During the CMMC Sixty-Day Review Period?
Accelerate your readiness and gain ground during the review period. Every action you take now proactively supports compliance and positions your business to secure future DoD contracts:
- Validate your self-assessment: Strengthen your documentation’s defensibility by confirming accuracy and aligning with current requirements.
- Focus on remediating gaps: Address vulnerabilities tied to applicable NIST SP 800-171 controls to improve your security posture and maintain eligibility.
- Engage an expert partner: Work with CMMC professionals with deep cyber expertise to gain an objective view, justify your SPRS score, and focus your team on winning contracts.
Turn Uncertainty Into Opportunity With Expert Clarity
CBIZ Pivot Point Security has the expertise to guide you through this transition with confidence. Since 2001, we have helped defense industrial base organizations strengthen cybersecurity, manage compliance obligations, and prepare for various frameworks, including CMMC. Contact our team today to schedule a consultation with our certified CMMC professionals and secure a clear, confident path forward, backed by a satisfaction guarantee.