top of page

CMMC Phase 2 is Paused: Why NIST SP 800-171 Compliance Still Matters for Defense Contractors | Jay Wiessner

Writer: My ISO Jay
My ISO Jay
Jul 14
5 min read

Updated: 2 days ago

CMMC Phase 2 remains paused, but defense contractors should not interpret the pause as a suspension of their underlying cybersecurity obligations. The Department suspended the planned Phase 2 rollout in July 2026 and kept the CMMC program in Phase 1 while it reviews and reforms the program.


For organizations that handle Controlled Unclassified Information (CUI), the practical message is straightforward: NIST SP 800-171 Revision 2 requirements tied to applicable defense contracts remain in force, and Phase 1 self-assessment and affirmation requirements continue.


Current CMMC Status in September 2026

The original CMMC implementation schedule called for Phase 2 to begin on November 10, 2026. That planned transition has been suspended. The program is currently paused in Phase 1 while the Department conducts a broader review of CMMC.


This is an important change from the original schedule. Contractors should no longer assume that Phase 1 automatically ends on November 9, 2026 or that the former Phase 2 date remains valid. Future certification and transition requirements should be based on official program updates rather than the superseded rollout calendar.


What Has Not Changed?

The suspension changes how CMMC validation is being implemented, but it does not eliminate contractual cybersecurity requirements for protecting federal information and CUI.


  • Applicable contractors still need to protect CUI in accordance with their contract requirements.

  • NIST SP 800-171 Revision 2 remains the current security-requirement baseline identified by the Department for CMMC Phase 1 Level 2 self-assessments.

  • Phase 1 self-assessment and affirmation requirements remain in effect.

  • Assessment results and affirmations must be entered into the Supplier Performance Risk System (SPRS) when required.

  • The government can continue using its own assessment and oversight mechanisms to evaluate contractor cybersecurity compliance.


What Phase 1 Requires Right Now

Under the current Phase 1 structure, the Department identifies two self-assessment levels.


Level 1: Federal Contract Information

Organizations at Level 1 perform an annual self-assessment against the 15 safeguarding requirements in FAR 52.204-21 and submit an annual affirmation. Results are entered into SPRS.


Level 2: Controlled Unclassified Information

Organizations at Level 2 self-assess against the 110 security requirements in NIST SP 800-171 Revision 2. The current Phase 1 framework calls for a self-assessment every three years, with annual affirmation of continued compliance. Results are entered into SPRS.


The general Phase 2 rollout of Level 2 third-party certification requirements is suspended. Contractors should still review each solicitation and contract carefully and follow current official guidance because cybersecurity requirements can be incorporated through contract clauses and other government oversight mechanisms.


Which Version of NIST SP 800-171 Applies?

NIST has published newer revisions of SP 800-171, but the Department's current CMMC Phase 1 guidance specifically identifies NIST SP 800-171 Revision 2 for Level 2 self-assessments. Contractors should not assume that a newer NIST publication automatically changes the contractual baseline.


The applicable requirement should be determined from the contract, current DFARS requirements, and official CMMC implementation guidance. Organizations should monitor future rulemaking and contract updates for any formal transition to a newer NIST revision.


Why Defense Contractors Should Not Slow Down

A pause in third-party certification does not make weak cybersecurity less risky. Contractors that postpone remediation can still face contract, operational, and legal consequences if required controls are not implemented or if compliance representations are inaccurate.


  • Contractual noncompliance and potential eligibility problems.

  • Increased exposure to cyber incidents involving sensitive defense information.

  • Greater scrutiny from prime contractors and customers.

  • Poor SPRS assessment results or unsupported compliance affirmations.

  • Government-led assessment findings.

  • Potential enforcement risk when compliance representations are knowingly inaccurate.


Self-Assessments Must Be Defensible

Self-assessment does not mean informal or unsupported attestation. A contractor should be able to show how each applicable requirement is implemented and support its assessment with objective evidence.


  • A current and accurate System Security Plan (SSP).

  • Documented policies and procedures that match actual operations.

  • Technical configuration and system evidence.

  • Training and awareness records.

  • Incident-response and access-control evidence where applicable.

