ITAR, EAR & CMMC: What Two Days at the Northwest Compliance Conference Revealed
- Mihir Datar
- 2 days ago
- 5 min read
Securim was a proud sponsor of PNDC's Northwest Compliance Conference. Here's what stood out across two days of sessions, and a development that wasn't on any agenda.

Securim was proud to sponsor the Pacific Northwest Defense Coalition's Northwest Compliance Conference, held July 22–23 at Clackamas Community College near Portland, Oregon. Over two days in one packed conference room, we sat through sessions from the FBI, CISA, and a roster of firms, Dorsey & Whitney, Buchalter, Schwabe Williamson & Wyatt, Bank of America's GovCon team, Baker Tilly, Total Logistics Resource, and Holland & Knight, covering nearly every corner of the compliance landscape defense contractors operate in: CFIUS, ITAR, EAR, bid protests, sanctions, and CMMC.
Three regimes came up again and again, in session after session, from different angles: ITAR, EAR, and CMMC. Each got its own dedicated session — dual-use exports and ITAR §126.7, EAR enforcement case studies, and a full CMMC panel plus a procurement-reform deep dive — and each pointed toward the same underlying shift: compliance is becoming a continuous, cross-functional capability rather than a one-time filing or license.
One thing didn't make it onto any printed agenda, simply because of timing: just over a week before the conference opened, the Department of War paused a major piece of the CMMC rollout. It's worth its own section, because it changes what “CMMC-ready” means for contractors right now.
The CMMC Story Developing in the Background: Phase 2 on Pause
On July 10-13, 2026, about a week and a half before the conference — the Department of War suspended CMMC Phase 2: the requirement that contractors handling Controlled Unclassified Information (CUI) pass a third-party assessment through a Certified Third-Party Assessment Organization (C3PAO) before winning certain awards. That requirement had been set to start appearing in contracts on November 10, 2026. It's now on hold, pending a 60-day review by a newly formed CMMC Reform Task Force, with a report expected around mid-September.
The reasoning is straightforward. By the Department's own numbers, more than 100,000 companies in the Defense Industrial Base would eventually need a third-party assessment — but only around 100 accredited C3PAOs exist to perform them. A March 2026 GAO report had already warned that the compliance burden risked pushing small and mid-sized businesses out of the defense supply chain. The Small Business Administration publicly backed the suspension.
Here's the part worth repeating: this is a pause on who verifies your cybersecurity, not a pause on what you're required to do.
What's still fully in force:
Level 1 and Level 2 self-assessment obligations under existing contracts
DFARS 252.204-7012 and the underlying NIST SP 800-171 security baseline
Your annual affirmation and score submitted to SPRS (the Supplier Performance Risk System)
Your legal duty to actually protect CUI and Federal Contract Information (FCI)
And here's the twist that makes the pause more consequential, not less: with third-party verification off the table for now, self-attestation is the only enforcement mechanism left. DOJ's Civil Cyber-Fraud Initiative hasn't slowed down — contractors have settled False Claims Act cases into the millions of dollars over stale or inflated SPRS scores, including a settlement that closed just five weeks before the pause was announced.
CMMC isn't cancelled. The Task Force could recommend narrowing it, restructuring it, or reinstating the original timeline outright — any formal change still requires separate rulemaking under 32 CFR Part 170. The practical takeaway: treat this as a pause in the certification mechanism, not a pause in the underlying obligation. Contractors who keep their System Security Plans, POA&Ms, and SPRS scores genuinely current are the ones who'll be ready — whichever direction the Task Force lands.

Inside the Sessions: A Quick Recap
Day 1
Eric Atherley (FBI) and Zeina Boulos (CISA) opened the conference with a look at the current cyber threat landscape facing the Defense Industrial Base, both nation-state and criminal activity.
Larry Ward (Dorsey & Whitney) walked through CFIUS fundamentals, including how broadly “covered transaction” now reaches, even passive minority investments can trigger review when critical technologies or sensitive data are involved.
The CMMC panel, moderated by Jerry Leishman (CMMC Advisors) with Jonathan Wolff, Raj Sidhu, and John Nolan, covered the practical realities of certification from the perspective of assessors and compliance leads actively working with contractors.
Kripa Upadhyay (Buchalter) tackled dual-use exports and ITAR head-on, opening with the single most expensive assumption in the room: “we only sell to U.S. primes, so export controls don't apply to us.” Her session made clear that sharing a drawing with a foreign-national engineer inside the U.S. is a “deemed export”, no border crossing required.
Paige Spratt, Chris Slottee, and Matt Berry (Schwabe Williamson & Wyatt) covered federal bid protests in a changing landscape, including the FAR Overhaul's new pleading standards and pilot programs that could make unsuccessful protesters pay the government's costs.
Andrew McAllister (Holland & Knight) closed Day 1 with EAR fundamentals and a notable enforcement case study — a recent DOJ declination where a major manufacturer avoided criminal prosecution entirely after a voluntary self-disclosure, full cooperation, and timely remediation.
Day 2
Erin Olenjack (Bank of America) opened with a banker's perspective on government contracting compliance — a reminder that compliance posture increasingly factors into financing and lending relationships, not just contract awards.
Tiffany Hixson (Baker Tilly) covered federal procurement reform and compliance priorities, including the CMMC certification timeline and how it intersects with the broader FAR Overhaul.
Tia Sandberg (Total Logistics Resource) presented on AUKUS and ITAR modernization, making the case that the new §126.7 exemption doesn't reduce compliance — it rewards companies that can already prove classification discipline and technical-data governance. “Less licensing” was explicitly framed as “not less compliance.”
Jessica Rhee (OFAC) discussed sanctions compliance and screening obligations.
The conference closed with an “Ask the Lawyers” panel Steven Weigler (Buchalter), Larry Ward (Dorsey & Whitney), and Chris Slottee (Schwabe) fielding audience questions across the full range of topics covered over the two days.

The Common Thread
Across CFIUS, ITAR, EAR, bid protests, and CMMC, the same message came through: the government is leaning harder on self-policing, and rewarding contractors who can prove — with real evidence, that their compliance program is a living process rather than a paper file. That's true whether the audit in question is a C3PAO assessment, a DDTC review of an ITAR §126.7 transfer, or a self-reported SPRS score.
Where We Can Help and Where We'll See You Next
As a conference sponsor, we're offering PNDC members and conference attendees a complimentary Level 1 compliance check — a straightforward way to get an honest read on where your program actually stands right now, independent of whichever direction the CMMC Reform Task Force ultimately lands. If it's been a while since your posture got a genuinely fresh look rather than a re-signed affirmation, this is a good place to start.
We're also looking forward to catching up with many of you again at PNDC's upcoming Summer Bash: register here. It's always one of our favorite events on the PNDC calendar, and we'd love to see you there.

