Guide

Is CMMC Still Required After the Suspension?

Last updated:

Quick answer: Yes—cybersecurity requirements tied to DFARS, NIST SP 800-171, and contract language still apply for covered work. A Phase II suspension changes certification timing and pathway details; it does not mean “CMMC is optional” or that primes will stop asking for SPRS scores and safeguarding evidence.

Key takeaways

  • Separate news headlines from the clauses in your contracts and solicitations.
  • SPRS reporting and 800-171 implementation often continue even when certification phases shift.
  • Use any pause to improve defensibility, not to discard the program.

Short answer

For most defense contractors in the CMMC conversation: yes, you still need to take cybersecurity requirements seriously. Suspension news does not delete:

  • Contract clauses you already accepted
  • Flow-downs from primes
  • Expectations to safeguard CUI
  • Requests for a current assessment score in SPRS

If someone claims “CMMC is dead, stop spending,” ask them which clause number disappeared from your contract.

How to decide for your company

Work through these questions in order:

  1. Do we handle or create CUI (or covered defense information) under DoD work?
  2. Which DFARS / solicitation cyber clauses apply to active and upcoming awards?
  3. Do primes require a SPRS score, SSP excerpts, or CMMC status affidavits today?
  4. Is our current score something a knowledgeable person can sign?

Questions 1–3 are legal/contractual. Question 4 is operational—and where most small contractors get hurt. See SPRS & the False Claims Act.

Suspension vs. obligation

Topic Often still required Changed by Phase II headlines
Safeguard CUI / follow 800-171 Frequently yes Wording and audit path may evolve
SPRS score when solicited Often yes Timing pressure may shift
Third-party certification windows Pathway-dependent Most likely area of “suspension” impact
Honest self-assessment Always good practice Becomes more important when calendars slip

For the full map, return to the main guide: CMMC after the Phase II suspension (2026).

What “still required” should trigger

  • Refresh system scope and CUI data flows
  • Reconcile SSP to reality
  • Re-calculate SPRS with correct weights (guide)
  • Challenge optimistic control marks with evidence
  • Document POA&Ms that are real, owned, and dated

Free next step

Use the Defensibility Check for a quick read on whether your current story holds. Then read the main suspension guide and the False Claims Act page if scores are signed or about to be.

Frequently asked questions

Is CMMC canceled?

No. Treat suspension language as a schedule/pathway change unless an official repeal says otherwise. Always verify against current DoD rule text and your awards.

Can I stop working on NIST 800-171?

Stopping is risky if you handle CUI or have DFARS cyber clauses. Implementation expectations typically remain even when third-party certification timing moves.

What is the fastest useful action this week?

Confirm contractual cyber requirements, validate your SPRS posture, and run a free defensibility check (no CUI required) before anyone re-signs a score.

This page is readiness and advisory guidance only. It is not legal advice, a certification, or a substitute for a formal NIST SP 800-171 / CMMC assessment. CUI designation is driven by government requirements and contract language—not by this site.