
The rumor is spreading: CMMC is dead.
That conclusion is wrong.
The Department of Defense has suspended the planned rollout of CMMC Phase 2 while it conducts a 60-day reform review. The pause may change certification timelines, assessment methods, and implementation milestones. It does not eliminate your existing cybersecurity obligations.
If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), you still need a defensible security program. You still need to understand your contract clauses. You still need to document your controls, maintain your assessment records, and protect the information entrusted to your organization.
The practical takeaway is simple:
CMMC certification requirements may be in flux. NIST 800-171 compliance, DFARS obligations, SPRS requirements, and prime contractor flow-downs have not disappeared.
Understand What the Phase 2 Suspension Changed
The Phase 2 suspension changes the immediate certification landscape.
During the review, the DoD has paused the broad implementation of third-party CMMC Level 2 certification requirements. That means many contractors may not need to complete a C3PAO assessment before the previously anticipated Phase 2 milestones.
The pause generally affects:
- The planned transition to widespread C3PAO Level 2 assessments.
- Future CMMC implementation milestones during the review.
- The ability of program offices to impose suspended third-party certification requirements in new solicitations.
- The timing and structure of future CMMC assessments.
The suspension does not mean that DoD contractors can stop securing CUI systems.
It also does not automatically invalidate requirements already included in your contracts, subcontracts, policies, or customer agreements. Review the exact clauses in each contract and solicitation. Requirements vary based on the type of information you handle, the role you perform, and the contract language that applies.
Read the DoD’s CMMC suspension announcement and monitor official updates as the review progresses.
Maintain the Obligations That Still Apply
Implement NIST SP 800-171 Controls
DFARS 252.204-7012 still requires contractors to provide adequate security for covered contractor information systems. For many systems handling CUI, that means implementing the security requirements in NIST SP 800-171.
NIST SP 800-171 defines security requirements for protecting CUI in nonfederal systems and organizations. The requirements cover areas such as:
- Access control.
- Awareness and training.
- Audit and accountability.
- Configuration management.
- Identification and authentication.
- Incident response.
- Media protection.
- Risk assessment.
- System and communications protection.
- System and information integrity.
A CMMC pause does not pause these controls. If your environment stores, processes, or transmits CUI, you must continue addressing the risks in that environment.
Report Cyber Incidents Within 72 Hours
DFARS 252.204-7012 also includes cyber incident reporting obligations. Contractors must rapidly report qualifying cyber incidents to the DoD and support follow-up activities, including forensic analysis and preservation of affected media.
The clause defines “rapidly report” as reporting within 72 hours of discovering a cyber incident.
Review the full DFARS 252.204-7012 text with your legal and security teams. Confirm that your incident response plan identifies:
- Who decides whether an incident is reportable.
- Who has authority to submit the report.
- How your team preserves relevant evidence.
- How you coordinate with your managed service providers and cloud providers.
- How you notify the prime contractor or customer.
Complete Your SPRS Assessment
If you handle CUI under a DoD contract, treat your NIST 800-171 self-assessment and SPRS score as active compliance requirements.
The Supplier Performance Risk System, or SPRS, gives the DoD visibility into a contractor’s cybersecurity posture. Your score should reflect your actual implementation status. It should not be a number created without supporting evidence.
Maintain documentation for:
- The assessment methodology used.
- The systems and assets included in scope.
- The security requirements implemented.
- Requirements that remain partially implemented.
- The evidence supporting your score.
- The date of the assessment.
- The individual responsible for the assessment and affirmation.
Your contract, solicitation, and applicable CMMC requirements determine the specific assessment and affirmation schedule. Keep the score current and update it when material changes affect your environment.
Flow Requirements Down to Subcontractors
Prime contractors still need to manage cybersecurity across their supply chains.
DFARS 252.204-7012 requires applicable flow-down to subcontractors whose performance involves covered defense information or operationally critical support. A subcontractor may not be able to avoid requirements simply because the prime contractor does not yet need a third-party CMMC certificate.
Primes and subcontractors should confirm:
- Whether CUI or covered defense information reaches the subcontractor.
- Whether DFARS 252.204-7012 appears in the subcontract.
- Whether the subcontractor has completed the required self-assessment.
- Whether the subcontractor maintains an appropriate SPRS score.
- Whether incident reporting responsibilities are clearly assigned.
- Whether cloud service providers meet applicable requirements.
Scope Your CUI Environment Before You Remediate
Do not begin with a generic checklist. Begin with scope.
Identify where CUI enters your organization, where it is stored, who accesses it, how it moves, and which systems protect it. Include business processes, people, facilities, endpoints, applications, cloud services, and external providers.

