Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

What Type of CMMC Assessment Do You Need?

  • cmmc
  • What Type of CMMC Assessment Do You Need?

Last updated: July 2026. The DoD suspended CMMC Phase 2 requirements on July 13, 2026. This article has been updated to reflect the suspension.

The Cybersecurity Maturity Model Certification (CMMC) program defines three types of assessments: self-assessments, third-party assessments conducted by a Certified Third-Party Assessment Organization (C3PAO), and government-led assessments conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). As of July 13, 2026, the DoD has suspended the Phase 2 transition, and all new DoD solicitations may only require self-assessments. The C3PAO and government-led assessment tiers described in this article reflect the CMMC program's design under 32 CFR Part 170 and remain available voluntarily, but are not currently required by contract.

This overview explains how self-assessment works, how the program's initial assessment framework was designed to work, and what each type of assessment involves.

CMMC assessments overview

CMMC 2.0 introduces a tiered approach to evaluating the cybersecurity posture of the Defense Industrial Base (DIB). Each assessment type exercises a different level of oversight, depending on the sensitivity of the information you handle and your role in the DoD supply chain.

During the current program review, understanding all three assessment types still helps defense contractors plan effectively, build the right documentation, strengthen their security practices, and prepare for whatever assessment model the Reform Task Force recommends.

Self-assessment

  • Frequency: Level 1: annually. Level 2: every three years, with an annual affirmation.
  • Applicable to: All Level 1 contractors, and all Level 2 contractors in new DoD solicitations during the current program review

What It Involves:

A CMMC self-assessment is an internal review of your security practices against the security requirements for CMMC Level 1 or Level 2. Instead of having a C3PAO perform the assessment, your team is responsible for completing it internally. Your team is also responsible for documenting and reporting the results, along with an executive affirmation of compliance, in the Supplier Performance Risk System (SPRS) to achieve a current CMMC status. The DoD uses self-assessment results to verify that suppliers can protect sensitive unclassified information before awarding or renewing contracts.

The self-assessment team can use self-assessment tools provided by the DoD Chief Information Officer, including scoping and self-assessment guidance, to inform their evaluation.

1. Review of control implementation and documentation

During their assessment, the team will:

  • Review the System Security Plan (SSP), which outlines the specific security controls and practices the organization has implemented
  • Evaluate each requirement and its assessment objectives, recording findings as MET, NOT MET, or NOT APPLICABLE based on what is implemented today

For Level 1, all 15 requirements must be fully implemented. For Level 2, all 110 NIST SP 800-171 requirements and 320 assessment objectives apply.

2. Scoring of results

For Level 1, the self-assessment is scored as MET or NOT MET in its entirety. No numerical score applies.

For Level 2, each requirement is assigned a weighted value of 1, 3, or 5 points based on the potential adverse effect of not meeting it. Starting from a baseline of -203, you gain points for each MET requirement, producing an SPRS score between -203 and 110. A score of 110 indicates full implementation.

  1. Creation of POA&M for any unmet requirements (Level 2 only)

If your Level 2 self-assessment does not achieve a score of 110, any NOT MET requirements must be documented in a Plan of Action and Milestones (POA&M). Note that certain requirements cannot be placed on a POA&M, and your score must reach at least 88 to achieve Conditional Level 2 (Self) status. POA&M items must be remediated within 180 days of your conditional status date.

3. Signature of attestation of compliance

Once complete, a senior official (the Affirming Official) must sign an affirmation confirming the accuracy of the assessment and the organization’s compliance.

This affirmation must be entered electronically in the SPRS. For Level 1, the affirmation is submitted annually. For Level 2, the affirmation is submitted following each triennial self-assessment and annually thereafter.

4. Submission in SPRS

The score and affirmation are submitted to the Supplier Performance Risk System (SPRS). This score helps the DoD evaluate contractor readiness and gauge risk when awarding contracts. Prime contractors also use SPRS to verify that subcontractors have a current CMMC status before awarding subcontracts.

How to Prepare:

Successful self-assessments rely on accurate documentation, internal audits, and consistent security practices. You should maintain a complete SSP, perform periodic reviews of your controls, and ensure that authentication, safeguarding, configuration management, audit logging, and other core practices are functioning as intended.

Because a senior executive affirms the score you submit, that number needs to reflect what your environment can prove.