  • Current assessment records and SPRS submissions.

  • A Plan of Action and Milestones (POA&M) only where the current program and contract rules allow one.


The purpose is not to create paperwork for its own sake. The evidence should demonstrate that cybersecurity requirements are actually implemented and maintained.


Government Oversight and False Claims Act Risk

The pause has not stopped government enforcement of contractual cybersecurity requirements. The Department continues to use self-assessments and selected government-led assessments, and recent Justice Department settlements in 2026 show that alleged failures to comply with NIST SP 800-171 requirements can create False Claims Act exposure when contract compliance representations are involved.


Contractors should therefore make sure SPRS scores, affirmations, and other statements about cybersecurity compliance accurately reflect the condition of the systems supporting the contract.


A Practical Path Forward During the CMMC Pause

The most useful strategy is to treat the pause as additional time to strengthen the compliance program rather than a reason to stop work.


  • Confirm which contracts and systems involve Federal Contract Information or Controlled Unclassified Information.

  • Review the current contractual cybersecurity clauses that apply.

  • Perform a structured NIST SP 800-171 Revision 2 gap assessment.

  • Update the SSP so it accurately describes system boundaries and implemented controls.

  • Prioritize unresolved security requirements and document permitted remediation plans.

  • Validate that technical controls and written policies match actual practice.

  • Review SPRS scores and affirmations for accuracy and supporting evidence.

  • Perform internal readiness reviews before a government or future CMMC assessment.

  • Monitor official CMMC reform announcements instead of relying on the former November 2026 Phase 2 schedule.


Organizations that need help identifying gaps or building a defensible compliance program can use My ISO Consultants' CMMC and NIST SP 800-171 consulting services for gap analysis, documentation support, implementation guidance, internal readiness reviews, and assessment preparation.


Frequently Asked Questions


Is CMMC Phase 2 still paused?

Yes. As of September 2026, the Department's official CMMC information states that the program remains paused in Phase 1 and the planned Phase 2 requirements have been suspended while the program is reviewed.


Does the CMMC Phase 2 pause eliminate NIST SP 800-171 requirements?

No. Applicable defense contractors still have contractual cybersecurity obligations, and the Department's current Phase 1 framework continues to use NIST SP 800-171 Revision 2 for Level 2 self-assessments.


Do Level 2 contractors still need to submit assessments and affirmations?

Yes, when the applicable CMMC and contract requirements apply. Under the current Phase 1 framework, Level 2 uses a self-assessment every three years plus an annual affirmation, with results recorded in SPRS.


Do contractors still need a C3PAO assessment right now?

The general Phase 2 rollout of Level 2 third-party certification requirements is suspended. Contractors should verify the requirements in each solicitation or contract and monitor official CMMC updates before assuming a third-party assessment is required or no longer relevant to future planning.


Should we wait for CMMC reform before fixing NIST SP 800-171 gaps?

No. If the requirements already apply through a contract, the obligation to protect CUI remains. Correcting known gaps now improves current compliance, strengthens cybersecurity, and puts the organization in a better position for future government or CMMC assessments.


Conclusion

CMMC Phase 2 may be paused, but the requirement to protect sensitive defense information has not been paused with it. Defense contractors should continue maintaining accurate self-assessments, implementing applicable NIST SP 800-171 Revision 2 requirements, supporting compliance statements with evidence, and monitoring official CMMC reform announcements.


If your organization needs help determining where its cybersecurity program stands during the CMMC pause, My ISO Consultants provides CMMC and NIST SP 800-171 consulting services to help defense contractors identify gaps, strengthen documentation and controls, and prepare for current and future assessment requirements.


Author: Jay Wiessner


DoD
CMMC Phase 2 is Paused

(844) MYISOPRO

PO Box 4372

Crestline, CA 92325

We service the entire United States and most countries, but we consider the following areas of California, Arizona, Texas and Nevada "Local" to us: San Bernardino County, Riverside County, Los Angeles County, Orange County, San Diego County, Ventura County, Sacramento County, San Jose, Santa Clara County, Fresno County, Phoenix Area, San Antonio, Austin, Reno and Las Vegas areas

© 2025 by My ISO Consultants

bottom of page