web analytics
AI Governance

Federal Contractor AI

CMMC Phase II Suspended, DFARS Still Binds, and the Assurance Doom Loop

The one-paragraph answer

Federal Contractor AI compliance is set by DFARS 252.204-7012 and NIST SP 800-171 Rev 2, and both still bind. CMMC Phase II was suspended on July 13, 2026, by a Department of War memorandum dated July 10, 2026, signed by DoW CIO Kirsten Davies. Phase II would have required third-party assessment against ~100,000 defense industrial base companies through ~104 authorized C3PAOs, a ratio the CIO described in the announcement as "the math just simply doesn't math." A 60-day CMMC Reform Task Force is running, with a public RFI due August 14, 2026, and a report expected roughly mid-September. Phase I self-assessment is still in force. Contractors are still contractually required to safeguard Covered Defense Information under DFARS 252.204-7012, and the DOJ Civil Cyber-Fraud Initiative is still bringing False Claims Act cases against contractors that submitted false SPRS scores or misrepresented their cybersecurity posture. The verification was cut; the obligation was not. That is the third jurisdiction in fourteen months to make that trade, after Colorado's repeal of its AI Act and the EU's Omnibus deferral of AI Act conformity assessment. AI-specific note: no separate rule for AI in federal contracting exists. AI systems inside a contractor's CUI environment inherit the 800-171 controls of the environment they sit in, and the SPRS score attests to the whole system, AI and all.

The pain Federal Contractor AI compliance is causing DIB companies

A defense contractor spent 18 months preparing for a C3PAO assessment against Phase II's November 10, 2026 deadline. Consultants, remediation, POA&M closure, a $600,000 line item that the SBA cited in the suspension memo as the norm rather than the outlier. On July 13, the third-party assessment requirement is suspended. On July 14, the contractor's board asks whether the programme should be paused. The correct answer, and the one every serious law firm published within 24 hours of the announcement, is no. The contract still requires 800-171 compliance. The SPRS score still has to be true. The DOJ still brings False Claims Act cases on cybersecurity misrepresentation. What was suspended is the verification. What binds is the obligation.

What was suspended, and what was not

Suspended (effective immediately, July 13, 2026):

  • The November 10, 2026 transition to CMMC Phase II.
  • All pending and future CMMC implementation milestones (Phase III and Phase IV are also held in abeyance).
  • Contract clauses requiring CMMC Level 2 C3PAO or CMMC Level 3 assessment as a condition of award. Contracting officers were directed to amend active solicitations and contracts to remove those clauses.

Not suspended (still in force):

  • DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting).
  • NIST SP 800-171 Rev 2 (the 110 security requirements).
  • CMMC Phase I self-assessment (Level 1 for FCI, Level 2 for CUI).
  • SPRS score submission and annual affirmation.
  • DFARS flow-down obligations from prime to subcontractor.
  • DOJ Civil Cyber-Fraud Initiative enforcement under the False Claims Act.

The Department also opened a Request for Information seeking industry input on cost drivers, which 800-171 controls deliver meaningful risk reduction, and whether commercial cybersecurity tools or managed services should be recognized in lieu of separate assessments. Responses are due August 14, 2026, at 12pm ET. The Reform Task Force will report within 60 days of establishment.

DFARS 252.204-7012 and NIST SP 800-171 still bind

DFARS 252.204-7012, the clause that has been in every DoD contract touching Covered Defense Information since 2016, requires contractors to implement the security requirements in NIST SP 800-171. That predates CMMC by years and is unaffected by the suspension. The 110 controls in 800-171 Rev 2 cover access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Contractors were required to implement these controls, submit an SPRS score reflecting the actual state of implementation, maintain a plan of action and milestones for open items, and annually affirm the accuracy of the SPRS score. All of that continues.

The DOJ Civil Cyber-Fraud Initiative has been prosecuting False Claims Act cases against contractors who represented their cybersecurity posture inaccurately. Recent resolutions have involved false SPRS scores, misrepresentation of 800-171 control implementation, and failure to implement controls that were represented as implemented. Those cases continue during the suspension. If anything, the enforcement posture strengthens: absent a third-party check, the government's remedy for cybersecurity misrepresentation is enforcement rather than pre-award verification.

The assurance doom loop, and why Article 43(6) is the same story

This is the third jurisdiction in fourteen months to cut a verification requirement while leaving the obligation in place. Colorado repealed its AI Act, whose rebuttable presumption was the largest driver of voluntary NIST AI RMF adoption in the US; the AI-liability regime remained through other statutes but the presumption did not. The EU's Digital Omnibus deferred AI Act conformity assessment for stand-alone high-risk systems from 2026 to December 2027, and for embedded-product high-risk to August 2028. Now CMMC Phase II is suspended and the ~100,000-vs-104 ratio is stated openly as the reason.

