Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

CMMC and NIST 800-171

What CMMC Is, and What Changed in July 2026

A common mistake is thinking that the suspension of CMMC Phase II third party certification means your obligations no longer apply. The Department of Defense still expects you to meet certain requirements, and the core elements of CMMC remain. It is important to be clear on what has shifted and what your business still needs to do.

What is CMMC and why does it matter?

CMMC stands for Cybersecurity Maturity Model Certification. It is a framework developed to ensure that companies handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) for the Department of Defense meet a set of cybersecurity standards.

The CMMC framework is structured into three levels:

  • Level 1 (Foundational): This level requires you to implement 17 practices to protect FCI. It aligns with FAR 52.204-21 and requires an annual self-assessment.
  • Level 2 (Advanced): This level covers 110 controls drawn from NIST SP 800-171 Rev 2, focused on protecting CUI. It applies to roughly 80,000 companies. Level 2 also requires an annual self-assessment and posting your score in the Supplier Performance Risk System (SPRS).
  • Level 3 (Expert): This highest level includes all 110 NIST SP 800-171 controls plus 24 enhanced controls from NIST SP 800-172. DIBCAC (the Defense Industrial Base Cybersecurity Assessment Center) conducts these assessments, and no plans of action and milestones (POA&Ms) are allowed.

Each control in Level 2 is broken down into specific assessment objectives, totaling 320 across all controls, and every objective must be met for a control to be considered satisfied.

What exactly changed with CMMC in July 2026?

On July 13, 2026, the Department of War suspended the Phase II requirement for third party certification by a CMMC Third Party Assessment Organization (C3PAO). This suspension is pending a 60 day strategic review, which has not yet reported. You should expect further guidance around mid September 2026.

What this means for you:

  • Suspended: The requirement for a C3PAO to certify your organization at Level 2 before contract award is on hold.
  • Not suspended: Everything else. DFARS 252.204-7012, your obligation to meet NIST SP 800-171 Rev 2, Level 1 and Level 2 self-assessments, SPRS posting, and the annual senior official affirmation remain fully in force. The Department of War has stated it will continue to enforce requirements through self-assessments and select government-led assessments.

It is important to be precise. Only the third party certification step is suspended. Your self-assessment, your documentation, and your executive affirmation are still required and subject to enforcement.

Does this suspension reduce my risk or obligations?

No, the suspension does not reduce your exposure or responsibilities. In fact, without a C3PAO acting as an independent assessor, your senior official’s signature on the annual affirmation is the only assurance the government receives. This increases your exposure under the False Claims Act if your score is inflated or your documentation is incomplete.

Recent False Claims Act settlements show the consequences of falsely certifying compliance. In one case, a contractor certified compliance but failed to scan and remediate known vulnerabilities. Another failed to implement required NIST SP 800-171 controls, used non-FedRAMP email, and had no SSP on file. A third failed controls and shared defense data with an unauthorized foreign entity, with the private equity owner named in the settlement. Liability can extend to primes, subcontractors, affiliates, and private equity owners. Whistleblowers have the ability to bring cases on behalf of the government.

What is required for a CMMC self-assessment?

For Level 1, you must complete a self-assessment of 17 practices and submit your score in SPRS. For Level 2, you must self-assess against all 110 NIST SP 800-171 controls and post your score in SPRS. You must also submit an annual affirmation signed by a senior official.

A self-assessment is more than a checklist. Each of the 110 controls is supported by specific assessment objectives, as detailed in NIST SP 800-171A. All objectives for a control must be met for it to be considered satisfied. Documentation must include a policy (defining intent), procedure (how you achieve it), and evidence (real, timestamped system artifacts). Documentation alone does not prove compliance, evidence must demonstrate actual execution.

Most companies in the defense industrial base have an average SPRS score of about 60, against the required 110 for full compliance. Fewer than half have completed their System Security Plan (SSP) or POA&M documentation.

How does CMMC scoping work?

CMMC scoping, as defined in 32 CFR 170.19(c)(1) Table 3, organizes your assets into five categories:

  • CUI Assets: These are assessed against all 110 controls.
  • Security Protection Assets: Assessed only against controls relevant to their function.
  • Contractor Risk Managed Assets: Undergo SSP review and a limited spot check. At Level 3, these must meet all CUI requirements.
  • Specialized Assets: Includes items like government furnished equipment, IoT, and test equipment. Only the SSP is reviewed.
  • Out of Scope Assets: Not assessed, but you must justify and document their separation.

When preparing for an assessment, you will need to provide a CUI flow diagram, a network boundary diagram, a physical site diagram, and an authorized user list.

What should I be doing now for CMMC compliance?

You must continue to perform your annual self-assessment and SPRS posting, maintain complete documentation, and ensure your senior official can confidently sign the annual affirmation. With the third party certification step suspended, your internal controls and documentation carry even more weight.

If you handle CUI, you should be working toward full implementation of all 110 NIST SP 800-171 Rev 2 controls. The required SPRS score for full compliance is 110. If you have not completed your SSP or your POA&Ms, you are not meeting requirements.

Common questions

Do I still need to do a CMMC self-assessment even though third party certification is suspended? Yes. The self-assessment and annual affirmation are still required, along with SPRS score posting.

Does the suspension mean the November 2026 certification deadline is gone? There is no November 2026 certification deadline at this time. The requirement for third party certification is suspended pending the Department of War’s review.

If I exaggerate my SPRS score, is there less risk now? No. With no third party assessor, the government relies entirely on your senior official’s affirmation. This increases your exposure under the False Claims Act for any misrepresentation.

Closing thoughts

The CMMC third party certification requirement is paused, but your responsibility to meet NIST SP 800-171 Rev 2 and document your compliance is unchanged. If you need help understanding your current status or closing gaps, the Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant delivered as services, covering all 110 NIST 800-171 controls for qualifying defense contractors. You can learn more at cybergrantsalliance.org/cmmc-gap-assessment-grant/.

At a glance

What the July 2026 CMMC suspension changed and what it left in placeWhat the 13 July 2026 suspension did and did not touchSuspended, pending reviewThe requirement that a C3PAOcertify Level 2 before award.A 60 day strategic review is running.A decision is expected aroundmid September 2026.That is one item. It is not the program.Still fully in forceDFARS 252.204-7012NIST SP 800-171 Rev 2Level 1 and Level 2 self assessmentsSPRS score postingAnnual senior official affirmationYour obligations did not pause.
What the July 2026 CMMC suspension changed and what it left in place
What the July 2026 suspension did and did not change
What the July 2026 suspension did and did not change

More on CMMC