· RNITS Compliance  · 13 min read

✦ Switch to AI view

CMMC Phase 2 Is Suspended. Your NIST 800-171 Obligations Are Not.

CMMC third-party assessments are suspended — but NIST 800-171, DFARS 7012, and your SPRS score still apply. What MA/NH defense subcontractors should do now.

CMMC Phase 2 Is Suspended. Your NIST 800-171 Obligations Are Not.

A machine shop in Nashua that supplies parts up the chain to a couple of big defense primes got two emails in the same week this month. The first, from a compliance consultant they had talked to last year, said the deadline had moved and they should lock in a C3PAO assessment slot now before the rush. The second, forwarded from their prime’s supply-chain contact, said the government had suspended the whole thing and they could stand down.

Both emails were describing the same event — the July suspension of CMMC Phase 2. Only one of them was honest about what it means.

Here is what actually happened, and what it does and does not change for a small manufacturer, machine shop, or engineering firm that handles the Defense Department’s controlled unclassified information. The short version is that the audit got suspended and the homework did not. If someone is telling you to pay for a certification assessment right now, they are selling you a ticket for a train that has no schedule.

What the Pentagon actually did

On July 13, 2026, the Defense Department issued a memorandum suspending Phase 2 of the Cybersecurity Maturity Model Certification program. Phase 2 was the part that would have started requiring independent, third-party assessments — the C3PAO audits — as a condition of winning contracts that involve controlled unclassified information (CUI). It had a hard start date of November 10, 2026. That date is gone. The memo also put the later phases, 3 and 4, on hold indefinitely and stood up a “CMMC Reform Task Force” to review the entire program over 60 days.

Then, on September 3, 2026, the Department went a step further and made the suspension operational. It issued a DFARS class deviation — the mechanism the government uses to tell its own contracting officers to do something different from the standing rule — directing those officers to strip the third-party CMMC assessment requirements out of solicitations and contracts. This matters because it turns the July announcement from an intention into an instruction. The requirement is not just paused on paper; contracting officers are actively removing it from the documents you sign.

The Task Force’s report was due to the Department’s CIO on September 11. As of late September it has not been made public. More than 1,100 comments came in during the review, and nobody outside the building knows yet what the program will look like when — or if — assessments come back. The Department’s CIO said plainly at a cybersecurity conference in early September that the pause “isn’t about whether cybersecurity is important or not. It is. It’s critical.” Read that carefully. They suspended the audit. They did not suspend the requirement to be secure.

The distinction that saves you money

There are two different things people lump together under “CMMC,” and the whole confusion in that Nashua machine shop came from mixing them up.

The first thing is the certification and assessment machinery: the C3PAO audits, the certification levels, the requirement that a third party come verify your security before you can win certain contracts. That is what got suspended. That is Phase 2.

The second thing is the underlying security standard you are contractually required to meet: NIST Special Publication 800-171. That is not suspended. It was never suspended. It has been a contract requirement since 2017 through a clause called DFARS 252.204-7012, and that clause is still in every relevant contract you hold. CMMC was only ever the mechanism to prove you were following 800-171. Suspending the proof does not suspend the obligation.

Think of it like a building code. The inspections got postponed. The code still says your wiring has to be up to standard, and if the building burns down because it wasn’t, “the inspector never came” is not a defense. Same idea here. The government is still buying from you under a contract that says you will protect its data to the 800-171 standard, and you still signed it.

A bright isometric illustration showing two paths splitting: one labeled path fading out with a paused assessment audit icon, the other continuing forward with an active security checklist and shield, light blues whites and soft greens

What is still fully in force

If you handle CUI for the Defense Department, none of the following went anywhere. This is the list your obligations actually live on, suspension or no suspension.

