The Sixty-Day Window
The public issue reads the liability that survived July 13. This one works the window: what changed in your contract language, what the RFI record fills with if small firms sit it out, which cost lines carry evidentiary weight, the affirmation review to run on every teaming partner, and the AI scope audit that postdates every System Security Plan on file.
★ Premium Capture Corner
The public issue reads the exposure. This Capture Corner works the sixty-day window before the August 14 RFI close: what changed in your contract language, what the record fills with if small firms sit it out, which cost lines carry evidentiary weight versus which read as complaint, the five-question affirmation review to run on every teaming partner, and the AI scope audit that postdates every System Security Plan on file. Premium members read the full brief. Subscribe at missionmeetstech.com/pricing.
See premium plansCapture Corner is the premium BD intelligence companion to Mission Meets Tech. Public-record sourced. Independent analysis. Not a recommendation, not vendor advocacy, not capture material. Built for federal health BD, capture, and proposal leaders who need analytical depth, not headlines.
This issue is the companion to "Health Net Never Had a CMMC Deadline," published this week. The public piece reads the liability that survived the July 13 suspension. This one works the window: what changed in your contract language, what the RFI record will contain if small firms sit it out, how to build a response the task force can actually use, the affirmation review to run on every teaming partner before your next award, and the AI scope audit that postdates every System Security Plan on file.
1. The window at a glance
| Field | Detail |
|---|---|
| Trigger | DoW suspension of CMMC Phase II, announced July 13, 2026 |
| Announced by | CIO Kirsten Davies; USD(A&S) Michael Duffey |
| Vehicle for input | SAM.gov RFI, "Reforming CMMC and Reducing Compliance Burden for the DIB" |
| Hard deadline | 12:00 PM ET, August 14, 2026 |
| Task force | 60-day top-to-bottom review; report expected ~mid-September 2026 |
| Cancellation | Explicitly not ruled out |
| What survives | DFARS 252.204-7012 · NIST SP 800-171 Rev. 2 · SSP · POA&M · SPRS score · annual affirmation · DIBCAC authority · DOJ Civil Cyber-Fraud |
Confidence: High (primary sources). The suspension, the officials, the task force duration, and the RFI deadline are all documented in the department's own release and the SAM.gov posting [CC1, CC4]. The mid-September report date is arithmetic off the stated sixty days, not a published milestone.
2. What actually changed in your contract language
Confidence: High on the direction; Medium on the mechanics.
The change is narrow and it is specific to designation. Program offices may now designate CMMC Level 1 (Self) or Level 2 (Self) only. No new C3PAO or DIBCAC designations. Existing C3PAO and DIBCAC requirements are to be amended out of contracts. No new waivers [CC2].
Three practical consequences for capture:
Solicitations in flight. DFARS 252.204-7025 states the required level in the solicitation, and 252.204-7021 carries it into the contract [CC3]. Anything on the street with a Level 2 (C3PAO) fill-in is now inconsistent with department direction. Expect amendments. Watch for COs who amend the level and COs who amend nothing, because the second group is where the confusion lands in Q4.
Awarded contracts with C3PAO requirements. The department's direction is to amend them out. That is a modification, not an automatic lapse. Until the mod is executed, read your clause as written.
Flow-down did not change. 252.204-7021 requires prime contractors to flow the appropriate level to subcontractors and to ensure subcontractors complete affirmations of continuous compliance in SPRS prior to subcontract award [CC3]. The self-assessment levels survive. The affirmation obligation survives at every tier.
The mechanics here are drawn from three independent law-firm reads of the announcement rather than from amended regulatory text [CC2]. Confirm against your specific contract before acting on any of it.
3. What the record contains if you sit this out
Confidence: Medium. This is an analytical projection from who has standing incentive to file, not a report of filings received.
The RFI record is going to be built out of whoever shows up. The predictable filers:
- Trade associations, filing on behalf of memberships weighted toward firms that can afford dues.
- C3PAOs and the assessor ecosystem. The Cyber AB grew its certified assessor corps from 633 in December 2025 to more than a thousand by June 2026, and its C3PAO count from 92 to 107 [CC5]. That capacity was built against a November 10 ramp that no longer exists. Those organizations have payroll and a documented case that the program should continue.
- Compliance vendors and MSPs, filing at length, with pricing attached, arguing the burden is manageable with the right tooling.
- Enclave and GCC High providers, whose customers bought against a deadline that vanished.
