top of page

CMMC Phase 2 is Paused: Why NIST SP 800-171 Compliance Still Matters for Defense Contractors | My ISO Consultants

  • Writer: My ISO Jay
    My ISO Jay
  • Jul 14
  • 5 min read

CMMC Phase 2 Paused: Why NIST SP 800-171 Compliance Still Matters for Defense Contractors

Recent Department of Defense (DoD) announcements regarding the Cybersecurity Maturity Model Certification (CMMC) program have created significant discussion throughout the Defense Industrial Base (DIB). The Pentagon has suspended the planned rollout of CMMC Phase 2 requirements and launched a comprehensive review of the program, causing many contractors to wonder whether cybersecurity requirements have been relaxed or postponed. The answer is clear: they have not. While the certification component of CMMC is under review, the underlying cybersecurity requirements remain firmly in place.


For organizations performing defense work—or seeking future Department of Defense contracts—the most important takeaway is:

NIST SP 800-171 remains a contractual requirement, and compliance is still expected even though CMMC Phase 2 is Paused.

What Has Changed?

Under the original rollout plan, CMMC Phase 2 was scheduled to begin on November 10, 2026. This phase would have required many contractors handling Controlled Unclassified Information (CUI) to obtain an assessment from a Certified Third-Party Assessment Organization (C3PAO). The DoD has now suspended those Phase 2 requirements while conducting a top-to-bottom review of the program.


According to the Pentagon, the review is intended to address concerns regarding compliance costs, assessment capacity, administrative burden, and barriers to entry for small businesses and non-traditional defense contractors. However, the DoD has also emphasized that cybersecurity remains a critical requirement and that contractors are still responsible for protecting federal information.


What Has Not Changed?

One of the most common misconceptions is that CMMC and NIST SP 800-171 are different cybersecurity requirements. In reality, most organizations pursuing CMMC Level 2 compliance must implement the same 110 security controls contained in NIST SP 800-171.


The major difference is how compliance is validated:

  • CMMC Phase 2: Third-party certification by an accredited assessor.

  • NIST SP 800-171: Organization self-assessment and self-attestation.

  • Both: Require implementation of the same fundamental security controls for protecting CUI.


In other words, the requirement to implement security controls has not disappeared. The certification requirement has merely been paused pending the DoD's review.


Self-Attestation Requirements Still Apply

A key point often overlooked in the recent headlines is that the DoD did not suspend existing self-assessment requirements. The Pentagon specifically stated that Phase 1 requirements remain in force, even while the future of Phase 2 is being evaluated.


Phase 1 began on November 10, 2025 and runs through November 9, 2026. During this period, applicable contractors must continue performing required self-assessments and maintaining their compliance affirmations. Organizations handling Controlled Unclassified Information (CUI) are expected to assess themselves against the same 110 NIST SP 800-171 requirements that would have been evaluated during a CMMC Level 2 certification assessment.


The important distinction is that, for now, organizations may be able to continue relying on self-attestation rather than obtaining a third-party certification. The obligation to implement the controls and accurately represent compliance remains.


Why Defense Contractors Should Not Slow Down

Some organizations may view this pause as an opportunity to postpone cybersecurity initiatives. That would be a costly mistake.

Defense contractors remain responsible for protecting Controlled Unclassified Information and meeting contractual cybersecurity obligations. The suspension of certain certification requirements does not eliminate the risks associated with non-compliance, including:

  • Contractual noncompliance

  • Increased cybersecurity risk

  • Supply chain scrutiny from prime contractors

  • Potential loss of future contract opportunities

  • Legal liability associated with inaccurate compliance representations


Prime contractors are unlikely to reduce their cybersecurity expectations simply because portions of CMMC are under review. If anything, many primes will continue to demand evidence of NIST SP 800-171 compliance from suppliers and subcontractors.


Expect Continued Government Oversight

While the future structure of CMMC is under review, contractors should not assume that oversight efforts will decrease. In fact, existing government oversight mechanisms may become even more important if third-party certification requirements are reduced or delayed.