  • NIST SP 800-171 Rev. 2. The 110 security controls remain the baseline. Access control, multifactor authentication, encryption, logging, incident response, media protection — all of it. Your obligation to implement these did not change on July 13.
  • DFARS 252.204-7012. The clause requiring you to safeguard covered defense information and report cyber incidents to the Department within 72 hours is untouched. It has applied to primes and subcontractors alike since 2017.
  • Your SPRS score. You are still required to have a current self-assessment score posted in the Supplier Performance Risk System. Primes check it. If your score is stale, missing, or inflated, that is a live problem today, not a Phase 2 problem for later.
  • Accurate self-attestation. When you certify your compliance, you are certifying it under penalty of the False Claims Act. The Justice Department has been pursuing contractors for false cybersecurity attestations for a couple of years now, and the CMMC suspension does nothing to slow that down. If anything, with the third-party audit gone, your self-attestation carries more weight, not less — it is the only thing standing between your claim and the government’s trust in it.
  • Flow-down to your subcontractors. If you pass CUI to anyone below you, the 7012 obligations flow down to them, and that is still on you to manage.

The pattern is simple. Everything about being secure still applies. Only the requirement to hire a third party to check went on pause.

The honest part: do not pre-pay for an assessment with no date

Here is where a certain kind of compliance shop is going to try to scare you, and where we are going to tell you not to spend the money yet.

There are consultants and assessors right now emailing defense subcontractors telling them to book their C3PAO assessment immediately, to get their certification prep locked in “before the deadline,” to buy a readiness package so they are not caught flat-footed when Phase 2 comes back. Some of them genuinely believe it. Some of them are protecting a revenue stream that the suspension just kicked out from under them.

Either way, the advice is wrong for a small business right now, for one concrete reason: there is no assessment to prepare for and no date to hit. The government has not said when — or in what form — third-party assessments will return. The Task Force could recommend a lighter model for small businesses. It could recommend a phased return. It could recommend scrapping the level structure entirely. Nobody knows, because the report is not public. Paying a firm today to prepare you for an audit whose rules may not survive the review is buying a service against a specification that does not exist.

That does not mean do nothing. It means spend your compliance dollars on the thing that is actually required — meeting the 800-171 standard — instead of the thing that is suspended. Every dollar that goes into genuinely implementing those 110 controls is a dollar that pays off no matter what the Task Force decides, because the controls are the requirement. Every dollar that goes into “certification prep” for a suspended audit is a bet on a rulebook nobody has written. We help clients tell those two categories apart in our CMMC compliance services, and the first thing we usually do is stop them from spending on the second one.

What a defense subcontractor should actually do now

The suspension is a gift of time, not a permission slip to ignore the problem. Use the runway to close the real gaps, cheaply, before assessments come back in whatever form they take. Here is the order that gets you the most protection for the least money.

1. Get your SPRS score honest and current

This is the highest-leverage thing you can do this quarter, and it is required today regardless of Phase 2. Do a real self-assessment against the 110 controls, score it honestly using the DoD scoring methodology, and post a current number in SPRS. If your existing score was optimistic — and many small-business scores are — fixing it now, on your own timeline, is far better than having a prime or the government find the gap for you. An honest low score with a plan is defensible. An inflated score is a False Claims Act exposure.

2. Build or refresh your System Security Plan and POA&M

The System Security Plan (SSP) describes how you meet each control. The Plan of Action and Milestones (POA&M) lists the ones you have not met yet and when you will. These two documents are the backbone of 800-171 compliance, they are required now, and they are exactly what any future assessment will start from. If yours are missing, stale, or were written by a consultant two years ago and never touched again, that is your project for this fall.

3. Close the controls that are also just good security

A lot of 800-171 overlaps with what you should be doing anyway to not get ransomwared. Multifactor authentication on everything. Encrypted laptops. Real backups you have tested. Logging you actually review. Removing access when someone leaves. These are controls under the standard and the difference between a bad Tuesday and a company-ending incident. Prioritize the ones that pull double duty.

4. Nail down where your CUI actually lives

Most small manufacturers cannot answer a simple question: which of our systems actually touch controlled defense information? The email with the drawing attached. The shared folder the shop floor pulls specs from. The ERP system. The engineer’s laptop. Until you know the boundary, you cannot secure it or scope it, and every future assessment — light or heavy — will ask you to draw that line. Draw it now, while you have quiet time to do it right.