The predictable non-filers are the firms with the best evidence: two-to-fifty-person shops with real invoices and no staff position whose job is writing to the government. That asymmetry is the same one that produced the cost problem, and it will produce the record.
The capture implication. Whatever the task force recommends in September will be defensible by reference to a record. If that record is built by the ecosystem that sells compliance, the recommendation will look like reform-and-continue. If small primes and subs file with cost data, the range of outcomes widens. Either way, the September report is going to reset the CMMC line in every capture plan you are running into FY2027, and the firms in the record will have more standing to comment on what comes next.
4. Building a response the task force can use
Confidence: Medium. Structure below is drawn from what the record demonstrably lacks, not from published RFI evaluation criteria. The RFI's own instructions govern; read them first.
Two pages beats twenty. The task force has sixty days, and roughly thirty of them are gone.
Lead with the number the record lacks. SBA priced all-in certification near $593,800; the department's regulatory impact analysis priced assessment-only at $104,670 for a small entity over three years [CC6]. Both are estimates. Neither is an invoice. Your invoices are the thing the record does not contain. A gap-assessment invoice, an MSP quarterly, a GCC High line item, a remediation SOW, and an hours log for the owner's time carry evidentiary weight that no association filing can match.
Separate the 7012 spend from the CMMC spend. This is the single most useful thing a small firm can put in the record, and it is the thing the record most lacks. The department's own regulatory impact analysis and SBA's July release differ by roughly six times on the same requirement, because they measure different things and no filer has separated them. Split your spend into three columns: what you would have spent to meet 800-171 under 7012 alone, what you spent because a third-party assessment was coming, and what you spent because the schedule moved. That third column is the sunk-cost number, and it is the one that argues for schedule stability rather than for cancellation.
Cost lines that carry weight versus lines that read as complaint:
| Carries weight | Reads as complaint |
|---|---|
| Dated invoices with vendor names | "Compliance is too expensive" |
| Owner hours logged against revenue work forgone | "This is killing small business" |
| Specific control and specific remediation cost | "The requirements are unclear" |
| A contract you declined to bid and why | "We might have to leave the DIB" |
| The delta between your first quote and your final | "The C3PAOs are price gouging" |
| A named 800-171 control your firm cannot implement at any price, with the reason | Assessor-interpretation grievances |
The left column is evidence. The right column is sentiment, and the record already has more sentiment than it can use.
Answer the security question honestly. The strongest filings will concede that the underlying obligation is legitimate. DFARS 252.204-7012 was finalized October 21, 2016 and required 800-171 implementation by December 31, 2017 [CC7]. A filing that argues the requirement is wrong will be discounted. A filing that argues the verification model is unaffordable, and proves it with invoices, is the one that moves.
5. The affirmation review to run on every teaming partner
Confidence: High on the legal exposure; the review protocol is my construction.
This is the part of the public piece with the most direct capture application, and most teaming checklists have not caught up to it.
32 CFR 170.22 requires an Affirming Official, defined at 170.4 as the senior level representative within the organization with authority to affirm continuing compliance, to attest annually in SPRS [CC8]. 252.204-7021 requires prime contractors to ensure subcontractors complete that affirmation prior to subcontract award and maintain it annually [CC3].
Primes do not have automated access to subcontractor SPRS data [CC9]. You have to ask.
In February 2025, Health Net Federal Services and Centene paid $11,253,400 to resolve allegations of falsely certifying cybersecurity compliance in annual reports to DHA under the TRICARE contract [CC10]. In July 2025, a successor-liability settlement put an acquirer on the hook for cybersecurity deficiencies predating the acquisition by years [CC9]. Holland & Knight's read is that CMMC compliance is now a core diligence workstream for anyone acquiring a firm with DoW touchpoints, including targets that do not self-identify as defense contractors: commercial technology providers, component manufacturers, software vendors [CC9].
The five questions to put to every teaming partner and every acquisition target:
- Who is your named Affirming Official, and what is their actual role in the company?
- Show me the SPRS affirmation record and the assessment date. Screenshot, not assertion.
- Show me the System Security Plan the affirmation refers to, and the POA&M.
- Which controls are on the POA&M, and what is the closeout date?
- Was any part of that SSP drafted with an AI tool, and if so, who validated it against actual operations?
Question five postdates every teaming checklist I have seen, and it is the one where the honest answer is most likely to be uncomfortable.
What to do with a bad answer. Not necessarily walk. But the exposure is now yours to price, the suspension did not reduce it, and a subcontractor's false affirmation is a fact pattern that reaches the prime.