Recommended reading

CMMC Self-Assessment Guide: Level 1 and Level 2 Process

Read More

Third-party assessment: How it's designed to work

  • Frequency: Every three years, with annual affirmations
  • Applicable to: CMMC Level 2 contractors handling prioritized CUI (Level 2 C3PAO certification requirements are suspended in new DoD solicitations during the current program review)

What It Involves:

Under the CMMC program design, organizations that handle CUI critical to national security must complete an independent third-party assessment conducted by a Certified Third-Party Assessment Organization (C3PAO). Organizations must choose a C3PAO from the list of authorized assessment organizations provided by the Cyber AB.

This review evaluates whether your security measures and documentation meet the full set of NIST SP 800-171 Revision 2 requirements that support CMMC Level 2 certification.

The CMMC Level 2 assessment process is more comprehensive than self-assessments and is broken down into four phases.

Phase 1: The Pre-Assessment

The C3PAO will review the SSP, validate scope, confirm availability of evidence, and make readiness determination if OSC should proceed to next phase.

Phase 2: Assess Conformity to Security Requirements

The C3PAO will conduct a detailed review of your cybersecurity practices and documentation, including the SSP, POA&M, access control policies, risk mitigation plan, incident response procedures, configuration management plan, separation of duties matrices, and evidence supporting each implemented control. They may conduct interviews, analyze logs, evaluate technical configurations, and review your vulnerability remediation history.

Following the review, the C3PAO provides preliminary findings to identify any gaps or issues. If any Level 2 requirements were partially implemented or not implemented, this report will include recommended corrective actions.

Phase 3: Complete and Report Assessment Results

The final results are entered into the CMMC Enterprise Mission Assurance Support Service (eMASS) and transmitted to SPRS. The C3PAO will then submit the final report along with SPRS score to the Cyber AB for review and the final certification decision.

Phase 4: Issue Certificate and Close out POA&M

During the final phase of a CMMC Level 2 certification assessment, the C3PAO issues a certificate of CMMC Status and closes out any POA&Ms that might exist.

This certification is valid for three years. During those three years:

  • Organizations must continue to monitor and improve their cybersecurity practices by maintaining their POA&M.
  • A senior official must also affirm continued compliance with the specified security requirements after every third-party assessment and annually thereafter.
  • Affirmations must be entered electronically in the SPRS.

How to Prepare:

Preparation requires strong documentation, repeatable processes, and a mature cybersecurity environment. Internal testing, regular risk assessment practices, and continuous monitoring help demonstrate you are meeting the intent of NIST SP 800-171 Revision 2 controls. Maintaining your POA&M and keeping your SSP accurate are essential.

This preparation is identical to what a strong self-assessment requires, so organizations that maintain their compliance posture during the review period will be positioned for whatever assessment model the Reform Task Force recommends.

Recommended reading

How to Meet CMMC Level 2 Compliance Requirements + Checklist

Read More

Government-led assessment

  • Frequency: Every three years, with annual affirmations
  • Applicable to: Level 3 contractors (Level 3 DIBCAC certification requirements are suspended in new DoD solicitations during the current program review; however, DIBCAC continues to conduct select government-led assessments during the interim period)

What It Involves:

Under the CMMC program design, DoD contractors seeking Level 3 certification, which involves handling the most sensitive Department of Defense information, are subject to security assessments led by DoD assessors. These assessments are the most rigorous and evaluate all NIST SP 800-171 requirements along with the enhanced cybersecurity measures from NIST SP 800-172.

These are broken up into three key stages.

Stage 1: Initiation

Organizations seeking this certification level must coordinate with the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) for a government-led assessment. This process typically begins with a pre-assessment meeting to discuss scope, timing, and process.

Stage 2: Interviews, Examination, and Testing

Like C3PAOs, government assessors will review key documentation, such as the SSP and POA&M. They will also conduct on-site evaluations including interviews and technical testing, and examine evidence like logs and configurations to verify that advanced security safeguards are implemented and effective.

Also like a C3PAO, government assessors may provide a preliminary report for addressing deficiencies before the final report is submitted to the Cyber AB for certification, which is valid for three years. To maintain compliance, organizations must continuously monitor systems, update their POA&M, and keep policies current.

Stage 3: Findings and Results

The DoD assessor will enter the assessment information electronically into the eMASS, that will electronically transmit the assessment results into SPRS. A senior official from the organization must affirm continuing compliance with the specified security requirements after every DoD assessment and annually thereafter. Annual affirmations are entered electronically in SPRS.

