Main guide

CMMC After the Phase II Suspension: What Contractors Must Do Now (2026)

Last updated:

Quick answer: A Phase II suspension pauses or reshapes parts of the certification rollout calendar—it does not erase DFARS cyber obligations, the need for an honest NIST SP 800-171 self-assessment, or the risk of signing an indefensible SPRS score. Contractors should keep a living SSP, a defensible score, and a clear CUI scope while policy details settle.

Key takeaways

  • Suspension is not a free pass on safeguarding CUI or reporting SPRS scores when contracts require them.
  • Self-assessment quality and signature risk matter more—not less—when formal certification timelines wobble.
  • Use the pause to fix optimistic scoring, evidence gaps, and SSP drift before enforcement windows return.
  • Track primary sources (DoD / 48 CFR / Task Force outputs) rather than rumor chains.

Why this guide exists

After a major CMMC policy jolt, a lot of advice online is recycled and slow to update. This page is a living map of what still binds you, what changed in practice, and how to stay defensible while formal pathways move—written for small and mid-size subcontractors, not enterprise GRC teams.

What a “Phase II suspension” is (and is not)

Is: a disruption to the expected cadence of CMMC Level 2 certification enforcement / pathway assumptions that many contractors planned around.

Is not: automatic relief from:

  • DFARS clauses that already require safeguarding covered defense information and cyber incident reporting
  • Contractual requirements to implement NIST SP 800-171
  • SPRS score submission when the solicitation or contract says so
  • Downstream prime flow-downs that still expect a score and a story

If your business development team heard “CMMC is paused, so we can ignore cyber,” correct that narrative in writing.

The posture that still wins: defensible self-assessment

Whether the near-term path emphasizes self-assessment, C3PAO certification, or a hybrid, one constant remains: someone may have to stand behind a score.

That is the DefensibleScore wedge:

  1. Accuracy — controls marked implemented are actually implemented.
  2. Evidence — you can show it without theater.
  3. Scoring integrity — weights and POA&M rules are applied correctly.
  4. Signature courage — a knowledgeable person can sign without inventing maturity.

If any of those four fail, the number in SPRS is a liability, not an asset. Read Your SPRS Score & the False Claims Act before anyone signs.

What to do now (practical sequence)

1. Freeze fantasy, inventory reality

Document in-scope systems, users, locations, and CUI entry/exit points. Unknown scope is the root of optimistic scoring.

2. Align the SSP with operations

Your System Security Plan should describe the environment you run—not the environment you wish you had next fiscal year. See Is Your SSP CUI?.

3. Re-score with discipline

Walk how to calculate your SPRS score and challenge every high-weight “implemented.”

4. Separate “still required” from “cert path”

Use Is CMMC still required after the suspension? for a plain yes/no, then map your contracts.

5. Know self-assessment vs C3PAO

Self-assessment vs. C3PAO explains what the suspension shifted in practice—and what remains your job either way.

6. Plan Rev 2 → Rev 3 without panic

NIST 800-171 Rev 2 vs Rev 3 keeps transition anxiety from becoming endless rewrites.

7. If you are local to East Tennessee

National tools do not show up on-site in the Tri-Cities. See CMMC help in the Tri-Cities & East Tennessee.

Alphabet soup?

Plain definitions of SPRS, CUI, C3PAO, POA&M, DFARS, and more: CMMC & DFARS glossary.

Need Page
Yes/no: still required? Is CMMC Still Required?
SPRS still needed? Do I Still Need a SPRS Score in 2026?
Signature risk SPRS & the False Claims Act
Scoring mechanics How to Calculate Your SPRS Score
Assessment path Self-Assessment vs C3PAO
SSP depth Is Your SSP CUI?
Baseline shift Rev 2 vs Rev 3
Local help East Tennessee CMMC
Free check Defensibility Check

How we stay current

Policy details move. When Task Force outputs, rulemakings, or DoD guidance shift the ground truth, this guide gets a new Last updated date and revised sections. Prefer primary sources over social media summaries.

Next action

Run the free SPRS Score Defensibility Check—a short check (no CUI required) that surfaces optimism and signature risk before you invest in a full remediation cycle.

Frequently asked questions

Did the Phase II suspension cancel CMMC?

No. Treat a suspension as a change to timing and pathway details, not a repeal of cybersecurity expectations for covered contractors. Confirm current rule text and your contract clauses.

Do I still need a SPRS score?

If your contracts or solicitations require a current NIST SP 800-171 assessment score in SPRS, that obligation is independent of marketing headlines about Phase II. See our guide on whether you still need a SPRS score in 2026.

What should I do first during the pause?

Re-validate scope and CUI flows, rebuild an honest self-assessment with evidence, fix scoring math, and only then decide what you can sign. Run a free non-CUI Defensibility Check to surface optimism risk.

This page is readiness and advisory guidance only. It is not legal advice, a certification, or a substitute for a formal NIST SP 800-171 / CMMC assessment. CUI designation is driven by government requirements and contract language—not by this site.