6. The AI scope audit
Confidence: Medium to High on the underlying facts; the audit protocol is my construction and has no published precedent.
The public companion makes the case at length. Here is the capture version.
On July 7, 2026, Sysdig's Threat Research Team published JADEPUFFER, which it assesses as the first documented case of agentic ransomware [CC11]. Entry was an internet-facing Langflow server through CVE-2025-3248, a missing-authentication flaw patched April 1, 2025 and added to CISA's Known Exploited Vulnerabilities catalog in May 2025 [CC12]. The agent harvested API keys and cloud credentials from the host environment, walked a MinIO store on default credentials, and pivoted to a production database. A human still provisioned the infrastructure and chose the victim [CC13].
Sysdig's own characterization of why these targets are attractive: AI-adjacent, frequently holding provider keys and cloud credentials, often stood up quickly without network controls [CC11].
Now the compliance overlay. NIST SP 800-171 Rev. 2 was published February 2020 and is what CMMC Level 2 maps to. Rev. 3 published May 2024 and is still not tied to CMMC; Class Deviation 2024-O0013 holds Rev. 2 until rescinded [CC14]. Your System Security Plan describes a boundary drawn against a February 2020 standard.
Run this against every firm in your teaming structure, starting with your own:
- Inventory every model endpoint, agent framework, orchestration tool, vector store, and demo environment.
- For each: is it internet-facing, and does it hold credentials in its environment or a .env file?
- Check that inventory against the System Security Plan asset list.
- Anything on list one and not list three is out of scope, unassessed, and inside your boundary anyway.
- Check patch currency against the CISA KEV catalog specifically.
Why this is a capture issue and not an IT issue. Health Net's entire $11.25 million case was failure to timely scan for known vulnerabilities and remediate them in accordance with its own SSP [CC10]. JADEPUFFER's entry was an unpatched, KEV-listed flaw on an AI server. Same control family. If your teaming partner's affirmation covers a network that does not include the AI layer, the affirmation is inaccurate on a control DOJ has already litigated, and it is inaccurate in your subcontract file.
There is a second-order scope trap. System Security Plans for defense contractors routinely contain CUI, which rules out most commercial SaaS models and pushes toward FedRAMP-scoped or self-hosted deployment [CC15]. A partner that drafted its SSP in a commercial chatbot may have moved CUI into an unassessed system, and the document it moved was the one describing how it protects CUI.
7. Timeline
| Date | Event |
|---|---|
| Oct 21, 2016 | DFARS 252.204-7012 finalized (DFARS Case 2013-D018) |
| Dec 31, 2017 | 800-171 implementation deadline under 7012 |
| Feb 2020 | NIST SP 800-171 Rev. 2 published (still the CMMC L2 baseline) |
| May 2024 | NIST SP 800-171 Rev. 3 published; not tied to CMMC |
| Dec 16, 2024 | 32 CFR Part 170 effective |
| Feb 18, 2025 | Health Net / Centene settle at $11,253,400 |
| Nov 10, 2025 | DFARS acquisition rule effective; Phase 1 begins |
| Dec 18, 2025 | SBA OIG Report 26-01: self-certification without verification |
| Mar 12, 2026 | GAO-26-107955 flags capacity, attrition, NIST drift |
| Jul 13, 2026 | Phase II suspended; task force stood up |
| Aug 14, 2026 | RFI responses due, 12:00 PM ET |
| ~Mid-Sep 2026 | Task force report expected |
| Nov 10, 2026 | Original Phase II start date |
| Not before 2027 | Expected Rev. 2 to Rev. 3 transition (analyst consensus) |
8. What to do this week
- If you are a small prime or sub with real compliance invoices, file by August 14. Two pages, three cost columns, dated invoices attached. You are the evidence the record does not have, and filing costs an afternoon.
- If you are a C3PAO or assessor organization, you have the opposite problem: standing to file and a visible commercial interest in the outcome. Lead with capacity data and utilization, not with advocacy for the program's continuation. The task force will discount the second and use the first.
- If you are a prime with a subcontractor tier, run the five affirmation questions in Section 5 across your teaming structure before your next award. The suspension did not touch flow-down and you do not have automated SPRS access to your subs.
- If you are in M&A on anything with DoW touchpoints, the July 2025 successor-liability settlement is your diligence trigger. That includes targets that do not think of themselves as defense contractors.
- If you are building or buying AI capability, run the Section 6 scope audit now, while the answer is still cheap. The window between "we stood up a demo" and "it is in the SSP" is where the exposure lives.
