Part 2: What the CMMC Pause Does Not Change
In Part 1 of this series, we explained what the Department of War paused on July 13, 2026 and why organizations should not interpret the announcement as the end of CMMC.
The next question is more important: What are defense contractors still required to do?
Numerous contractors are already required to implement cybersecurity requirements. CMMC is one method of assessing and verifying that implementation, but the underlying cybersecurity obligations did NOT begin with CMMC. Many of those obligations remain in effect during the Phase II suspension. This is a distinction that has been blurred throughout CMMC’s history.
CMMC Is Not the Security Control Framework
Organizations sometimes say that they are “implementing CMMC.” While that phrase is commonly used, it can create confusion with CMMC levels being different:
- At CMMC Level 1, contractors are generally addressing the basic safeguarding requirements associated with Federal Contract Information under FAR 52.204-21.
- At CMMC Level 2, contractors are implementing the applicable NIST SP 800-171 requirements for systems that process, store, or transmit CUI, while continuing to protect any FCI in accordance with applicable FAR requirements.
CMMC establishes assessment and affirmation mechanisms around those requirements. It does not replace the requirements themselves. The July Cyber AB Town Hall reinforced this distinction by describing CMMC as an assessment program rather than the underlying set of security practices. That distinction helps explain why pausing Phase II does not remove NIST SP 800-171 obligations from contracts that already include them.
DFARS 252.204-7012 Remains Important
DFARS 252.204-7012 requires covered contractors to provide adequate security on covered contractor information systems and to report certain cyber incidents. For contractors handling Covered Defense Information, the clause has long tied adequate security to the security requirements in NIST SP 800-171, subject to the terms and alternatives described in the clause.
The Phase II suspension did not remove DFARS 252.204-7012 from existing contracts. Affected contractors must therefore continue to consider these requirements which include:
- protection of Covered Defense Information;
- implementation of applicable NIST SP 800-171 requirements;
- rapid reporting of covered cyber incidents within 72 hours of discovery;
- preservation of affected system images and data;
- access for forensic analysis; and
- flowdown of applicable requirements to subcontractors.
An organization that was subject to these requirements before July 13 did not stop being subject to them merely because the Phase II schedule changed.
Phase I Self-Assessments Remain in Place
A pause in the expansion of mandatory C3PAO assessments does not mean that self-assessment requirements are optional. The Department expressly stated that all Phase I self-assessment requirements remain in effect. Depending on the contract and information involved, this would include Level 1 self-assessments for organizations handling FCI and Level 2 self-assessments for organizations handling CUI; along with requirements of:
- annual affirmations of continuing compliance;
- maintaining the required CMMC status for the applicable contract; and
- ensuring that subcontractors have the appropriate status before receiving FCI or CUI.
SPRS Scores Still Matter…With Additional Risk
Organizations subject to DFARS 252.204-7019 and 252.204-7020 may be required to perform NIST SP 800-171 assessments using the DoD Assessment Methodology and maintain the resulting score in the Supplier Performance Risk System (SPRS). This system is the location for vendors to enter, edit, affirm, and manage CMMC and NIST cyber reports.
The SPRS score is not simply an informal estimate of cybersecurity maturity; it is a representation about the implementation of specific security requirements at a particular point in time. This score should be based on the required methodology that is consistent with the System Security Plan (SSP); calculated against the correct system boundary; supported by evidence; and adjusted when the environment materially changes and otherwise updated as required.
One of the more significant risks in CMMC readiness is the unsupported score. Some organizations choose to arrive at their score by beginning with the maximum score of 110, then subtracting only for weaknesses that have been formally identified. That approach can overstate implementation when requirements have not actually been tested, when evidence is not collected, or when a product is assumed to satisfy a requirement without confirming proper operation or configuration. This makes the SPRS score indefensible.
The System Security Plan Is Still Necessary
NIST SP 800-171 requires organizations to develop and maintain system security plans describing the system boundary, the operational environment, how security requirements are implemented, and any relationships with or connections to other systems.
The SSP should describe the environment that exists now. It should not describe the environment management expects to have after the next budget cycle, after a new system is installed, or before an assessor arrives. Most importantly, the SSP needs to have an update mechanism. An inaccurate or outdated SSP creates more than an assessment problem. It can undermine the organization’s SPRS score, remediation plans, customer communications, and management affirmations.
