Holy Roman Emperor Joseph II of Habsburg reportedly proposed his own epitaph before he died in 1790: “Here lies a prince whose intentions were pure, but who had the misfortune to see all his plans fail.”
The wording is probably embellished. The sentiment was real. During his decade as sole ruler of the Habsburg Monarchy, Joseph issued thousands of decrees: toleration for Protestants, Orthodox Christians, and Jews; state supervision of church institutions; the abolition of personal serfdom. Many of his headline reforms look admirable by modern standards.
His methods do not.
By 1789, Hungary’s nobles were near rebellion, the Austrian Netherlands was in revolt, and the bureaucracy could not absorb the instructions arriving from Vienna. In January 1790, weeks before his death, Joseph withdrew most of his contested measures in Hungary.
If you work in the defense industrial base, this story should sound uncomfortably familiar. I write from inside it: I created GovCon Enclave, carried it from concept through several perfect CMMC Level 2 assessments with zero POA&Ms, and watched it become the core product behind BOOST LLC’s acquisition of Rimstorm. From that seat, the past several years look like our Josephine decade. On July 13, 2026, CMMC reached its January 1790.
Reform without a constituency
Joseph chose the right goals; his problem was pursuing too many at once, at maximum speed, from the top, without building a durable coalition behind them.
He refused to be crowned King of Hungary because coronation required an oath that constrained royal power, and had the Crown of St. Stephen removed to Vienna instead. The message to an entire kingdom: I will not negotiate with you, because I am right.
Being right did not make the method sustainable.
The reforms threatened a different interest in every direction: nobles lost jurisdiction and privilege, the Church lost monasteries and power, Hungary lost constitutional autonomy, and even the intended beneficiaries received their new freedoms wrapped in administrative disruption and uncertainty about which obligations had actually changed.
Even the celebrated 1781 patents show the pattern. They abolished personal servile status but left the robot, the labor and payments attached to peasant holdings, in place, and the later attempt to convert those obligations into money failed. A legal liberation and an economic transition are not the same reform.
When a policy’s intended beneficiaries and its threatened interests are both alienated, the policy has not built a constituency. It has built a siege.
CMMC was born with a related structural problem. The beneficiary of protecting controlled unclassified information is national security in the abstract: the warfighter, the taxpayer, and the future battlefield where an adversary does not already possess American technical data. Those beneficiaries do not show up to comment periods. The direct costs fall on tens of thousands of small and midsize contractors, which experience the program as expense, ambiguity, and paperwork arriving from a capital that did not have to implement it for them. And unlike Joseph’s decrees, CMMC arrived through notice-and-comment rulemaking; the docket holds years of industry comments. But procedure is not constituency. A rule can clear every comment period and still reach the market without anyone invested enough to defend it when the costs land.
I say this as someone who has already taken that bet. I have spent years building and operating the kind of environment this policy requires, and my interest is not hidden: I believe the market will reward contractors that make secure CUI operations repeatable, and I built a platform around that belief.
I believe in the mission. Protecting CUI is a response to sustained industrial espionage and the loss of sensitive defense information, not bureaucratic theater. The requirements in NIST SP 800-171 are mostly sensible security practices. Many of Joseph’s reforms were sensible, too.
Six thousand edicts
Consider CMMC 1.0, announced in 2019 and released in January 2020. It had five maturity levels, CMMC-specific process-maturity requirements, and third-party assessment reaching down to companies handling only federal contract information. The certification body, assessment organizations, training system, and individual assessor workforce all had to be created while the program was advancing toward implementation.
The design demanded an ecosystem before that ecosystem existed.
Joseph’s bureaucracy could not implement decrees as quickly as he issued them. Local officials fell behind, enforcement became inconsistent, and inconsistency bred resentment. CMMC’s analogous constraint was assessment capacity: the program depended on a private verification market that needed time, trained people, and enough demand certainty to justify investment.
CMMC 2.0, announced in 2021, was the first strategic retreat. Five levels became three. The CMMC-specific maturity processes disappeared. Level 1 became a self-assessment, and some Level 2 procurements could use self-assessment as well. The program centered Level 2 on NIST SP 800-171 Revision 2.
That mattered because 800-171 already had roots. Contractors handling covered defense information had been required to implement it under DFARS 252.204-7012 by the end of 2017. Contractors might not have loved the requirement or implemented it fully, but it was already in their contracts.
The revised rollout began on November 10, 2025, with Phase I assessments. Phase II was scheduled for November 10, 2026, and would have expanded the use of Level 2 third-party certification as a condition of award when a solicitation specified it. Full implementation was supposed to phase in over three years, not arrive for the entire DIB on one morning.