Use this scoping process:
- Identify CUI and FCI. Review contract documents, markings, data repositories, email, file shares, collaboration platforms, and physical records.
- Map data flows. Document how information moves between your organization, customers, primes, subcontractors, cloud platforms, and users.
- Define the CUI enclave. Separate systems that handle CUI from systems that do not whenever practical.
- Inventory assets. List endpoints, servers, network devices, applications, accounts, service providers, and facilities within the assessment boundary.
- Assign ownership. Give each system and control an accountable owner.
- Validate the boundary. Make sure your proposed scope matches how employees and systems actually work.
A defensible boundary can reduce cost, simplify remediation, and improve assessment readiness. An inaccurate boundary creates risk regardless of whether Phase 2 is active.
Build the Documentation Auditors and Customers Expect
Technical controls require evidence. Policies alone will not demonstrate that your organization protects CUI.
Create or update your System Security Plan (SSP). An SSP describes your system boundary, system components, operating environment, security controls, responsible personnel, and implementation status.

Your SSP should connect your controls to your real environment. Avoid generic language that does not identify specific systems, roles, technologies, or procedures.
Also maintain a Plan of Action and Milestones (POA&M) for permitted gaps. A POA&M should identify:
- The unmet security requirement.
- The risk created by the gap.
- The planned remediation activity.
- The responsible owner.
- Required resources.
- Target completion date.
- Validation steps.
- Any interim protections.
A POA&M is not a substitute for implementing required controls. Use it to manage approved remediation work, not to postpone action indefinitely.
Train Employees to Protect CUI
Your employees remain a critical part of your security boundary.
Deliver role-based CUI training that explains what employees must do with sensitive information. Training should address:
- How to identify CUI and contract-related data.
- Where employees may store or transmit CUI.
- How to use multifactor authentication and approved devices.
- How to recognize phishing and social engineering.
- How to report suspected incidents.
- How to handle removable media and printed documents.
- What to do when a customer or subcontractor sends data through an unapproved channel.

Track attendance, completion, training content, and follow-up actions. Your records should demonstrate that training is an operating process, not a one-time compliance event.
Use the Pause to Get Audit-Ready
Waiting for the final reform outcome may appear cautious. In practice, it can increase your risk.
The DoD may revise certification timelines. It may adjust assessment procedures. It may clarify scoping requirements or modify how evidence is reviewed. None of those possibilities removes the value of implementing effective controls now.
Use the window to:
- Complete a CMMC readiness assessment.
- Improve your SPRS score based on verified evidence.
- Close high-risk NIST 800-171 gaps.
- Finalize your System Security Plan.
- Maintain a practical Plan of Action and Milestones.
- Test your incident response process.
- Train employees who handle CUI.
- Review subcontractor and cloud service provider obligations.
- Prepare for customer questionnaires and government-led assessments.
Companies that use the pause productively will be better positioned when the next requirements become effective. They will also be stronger candidates for new DoD work while less-prepared competitors struggle to document their security posture.
Follow This 2026 CMMC Readiness Checklist
Use this checklist to establish your next steps:
- Identify all FCI and CUI handled by your organization.
- Map CUI data flows across systems, people, facilities, and providers.
- Define and validate your CUI assessment boundary.
- Complete a CMMC readiness assessment against applicable requirements.
- Review DFARS 252.204-7012 and all applicable contract clauses.
- Implement and document NIST SP 800-171 controls.
- Develop or update your System Security Plan.
- Create a controlled Plan of Action and Milestones for permitted gaps.
- Calculate and validate your SPRS score.
- Complete required SPRS submission and affirmation activities.
- Deliver and document CUI training.
- Test cyber incident reporting and evidence preservation procedures.
- Confirm subcontractor flow-down and supplier responsibilities.
- Establish ongoing monitoring and review.
Get Expert Support for CMMC Compliance
CMMC is not dead. The certification path is changing, but the need to protect CUI is not.
Quad-B Systems helps DoD contractors move from uncertainty to an actionable compliance program. We provide CMMC gap analysis, detailed roadmaps, System Security Plan development, technical and procedural control implementation, CUI training, SPRS support, and ongoing monitoring.
Our team is trusted by more than 20 DoD contractors. We support you from assessment through long-term compliance maintenance.
Explore Quad-B Systems CMMC compliance services, or request a CMMC consultation to review your environment, current score, and next steps.
This article provides general information and is not legal advice. Review your specific contracts, solicitations, and obligations with qualified legal and compliance professionals.