- Prompt injection attacks manipulate AI guardrails using natural language, exploiting the semantic gap to get models to ignore developer instructions.
- AI social engineering scales faster and lowers attacker skill barriers, enabling automated, targeted campaigns like deepfakes and credential theft.
- Primary harms include data exfiltration, unauthorized transactions, and malicious or biased outputs that damage reputation and operations.
- Defenses are immature; require layered controls: human in the loop, prompt firewalls, input sanitization, least privilege, fuzz testing, patching, and user training.
Last Updated on July 31, 2026
On July 13, 2026, the US Department of War (DoW) announced the suspension of its Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements and initiated a 60-day review of the program.
This short article shares what we know so far and recommendations for how our clients and their peers in the defense supply chain can best respond.
What we know so far
There are more questions than answers at this point.
The DoW has not indicated what the outcome of the review will be or whether CMMC will be modified, streamlined, replaced, or reinstated in a different form. We expect additional details to emerge over the coming weeks as the review progresses.
What we do know for sure is that this announcement does not remove the underlying responsibility to protect federal information, notably controlled unclassified information (CUI). The DoW has stated that contractors remain responsible for cybersecurity requirements under federal data protection, it and will continue to enforce NIST SP 800-171 requirements during the review period.
Recommendations for defense suppliers
For organizations with C3PAO assessments already scheduled or contracted, we recommend waiting for guidance from your assessment provider and/or the CMMC accreditation ecosystem before making changes to your plans.
Organizations should also remain attentive to customer and prime contractor flow-down requirements. While the DoW announcement addresses Phase II certification requirements, many organizations may still face requirements for CMMC Level 2 self-assessments, SPRS submissions, and other contractual cybersecurity obligations. These requirements exist independently of Phase II certification requirements and could continue to appear in contracts and subcontract agreements.
A probable outcome
The review also appears consistent with broader 2025 DoW acquisition reform initiatives that focused on reducing bureaucracy, streamlining processes, and lowering barriers to participation while maintaining mission and security objectives. In those cases, the Department generally did not remove the underlying requirements. Rather, it looked for ways to simplify implementation and reduce administrative burden.
It remains to be seen whether a similar approach will be taken with CMMC, but that prior context is likely relevant and worth considering as the review progresses.
The key takeaway
For now, we believe it is not prudent to make significant compliance or contracting decisions based solely on the July 13 announcement. We are monitoring the situation closely and will share updates as additional information becomes available.
Please contact CBIZ Pivot Point Security to discuss your specific circumstances.