CMMC Phase II is suspended. Obligations are not.

 

On July 13, 2026, the Department of War suspended the third-party certification requirement planned for November. But DFARS and NIST 800-171 obligations remain fully in force, making accurate self-attestation more important than ever. CSS helps you build and maintain a defensible, audit-ready posture.

CMMC Phase II Status
Paused
Verification step

Third-Party Certification

Phase II and mandatory C3PAO certification as a condition of award are currently on hold.

Active Today
Binding obligations

Your Requirements Remain

  • DFARS 252.204-7012
  • NIST SP 800-171 controls
  • Phase 1 self-assessments
  • SPRS score and annual affirmation

First, the facts - without the noise

The suspension is real, but narrower than the headlines suggest. What paused is who checks your homework. What did not pause is the homework.

STILL IN EFFECT

Binding today

  • DFARS 252.204-7012 — safeguard covered defense information and report incidents within 72 hours
  • NIST SP 800-171 Rev. 2 — all 110 security requirements
  • Phase 1 self-assessments for Level 1 and Level 2 Self
  • Your SPRS score and annual senior-official affirmation
  • Select government-led DIBCAC assessments

ON HOLD

Pending the 60-day review

  • The November 10, 2026 move to Phase II
  • Mandatory C3PAO Level 2 certification as a condition of award
  • DIBCAC Level 3 certification designations

The pause raises your risk - it doesn’t lower it

With third-party auditors out of the loop, the government relies more heavily on what you self-certify. That isn’t a loophole – it’s exposure.

1. False Claims Act Liability Is Still Rising

Knowingly posting an inflated SPRS score or affirming compliance you haven’t achieved can trigger False Claims Act liability, including 3× damages, penalties and whistleblower claims.

In June 2026, a contractor settled for $507,144 after reporting a score of 110 that a later assessment scored at −170.

If you receive Conditional Level 2 Self status, remaining items must be closed within 180 days of the conditional date.

Miss that deadline and your status expires. Knowing your real gaps and remediating them on schedule remains a present-day requirement.

Some Level 2 and Level 3 requirements may be removed from new solicitations, but subcontractors may still be contractually required by their prime to complete a third-party assessment.

Don’t assume the requirement disappeared. Confirm it with your prime or contracting officer.

We get you “good to go” - and keep you there

Four responsibilities. One defensible path forward.

You have four responsibilities right now. We handle each one through fixed-scope engagements, so you know the cost, deliverable and outcome before we begin.

1. Know Exactly Where You Stand

We assess your environment against all 110 NIST 800-171 controls and give you an honest, defensible score-not an optimistic guess.

You’ll know what is met, what is missing and what it will take to close the gaps.

2. Report It Right

We make sure your SPRS score is posted correctly and your senior-official affirmation is accurate and current.

What you certify to the government will be truthful, documented and audit-ready.

3. Close the Gaps on the Clock

We build a credible Plan of Action and Milestones, prioritize the controls that matter and drive remediation within the 180-day window.

We also handle the closeout self-assessment.

4. Finalize Your SSP

We make sure your System Security Plan reflects your real environment and stands up to scrutiny.

An SSP that matches reality becomes evidence—not a liability.

Cyber Security Solutions

All-in-One Compliance — one team covering CMMC, NIST 800-171, and DFARS requirements end to end.

Founded in 2015 by veterans. Based in Florida, USA.

We help defense contractors and suppliers achieve and maintain compliance — with the documentation and discipline to prove it. SPRS Score Validation brings that same defense-grade standard to the single number the government screens you on.

Validated vs. Unvalidated: What Changes

Most contractors are working off a number someone estimated once. Here’s what changes when it’s validated.

What We Look At An Unvalidated Score
01Scoring method Estimated Often optimistic, rarely re-checked Recalculated Control by control, DoD methodology
02Evidence per control Assumed “We think it's in place” Verified Each control matched to real evidence
03Alignment with your SSP Drifts Score and SSP slowly diverge Reconciled Score tied back to your SSP
04Support for annual affirmation None Official signs without proof Documented A basis the affirming official can rely on
05When gaps surface At assessment DIBCAC, or a whistleblower Before you post Found and prioritized first
06What you walk away with A number No paper trail A report Written, defensible findings

A Simple Path to Ready

From the first conversation to ongoing compliance, every step is clear, practical and defensible.

Free Readiness Consultation

Start with a clear picture of where you stand.

We review your contracts, CUI footprint, current SPRS score, SSP and open POA&M items—then map the most practical path to a defensible, audit-ready posture.

Fixed Scope · Clear Outcomes
Free Readiness Consultation
  1. 1
    Consult

    Understand your contracts, CUI footprint and current compliance posture.

  2. 2
    Assess

    Validate all 110 NIST 800-171 controls and identify every gap.

  3. 3
    Remediate

    Build your POA&M and close required items within the 180-day window.

  4. 4
    Finalize

    Align your SSP, SPRS score and senior-official affirmation with your real environment.

  5. 5
    Maintain

    Keep your documentation and compliance posture audit-ready as requirements evolve.

Don’t wait for the deadline to come back.

Use this pause to close gaps, correct your SPRS score and finalize your SSP while there’s still time.

Talk to a CMMC readiness specialist

(813) 336-8175 ext. 1004

Ready to build a defensible posture?

Book Free Consultation →

Frequently Asked Questions

Clear answers about what the Phase II suspension does—and does not—change for your organization.

1. Does the suspension mean I can stop working on CMMC?

No. Phase 1 self-assessment requirements, DFARS 252.204-7012 and all 110 NIST 800-171 controls remain in effect. Only the third-party certification step is paused.

Not necessarily. Your prime may still contractually require a third-party assessment. Confirm the requirement with your prime or contracting officer rather than assuming it disappeared.

If your SPRS score and affirmation accurately reflect your environment, you are in a stronger position. If they may overstate your posture, validate and correct them before they are tested.

You can. A completed certification may still provide a market advantage. You can also pause and evaluate the review period based on your contracts and customer requirements.

Our core self-assessment validation and SSP finalization services are fixed-scope engagements. You will know the price, deliverables and expected outcome before work begins.