The CMMC Safety Net Just Disappeared…Is Your MSP Contract Ready?

On July 13, 2026, the Department of War hit pause on the part of the Cybersecurity Maturity Model Certification program that mattered most to independent verification: Phase II. Third-party assessments by CMMC Certified Third-Party Assessment Organizations (C3PAOs), which were set to start appearing in contracts on November 10, 2026, are now suspended indefinitely while a newly formed CMMC Reform Task Force spends 60 days studying the program and reports back around mid-September. CMMC Level 3 (DIBCAC) assessments are suspended too.
What survives, for now, is Phase I: self-assessment. Contractors in the Defense Industrial Base (DIB) will keep scoring themselves against NIST SP 800-171, entering that score in SPRS, and having an Affirming Official sign an annual affirmation swearing it's accurate. DFARS 252.204-7012 hasn't gone anywhere, and neither has the Department of Justice's appetite for False Claims Act cases against contractors who get their cybersecurity posture wrong. What's gone, at least for the foreseeable future, is the independent check that was supposed to backstop all of it.
That doesn't mean no one is looking. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) - the government's own assessment arm - hasn't been suspended along with the C3PAO framework, and it can still show up to conduct assessments at any time, for any contractor it chooses to look at. DIBCAC isn't a replacement for the independent third-party layer MSPs and their clients were counting on, but it is the entity most likely to be the first outside party to actually test a self-assessment against reality. That matters, because a DIBCAC assessment functions as a pressure valve that didn't exist before Phase II was suspended: it's an opportunity for a contractor (and, by extension, the MSP behind the environment) to find out about a gap and correct course before the discrepancy hardens into a False Claims Act referral. Once DOJ's Civil Cyber-Fraud Initiative is involved, the posture of the case changes from "fix the SSP" to "defend a false certification." A DIBCAC finding is where problems are supposed to surface before they get to that point.
For MSPs who serve the DIB, that's not a footnote. It's a fundamental shift in where the risk sits, and it lands squarely on the consulting relationship between the MSP and its client.
Why This Matters More to MSPs Than It First Appears
Under the Phase II model that was supposed to arrive this November, an MSP's implementation work would eventually be checked by an independent assessor before a contractor could claim Level 2 status. That assessor served, whether anyone said it out loud or not, as a kind of liability buffer. If the C3PAO signed off, the client's compliance posture had outside validation. If something was missed, there was a professional third party in the chain who had also looked at the environment and made a judgment call.
Take that assessor out of the picture, and the chain shortens. It runs from the MSP's technical work, directly to the client's self-assessment score, directly to a federal affirmation signed under something close to penalty of perjury. There's no longer an independent professional standing between the MSP's advice and the government's reliance on it.
That has real consequences:
- The client's self-assessment now rests more heavily on the MSP's work product (configuration decisions, policy documents, SSPs, POA&Ms, gap assessments) without a third party to catch errors before they become part of a federal submission.
- If a self-assessment turns out to be wrong, DOJ's Civil Cyber-Fraud Initiative doesn't need a C3PAO's blessing to bring a False Claims Act case. It needs a false certification and a contract involving federal funds. MSPs who advised on or performed the underlying work can be pulled into scrutiny at best as witnesses, at worst as co-defendants, depending on how their advice was documented and how their contract is written.
- Regulatory whiplash is now a fact of life. The Reform Task Force's report is due in September, and industry comments on the RFI are due August 14. Whatever the program looks like at the end of this review cycle may not resemble what it looks like today. MSPs who build engagements around the current, unsettled requirements without contractual flexibility could find themselves locked into scope that no longer matches the rules.
None of this makes MSPs legally responsible for their clients' compliance. But it does mean the paper trail that used to include an independent assessor's judgment now stops with the MSP. That's exactly the kind of gap plaintiffs' lawyers, and occasionally DOJ, look for.
Where MSP Contracts Need to Get Sharper
If you run an MSP serving DIB clients, or you're a client-side counsel evaluating one, here's where the contract needs real attention right now.
- Define the deliverable, not the outcome. Your MSP agreement should describe the specific services performed - configuration, monitoring, documentation, gap remediation, and should not promise "CMMC compliance" as an outcome. Compliance is a legal and factual conclusion the client's Affirming Official reaches and certifies to the government. The MSP provides inputs to that conclusion; it shouldn't be on the hook for the conclusion itself.
- Put the affirmation obligation where it belongs. The contract should make explicit that the client, through its own Affirming Official, bears sole responsibility for the accuracy of any SPRS score and any annual affirmation. The MSP's role is advisory and technical, not certifying.
- Tighten scope-of-work and change-order language. With the program's shape likely to shift again after the Task Force reports, contracts should build in defined triggers for renegotiating scope, fees, and deliverables if CMMC requirements change materially. A fixed-scope, fixed-fee engagement signed today assuming today's rules is a liability if the rules move in September.
- Reassess limitation-of-liability and indemnification clauses. With no C3PAO in the chain, MSPs carry a larger share of the practical (if not legal) responsibility for how the environment performs. Liability caps, mutual indemnification carve-outs, and exclusions for consequential damages deserve a fresh look, not a rollover from a template drafted before Phase II was suspended.
- Build a documentation regime that stands in for the missing third party. Since there's no outside assessor validating the work, MSPs should be even more disciplined about contemporaneous documentation: what was assessed, what was recommended, what the client accepted or declined, and when. This protects the MSP if a self-assessment is later challenged, and it gives the client something to point to if it needs to show good faith.
- Address False Claims Act exposure directly. Consider contract language that requires the client to review and independently approve any documentation that will feed into a federal certification, and that clarifies the MSP is not itself making representations to the government. This won't eliminate FCA risk, but a clear delineation of who is certifying what can matter a great deal if a case ever gets litigated.
- Plan for the possibility of a DIBCAC visit. Because DIBCAC can conduct assessments on its own timeline regardless of what happens with Phase II, MSP contracts should spell out what happens if the client is selected: who pulls evidence, who represents the environment to the assessor, what the MSP's obligation is to make personnel and documentation available, and how quickly the MSP is expected to respond to remediation requests that come out of a DIBCAC finding. Treat a DIBCAC assessment as the checkpoint where a fixable gap gets fixed — the contract should make clear the MSP will cooperate promptly, because a sluggish or unclear response at that stage is what turns a correctable finding into the kind of unresolved discrepancy DOJ notices later.
- Check your insurance, not just your contract. Errors-and-omissions and cyber liability policies written with Phase II's third-party backstop in mind may not reflect the risk profile MSPs now face. This is a good moment to have that conversation with your broker.
- Don't quietly become a "covered contractor." MSPs contracting to process, store, or transmit CUI on behalf of a DIB client can trigger their own DFARS 7012 and CMMC obligations. Contracts should clearly define data handling, flow-down obligations, and where CUI is permitted to reside, so the MSP doesn't inherit compliance duties it never intended to take on.
The Bottom Line
Self-assessment without an independent backstop doesn't mean less cybersecurity work for MSPs. If anything, DIB clients need experienced technical guidance more than ever, since there's no third party left to catch problems before a certification goes to the government. But it does mean MSPs are now closer to the center of the compliance chain than the current contract templates in this industry were built to handle.
This is a good time to pull out your standard MSP services agreement and read it as if a False Claims Act investigator, not just your client, is going to read it too. If it still assumes a C3PAO is standing behind the work, it's already out of date.
This post is for general informational purposes and does not constitute legal advice. MSPs and DIB contractors should consult qualified counsel about how these developments affect their specific contracts and compliance obligations.