- If you have a solicitation in flight with a Level 2 (C3PAO) fill-in, raise it with the CO in writing. Get the amendment or get the position on the record.
- Everyone: set a SAM.gov watch on the RFI (opportunity 89ef9bfb0834473791e991c712698d94) and calendar mid-September for the task force report. Do not build an FY2027 capture plan that assumes CMMC is dead. The clause underneath it is nine years old, and the RFI asks about the program.
Editorial discipline note
Capture Corner is built to be useful, not provocative. It does not name preferred vendors. It does not recommend awards. It does not characterize any firm's compliance posture beyond what public records support. It does not reveal nonpublic information. It does not advocate for any specific offeror's win.
Several things in this issue are my construction rather than reported fact, and they are marked as such: the RFI filer projection in Section 3, the response structure in Section 4, the affirmation review protocol in Section 5, and the AI scope audit in Section 6. No published RFI evaluation criteria exist. The Section 2 mechanics rest on three law-firm reads of the department's announcement rather than on amended regulatory text.
Health Net and Centene denied all allegations, admitted no liability, and maintain that no vulnerability was exploited and no data was lost. The settlement is not an admission of wrongdoing. It is used here as a fact pattern, not a characterization of either company.
Mary
Mission Meets Tech Premium
Next Capture Corner: scheduled for the next major federal health or defense-health opportunity in active capture. Subscribers will receive an alert when the next issue publishes.
Capture Corner is an independent intelligence product. It is not affiliated with the Department of War, the Defense Health Agency, the Small Business Administration, the Cyber AB, or any company named here, and it is not connected to any offeror's bid strategy. Premium subscription includes access to the standing intelligence sidebar plus the searchable archive.
Sources
[CC1] Department of War, "War Department Changes Cybersecurity Maturity Model Certification Requirements," July 13, 2026 (Davies; Duffey; sixty-day task force; stated rationale). https://www.war.gov/News/News-Stories/Article/Article/4542849/war-department-changes-cybersecurity-maturity-model-certification-requirements/ · DefenseScoop, July 13, 2026 (cancellation not ruled out; ">$7B annually" for small and medium firms; "the math just simply doesn't math"). https://defensescoop.com/2026/07/13/dod-halts-cmmc-cybersecurity-requirements-phase-2/
[CC2] Post-suspension designation mechanics (L1/L2 Self only; no new C3PAO/DIBCAC designations; existing requirements amended out; no new waivers): Crowell & Moring, July 2026; Truvisory; GetPeerless. Three independent law-firm/analyst reads; not amended regulatory text. https://www.crowell.com/en/insights/client-alerts/department-of-war-immediately-suspends-cmmc-phase-ii-requirements-launches-60-day-reform-review
[CC3] DFARS 252.204-7021 (contract clause: CMMC status, annual affirmation by the affirming official, subcontract flow-down) and 252.204-7025 (solicitation provision). Acquisition.gov. https://www.acquisition.gov/dfars/252.204-7021-contractor-compliance-cybersecurity-maturity-model-certification-level-requirements. · Final rule: 90 FR 43560, September 10, 2025 (DFARS Case 2019-D041).
[CC4] SAM.gov RFI, "Reforming CMMC and Reducing Compliance Burden for the DIB," opportunity 89ef9bfb0834473791e991c712698d94; responses due 12:00 PM ET, August 14, 2026. https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view · Washington Technology, July 2026.
[CC5] Cyber AB June 2026 Town Hall (107 C3PAOs; >1,000 certified assessors, from 92 and 633 in December 2025). https://www.cmmc.com/newsroom/cyber-ab-town-hall-06-2026 · December 2025 baselines via GAO-26-107955. Note: the "~100 assessors vs 100,000 firms" comparison in circulation conflates C3PAO organizations with individual assessors. Not used.
[CC6] SBA release, July 13, 2026 (~$593,800 all-in per certification; 100,000+ small businesses; Loeffler on costs approaching $600,000). https://www.sba.gov/article/2026/07/13/sba-commends-us-department-wars-suspension-cmmc-phase-ii-small-defense-contractors · 32 CFR Final Rule RIA via InsideDefense and GAO-26-107955 ($104,670 L2 C3PAO, small entity, three years; DoD range $4,042–$117,768).