Even with that qualification, the capacity problem was serious. The Small Business Administration said more than 120,000 small businesses would be affected and contrasted that demand with roughly 100 approved assessment organizations (C3PAO). It estimated total compliance costs as high as $593,800 for a small firm requiring third-party certification. The exact cost for any one contractor depends heavily on scope and starting posture, but the order of magnitude was enough to turn a security program into a barrier to market entry.
You do not need a maturity model to see the absorption problem in that arithmetic.
The headline figure deserves an honest footnote, though. The assessment is not the expensive part. C3PAO representatives put small-business assessment fees on the record at under $100,000, which leaves the large majority of that $593,800 in implementation rather than verification. The SBA’s own numbers point the same direction: it estimates $388,600 even for firms eligible to self-assess, whose bill involves no assessor at all. And the implementation is not new: it covers controls that DFARS 252.204-7012 has required since the end of 2017, controls many of the same firms had already affirmed in SPRS. As Fernando Machado of the C3PAO Cybersec Investments put it after the suspension, those implementation costs “should have already been incurred.” A firm facing a half-million-dollar bill to reach the posture it once attested to is pricing the gap between its attestation and its environment, not pricing CMMC itself.
Not all of that gap is bad faith. A self-assessment is only as reliable as the person performing it, and the person scoring 110 requirements is often an IT generalist reading them for the first time, not a trained Lead CCA who knows what evidence each control actually demands. Someone can attest to a control they do not fully understand and be sincerely wrong. That gap, honest or not, is a great argument for the verification machinery.
Our January 1790
On July 13, 2026, the Department suspended CMMC Phase II. Its implementation memorandum held pending and future milestones in abeyance, while an accompanying request for information created a 60-day CMMC Reform Task Force. Phase I remained in force.
This withdrew a planned verification gate whose cost and capacity had become politically unsustainable; the underlying obligations stayed in force.
Joseph’s own retreat offers a useful distinction. His January 1790 rescript withdrew most of his Hungarian measures but preserved religious toleration and core peasant reforms. The changes that survived had already altered legal status and daily life; they could not be removed as casually as an administrative instruction.
The same distinction appears in CMMC’s suspension.
DFARS 252.204-7012 remains in force. NIST SP 800-171 Revision 2 remains the contractual standard for covered defense information under that clause. Phase I self-assessments remain. SPRS reporting, affirmations required by applicable CMMC clauses, and government-led assessments remain parts of the enforcement environment.
False Claims Act exposure did not pause either. In 2025, MORSECORP agreed to pay $4.6 million to resolve allegations involving contractual cybersecurity failures. The company acknowledged that it had submitted a score of 104 in SPRS before a consultant calculated its actual score at negative 142. The lesson is that a contractor can create serious exposure when it knowingly submits a materially false score or affirmation, not that every control gap constitutes fraud, and “knowingly” is broader than it sounds: the False Claims Act reaches deliberate ignorance and reckless disregard, not just intentional lies. An honest mistake after a real effort is defensible. Assigning the attestation to someone unequipped to make it, and never verifying the result, may not be.
flowchart TD
S["July 13, 2026<br/>CMMC Phase II suspended"]
S --> M["The machinery: stopped"]
S --> O["The obligations: in force"]
M --> M1["Expansion of Level 2 certification<br/>as a condition of award"]
M --> M2["Pending and future<br/>rollout milestones"]
O --> O1["DFARS 252.204-7012 and<br/>NIST SP 800-171 Rev. 2"]
O --> O2["Phase I self-assessments,<br/>SPRS scores, affirmations"]
O --> O3["Government-led assessments and<br/>False Claims Act exposure"]
style M fill:#5c1a1a,stroke:#cc4444,color:#f5c6c6
style M1 fill:#5c1a1a,stroke:#cc4444,color:#f5c6c6
style M2 fill:#5c1a1a,stroke:#cc4444,color:#f5c6c6
style O fill:#1a3d1a,stroke:#44cc44,color:#c6f5c6
style O1 fill:#1a3d1a,stroke:#44cc44,color:#c6f5c6
style O2 fill:#1a3d1a,stroke:#44cc44,color:#c6f5c6
style O3 fill:#1a3d1a,stroke:#44cc44,color:#c6f5c6What stopped on July 13 was the expansion of the machinery. What survived was the underlying duty, especially where that duty already had contractual roots. History does not repeat, but it does appear to file continuations.
