← All notes

The Requirement Never Moved. Only the Markup Did

Hector Velez ·


On July 13, 2026, the Department of War suspended CMMC Phase 2. If you run a defense contracting business, you have already seen fourteen contradictory takes about what this means. Here is the version without a sales agenda attached, from someone who spent 21 years in Special Operations communications before ever writing a compliance document, and who has seen what weak security costs when the price is not measured in dollars.

What actually happened

The DoW CIO announced the immediate suspension of Phase 2 requirements, which were scheduled to take effect November 10, 2026. Third-party assessment mandates are frozen. Contracting officers were directed to amend active solicitations containing Phase 2 requirements. A reform task force will review the entire program and report within 60 days.

The official rationale, from the department’s own July 10 memo: the program imposes significant and often prohibitive burdens on the Defense Industrial Base, particularly small and non-traditional businesses.

Read that twice. The government did not say the DIB was unready. It did not say fraud was rampant. It said the cost was the problem.

What did not happen

Your obligations did not go anywhere. DFARS 252.204-7012 is still in your contracts. NIST SP 800-171 Rev 2 is still the enforceable standard, verified through self-assessments and select government-led assessments. SPRS scores still matter. The False Claims Act still applies to every affirmation you sign.

Anyone telling you compliance is dead is selling you something. Anyone telling you nothing changed is also selling you something. Both pitches will arrive in your inbox this week.

The part nobody selling services will say

For two years, an industry told 80,000 companies that meeting 110 security controls required six-figure engagements, 12 to 18 month timelines, and cloud migrations that the underlying regulation never actually mandated.

The requirement was never the expensive part. The markup was.

The proof has been sitting in plain sight. DFARS 7012 requires FedRAMP Moderate or equivalent for clouds handling covered defense information. Commercial cloud regions meet that bar at zero premium. The 110 controls in 800-171 describe system configurations, access management, logging, and boundary protection: engineering work, not consulting hours. And when implementation is done as engineering, live systems can generate the documentation that assessors need, because the documentation is simply a description of what is actually running.

I know this is true because we did it. We built the platform in two weeks. It was assessed and certified by a third party in week three. Zero to certified in under a month. Not because we are special. Because the 6 to 18 month timeline was never a technical requirement. It was a business model.

What the government just validated

The suspension memo asks for realistic, scalable security measures that prioritize speed to capability and lower barriers for small and non-traditional businesses. It asks for tangible cyber hygiene rather than administrative overhead.

That is a description of infrastructure-first compliance. Build the secure environment. Let the environment document itself. Skip the theater.

And this was not one department acting alone. The next day, the Small Business Administration publicly stood with the decision, stating that compliance burdens were threatening to drive small firms out of the defense supply chain entirely. Read that framing carefully, because it is stronger than a cost complaint: two federal agencies just said the markup is a national security problem. Every company priced out of the industrial base is capacity our country loses.

The Department has also started publishing the knowledge itself. Its new Brilliant at the Basics guidance (dodcio.defense.gov/BrilliantBasics) is a free, practical top-ten list for IT and OT security, written explicitly to strip away administrative complexity. The government is open-sourcing the what. The how is coming, and it will be free too. More on that below.

The task force reviewing the program will hear from every incumbent with a revenue stream to protect. They should also hear from the 80,000 companies who were priced out. That is who we intend to speak for.

What you should do during the reform window

First, keep your self-assessment current and honest. The obligation is live and the enforcement mechanism that survived the suspension is the one with treble damages attached.

Second, before signing any compliance engagement this quarter, ask what it improves about your actual security posture separate from audit preparation. Insist on a specific answer.

Third, if a proposal includes a cloud migration, ask the vendor to show you the contract clause that requires it. Not the whitepaper. The clause.

Fourth, and this is the one that matters most: put your experience on the record. The Department is running a formal Request for Information on CMMC reform, and responses are due by 12:00 PM Eastern on Friday, August 14. It asks exactly the questions small businesses have been answering into the void for years: what drives your costs, which controls actually reduce risk, and how your existing commercial tools should count. If you have ever said they never listened to us, this is the listening. The RFI and submission instructions are in the DoW CIO Library at dodcio.defense.gov/library. Ten pages maximum, plain language welcome. We are filing ours weeks early. File yours.

Fifth, watch September. The task force report will set the terms for whatever replaces Phase 2, and we will publish a plain-language breakdown the day it drops.

Something else is coming this fall. The entire CMMC Level 2 implementation, open source, free. Because the knowledge was never worth $200K. It was just priced that way.

Compliance without the markup.

EDUCAUSE 2026Booth C3 · Sep 29 to Oct 2