On July 13, 2026, the Defense Department suspended Phase 2 of the Cybersecurity Maturity Model Certification program — the milestone that, as Federal News Network reported, "would have involved DoD requiring third-party cybersecurity assessments across all contracts involving sensitive but unclassified information starting Nov. 10, 2026." In its place, DoD Chief Information Officer Kirsten Davies stood up a 60-day "top-to-bottom" review, and the memo suspended "all pending and future CMMC milestones" until further notice. The CMMC Reform Task Force's recommendations are, per reporting in mid-August, "expected to take roughly one more month" — meaning they land with the DoD Office of the CIO within weeks.
Read the headline and it sounds like defense contractors got a reprieve. Read the memo and they didn't. DoD was explicit that "the phase one requirements for applicable contracts to require a CMMC self-assessment, which went into effect last November, remain in force," and that during the pause it "will continue using the self-assessments and select government-led assessments." What was frozen is the third-party audit — the verification mechanism. The obligation to actually protect controlled unclassified information did not move an inch.
Davies framed the pause as a burden problem, not a security retreat. The current program, she wrote, "imposes significant and often prohibitive burdens on the Defense Industrial Base (DIB), particularly the small and non-traditional businesses that are the engine of American innovation," and DoD would refocus on "tangible cyber hygiene rather than third-party certifications and bureaucratic, high cost-imposing red tape." That distinction — hygiene over paperwork — is the whole story for anyone thinking about AI.
CMMC is, at bottom, a program about a data boundary
Strip away the assessment machinery and CMMC exists to answer one question: is a contractor's environment secure enough to store, process, and transmit controlled unclassified information (CUI)? CUI, as Federal News Network describes it, is "sensitive government data that doesn't meet strict criteria for national security classification, but still requires special protection and handling controls under federal laws or policies." DoD officials estimated "roughly 80,000 companies would eventually be subject to the third-party assessment requirements."
The program was designed for CUI the way CUI used to live: in databases, file shares, and email — data at rest inside an enclave you control. Its controls are about who can reach that enclave and how it's hardened. That model was reasonable when the only way controlled data left the building was a person emailing a file. It is no longer the only way.
The part the whole debate assumes away
The loudest theme in industry's comments to the Reform Task Force isn't cost — it's that contractors can't reliably tell what CUI is. The SBA's Office of Advocacy called CUI uncertainty the "most frequently cited concern" for small businesses under CMMC. As Kate Growley of Crowell & Moring put it, "CMMC follows the data" — "if CUI is being over- or under-scoped, so will the scope of CMMC."
And the data is not static. Michael Lowell of Reed Smith pointed out that "a contractor may receive little or no marked CUI from DoD but create information during contract performance that qualifies as CUI." His examples: "engineering data, technical reports, drawings or other work product." In other words, the CUI that matters most is often generated during the work — not handed down pre-marked from a program office.
That single fact is where artificial intelligence quietly redraws the boundary CMMC was built to defend.
AI moved the boundary — and nothing sits on the new one
The engineering data, technical reports, and drawings Lowell describes are exactly the work product now being generated with, or pasted into, frontier AI tools. An engineer drops a technical drawing into ChatGPT to speed a design review. A copilot summarizes a test report. An autonomous-systems team wires a large language model into a build loop. Each of those is a CUI crossing — controlled data leaving the contractor's enclave for a model the contractor does not run and cannot audit.
CMMC has no control for that moment. It can attest that your network is hardened and your access controls are sound, and the instant an employee pastes a controlled drawing into a chat window, every one of those controls is behind them. The certification verifies the walls of the room; it says nothing about the doorway a browser tab just opened in the wall.
And you cannot mark your way out of it. If a contractor can't confidently classify its own engineering output as CUI — the exact problem the Reform Task Force is now wrestling with — it certainly can't expect an employee, or an AI agent acting on that employee's behalf, to make the call correctly every time, thousands of times a day. "Follow the data" is sound advice right up until the data is moving faster than any human can label it.
A data-boundary problem has a data-boundary answer
The reform review is not asking for more paperwork. Davies tasked the task force with a framework that "replaces prohibitive, third-party compliance models with scalable, realistic security measures." A snapshot audit on a multi-year cycle is not that. A control that sits on the boundary and rules on every crossing, in real time, is.
Concretely, that control is a deterministic, non-bypassable enforcement point at the seam where controlled data would leave the enclave for an AI model: it inspects every prompt and agent action for controlled content before it crosses, applies the organization's policy at the crossing — permit, redact, deny — and records a replayable, signed decision for every ruling. Our Mission Authorization Gateway is built for exactly this seam: enforcement outside the agent, a decision before the data leaves, and evidence an independent party can re-run.
Note how that differs from what CMMC measures. A certification is a periodic snapshot of whether your environment could hold CUI. A gateway decision is proof of what actually crossed the AI boundary and why it was allowed — a record that survives the moment. One answers "is your posture adequate?" once a cycle; the other answers "may this specific data cross into this specific model right now?" every time it's asked.
None of this replaces CMMC, and it isn't a certification. It fills the gap the program leaves open: the AI boundary the current framework never contemplated and the reform review is not scoped to close. We hold ourselves to the same evidentiary standard we ask of others and publish what is shipped, what is staging-verified, and what is still in development on our Trust page — not in the present tense of a roadmap.
Three questions worth an hour this week
Whatever the task force recommends within the next few weeks, the underlying obligation isn't going away, and the AI boundary keeps widening while the audit is paused. For any DIB program handling CUI:
- Which AI tools can your workforce reach, and what stops CUI from entering them? If the answer is a policy memo and training, that is a description of a boundary, not a boundary.
- Can you name the exact seams where controlled data would cross into a model you don't run? Every browser tab, copilot, and agent integration is a candidate.
- If a crossing were blocked, could you replay the decision for an auditor? A verdict you can't reproduce is an opinion with a timestamp.
If you want a second set of eyes on those answers, request a 30-minute Boundary Review. We'll map where controlled data would cross into an AI model in your environment, and show you what deterministic enforcement looks like on one of those seams.