[CC7] Federal Register, DFARS Case 2013-D018, final rule establishing DFARS 252.204-7012, October 21, 2016; NIST SP 800-171 implementation required not later than December 31, 2017. https://www.federalregister.gov/documents/2016/10/21/2016-25315/defense-federal-acquisition-regulation-supplement-network-penetration-reporting-and-contracting-for
[CC8] eCFR, 32 CFR 170.22 ("Affirmation") and 170.4 (Affirming Official: the senior level representative within each OSA responsible for ensuring compliance and with authority to affirm continuing compliance). https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170/subpart-D/section-170.22
[CC9] Holland & Knight, "CMMC Affirmation Trap: FCA Exposure for Defense Contractors and Acquirers," January 2026 (primes lack automated access to subcontractor SPRS data; July 2025 successor-liability settlement; diligence scope including non-self-identifying defense suppliers; relator share 15–25%; reckless disregard standard). https://www.hklaw.com/en/insights/publications/2026/01/cmmc-affirmation-trap-fca-exposure
[CC10] DOJ Office of Public Affairs and DOJ Eastern District of California, February 18, 2025: Health Net Federal Services and Centene, $11,253,400, falsely certified cybersecurity compliance in annual reports to DHA under the TRICARE contract, 2015–2018; failure to timely scan for known vulnerabilities and remedy flaws per its own System Security Plan; DIBCAC among investigators. Both companies denied liability; no admission of wrongdoing. https://www.justice.gov/opa/pr/health-net-federal-services-llc-and-centene-corporation-agree-pay-over-11-million-resolve
[CC11] Sysdig Threat Research Team (Michael Clark), "JADEPUFFER: Agentic ransomware for automated database extortion," July 2026. https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
[CC12] NVD, CVE-2025-3248 (Langflow /api/v1/validate/code, missing authentication, unauthenticated RCE, CVSS 3.1 base 9.8, versions <1.3.0); patched April 1, 2025; CISA KEV early May 2025. Corroborated by BleepingComputer and NSFOCUS, July 2026.
[CC13] CyberScoop, "Sysdig clocks first documented case of agentic ransomware," July 2026 (Clark: a human set up and pointed the operation, provisioned C2 and staging, and chose the victim; root MySQL credentials originated in a prior compromise). https://cyberscoop.com/sysdig-judepuffer-ai-agentic-ransomware-attack/
[CC14] NIST SP 800-171 Rev. 2 (February 2020, incorporated by reference at 32 CFR 170.2) and Rev. 3 (May 2024, not tied to CMMC). https://csrc.nist.gov/pubs/sp/800/171/r3/final · DoD Class Deviation 2024-O0013 retains Rev. 2 until rescinded. Rev. 2 to Rev. 3 transition "not before 2027" is analyst consensus, not a published date. GAO-26-107955 flags the drift.
[CC15] GovEagle (Akash Mandavilli), "AI and CMMC Assessments: Realistic Applications," June 24, 2026 (SSPs often contain CUI, ruling out most commercial SaaS AI and pushing toward FedRAMP-scoped or self-hosted deployment; "the AI said so is not an acceptable audit trail"). Vendor source with a commercial interest in AI compliance tooling; cited against its own interest. https://www.goveagle.com/blog/ai-cmmc-assessments-realistic-applications
[CC16] SBA Office of Inspector General, Report 26-01, December 18, 2025 (self-certification without verification as top FY2026 management challenge). https://www.oversight.gov/sites/default/files/documents/reports/2025-12/SBA%20OIG%20Report%2026-01%20-%20Top%20Management%20and%20Performance%20Challenges%20Facing%20the%20SBA%20in%20Fiscal%20Year%202026.pdf · GAO-26-107955, March 12, 2026 (capacity, demand/attrition, NIST drift only partially addressed). https://business.cch.com/CybersecurityPrivacy/gaocmmcreport.pdf
Want a custom deep-dive on any line in this brief?
Every line in this brief traces to a primary source: the DoW release, the SAM.gov RFI, DFARS 252.204-7021, 32 CFR 170.22, the Health Net settlement, and the Sysdig JADEPUFFER writeup. Want the affirmation review or the AI scope audit turned into a one-page checklist for a specific teaming structure or acquisition target? Reply to this issue and tell me the firm and the vehicle.
I will pull the additional public-record sources, read the visible signal, and write a 4–6 page custom intelligence memo on the area you select. You name the question; I do the BD-grade analysis.
Buy a Custom Deep Dive — $50 →
Examples: Deep Dive — the five-question affirmation review for a named teaming partner · Deep Dive — the AI scope audit mapped to your current SSP asset list