Insights
Pentagon to C3PAOs: Drop Dead
The Pentagon has all but decided to fire the 3rd party auditors they asked the industry to set up to make sure CMMC had teeth.
The lawyers are still around.
A Sept 3 memo from John Tenaglia, DOD's principal director for defense pricing, reinforces the suspension of the CMMC Phase 2 deadline that would have required contractors to get an auditor to confirm they comply with CMMC Level 2.
The CMMC Reform Task Force is slated to send its recommendations on Friday Sept. 11.
Unfortunately, too many small shops read this as "we’re off the hook."
My friends, you are not off the hook.
Contractors still must self-attest to NIST 800-171 in SPRS. They still need to have a passing score. The DIBCAC can still audit. The False Claims Act still eats people. Logzone got cute, faked a near-perfect score, got caught, and paid about $500K to settle.
The onus remains on companies to prove compliance, whether or not they had an outsider give them a stamp of approval. This is no different than cheating on your taxes and hoping you don’t get caught.
Yes this is an annoying problem. But here’s what you can do today.
- Dust off your System Security Plan
- Write the policies your SSP references
- Collect fresh evidence of the controls (ie screenshots and logs)
- Score it against the official CMMC methodology.
- Update in SPRS.
- Create a calendar reminder for 90 days to update and keep current (until further notice)
If you haven’t started, then reach out. That’s what we’re here for.
The Pentagon has all but decided to fire the 3rd party auditors they asked the industry to set up to make sure CMMC had teeth.
The lawyers are still around.
[A Sept 3 memo from John Tenaglia, DOD's principal director for defense pricing,](https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_Rev3_TAB_A_Deviation_Memo.pdf) reinforces the suspension of the CMMC Phase 2 deadline that would have required contractors to get an auditor to confirm they comply with CMMC Level 2.
The CMMC Reform Task Force is slated to send its recommendations on Friday Sept. 11.
Unfortunately, too many small shops read this as "we’re off the hook."
My friends, you are not off the hook.
Contractors still must self-attest to NIST 800-171 in SPRS. They still need to have a passing score. The DIBCAC can still audit. The False Claims Act still eats people. Logzone got cute, faked a near-perfect score, got caught, and paid about $500K to settle.
The onus remains on companies to prove compliance, whether or not they had an outsider give them a stamp of approval. This is no different than cheating on your taxes and hoping you don’t get caught.
Yes this is an annoying problem. But here’s what you can do today.
- Dust off your System Security Plan
- Write the policies your SSP references
- Collect fresh evidence of the controls (ie screenshots and logs)
- Score it against the official CMMC methodology.
- Update in SPRS.
- Create a calendar reminder for 90 days to update and keep current (until further notice)
If you haven’t started, then reach out. That’s what we’re here for.