The story is not that regulators are backing off cybersecurity or AI safety. The story is that third-party assurance capacity does not exist at the scale the regulations assumed. The EU AI Act's Article 43(6) makes this explicit: the Commission may move Annex III points 2-8 onto the notified-body route by delegated act, and one of the factors it must consider is "the availability of adequate capacities and resources among notified bodies." Build the assurance capacity and the regime tightens. Fail to build it and the verification requirement gets cut, again. Federal contractors sitting on the CMMC news should read the AI Act's Article 43(6) in that light: the delegated acts are due by August 2, 2027, and the same capacity constraint that killed CMMC Phase II is what the Commission is being asked to weigh.

Where AI actually attaches to Federal Contractor AI compliance

There is no separate federal AI rule for contractors. An AI system inside a contractor's CUI environment is an information system under 800-171 and inherits every applicable control. The SPRS score attests to the whole system, AI and all. Three attachment points matter:

SPRS scoring: AI components inside the CUI boundary have to be enumerated in the System Security Plan. Their controls have to be assessed. If the SPRS score claims the environment implements MFA, audit logging, and configuration management, the AI components have to be in scope for those claims.

CUI boundary decisions: An external LLM API that processes CUI is an external system. Sending CUI to it without an authorised path is a boundary violation. Air-gapped inference, private cloud, and on-premises deployment are the paths that keep the CUI inside the assessment boundary. "We do not send CUI to the model" is a claim that has to be verifiable at the packet level, not asserted in a policy.

FedRAMP: If the AI component runs in a cloud environment that stores CUI, that cloud must be FedRAMP Moderate authorized (or DoD-authorized at the appropriate impact level). The AI vendor's SOC 2 is not sufficient. FedRAMP authorisation of the underlying platform is.

What the research says about Federal Contractor AI and defense industrial base cybersecurity

Government-provided cyber threat intelligence helps businesses within the Defense Industrial Base prevent and respond to attacks when firms are familiar with it, but a large percentage of small firms are not familiar with the feeds and consequently are not utilizing them, largely due to financial constraints that prevent effective use.

That is the same constraint the DoW cited in the Phase II suspension memo, applied to a different verification mechanism. Small businesses in the DIB cannot afford the compliance costs the regime assumed, and the programme fails because of it.

Analysis of Security Control Deficiencies across 127 DoD contractors identified consistent gaps against DFARS 252.204-7012 and NIST SP 800-171 controls, particularly in access control, audit and accountability, and system and communications protection, showing that non-compliance is patterned and predictable rather than idiosyncratic.

How to comply with Federal Contractor AI obligations: a 5-step path

  1. Do not stand down the 800-171 programme. The suspension of Phase II changes the verification mechanism, not the underlying obligation. Continue closing POA&M items and honestly maintain the SPRS score.
  2. Enumerate every AI component that sits inside the CUI boundary. Include external APIs, retrieval indexes, prompt logs, and any tool the workforce has adopted informally. Each has to appear in the System Security Plan or be removed from CUI-adjacent workflows.
  3. Verify the CUI boundary at the packet level. "We don't send CUI to the model" is only defensible if the network egress rules and the DLP tooling can prove it. Air-gapped inference, private cloud, and DoD-authorized FedRAMP paths are the compliant deployment patterns.
  4. Reconfirm SPRS accuracy against the AI-augmented environment. If AI deployment changed any of the 110 controls' implementation state, the SPRS score has to move with it. False SPRS scores drive False Claims Act cases. Truth is the defence.
  5. Respond to the RFI if it applies to you, and read the Task Force report when it lands. The programme that emerges from the 60-day review is what contractors will actually have to comply with. RFI responses close the loop between industry constraint and regulatory design. Report expected mid-September 2026.

Frequently asked questions about Federal Contractor AI

Is CMMC dead?

No. Phase II is suspended, not repealed. Phase I self-assessment is still required. CMMC is codified in 48 CFR, and removing it would require notice-and-comment rulemaking. The 60-day review will produce a recommendation for a reformed framework. Under the Administrative Procedure Act, an indefinite pause could be treated as a de facto repeal, which is why the Task Force timeline matters. The most likely outcome is not elimination but a materially different Phase II with different assurance mechanisms.

Can we stop preparing for third-party assessment?

No, and the major DoD legal advisories all say this in the same words: "do not mistake the suspension for a reprieve." The underlying cybersecurity requirements are the same, and enforcement of misrepresentation is increasing, not decreasing. A contractor who used the suspension as an excuse to stop closing 800-171 gaps will simply be 60 days behind when the successor programme lands.

Does AI in a DIB workflow trigger any special federal rule?

Not currently. There is no federal contractor AI rule. AI systems inside a CUI environment inherit the 800-171 controls of the environment they sit in. The SPRS score attests to the whole system. External AI services that process CUI must be in an authorised boundary; on the DoD side that means DoD-authorized FedRAMP or an equivalent authorisation.

Where does Federal Contractor AI fit in SRJ's work?

The Volume V CISO-domain buildout produces the artefacts DFARS 252.204-7012 requires and the SPRS score depends on: an accurate System Security Plan reaching AI components, a POA&M closing the enumerated gaps, and evidence that the CUI boundary decisions are enforceable at the network layer, not merely asserted in policy. See Volume V: The AI IT Security Audit.

Primary sources on Federal Contractor AI

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including Federal Contractor AI, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation