In July of 2026, the Department of War (DoW) announced a suspension of CMMC Phase 2 requirements in order to launch a comprehensive review of the program. The suspension has created new questions across the Defense Industrial Base about what comes next. But it did not eliminate the cybersecurity requirements defense contractors are responsible for meeting today.
During this pause, CMMC Phase 1 still remains in effect--including level 1 and level 2 self-assessment requirements. For contractors handling Controlled Unclassified Information (CUI), NIST SP 800-171 Rev. 2 requirements also remain in place underDFARS 252.204-7012. In other words, the CMMC program may be under review, but protecting CUI and being able to demonstrate compliance have not been put on hold.
What has NOT Changed: Your Self-assessment Still Matters
The CMMC Phase II suspension did not suspend Phase I self-assessment requirements. Level 1 organizations must complete an annual self-assessment, while organizations subject to CMMC Level 2 (Self) must complete a self-assessment every three years. Both require an affirmation of continued compliance, with Level 2 requiring that affirmation annually after the assessment. Assessment results and affirmations are entered into the Supplier Performance Risk System (SPRS).
This means that the accuracy of your self-assessment is important. An organizations SPRS score is not just an internal measure of an organization's compliance posture. When a contract requires an applicable CMMC level, a current CMMC status and affirmation in SPRS can be conditions of contract award. A self-assessment should therefore reflect what is actually implemented in your environment today. Contractors should be prepared to support their reported status with documentation and evidence rather than treating the assessment as a checklist or an estimate of where they expect to be in the future.
The Government May Check Your SPRS Score
However, submitting a self-assessment does not mean the score will never be checked. SPRS assessment scores are available to authorized DoD personnel, giving the government visibility into the cybersecurity posture contractors have reported. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) can, at any time, conduct an audit on your organization against NIST SP 800-171 requirements. That is why your SPRS score needs to be accurate and defensible. The score you report should align with your SSP, supporting evidence, and the security controls actually implemented within your environment.
The False Claims Act
Accuracy also matters from a legal perspective. Knowingly misrepresenting your cybersecurity compliance, including submitting an inaccurate or unsupported SPRS score, can create potential liability under the False Claims Act. Recent DOJ enforcement actions reinforce the importance of making sure your reported compliance posture matches what is actually implemented in your environment.
Is Your Company Prepared for a Self-assessment?
A defensible self-assessment requires more than reviewing the NIST SP 800-171 requirements and assigning a score. Your organization should be able to demonstrate how those requirements are implemented within your environment and support your assessment with accurate documentation and evidence.
Evidence Based Scoping
Your score should reflect what is implemented today. Each requirement you claim as implemented should be supported by appropriate evidence demonstrating how the requirement is being met. A control that is planned or still being implemented should not be treated the same as one that is fully implemented.
System Security Plan (SSP)
Your SSP should accurately describe your current environment, including your system boundaries and how NIST SP 800-171 requirements are implemented. As systems, processes, or configurations change, the SSP should be updated so it continues to reflect your actual environment.
Plan of Action and Milestones (POAM)
When permitted, a POA&M should clearly document remaining deficiencies, planned remediation activities, responsibilities, and completion dates. Under the current CMMC Level 2 (Self) requirements, POA&Ms are permitted only within defined limits and must be closed within 180 days.
Continuous Monitoring
Compliance does not end when the self-assessment is submitted. Organizations need to maintain the security practices, documentation, and technical controls supporting their assessment as their environment changes. Maintaining compliance helps ensure that the posture represented in SPRS continues to align with the organization's actual security environment.
DFARS 252,204-7012 is Still Active
While CMMC Phase II has been suspended, DFARS 252.204-7012 remains an active contractual requirement. For covered contractor information systems, the clause requires contractors to provide adequate security and, where applicable, implement NIST SP 800-171 requirements to protect Covered Defense Information (CDI).