Key components of a useful SSP include:
- where CUI enters the organization, how it is stored, how it is transmitted, and which people/roles can access it;
- which technologies are in scope;
- which service providers support the environment;
- which controls are inherited; and
- who is responsible for maintaining each part of the security program.
POA&Ms Do Not Make Every Deficiency Acceptable
Plans of Action and Milestones remain an important part of managing incomplete security requirements; however, the existence of a POA&M does not automatically make every deficiency acceptable. While CMMC Level 1 does not permit POA&Ms, Level 2 rules and contract-specific requirements determine what may be handled through POA&M and under what conditions.
Organizations should especially understand whether a particular requirement may be placed on a POA&M and whether the contract permits the organization to operate with the deficiency. There are times when the deficiency contradicts a representation already made to a customer or the government. The CMMC pause could provide an opportunity for organizations to work on resolving key POA&M items, rather than simply extending old target dates.
Prime Contractors Still Have Supply-Chain Responsibilities
Prime contractors remain responsible for understanding how FCI and CUI move through their supply chains. That requires more than inserting the same clause into every purchase order. It requires that Primes be able to determine which subcontractors receive FCI and/or CUI, why the information must be shared, and most importantly, what assessment level is appropriate.
Ultimately, a Prime must determine whether the subcontractor’s environment can protect the provided information; and if things go wrong, how incidents will be communicated and what happens when the subcontractor cannot meet the requirements.
The pause will likely result in prime contractors relying more heavily on their own questionnaires, reviews, risk ratings, evidence requests, and more precise contractual language.
Subcontractors Should Expect Continued Scrutiny
Subcontractors may not have a direct contract with the Department, but that does not place them outside the supply-chain requirements. When FCI or CUI is shared with a subcontractor, applicable contractual obligations may be flowed down from the prime or higher-tier subcontractor. As a result, subcontractors should be prepared to explain what defense information they receive and whether that information includes CUI. If it does, then they should have the documentation that describes;
- where the information is processed, stored, and transmitted;
- whether external providers have access;
- the organization’s SPRS score where applicable;
- significant unresolved deficiencies;
- incident-reporting arrangements; and
- any future certification plans if they exist.
Determining where the information is processed, stored, and transmitted isn’t a trivial matter in today’s computing environment. Most organizations rely on managed service providers, cloud-hosting companies, Microsoft 365 environments, outsourced help desks, or other software-as-a-service applications and specialized platforms. The contractor remains responsible for understanding how those services affect their contracted obligations and handling of CUI. Ultimately, the responsibility remains with the contractor to ensure the service provider’s security architecture matches or exceeds what is described in their own SSP and in the contract with the company supplying CUI.
Annual Affirmations Require More Than a Signature
CMMC requirements include annual affirmations of continuing compliance for applicable status levels. This affirmation is a management representation that should be supported by evidence that:
- the assessment scope remains accurate;
- required practices remain implemented;
- material system changes have been considered;
- significant deficiencies are known and POA&M items are being managed;
- required evidence remains available; and
- the submitted information is not misleading.
An executive should not be placed in the position of signing an affirmation based only on a statement that “IT says we are compliant.” The organization should establish a repeatable review process that produces enough information for the affirming official to make an informed decision.
The Bottom Line
The Phase II pause affects the rollout of expanded Level 2 certification requirements. It does not eliminate:
- existing contract clauses;
- protection requirements for FCI and CUI;
- Phase I self-assessment requirements;
- NIST SP 800-171 obligations;
- the SPRS scoring system;
- flowdown responsibilities; or
- the need for accurate management representations.
Organizations should revisit their CMMC plans, but they should not confuse a change in the assessment schedule with relief from the underlying requirements.
Coming Next
The obligation to make accurate representations creates a separate concern for defense contractors.
An unsupported SPRS score, inaccurate affirmation, or claim that requirements are implemented when they are not may create more than a failed assessment. It may create legal and financial exposure.
In Part 3, we will explain the False Claims Act, how it has been applied to cybersecurity requirements, and how independent third-party assistance can help reduce the risk of unsupported representations.
This series provides general information and does not constitute legal advice. Organizations facing potential contractual, False Claims Act, disclosure, or incident-reporting concerns should consult qualified legal counsel.



