Compliance · CMMC, Private AI, Governance · ~6 min read

On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II, the third-party certification requirement that had been scheduled to start appearing in defense contracts on November 10, 2026, roughly four months out (DefenseScoop). Read the announcement closely: the suspension covers only the certification gate. DFARS 7012 still applies. The NIST 800-171 self-assessment still applies. For anyone bringing AI into the defense supply chain, that means less paperwork sitting on top of the same responsibility. Piping that data into someone else’s cloud model is still a risk you own.

What the suspension actually covers

Phase II is the part of CMMC where an outside assessor certifies you, meaning Level 2 assessments conducted by a C3PAO and the Level 3 assessments above them. That requirement is now suspended while a new CMMC Reform Task Force runs a 60-day review, and Phases 3 and 4 are frozen along with the program’s future implementation milestones. The stated reason is cost. The department wants to cut compliance expense and bureaucratic burden as part of a wider effort to streamline defense acquisition, and for a small contractor that is genuinely good news.

The review leaves the standing rules in place. DFARS clause 252.204-7012, which requires you to safeguard covered defense information and report cyber incidents, remains in force. So does the CMMC Phase I self-assessment: you still complete a NIST SP 800-171 self-assessment and upload your score to the DoD’s SPRS system. An inaccurate score can still create liability under the False Claims Act. The only thing removed from the calendar is the assessor’s visit. Every rule that assessor would have checked remains on the books.

What the pause means for how you handle CUI

The obligation follows the data, and it always has. Controlled unclassified information, CUI, carried the same obligations on July 14 that it carried on July 12, whether or not anyone is scheduled to check your work. Now consider where CUI actually goes when someone on your team pastes a spec or a contract excerpt into a public AI chat tool. It leaves your network and lands on infrastructure you cannot inspect, under retention terms you never negotiated. DFARS 7012 still expects you to report incidents involving that information, and you cannot report what you cannot see.

There is also the score you already attested. Your SPRS submission describes an environment where CUI stays inside defined controls. If CUI is quietly flowing into public tools, that submission stops being true, and the False Claims Act does not pause for a task force. The right response is simply to know where your data goes, and that is a thing you get to decide.

The private-AI answer for defense work

The same move that satisfies the standing rules also unlocks the AI you wanted in the first place: run the model inside a boundary you control. That can be your own environment, or a private one a partner builds and operates for you. When the model lives where the data lives, CUI never crosses into a system you cannot account for. This maps directly onto what survived the review. 7012 asks you to safeguard covered defense information; a boundary you control is the safeguard. The 800-171 self-assessment asks you to score your environment honestly; a contained environment is one you can score honestly and keep scoring honestly, review or no review.

You can move before the task force reports, and you can bring in help to do it. Modular Technology Group builds and runs private AI for contractors in exactly this position, and we own the whole stack. Your data, your rules, from dirt to desktop. Use the pause to get your AI inside your boundary, so that whatever comes back from the review, you are already standing where the rules point.

Your data, your rules.