The CMMC Reform Task Force’s public comment period closed last week, with industry input due August 14. It’s a fitting moment to clear up a misconception that’s been circulating since the Department of War paused CMMC Phase II last month: that pause has nothing to do with DIBCAC Medium or High Assessments, and contractors who assume otherwise may be caught off guard.

What got paused on July 13

On July 13, 2026, DoW Chief Information Officer Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey announced the pause of CMMC Phase II. Phase II was set to take effect November 10, 2026, and would have marked an introduction of Level 2 (C3PAO) certification language for applicable solicitations, with Level 3 (DIBCAC) certification following for the most sensitive programs.

During the suspension, contracting officers may only designate CMMC Level 1 (Self) or Level 2 (Self) assessments in new solicitations and contracts. Level 2 (C3PAO) and Level 3 (DIBCAC) certification designations are off the table for now, and active contracts containing those requirements are being amended to remove them.

A CMMC Reform Task Force was stood up to review the program, drawing on responses to the RFI that closed August 14. Its recommendations are expected by the end of September 2026, though any structural changes would still require formal rulemaking, which takes longer.

What didn’t pause: Phase I self-assessment obligations, DFARS 252.204-7012, NIST SP 800-171 Revision 2 compliance, and annual SPRS affirmations all remain in full effect.

Where DIBCAC Assessments fit in

Here’s the part that gets missed. DIBCAC’s Medium and High Assessments, conducted under DFARS 252.204-7019 and 252.204-7020, are not part of the CMMC certification pipeline that just got paused. They’re a separate, longstanding mechanism DIBCAC uses to verify NIST SP 800-171 compliance directly, independent of CMMC entirely.

A Medium Assessment involves DIBCAC reviewing a contractor’s System Security Plan and supporting documentation, along with interviews, without on-site verification. A High Assessment goes further: DIBCAC assessors conduct an on-site examination to verify that security controls are not just documented, but actually implemented and operating as described.

Because these assessments sit outside the paused CMMC certification pathway, contractors handling Controlled Unclassified Information under DFARS 252.204-7012 remain fully subject to them, regardless of what happens with CMMC Phase II or the task force’s eventual recommendations.

A scoping distinction worth understanding

One area that creates confusion for contractors preparing for a DIBCAC Assessment is scope. DIBCAC applies the NIST SP 800-171 Scope of Applicability defined in section 1.1 of that standard, which covers system components that process, store, or transmit CUI, or that provide security protection for those components.

This is a distinct concept from the CMMC Assessment Scope described in the CMMC Assessment Guide and Scoping Guides, which apply specifically to C3PAO and DIBCAC certification assessments under the CMMC program rule. The two scoping frameworks aren’t interchangeable. An organization that has only mapped its environment against CMMC scoping guidance may find gaps when a DIBCAC Assessment applies the broader NIST SP 800-171 standard instead.

What this means right now

The pause on CMMC Phase II doesn’t reduce a contractor’s exposure to DIBCAC oversight. If anything, it puts more weight on the accuracy of self-attested SPRS scores, especially for those organizations who are choosing not to proceed with an independent third-party CMMC certification with a C3PAO. DIBCAC assessments, along with potential False Claims Act scrutiny of inaccurate self-assessments, remain very much active.

For organizations handling CUI, this is a reasonable moment to revisit whether your System Security Plan, supporting evidence, and Plan of Action and Milestones reflect your actual current environment, not just what was documented at your last self-assessment.

Questions worth asking before a DIBCAC assessor arrives

  • Does your SSP reflect your environment as it exists today, not as it existed a year ago?
  • Is your NIST SP 800-171 scope of applicability documented separately from any CMMC scoping work you’ve done?
  • Can you demonstrate that your controls are operating, not just that a policy describing them exists?
  • Is your most recent SPRS score backed by evidence you could produce on request?

If you’re navigating a DIBCAC notification or want a clearer picture of how your environment maps to the NIST SP 800-171 scope of applicability, Insight Assurance can walk through what an independent assessment of your posture would look like.