Top
Protect your contracts. Secure your CUI. Prepare for CMMC. Explore NerdsToGo Alexandria’s Defense Compliance Practice. Click Here

DFARS 7012 Never Paused — And the CUI Problem Underneath It Just Got Harder to Ignore.

|

There is a lot of conversation in the defense industrial base about what happens next with CMMC Phase II. For business owners, there is a question that deserves just as much attention: Do we know what information we are responsible for protecting?

On July 13, 2026, the Department suspended the planned Phase II transition. Its implementing guidance expressly preserved DFARS 252.204-7012 requirements, self-assessments, and select government-led assessments.

That leaves contractors with work to do today. It also makes clarity about Controlled Unclassified Information, or CUI, essential. If you cannot confidently identify what needs protection, it becomes much harder to decide where your security investment belongs.

What DFARS 7012 actually requires.

DFARS 252.204-7012 requires adequate security for covered contractor information systems. For most contractor-operated systems handling covered defense information, NIST SP 800-171 supplies the minimum baseline. The clause’s implementation deadline was December 31, 2017.

Current suspension guidance retains NIST SP 800-171 Revision 2 as the Level 2 baseline. That revision contains 110 security requirements. Your applicable contract terms and deviations matter.

Accurate representations matter, too. DOJ’s Civil Cyber-Fraud Initiative addresses conduct including knowing misrepresentations about cybersecurity practices and knowing violations of incident-reporting obligations. False Claims Act exposure does not depend on the arrival of a CMMC certification deadline.

The practical expectation is straightforward: understand your obligations, implement the required protections, and make sure your representations match what you can demonstrate.

The survey shows why the work continues.

ISC2’s September 2026 report, Navigating Cybersecurity Regulatory Requirements and the CMMC Pause, examined an August survey of 219 U.S. cybersecurity professionals involved in CMMC work during the preceding year.

  • 76% agreed that a CMMC program is needed to ensure cybersecurity standards are met.

  • 57% reported spending at least six hours weekly on CMMC work over the preceding year, combining the two higher time categories.

  • Among respondents at organizations with 1–99 employees, 35% fell in the 20-plus-hours-per-week category.

  • 68% continued working on CMMC-related tasks after the suspension.

ISC2 cautions that the findings are directional, with small subgroup samples. They should not be presented as a census of the entire CMMC community.

My takeaway: there is support for credible cybersecurity verification alongside a substantial workload that reform needs to address. For a small business, those hours compete with client delivery, staff development, and other security priorities. Clear requirements help owners make those tradeoffs responsibly.

The CUI problem underneath the cost.

Comments submitted to the CMMC Reform Task Force put CUI identification and marking directly in the conversation about compliance costs.

The SBA Office of Advocacy highlighted unclear CUI scope among the burdens facing small firms. The Professional Services Council called for consistent identification, marking, and flow-down so contractors have clearer direction about what requires protection.

The practical concern is easy to understand. An uncertain contractor may bring additional users, devices, applications, and workflows into its compliance boundary as a precaution. Each expansion can increase implementation and assessment work.

The opposite mistake is also possible: information that needs protection may be overlooked.

Either outcome makes CUI scoping a business decision worth getting right. Before buying more technology or expanding your environment, establish what information is involved and how it moves through your operation.

Blanket flow-down requirements deserve specific questions.

The Alliance for Digital Innovation raised this issue in its August submission. ADI reported that some primes impose Level 2 requirements broadly across their suppliers, including commercial-product machine shops with no CUI involvement. It attributed that practice to uncertainty about scope and concern about audit exposure.

If your prime requires Level 2, ask:

  • Which CUI categories apply to our work?

  • What information will we receive or create?

  • Which systems and services will handle it?

  • Is Level 2 self-assessment or third-party certification required, and what contract language establishes that requirement?

DFARS 7012 flow-down applies to subcontract performance involving covered defense information or operationally critical support.

Get clarification in writing and resolve any changes through the appropriate contracting process. Asking the question does not, by itself, change an existing obligation.

Government agencies have responsibilities here, too.

On September 2, 2026, the Information Security Oversight Office issued ISOO Notice 2026-07. It directs agencies to provide prime contractors with guidance identifying government-furnished CUI, explaining how contractor-developed information will be identified as CUI, and establishing a process for challenging CUI designations.

That gives contractors a concrete request to make: provide the CUI guidance for this contract. Subcontractors should work through their prime to obtain it.

Contractor-developed technical information can qualify as covered defense information when it meets the applicable criteria. A missing marking alone does not settle the question.

The September notice addresses agency responsibilities. It does not independently rewrite every contractor’s agreement. Its practical value is the clearer basis it provides for requesting and documenting scope guidance.

The 72-hour clock still matters.

DFARS 7012 requires reporting within 72 hours of discovering a qualifying incident affecting a covered system, covered defense information, or designated operationally critical support. Reporting goes to DoD through DIBNet. A confirmed CUI theft is not a prerequisite.

Your response plan should identify who evaluates the trigger, who files the report, and how they access the reporting system. Rehearse those steps before an incident forces the issue.

What business owners should do now.

  1. Review the actual agreement. Check the incorporated clauses, modifications, and applicable deviations with your contracts team.

  2. Request written CUI guidance. Ask your contracting officer, or your prime if you are a subcontractor, what information you will receive and may create during performance.

  3. Map the information flow. Identify the people, devices, applications, cloud services, and providers that handle that information. Use the map to validate your security boundary.

  4. Reconcile your assessment with your evidence. Check whether your SPRS submission and other compliance representations reflect what is implemented. Document gaps and prioritize remediation.

  5. Rehearse incident reporting. Confirm that your team can recognize a reporting trigger and act within the required timeframe.

Make the work count.

Small businesses have limited time and capital. Every security investment should have a clear purpose, and every compliance representation should have evidence behind it.

The Phase II suspension gives contractors an opportunity to review how that work is organized while continuing to meet their existing obligations. Use it to clarify your CUI scope, address weaknesses, and build a security program your team can maintain.

Clear scope helps you direct your budget toward protecting the information, operations, and relationships your business depends on.

Need help connecting your contract requirements, CUI scope, and security plan? Start a conversation with NerdsToGo Alexandria about your next practical step.