The Leopold test
Joseph’s brother Leopold II inherited a monarchy close to fragmentation. He took the coronation oaths Joseph had avoided, restored Hungary’s constitutional position, and negotiated with the institutions his brother had tried to route around. His reign lasted only two years, but it demonstrated the method Joseph had rejected: reform is more durable when it acquires consent, legal form, and a constituency outside the ruler’s office.
The CMMC Reform Task Force is now auditioning for a version of Leopold’s role. Four principles would move the program in that direction.
Make security valuable in source selection. CMMC has mostly framed security as an obligation: a contractor satisfies the gate or loses eligibility. A reformed program could also let verified security posture earn meaningful evaluation credit, much as acquisition teams weigh technical strength or past performance. When better security helps win work, contractors have a market reason to compete on it.
Preserve what has roots, and recognize evidence produced elsewhere. Existing DFARS obligations and the 800-171 baseline are the obvious foundation. The Department should also publish defensible crosswalks that give partial assessment credit for evidence already produced through FedRAMP authorizations, properly scoped SOC 2 reports, ISO 27001 certifications, and comparable government assessments. None proves CMMC wholesale, and a SOC 2 report is not a certification. But requiring a company to prove the same implementation twice adds cost without adding security.
Shrink the scope before financing the gap. Cost allowability is determined under FAR Part 31, but formal allowability does not mean a small fixed-price contractor or lower-tier subcontractor can recover a six-figure investment in practice. The more durable fix is architectural: confine CUI to an enclave with a small, pre-hardened boundary, and the assessment scope shrinks with it. A twelve-person machine shop should not have to become a cloud-security integrator to protect a narrow set of sensitive data; it needs a contained environment sized to what it actually handles. The Department could accelerate this cheaply by recognizing the category: publish which shared environments have themselves passed C3PAO assessment, the way FedRAMP publishes authorized services, and make control inheritance predictable so a tenant’s assessment covers only the delta. That recognizes without endorsing, and it asks no one to violate the ecosystem’s conflict-of-interest rules, which rightly stop assessors from recommending solutions. No one has to recommend anything: when operating in a certified environment makes an assessment demonstrably smaller and cheaper, the economics do the recommending. Primes could steer their supply chains the same way without waiting for a rule. I built GovCon Enclave on exactly this model, so my interest is explicit, but the logic does not depend on my product: verified once and inherited many times is already how the rest of the federal security ecosystem scales. Where even a scoped environment is out of reach, grants, tax credits, and expanded free cybersecurity services can close the rest.
Match verification to absorption capacity and risk. Phase requirements should follow CUI sensitivity, program criticality, and available assessment capacity instead of treating a date as proof that the market is ready. The original three-year rollout recognized this in principle. A reformed version should make the sequencing explicit, measurable, and adjustable as the assessment ecosystem grows.
What contractors should do during the pause
Most people reading this do not sit on the task force. They work for contractors, lead security programs, or operate the environments where CUI lives. For them, the important distinction is between three decisions that are too often collapsed into one.
The first is whether to continue controls already required by contract. That answer is yes. Keep the system security plan accurate, work the POA&M, maintain a supportable SPRS score, and make only affirmations the evidence can sustain. Stopping implementation while continuing to represent compliance does not eliminate a burden. It turns an engineering gap into legal risk.
The second is whether to continue a major architecture change. That answer depends on why the change exists. If an enclave, identity migration, or logging program is needed to satisfy an active contract or to reduce a real security risk, the Phase II suspension did not remove its purpose. If the investment exists solely to satisfy one feature of the suspended certification machinery, reevaluate it against the task force’s eventual recommendations before making an irreversible commitment.
The third is whether to purchase a voluntary C3PAO assessment now. That decision should follow the business case. If a prime requires certification, a target procurement rewards it, or independent validation will strengthen customer confidence, proceeding can create an advantage while competitors wait. If none of those conditions exists, keep the environment assessment-ready and time the assessment spend against the task force’s recommendations. The mistake is allowing a pause in certification spending to become a pause in security implementation.
flowchart TD
ROOT["Three decisions,<br/>decided separately"]
ROOT --> D1["Controls already<br/>required by contract"]
ROOT --> D2["Major architecture<br/>change in flight"]
ROOT --> D3["Voluntary C3PAO<br/>assessment"]
D1 --> A1["Continue. Keep the SSP accurate,<br/>work the POA&M, affirm only<br/>what the evidence sustains"]
D2 --> Q2["Why does it exist?"]
Q2 -->|"active contract or<br/>real risk reduction"| A2["Continue: the suspension<br/>did not remove its purpose"]
Q2 -->|"only the suspended<br/>certification machinery"| A2B["Reevaluate against the<br/>task force outcome first"]
D3 --> Q3["Business case now?"]
