AGP Picks
View all

Atlantic Digital says CMMC pause does not stop DFARS duties

Sep. 15, 2026
By AI, Created 11:30 UTC, Sep 15, 2026, AGP -

Atlantic Digital is warning defense contractors that the federal suspension of CMMC Phase 2 does not pause core cybersecurity obligations under DFARS 252.204-7012 or reporting requirements in SPRS. The firm says contractors should use the 60-day review window to close documented gaps, not relax compliance efforts.

Why it matters: - Defense Industrial Base contractors still face cybersecurity exposure even though CMMC Phase 2 is on hold. - DFARS 252.204-7012 obligations remain active, including implementation of NIST SP 800-171 Revision 2 controls and cyber incident reporting. - Self-assessed SPRS scores remain the government’s primary visibility into a contractor’s security posture while third-party assessments are paused. - Unsupported scores can still create False Claims Act risk under the Department of Justice Civil Cyber-Fraud Initiative.

What happened: - Atlantic Digital, Inc. said the July 13, 2026 suspension of CMMC Phase 2 does not remove underlying cybersecurity duties for defense contractors. - The U.S. Department of War suspended Phase 2 before its Nov. 10, 2026 effective date and launched a 60-day review through a newly formed CMMC Reform Task Force. - The suspension covers certification assessments by CMMC Third-Party Assessment Organizations and pending implementation milestones in Department solicitations and contracts, applied through contract modification. - Atlantic Digital said contractors should treat the review period as time to close documented gaps.

The details: - DFARS 252.204-7012 still requires contractors to implement the 110 security requirements in NIST SP 800-171 Revision 2. - Contractors must continue to report cyber incidents under DFARS 252.204-7012. - Level 1 and Level 2 self-assessment requirements remain in force. - Contractors must continue posting assessment scores to the Supplier Performance Risk System. - Contractors must continue affirming compliance annually. - The Civil Cyber-Fraud Initiative has pursued alleged non-compliance with DFARS 252.204-7012 and 252.204-7020 as a basis for False Claims Act liability. - Atlantic Digital warned that the self-attested SPRS score remains exposed to the same risk it carried before July 13 if the score is not supported. - Matt Carson, who leads technical architecture on Atlantic Digital’s CMMC engagements, said contractors are often failing because of technical debt, not because they chose the wrong tools. - Carson said time spent maintaining systems that should be replaced reduces time available for threat monitoring and documentation. - Carson said the review does not retire technical debt and gives contractors 60 days of quiet to work on it. - Carson discussed enclave architecture under budget constraints, privileged access in software development environments and stalled compliance programs in a recent long-form interview on IntelliGRC’s podcast hosted by Steven Molter. - Matt Hall, co-owner of Atlantic Digital, said CMMC is a business maturity change before it is a technology change. - Hall said compliance efforts stall when an IT director carries the work alone, but plans of action close when ownership sits with leadership. - Atlantic Digital advises contractors not to revise a previously submitted SPRS score or slow plan-of-action closeout because of the suspension. - Atlantic Digital was founded in 2009 and serves federal, defense and Defense Industrial Base organizations. - The firm provides cybersecurity compliance and digital modernization services CONUS and OCONUS. - Atlantic Digital’s services include vCISO subscriptions, CMMC readiness strategy, NIST SP 800-171 implementation, compliance documentation and GRC platform integration through its partnership with IntelliGRC. - Atlantic Digital staffs engagements exclusively with U.S. citizens. - Atlantic Digital is not a CMMC Third-Party Assessment Organization and does not perform certification assessments.

Between the lines: - The suspension appears to pause the certification pathway, not the broader compliance burden. - That means contractors may have less external assessment pressure for now, but they do not get a reset on documentation, self-assessment or incident-reporting obligations. - Atlantic Digital is framing the pause as an operational window, not a policy retreat.

What’s next: - The CMMC Reform Task Force review is expected to conclude in mid-September 2026. - Contractors should expect continued scrutiny of SPRS submissions and open plan-of-action items during the review period. - Atlantic Digital is urging defense contractors to use the window to document fixes and reduce technical debt before the next milestone.

The bottom line: - CMMC Phase 2 is suspended, but core DFARS and SPRS obligations are still in force.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

The Political Ledger

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

The Political Ledger

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.