DFARS 252.204-7012 also includes requirements for reporting covered cyber incidents to DoD, protecting and preserving information following an incident, and meeting specific security requirements when external cloud service providers are used to store, process, or transmit covered defense information.
The CMMC timeline may be changing, but the underlying responsibility to safeguard sensitive DoD information has not gone away. Contractors should continue treating DFARS 252.204-7012 and NIST SP 800-171 compliance as active contractual obligations.
Prime Contractors Will Still Require Compliance
Despite the pause, many prime contractors including Lockheed Martin, Boeing, and L3 Harris have reaffirmed their enforcement of NIST 800-171 requirements across their supply chain. Depending on the contract and the information being shared, subcontractors may be required to demonstrate their cybersecurity and compliance posture before receiving an award. This can include maintaining the appropriate CMMC status, completing required affirmations, and providing evidence that applicable security requirements are being met.
What Should Contractors Do Now?
The CMMC Phase II suspension provides contractors with additional time, but it should not be viewed as a reason to pause cybersecurity or compliance efforts. Instead, contractors should use this time to strengthen their current security posture and make sure their self-assessment accurately reflects what is implemented within their environment.
-
Validate your SPRS score: Review your self-assessment and make sure the score is accurate, current, and supported by evidence.
-
Strengthen NIST 800-171 Implementation: Identify remaining gaps and continue implementing the security requirements applicable to your environment.
-
Update your SSP and POAM: Make sure documentation reflects your current environment and that outstanding remediation items are actively being addressed.
-
Prepare for additional scrutiny: Be ready to provide documentation and evidence if your cybersecurity posture is reviewed by the government or requested by a prime contractor.
-
Continue building toward CMMC readiness: Use the additional time to strengthen your security and compliance program so your organization is prepared as CMMC requirements continue to develop.
How CorpInfoTech Can Help
Whether you are completing a CMMC self-assessment, strengthening your NIST SP 800-171 implementation, or preparing for future CMMC requirements, CorpInfoTech helps defense contractors build and maintain a secure, defensible compliance program. As your partner from CMMC readiness through continuous compliance, CorpInfoTech guides organizations through our five-step compliance roadmap:
Define – Determine your CMMC scope, CUI boundary, and compliance strategy.
Assess – Evaluate your current environment and identify compliance gaps.
Implement – Remediate gaps and implement the required NIST SP 800-171 security controls.
Validate – Prepare your documentation, evidence, and organization to demonstrate that requirements are implemented and operating as intended.
Maintain – Sustain continuous compliance through ongoing monitoring, management, and managed compliance services.
Stay the course on compliance. If you need help evaluating your current NIST SP 800-171 implementation or determining whether your organization is prepared for its self-assessment, contact CorpInfoTech to review your CMMC readiness plan.
Key Takeways
-
CMMC Phase II may be suspended, but compliance is not. Phase I self-assessment requirements remain in effect.
-
Your SPRS score needs to be accurate and defensible. Your reported score should align with your SSP, supporting evidence, and the controls actually implemented in your environment.
-
DFARS 252.204-7012 remains an active contractual requirement. Contractors must continue protecting covered defense information and meeting applicable cybersecurity obligations.
-
Prime contractor expectations still matter. Subcontractors should understand the cybersecurity and compliance requirements associated with their specific contracts and supply-chain relationships.
- Submitting an inaccurate or unsupported SPRS score can trigger False Claims Act liability — your reported compliance must match what’s actually implemented in your environment.

CorpInfoTech, a Managed Service Provider (MSP) with over 25 years in the SMB space, is a trusted partner for business pursuing compliance and cybersecurity. We are a CMMC Level 2 certified MSP and a Cyber AB Registered Provider Organization (RPO). Also, as the first CIS accredited organization, we help organizations implement the CIS controls as it pertains to CMMC and your overall cybersecurity posture. CorpInfoTech is your trusted partner for secure, compliant growth in every changing digital landscape.