5. Manage your subcontractors and vendors

If you flow CUI down to anyone, their security is your liability. Confirm your own subcontractors have current SPRS scores and are meeting 7012. This is the part that gets forgotten and the part a prime will ask you about.

A bright isometric illustration of a small manufacturing team reviewing a compliance checklist on a tablet beside industrial equipment, a green shield and organized document icons, light blues and warm accents

Why this hits Massachusetts and New Hampshire shops specifically

The defense supply chain in this region runs deep and runs small. The big primes up here — the Raytheon and BAE Systems footprints across Massachusetts, the aerospace and electronics manufacturers along the 495 belt and up into southern New Hampshire — do not make everything themselves. They buy from a long tail of machine shops, fabricators, circuit-board assemblers, coatings specialists, and engineering firms, most of them under 100 employees, many under 20.

Those small suppliers are exactly the businesses that CMMC was going to squeeze hardest, because they got the same 800-171 obligations as a defense giant with none of the compliance staff to handle them. When Phase 2 got suspended, the relief in that community was real — and so was the confusion, because primes still care about your security posture whether or not the government is auditing it. A prime can, and increasingly does, impose its own security requirements on suppliers through the purchase order, independent of what the Pentagon is doing with CMMC. Your customer’s expectations did not get suspended even if the federal audit did.

So for a local shop, the practical reality is this: the government gave you breathing room, but your primes did not. Use the room to get genuinely compliant with 800-171, because that is what satisfies both the standing DFARS clause and the prime who is quietly deciding whether you are a supply-chain risk. If you want a steady hand on the security program without hiring a full-time compliance person, that is what a fractional security leader is for — our virtual CISO service exists precisely for small manufacturers who need the expertise without the headcount, and the broader security work lives in our managed cybersecurity services.

Questions to ask whoever handles your compliance

Whether it is an internal person, an MSP, or an outside consultant, these questions will tell you fast whether you are getting honest guidance or a sales pitch. Ask them in writing.

  1. Is our SPRS score current and honest? If they cannot tell you the number and when it was last assessed, that is the first job, and it is required today.
  2. Are you recommending we pay for a C3PAO assessment or certification prep right now? If yes, ask them to point to the assessment date and the current rules. There are none. A good advisor will steer that budget to 800-171 implementation instead.
  3. Do we have a current SSP and POA&M? These are required now and are the foundation of everything. “We’ll do that when CMMC comes back” is the wrong answer.
  4. Where does our CUI actually live, and is that boundary documented? Vagueness here means the security scope has never been defined.
  5. What are our primes requiring of us independently of CMMC? The federal audit is paused. Your customers’ contractual security demands may not be.

If the answers lean toward “buy the certification package now,” you are talking to someone protecting their revenue, not your budget.

The short version

The Defense Department suspended CMMC Phase 2 in July and, in September, started actively removing the third-party assessment requirement from contracts. There is no assessment date, no final word on what the program becomes, and no reason for a small defense subcontractor to spend money preparing for an audit that does not currently exist.

What was not suspended is everything that matters day to day: NIST 800-171, the DFARS 7012 clause, your SPRS score, your incident-reporting duty, and your obligation to tell the truth when you attest to compliance. Those are still contract requirements, still enforced, and still the right place to put your compliance budget. The suspension bought you time to get genuinely secure on your own schedule instead of scrambling for a certificate. That is a good deal — if you spend the time on the standard and not on a suspended audit.

If you want an honest assessment of where your shop actually stands against 800-171 — a real score, a look at where your CUI lives, and a straight answer on what is worth spending on right now versus what can wait — that is what our free cyber security audit delivers. You keep the findings whether or not you ever hire us, and if you are already in good shape, we will tell you that too. We work with manufacturers and defense suppliers across New Hampshire and Massachusetts, and we would rather help you spend the suspension wisely than watch you pay for a train that has no schedule. Or just get in touch and ask.

Back to Blog
Free Cyber Security Audit

Not sure where your business stands on security?

Get a free, no-obligation cyber security audit from RNITS. We'll show you exactly what's exposed and what to fix first — in plain English.

Related Posts

View All Posts »