On July 13, 2026, the Department of War (DoW) suspended CMMC Phase 2, which had been scheduled to begin on November 10, 2026 and would have introduced third-party (C3PAO) Level 2 certification requirements into more contracts.1 The DoW Chief Information Officer initiated a 60-day review of the program and stated that further guidance would follow its conclusion.2 As of this article's publication date, that guidance has not been issued.
The suspension did not remove the underlying obligations. DFARS Class Deviation 2026-O0025, Revision 3, directs contracting officers to remove third-party CMMC requirements from solicitations and contracts, permits CMMC Level 1 and Level 2 requirements to be met through self-assessment, and leaves the safeguarding requirements of DFARS 252.204-7012 in place.3 A Level 2 self-assessment is entered in the Supplier Performance Risk System (SPRS) and affirmed by a senior company official.4 That affirmation is a representation to the government. In March 2025, MORSECORP Inc. agreed to pay $4.6 million to resolve False Claims Act allegations that included failure to meet NIST SP 800-171 requirements.5
For contractors, the practical conclusion is that readiness work remains necessary. Five readiness gaps deserve particular attention.
1. Scope defined by organization chart instead of data flow
Scoping begins with where Controlled Unclassified Information (CUI) is received, stored, processed, and transmitted. CUI arrives by email, is attached to quotes, is saved to shared drives, is opened on laptops, and is sent to suppliers. Each of these systems is in scope.
The CMMC scoping rule at 32 CFR 170.19 defines asset categories, including CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets.6 Security Protection Assets, which provide security functions for the assessment scope, are in scope even if they never store CUI. Identity providers, security monitoring platforms, and endpoint management tools therefore require attention. A CUI data flow diagram should precede any control-by-control assessment.
2. The enclave decision made late or not enforced
Contractors can bring the entire environment into compliance or establish a defined enclave for CUI. An enclave is often faster and less costly, but only if the boundary is decided early and enforced. The critical design element is the intake path: how CUI moves from a customer into the enclave without passing through the general environment, and what controls prevent the alternative. This usually requires a controlled intake mechanism, labeling or data loss prevention controls in the general environment, and training that explains the approved path.
3. Shared responsibility assumed rather than documented
A compliant cloud platform does not configure the contractor's conditional access, session timeouts, access reviews, or incident response. Each external service in scope needs a customer responsibility matrix identifying which requirements the provider meets, which the contractor meets, and which are shared.
Under DFARS 252.204-7012, a cloud service provider that stores, processes, or transmits covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline. The DoD CIO's December 2023 memorandum sets out what equivalency requires for providers that are not FedRAMP authorized.7 Verify a provider's authorization status in the FedRAMP Marketplace rather than relying on vendor marketing.
4. Evidence that exists only as of today
Several NIST SP 800-171 requirements describe recurring activities, including periodic assessment of security controls (3.12.1) and creation and retention of audit logs (3.3.1).8 Demonstrating these requirements depends on dated records produced over time, such as access reviews, vulnerability scans, log retention, training records, and remediation tickets. Records cannot be created retroactively, so evidence generation should begin at the start of the project.
Note that NIST published SP 800-171 Rev. 3 in May 2024, but DoW continues to require Rev. 2 under DFARS 252.204-7012.38 Self-assessed status also does not limit the government's own review: under DFARS 252.204-7020, contractors must provide access for Medium and High assessments conducted by government personnel.9
5. Reliance on a Plan of Action and Milestones
Under 32 CFR 170.21, a Conditional Level 2 status requires an assessment score of at least 80 percent of the Level 2 requirements (88 of 110). Only requirements with a point value of 1 may be included on a Plan of Action and Milestones (POA&M), with a limited exception for SC.L2-3.13.11 where encryption is used but is not FIPS-validated, and certain requirements are excluded regardless of point value. Open items must be remediated and closed out within 180 days, or the conditional status expires.10 Identify the requirements that are not POA&M-eligible at the start of the project and treat them as gating items.
Practical takeaways
- Continue Level 2 readiness work; the suspension changed the assessment method, not the requirements.
- Document CUI data flows before assessing individual requirements.
- Obtain a customer responsibility matrix for every external service in scope.
- Start generating dated evidence immediately.
- Treat the SPRS affirmation as a formal representation and support it with documentation.
- Monitor DoW for guidance issued after the 60-day review.
References
- U.S. Department of War, "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements," July 2026. war.gov
- Department of War Chief Information Officer, memorandum implementing the suspension of CMMC Phase II, July 2026. dowcio.war.gov
- Office of the Assistant Secretary of War, DFARS Class Deviation 2026-O0025, Revision 3, September 2026. acq.osd.mil
- 32 CFR 170.16, CMMC Level 2 self-assessment and affirmation requirements. ecfr.gov
- U.S. Department of Justice, "Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations." justice.gov
- 32 CFR 170.19, CMMC scoping. ecfr.gov
- DoD Chief Information Officer, "Federal Risk and Authorization Management Program Moderate Equivalency for Cloud Service Provider's Cloud Service Offerings," December 2023. dodcio.defense.gov
- National Institute of Standards and Technology, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations," NIST SP 800-171 Rev. 2. csrc.nist.gov
- DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements. acquisition.gov
- 32 CFR 170.21, Plan of Action and Milestones requirements. ecfr.gov
DefenseLogix supports regulated and trust-sensitive organizations with this work. To discuss your organization's situation, start a conversation or review the Government / CMMC Readiness service.