Q3 -->|"prime requires it, procurement<br/>rewards it, customers value it"| A3["Proceed while<br/>competitors wait"]
Q3 -->|"none of those"| A3B["Stay assessment-ready<br/>and time the spend"]
style A1 fill:#1a3d1a,stroke:#44cc44,color:#c6f5c6
style A2 fill:#1a3d1a,stroke:#44cc44,color:#c6f5c6
style A3 fill:#1a3d1a,stroke:#44cc44,color:#c6f5c6The broader federal direction still matters. The proposed government-wide FAR CUI rule would apply common safeguarding requirements to federal contracts involving CUI, including civilian-agency work. The current policy direction points toward NIST SP 800-171 Revision 3, so today’s Revision 2 implementation will not map perfectly to every future requirement. It will, however, leave a contractor far closer to the destination than starting from zero.
Preparedness is a competitive asset, not merely a compliance option. The Cyber AB reported in August 2026 that approximately 2,000 defense contractors had attained Level 2 certification and that the supporting ecosystem had grown beyond 110 assessment organizations and 1,100 Certified Assessors. Two thousand certifications against a DIB of well over a hundred thousand firms is simultaneously an indictment of the machinery’s pace and a roster of early movers. If independent verification returns, organizations with accurate documentation and operating controls will move while competitors are still discovering their gaps. If it does not, those same organizations will still possess a stronger security program, better evidence for primes and contracting officers, and a more defensible account of their contractual compliance.
The controls were never good because they were decreed. They were decreed because they were good, at the time. NIST published SP 800-171 in 2015, and the machinery took a decade to make it enforceable, so the baseline the DIB defends today is the best practice of ten years ago, already superseded on paper by Revision 3. That is an argument for faster machinery, not weaker obligations. Multifactor authentication does not stop reducing risk because a certification phase was suspended. The adversaries targeting defense information did not stand down for a 60-day review.
The long view
Josephinism lost its decade and won the long run. Religious toleration, the end of serfdom, a state no longer subordinate to the church: by 2026 these are not reforms, they are the baseline of every European state. The last remnants of the robot fell in 1848, more than half a century behind Joseph’s schedule, and there was no smooth march from decree to modern state; some measures stayed reversed for generations. But Joseph did not fail. His reforms took longer than he expected, and longer than he had. Faltering machinery did not change the destination. It cost time.
I believe independent verification will return in some form because self-attestation alone has already demonstrated its limits. By 2036, I expect the federal supply chain to have a stronger system for protecting controlled unclassified information. I expect it to phase verification according to risk and capacity, recognize relevant commercial evidence, and make security matter in acquisition rather than only at a pass-fail gate.
The GovCon Enclave architecture that survived was the one that made secure operations repeatable enough for a small team to deploy, assess, and run at scale, not the one that produced the most compliance artifacts. CMMC’s machinery may change. That capability will keep compounding.
The contractors most likely to thrive are not the ones pretending July 13 changed nothing, nor the ones treating it as permission to abandon the work. They separate durable obligations from faltering machinery and keep investing in security work that pays off regardless of what the task force decides.
Joseph’s proposed epitaph called all his plans failures. From 1790, that is how it looked. From 2026, most of what he fought for is simply how Europe works. The epitaph mistook delay for defeat. The DIB should not make the same mistake in either direction: the obligations will outlast the machinery, and what the machinery decides is how long everyone waits for the protection, not whether it arrives.
Sources
- German History in Documents and Images: Emperor Joseph II’s Patent on Serfdom (1781)
- German History in Documents and Images: Joseph II’s Taxation and Urbarial Patent (1789)
- German History in Documents and Images: Leopold II’s Profession of Political Principles (1790)
- Library of Congress Country Studies: Hungary under enlightened absolutism
- Department of War Chief Information Officer: CMMC suspension and current program status
- U.S. Small Business Administration: CMMC Phase II suspension, cost, and capacity estimates
- National Defense Magazine: Assessors report contract cancellations and layoffs after the CMMC pause
- U.S. Government Accountability Office: Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation
- U.S. Department of Justice: MORSECORP cybersecurity False Claims Act settlement
- The Cyber AB: Response to the 2026 CMMC reform request for information
- The Cyber AB: CMMC Code of Professional Conduct v2.0
- Federal Register: CMMC Program final rule
- Federal Register: DFARS final rule adding CMMC to contracts, effective November 10, 2025
- Federal Register: Proposed government-wide CUI rule