CMMC IT requirements remain enforceable today even though the Department of War suspended Phase II third-party assessment rollouts on July 13, 2026. Self-assessments, NIST SP 800-171 Rev. 2 controls, DFARS 252.204-7012 obligations, Supplier Performance Risk System (SPRS) reporting, and cyber incident reporting all remain in force. The pause only stops the rollout of certified third-party audits, not your contractual duty to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).
You still need these artifacts on hand right now:
- A System Security Plan (SSP) that reflects your actual environment.
- A Plan of Action and Milestones (POA&M) where your contract permits one.
- A current SPRS score, since contracting officers still pull it before award.
- Annual affirmations for Level 1 and Level 2 self-assessed contracts.
Pro Tip: If you only fix three things this quarter, fix multi-factor authentication on every administrative account, centralized log retention, and a verified backup restore test. Auditors and contracting officers check these first because they're the fastest indicators of real security hygiene.
Key Takeaways
CMMC IT requirements stay enforceable through NIST SP 800-171, DFARS 252.204-7012, and SPRS reporting, regardless of the Phase II third-party assessment pause.
| Point | Details |
|---|---|
| Phase II is paused, not gone | Third-party assessment rollouts stopped July 13, 2026, but self-assessment and reporting duties continue. |
| NIST SP 800-171 is your baseline | Level 2 contractors must still implement all 110 controls across 14 families, documented in a current SSP. |
| Legal risk didn't pause | False Claims Act exposure from inaccurate SPRS scores or SSPs remains active under DOJ civil cyber-fraud enforcement. |
| Evidence beats policy | Auditors expect logs, configuration snapshots, and test records tied to each control family, not just written policies. |
| Managed support closes gaps faster | Greatplainsnetworking helps small defense contractors implement MFA, logging, backups, and documentation without an in-house compliance team. |
Table of Contents
- What Is the CMMC IT Requirements Program Right Now?
- Which IT Controls Does CMMC Actually Require?
- How Do Contractors Report and Get Assessed Today?
- What Should IT Teams Do in the Next 30, 90, and 180 Days?
- Does the Phase II Pause Change Your Legal Risk?
- What the CMMC Pause Really Means for Contractors
- Get IT Support Built for Defense Contractors in Oklahoma
- Frequently Asked Questions
- Sources
What Is the CMMC IT Requirements Program Right Now?
CMMC applies to Department of War contractors and subcontractors who handle FCI or CUI, and the obligation flows down through prime contracts into the supply chain. A subcontractor building a single part for a prime doesn't get a pass just because the government never signs their contract directly. If CUI touches their systems, CMMC requirements travel with it.
CMMC 2.0 organizes requirements into three levels tied to information sensitivity:
- Level 1 covers FCI only and maps to the basic safeguards in FAR 52.204-21, verified through annual self-assessment.
- Level 2 covers CUI and maps to the 110 controls in NIST SP 800-171 Rev. 2, with either self-assessment or third-party certification depending on contract sensitivity.
- Level 3 adds enhanced requirements for the highest-priority programs, assessed by the Defense Contract Management Agency.
The Department of War's suspension halts the certified third-party assessment rollout, including the November 10, 2026 deadline, while directing a 60-day review by a CMMC Reform Task Force. Self-assessment obligations and government-led selective assessments continue without interruption.
In practice, that means contracting officers are amending solicitations to strip out Certified Third-Party Assessment Organization (C3PAO) and Defense Industrial Base Cybersecurity Assessment Center requirements, but they aren't waiving the underlying security expectations behind them.
Which IT Controls Does CMMC Actually Require?
The technical baseline hasn't moved. Level 1 contractors still work from the 15 controls in FAR 52.204-21. Level 2 contractors, whether self-assessing or awaiting a future third-party review, still build against the 110 controls in NIST SP 800-171 Rev. 2. These controls cluster into 14 families, and a handful carry the most weight for IT teams building out infrastructure.
| Control Family | Why It Matters | Typical Evidence |
|---|---|---|
| Access Control | Limits who can reach CUI and what they can do with it | Role-based permissions, least-privilege reviews |
| Identification and Authentication | Confirms users are who they claim to be | MFA logs, password policy configuration |
| Audit and Accountability | Creates a trail investigators and auditors can follow | Centralized log retention, SIEM alerts |
| Configuration Management | Prevents unauthorized or insecure system changes | Baseline configs, change tickets |
| Incident Response | Governs how you detect and report breaches | IR plan, tabletop exercise records |
| System and Communications Protection | Secures data in transit and at network boundaries | Encryption standards, firewall rules |
Auditors and contracting officers expect evidence tied to each family: SSP sections describing implementation, referenced policies, configuration snapshots, MFA logs, and documented backup and recovery test results. A written policy with no supporting log or screenshot behind it rarely survives scrutiny.
Pro Tip: If a control genuinely doesn't apply to your environment, say so directly in the SSP with a clear rationale and supporting evidence. Undocumented exceptions get treated as gaps, not as informed decisions, during assessment or enforcement review.
How Do Contractors Report and Get Assessed Today?
Assessment type depends on your level and, for now, on which pathway the government still recognizes. Level 1 contractors self-assess annually. Level 2 contractors self-assess on a multi-year cadence unless their contract calls for certified third-party review, and those third-party rollouts are the piece currently suspended. Government-led assessments can still happen for select programs regardless of the pause.
Here's the sequence contractors should follow right now:
- Run a self-assessment against your applicable control set.
- Build or update your SSP, and add POA&M entries wherever your contract allows partial implementation.
- Post your current score to SPRS.
- Submit annual affirmations (Level 1) or maintain your three-year self-assessment record (Level 2).
Separately, DFARS 252.204-7012 requires reporting a cyber incident within 72 hours of discovery through the DoD's designated reporting portal, a duty that exists independent of your CMMC level or assessment status.
- Keep exportable evidence packages ready for each control family.
- Script recurring checks (patch status, MFA enforcement, backup success) so SPRS updates take minutes, not weeks.
Pro Tip: Treat your SPRS score as a living business metric, not a one-time form. A stale or inflated score can quietly disqualify you from contracts you'd otherwise win.
What Should IT Teams Do in the Next 30, 90, and 180 Days?
Contractors who treat the Phase II pause as a deadline extension, rather than a chance to catch up, tend to fall further behind. Use the window deliberately.
In the next 30 days:
- Enforce MFA on every administrative and remote-access account.
- Set and enforce a documented password policy.
- Verify backups with an actual restore test, not just a completed job log.
- Deploy endpoint detection and response (EDR) across covered systems.
- Turn on baseline logging with defined retention periods.
In the next 90 days:
- Complete a full SSP draft covering every applicable control family.
- Open POA&M entries for known gaps with realistic remediation dates.
- Review cloud and Microsoft 365 vendor contracts for CMMC flow-down clauses.
- Run a tabletop exercise testing your incident response plan.
In the next 180 days:
- Package evidence by control family so it's ready for a future audit request.
- Harden technical controls further, including patch cadence and network segmentation, as covered in guidance on protecting manufacturing data.
- Maintain staff security training records.
- Loop in contracting and legal counsel on SPRS accuracy and False Claims Act exposure.
Cloud services and subcontractors need the same rigor. If a vendor touches CUI, get their flow-down commitment in writing and confirm minimum evidence they can produce on request, a topic covered in more depth in guidance on subcontractor and supply chain flow-down.
Pro Tip: Log every remediation ticket in your CMDB or ticketing system with control-family tags. When an assessor or contracting officer asks for proof, you want a searchable trail, not a scramble through email threads.

