CMMC and NIST 800-171
After the Suspension: What You Still Have to Do
The CMMC self-assessment process is still a requirement for defense contractors, even after the Department of War suspended the third-party certification mandate on July 13, 2026. While you no longer need a C3PAO to certify at Level 2 before award, everything else about CMMC, NIST SP 800-171 Rev 2, and DFARS 252.204-7012 remains in force. If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), your obligations did not get any lighter. In fact, with no third party between you and the government, your senior official’s annual affirmation now carries even more legal risk.
What does the CMMC suspension actually change?
The only thing that changed is the requirement for a C3PAO (Certified Third Party Assessor Organization) to certify your CMMC Level 2 compliance before contract award. This requirement was suspended by the Department of War, effective immediately, pending a 60-day review. As of now, you are not required to schedule or pay for a third-party assessment to win new contracts. However, DFARS 252.204-7012, NIST SP 800-171 Rev 2, self-assessments for both Level 1 and Level 2, posting your score in the Supplier Performance Risk System (SPRS), and the annual senior official affirmation are all still required and enforceable.
What CMMC self-assessment obligations do you still have?
You are still required to perform a CMMC self-assessment if you handle FCI or CUI. For Level 1 (Foundational), this means meeting 17 practices aligned to FAR 52.204-21, with an annual self-assessment. For Level 2 (Advanced), you must implement all 110 controls from NIST SP 800-171 Rev 2. These controls are grouped under 14 families, including Access Control, Awareness and Training, Audit and Accountability, and others. The required SPRS score for full compliance is 110.
Each of the 110 controls has multiple assessment objectives, totaling 320 across all controls (NIST SP 800-171A). You must meet every objective under a control to mark that control as MET.
For full context, Level 3 (Expert) is assessed by DIBCAC, and no Plan of Actions and Milestones (POA&Ms) are permitted at that level, but most small and mid-sized companies in the defense supply chain are focused on Level 1 or Level 2.
How do you scope your CMMC self-assessment?
Scoping determines which assets are subject to assessment. According to 32 CFR 170.19(c)(1) Table 3, there are five asset categories:
- CUI Assets: Assessed against all 110 controls.
- Security Protection Assets: Assessed against controls relevant to their function.
- Contractor Risk Managed Assets: Subject to SSP review and spot checks. At Level 3, these are treated as CUI Assets.
- Specialized Assets: Includes government-furnished equipment, IoT, operational technology, and test equipment. SSP review only.
- Out of Scope Assets: Not assessed, but you must be able to justify their separation from the in-scope environment.
When preparing for an assessment, you should be able to provide a CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and an Authorized User List. These artifacts help demonstrate your scoping decisions.
What are the documentation and proof requirements?
Documentation is necessary but not sufficient. Policy defines your intent, procedure describes how you achieve it, and evidence proves execution through timestamped, system-generated artifacts. Assessment validates that your implementation matches your documentation. Remember, documentation alone does not count as proof.
Fewer than half of companies have completed their System Security Plan (SSP) or POA&M documentation, according to the available data. The average SPRS score across the defense industrial base is about 60, well short of the required 110 for Level 2.
What are the legal risks of CMMC self-assessment after the suspension?
With the third-party assessor requirement suspended, your annual affirmation by a senior official is the primary assurance the government receives. This increases your exposure under the False Claims Act if you submit an inflated SPRS score or falsely claim compliance.
Recent False Claims Act cases show the risks:
- Health Net Federal Services falsely certified compliance and failed to scan and remediate known vulnerabilities.
- MORSECORP failed NIST SP 800-171 controls, used non-FedRAMP email, and had no SSP on file.
- Aero Turbine failed controls and shared defense data with an unauthorized foreign entity. In this case, the private equity owner was included in the settlement.
Liability can extend to primes, subcontractors, affiliates, and even private equity owners. Whistleblowers can file qui tam actions on behalf of the government. In short, if your self-assessment does not match your actual security posture, your senior official is exposed to real legal risk.
How do you post your SPRS score and complete the annual affirmation?
You must calculate your score based on the number of NIST SP 800-171 controls fully implemented. The maximum score is 110. Partial implementation does not count, each assessment objective must be met.
Once you have completed your self-assessment, you post your score to the Supplier Performance Risk System (SPRS). You must also submit an annual affirmation, signed by a senior official, certifying the accuracy of your self-assessment and the information in your SSP. The Department of War has stated it will enforce compliance through self-assessments and select government-led assessments.
For more information on SPRS and DFARS requirements, see the Defense Pricing and Contracting official site.
What does this mean for your compliance planning and budget?
With the C3PAO requirement suspended, most companies will focus on self-assessment, remediation, and documentation. Budgeting for these activities is still necessary. Most mid-sized defense contractors spend between $200,000 and $500,000 in their first year to reach compliance. This includes gap assessment, remediation tools, documentation, consulting, and personnel. Even though you are not paying for a C3PAO assessment at this time, you should not reduce your compliance investment.
Common questions
Do I still have to comply with DFARS 252.204-7012 and NIST SP 800-171 Rev 2? Yes. These requirements remain fully in force. You must implement all applicable controls and complete annual self-assessments.
What happens if I exaggerate my SPRS score? If your self-assessment does not match reality, your senior official could face False Claims Act liability. Recent cases have targeted contractors and their owners for false claims and inadequate security.
Can I use a Plan of Actions and Milestones (POA&M) to defer controls? At Level 2, POA&Ms are allowed for some controls but do not reduce your obligation to close gaps quickly. At Level 3, no POA&Ms are permitted.
Update Your Cybersecurity Documentation Now
The CMMC self-assessment process remains a critical requirement for defense contractors. The temporary suspension of third-party certification has not reduced your obligations under DFARS and NIST SP 800-171 Rev 2. If you need help understanding your current posture or closing gaps, the Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant, delivered as services, covering all 110 NIST 800-171 controls for qualifying defense contractors. Learn more at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.
Stay focused on accurate self-assessment, thorough documentation, and ongoing remediation to keep your business eligible for defense contracts and protected from legal risk.