Yesterday, the Department of War CIO announced the immediate suspension of CMMC Phase II requirements. If you're a small or mid-size defense contractor, you probably felt a mix of relief and confusion. Relief because that $150k+ third-party assessment is off the table. Confusion because... what exactly are you supposed to do now?
Let's cut through the noise.
CMMC Phase II required third-party assessments by certified C3PAOs for any organization handling CUI. That requirement is suspended effective immediately. A Reform Task Force led by DoW CIO Kirsten Davies will spend the next 60 days reviewing the entire program.
That last point matters more than people realize.
The DoW Inspector General and GAO have repeatedly found that contractors over-report their compliance scores. It's not always intentional. NIST 800-171 has 110 controls. Interpreting whether you truly "meet" each one is genuinely hard, especially when you're a 50-person machine shop and not a cybersecurity firm.
If you submit an SPRS score of 95 and your actual posture is a 40, that's a problem. The False Claims Act doesn't care about your intent. Multiple FCA settlements in the last two years have made this very real.
The entire reason CMMC existed was because self-assessment alone wasn't working. The scores didn't match reality. So the question becomes: how do you self-assess honestly without spending $200k on outside help?
The gap between a good self-assessment and a bad one comes down to one thing: evidence.
A bad self-assessment looks like someone reading each control requirement, thinking "yeah, we probably do that," and checking a box. A good self-assessment looks like pulling your actual security configurations, scan results, access logs, and policy documents, then measuring those against each control requirement.
The problem has always been that gathering that evidence manually is brutal. It means logging into a dozen tools, exporting reports, mapping findings to specific controls, and writing up implementation narratives. For a small company doing this quarterly, it's weeks of work.
This is exactly the problem we built SecureX to solve.
SecureX is a Tradewinds Awardable solution - vetted and approved for streamlined procurement by DoD organizations. It connects directly to your infrastructure and security tools. AWS configs, vulnerability scanners, source code repos, endpoint management. It pulls evidence continuously, maps it to NIST 800-171 controls automatically, and uses AI to generate implementation narratives based on what it actually found.
Your self-assessment score isn't based on what you think is true. It's based on what IS true, right now, with the artifacts to back it up.
Not a snapshot from six months ago. If something drifts out of compliance, you know immediately.
DCMA, DIBCAC, or a prime asks for evidence? Export it. Already mapped, narrated, and formatted.
See exactly which controls are failing and why. Fix actual problems instead of papering over them.
New framework in 60 days? Our platform supports new requirements through configuration, not code rewrites.
Right now, the defense industrial base is in a weird in-between state. The old rules are suspended. New rules haven't been written yet. A lot of companies are going to treat this as a vacation from compliance.
That's a mistake.
The companies that use this window to get their actual security posture documented and their real gaps identified will be in the strongest position when the Task Force announces reforms. Whether the new framework is lighter-weight CMMC, enhanced self-assessment with spot checks, or something nobody's predicted yet, having continuous evidence-based compliance puts you ahead.
The contractors who spent this window doing nothing will be scrambling again in 60 days, the same way they scrambled when CMMC was first announced.
The suspension of CMMC Phase II doesn't mean security compliance is optional. It means the mechanism for verifying compliance is shifting back to self-assessment, at least for now. That makes it more important, not less, that your self-assessment is rigorous and evidence-based.
We built SecureX because we believed compliance should be driven by what your environment actually looks like, not by what a consultant writes in a Word document once a year. The DoW's decision to pause third-party assessments doesn't change that mission. If anything, it makes the need for honest, automated self-assessment more urgent.
If you want to see what evidence-based self-assessment looks like for your environment, reach out. We'll show you your actual posture, no sugar-coating. SecureX is Tradewinds Awardable, so procurement is already streamlined for DoD organizations.