Does the Phase II Pause Change Your Legal Risk?
No. The suspension stops the certified third-party assessment rollout. It does nothing to DFARS 252.204-7012, your NIST SP 800-171 obligations, or your exposure under the Department of Justice's civil cyber-fraud enforcement initiative. If you submit an SPRS score or sign a contract affirmation that overstates your actual security posture, you're still exposed to False Claims Act liability.
Legal analysis of the suspension is consistent on one point: contractors should continue self-assessment, SPRS reporting, and honest SSP and POA&M documentation to limit enforcement risk, regardless of when third-party audits resume.
Reduce your exposure with a few concrete habits:
- Keep SSPs accurate and current, updated whenever your environment changes.
- Write POA&Ms honestly, with realistic timelines rather than aspirational ones.
- Report incidents within the 72-hour DFARS window every time, without exception.
- Score conservatively in SPRS. An inflated score is worse than a modest, accurate one.
Pro Tip: Loop legal counsel in before any public or contractual statement affirming your compliance status. A rushed affirmation is exactly the kind of document DOJ investigators look for first.
What the CMMC Pause Really Means for Contractors
The conventional read on the Phase II pause treats it as a reprieve, and that's the wrong lens entirely. Nothing about the technical burden changed. What changed is who checks your work and when. That's actually worse for contractors who were waiting on a certified assessor to tell them what to fix, because now the accountability sits entirely on your own self-attestation, with DOJ's civil cyber-fraud initiative watching the gap between what you claim and what you've built.

The overlooked nuance is that small contractors usually don't fail on the technical controls. MFA, backups, and logging aren't exotic. They fail on documentation, an SSP that doesn't match reality, or a POA&M nobody updated in a year. If you're prioritizing anything during this pause, prioritize the paper trail as hard as the infrastructure. An accurate SSP with three open items you're actively fixing is safer, legally and operationally, than a polished SSP claiming full compliance you can't actually demonstrate.
Get IT Support Built for Defense Contractors in Oklahoma
Greatplainsnetworking gives small defense contractors and subcontractors in Norman, Moore, and Oklahoma City a path to CMMC readiness without hiring a full-time compliance team. Where a national consulting firm bills for a lengthy audit engagement, Greatplainsnetworking works hands-on with your existing systems, from MFA rollout to log retention to backup verification, in plain language, with same-day response and no long-term contract locking you in.

If you're staring at a POA&M full of unresolved items or an SSP that hasn't been touched since last year, that's exactly where Greatplainsnetworking's cybersecurity services come in: continuous monitoring, documented evidence, and remediation tracking built around what CMMC actually expects to see. Reach out for a readiness review through managed IT support and find out exactly where your gaps are before an assessor does.
Frequently Asked Questions
Does the CMMC Phase II pause mean I can skip self-assessment? No. Self-assessment requirements for Level 1 and Level 2 contractors remain fully in force. Only the certified third-party assessment rollout is suspended.
What's the difference between FCI and CUI for CMMC purposes? FCI is information provided by or for the government that isn't intended for public release, triggering Level 1 requirements. CUI is more sensitive unclassified information requiring safeguarding, triggering Level 2 requirements under NIST SP 800-171.
Do I still need to report cyber incidents during the pause? Yes. DFARS 252.204-7012 requires reporting a cyber incident within 72 hours of discovery, and that clause was never part of the suspension.
Can I still get awarded a contract if my SPRS score is low? A low score doesn't automatically disqualify you, but contracting officers weigh it heavily. Document your POA&M honestly and show active remediation rather than leaving the score unexplained.
What happens to contracts that already required third-party certification? Contracting officers are amending active solicitations to remove suspended third-party assessment designations, according to DoD guidance to contracting activities. Underlying security control requirements remain unchanged.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
