The Department of War suspended CMMC Phase 2 on July 13, 2026. Third-party certification requirements are on hold pending a 60-day review by the new CMMC Reform Task Force. Self-attestation is not.
Sera Brynn writes this as an Authorized C3PAO (CyberAB CPN 59175), one of the organizations the CMMC ecosystem designated to conduct the certification assessments now on hold. We have advised Defense Industrial Base contractors on federal cybersecurity requirements since 2011, through the original DFARS 7012 rollout, the 2021 CMMC overhaul, and now this suspension. The pattern below is one we have watched before.
Phase 1 remains in full force. Contractors handling Federal Contract Information or Controlled Unclassified Information must still conduct NIST SP 800-171 self-assessments, submit scores to the Supplier Performance Risk System (SPRS), and file annual affirmations signed by a senior company official. The July 10 memorandum from DoW CIO Kirsten Davies suspends the transition to third-party assessments. It changes nothing about what you attest to today.
The Pause in Five Points
- CMMC Phase 2 is suspended. NIST SP 800-171 is not.
- DFARS 252.204-7012, 7019, and 7020 remain in your contracts and require implementation, current SPRS scores, and government audit rights.
- Annual affirmations carry False Claims Act exposure, signed by a named executive.
- The 2021 pause produced CMMC 2.0 with NIST 800-171 intact. Expect the same foundation this time.
- Contractors who maintain accurate self-assessments through the review enter the next phase ahead of those who stop.
Your Contract Clauses Predate CMMC
DFARS 252.204-7012 has required contractors to implement NIST SP 800-171 since 2017. DFARS 252.204-7019 and 7020 require current SPRS scores and grant the government audit rights. These clauses sit in your contracts now, independent of the CMMC rollout, and the suspension memo leaves them untouched.
CMMC was never the source of the obligation. It was the verification mechanism. Removing the verifier does not remove the requirement.
Self-attestation carries personal and corporate liability. Every SPRS score and annual affirmation is a representation to the federal government. The Department of Justice's Civil Cyber-Fraud Initiative has pursued False Claims Act cases against contractors whose cybersecurity representations did not match their implementation. Settlements have reached into the millions, and whistleblower provisions give insiders a financial incentive to report gaps.
The affirmation requirement raises the stakes. A named executive signs it. An inflated SPRS score is no longer a paperwork problem. It is a false statement with a signature attached.
The suspension arguably increases this exposure. With third-party assessments paused, self-attestation is the only compliance signal the government receives. Certifications relieve pressure on contractors from the perspective of assurance during bidding processes. The concept that a business may win a contract and be fast-tracked to do business is still very much alive during this period. Certifications also serve as a component similar to insurance: having a third party review and state that your system is compliant staves off the potential ramifications of the False Claims act for businesses.
The Review Window Rewards Contractors Who Keep Moving
The Reform Task Force reports within 60 days. The department has stated that cybersecurity remains essential and that the review targets administrative burden, not the underlying standard. NIST SP 800-171 is the floor in every likely outcome.
Contractors who treat the pause as a stopping point will restart from behind when requirements return in revised form. Contractors who maintain accurate SPRS scores, current System Security Plans, and disciplined POA&M management enter the next phase ready to compete for awards while others scramble.
Primes have not paused either. Flow-down requirements and supplier scrutiny continue regardless of DoW's certification timeline. An accurate, current self-assessment answers the questions your primes are asking now.
What Accurate Self-Attestation Requires
An SPRS score is only as strong as the assessment behind it. That means scoring all 110 controls against the DoD Assessment Methodology, documenting implementation in a System Security Plan, and tracking open items in a Plan of Action and Milestones with realistic completion dates. Scores must be refreshed when your environment changes, not just when a contract requires it.
Sera Brynn conducts NIST SP 800-171 gap assessments that give leadership an accurate picture of where implementation stands and what their SPRS submission should reflect. As an Authorized C3PAO, we apply the same assessment discipline the certification regime was built on.
The pause is a policy review, not an amnesty. The contractors who win the next phase are the ones whose attestations were accurate through this one.
Verify Your Score Before the Government Does
An SPRS submission you cannot support is a liability. An accurate one is a competitive asset for doing business today and a head start on whatever verification model follows the review.
Sera Brynn conducts NIST SP 800-171 gap assessments using the same methodology we apply as an Authorized C3PAO. Leadership receives a control-by-control view of implementation, a validated basis for your SPRS score, and a clear picture of what your next affirmation represents.
Schedule a gap assessment consultation or contact our team at info@serabrynn.com.
Frequently Asked Questions
Did the CMMC suspension eliminate NIST 800-171 requirements?
No. NIST SP 800-171 implementation remains a contractual requirement under DFARS 252.204-7012, which has been in effect since 2017. The July 2026 suspension paused third-party certification, not the underlying standard. Self-assessments, SPRS score submissions, and annual affirmations under CMMC Phase 1 continue unchanged.
Has CMMC been paused before?
Yes. The Department of Defense suspended the original CMMC program in March 2021 and conducted an internal review that ran eight months. The result was CMMC 2.0, announced in November 2021, which cut the model from five levels to three and aligned Level 2 directly with the 110 controls of NIST SP 800-171. The 2021 review reduced administrative structure but kept NIST 800-171 as the foundation. Contractors who continued implementation through that pause entered the 2.0 era ready. Contractors who stopped restarted years behind, and the 2026 review is following the same pattern: the department has targeted burden reduction, not the standard itself.
Do I still need to submit an SPRS score?
Yes. DFARS 252.204-7019 requires a current NIST SP 800-171 self-assessment score in SPRS before contract award, and Phase 1 affirmation requirements remain in force. Scores must reflect an assessment conducted within the last three years and should be updated when your environment changes.
Can the government still audit my self-assessment?
Yes. DFARS 252.204-7020 grants the government the right to conduct medium and high assessments of your NIST SP 800-171 implementation. The Department of Justice can also pursue False Claims Act actions against contractors whose SPRS scores or affirmations misrepresent their implementation. Both mechanisms operate independently of the CMMC certification timeline.
Should I cancel my C3PAO assessment preparation?
Preparation completed for a Level 2 certification maps directly to the self-assessment obligations still in force. Your System Security Plan, control implementation, and POA&M discipline support accurate SPRS scoring today and position you for whatever verification model emerges from the 60-day review. The 2021 precedent suggests requirements return in revised form rather than disappear.
What happens after the 60-day review?
The CMMC Reform Task Force will deliver findings and recommendations to DoW leadership, informed by industry feedback gathered through a public Request for Information. The department has stated that cybersecurity remains essential to the Defense Industrial Base. No timeline for a revised program has been announced, and contractors should watch for updated rulemaking following the report.