How to Prepare:

Level 3 readiness requires a mature cybersecurity program capable of defending against advanced cyber threats. This includes comprehensive documentation, strong incident detection and response capabilities, continual improvement practices, and demonstrated effectiveness of all controls. Preparing early and maintaining an accurate SSP and POA&M are critical for a successful government-led assessment.

Recommended reading

CMMC Level 3: All Requirements, Costs + Checklist

Read More

Assessment requirements during the current program review

On July 13, 2026, the DoW paused CMMC Phase 2 requirements, which were scheduled to take effect on November 10, 2026.

What is on hold: The Phase 2 transition to mandatory C3PAO assessments, all pending and future CMMC implementation milestones, Level 2 (C3PAO) and Level 3 (DIBCAC) designations in new solicitations, and these requirements in active solicitations and existing contracts, which are being amended out.

What remains in effect: CMMC Level 1 and Level 2 self-assessment requirements, NIST SP 800-171 Rev 2 enforcement through self-assessments and select government-led assessments, DFARS 252.204-7012 obligations for all defense contractors, and SPRS score submission and annual affirmation requirements.

What happens next: The DoW CIO has established a CMMC Reform Task Force to conduct a top-to-bottom review of the program, informed by industry feedback through a public Request for Information. The task force will deliver its final report within 60 days of July 13, 2026, and the DoW has said further guidance will follow at the conclusion of the review.

Until then, contractors should treat their NIST 800-171 obligations as unchanged and maintain their compliance posture while the review proceeds.

FAQs

What is a CMMC assessment?

A CMMC assessment is a formal evaluation of an organization's cybersecurity practices to determine whether they meet the requirements for their designated CMMC level.

What type of CMMC assessment do I need?

As of July 2026, new DoD solicitations may only require a self-assessment. During the 60-day program review, Level 2 (C3PAO) and Level 3 (DIBCAC) designations are suspended from all new procurement requirements.

  • CMMC Level 1: Requires an annual self-assessment by the organization for all contractors handling Federal Contract Information (FCI).
  • CMMC Level 2: During the current program review, all new solicitations require a Level 2 self-assessment. The program's original design required C3PAO assessments for most Level 2 contractors handling CUI critical to national security; that requirement is suspended while the Reform Task Force reviews the program.
  • CMMC Level 3: During the current program review, Level 3 (DIBCAC) certification requirements are suspended in new solicitations. The program's original design requires government-led assessments for the highest-sensitivity programs.

Verify applicable requirements by reviewing your DoD contract or consulting with a contracting officer.

Can CMMC Level 2 contractors self-assess?

During the DoD's current program review, Level 2 (Self) is the only Level 2 designation Program Managers can include in new solicitations. The CMMC program design originally required C3PAO assessments for organizations handling CUI critical to national security, with self-assessment reserved for a smaller subset handling non-critical CUI. Whether to pursue a voluntary C3PAO assessment during the suspension is a business decision; contact your C3PAO and contracting officer for guidance.

How does CMMC relate to DFARS and NIST SP 800-171?

CMMC Level 2 aligns directly with the NIST SP 800-171 security standards required by DFARS 252.204-7012. CMMC adds independent verification for certain contracts and provides a more structured certification process for DoD contractors and subcontractors across the DIB.

Does CMMC overlap with FedRAMP?

CMMC and FedRAMP both evaluate the implementation of security controls, but they apply to different federal environments. FedRAMP authorizes cloud service providers, while CMMC focuses on safeguarding FCI and CUI within the Defense Industrial Base.

What are the key takeaways for defense contractors?

  • Self-assessment is the active requirement for all new DoD solicitations during the current program review.
  • Level 1 self-assessments cover the basic FCI safeguarding requirements in FAR 52.204-21 and are conducted annually.
  • Level 2 self-assessments cover all 110 NIST SP 800-171 requirements and are conducted every three years with an annual affirmation.
  • The program's original design required C3PAO assessments for most Level 2 contractors and DIBCAC assessments for Level 3 contractors; both are suspended in new solicitations during the review.
  • Maintaining an accurate SSP, POA&M, SPRS score, and risk management program is essential regardless of which assessment type applies.
  • The SPRS score you submit and affirm is a representation to the federal government; it carries False Claims Act exposure if it misrepresents your actual posture.
Loading...