The Department of Defense has repeatedly emphasized that the requirement to protect CUI remains unchanged. The suspension of CMMC Phase 2 did not eliminate cybersecurity obligations; it simply paused one method of verifying them.


Organizations should continue to expect scrutiny through existing mechanisms such as:

  • SPRS assessment submissions and affirmations

  • Contracting Officer reviews

  • Prime contractor supply chain oversight

  • DCMA and DIBCAC cybersecurity assessments

  • Targeted reviews of contractors handling sensitive information


Even before CMMC existed, the government had mechanisms for evaluating NIST SP 800-171 compliance. Those tools remain available today and may become increasingly important as the DoD evaluates alternatives to widespread third-party certification.


For that reason, contractors should operate under the assumption that their System Security Plan (SSP), Plan of Action & Milestones (POA&M), policies, procedures, technical controls, training records, and assessment evidence may be reviewed at any time.


The False Claims Act Risk Is Growing

An important consideration that many contractors overlook is the potential application of the False Claims Act (FCA) to cybersecurity compliance.

Over the past several years, the federal government has demonstrated an increasing willingness to pursue contractors that inaccurately represented their cybersecurity compliance status. Cybersecurity certifications, self-assessments, attestations, and contractual representations are increasingly being treated as material statements to the government rather than administrative paperwork.


This issue becomes even more significant when self-attestation serves as the primary compliance mechanism.


When an organization submits a NIST SP 800-171 self-assessment score, records information in SPRS, or affirmatively represents compliance with contract requirements, the government reasonably expects that those representations are supported by objective evidence. If a contractor knowingly exaggerates its compliance posture, conceals significant deficiencies, or makes inaccurate compliance affirmations, it could face consequences that extend far beyond a failed audit.


In many respects, the suspension of third-party certifications increases the importance of accurate self-attestations. If the government relies more heavily on contractor affirmations, it also has a stronger incentive to verify those representations through DCMA reviews, DIBCAC assessments, contractual oversight activities, and enforcement actions where appropriate.


The message for defense contractors is straightforward:

Self-attestation should never be viewed as a paperwork exercise. It should be treated as a formal representation to the U.S. Government that can be supported by documented evidence, implemented controls, and demonstrable compliance with NIST SP 800-171.

A Practical Path Forward

Rather than slowing cybersecurity efforts, organizations should use this period to strengthen their compliance programs and improve their readiness.

Recommended actions include:

  1. Conduct a formal NIST SP 800-171 gap assessment.

  2. Update or develop a System Security Plan (SSP).

  3. Maintain a current Plan of Action & Milestones (POA&M).

  4. Implement and document missing security controls.

  5. Perform internal audits and compliance reviews.

  6. Ensure SPRS submissions and self-attestations are accurate and supported by evidence.

  7. Prepare for future government assessments, regardless of whether they come from CMMC, DIBCAC, DCMA, or another oversight mechanism.


Organizations that develop mature cybersecurity programs today will be well positioned regardless of how the DoD ultimately reforms CMMC.


Final Thoughts

The recent DoD announcement should not be viewed as a reduction in cybersecurity expectations. Instead, it represents a reconsideration of how compliance is validated. The underlying requirement to protect Controlled Unclassified Information and implement NIST SP 800-171 remains unchanged.


For defense contractors, the message is simple:

CMMC certification may be paused, but NIST SP 800-171 compliance remains essential for doing business with the Department of Defense.

Companies that continue investing in cybersecurity, maintain accurate self-attestations, and build defensible compliance programs will be in the strongest position as the DoD determines the future direction of CMMC.

At My ISO Consultants, we help organizations assess, implement, audit, and maintain NIST SP 800-171 compliance programs that support both current contractual requirements and future CMMC readiness. Whether you need a gap assessment, internal audit, remediation support, SSP development, or compliance guidance, our team can help your organization navigate the changing cybersecurity landscape with confidence.


DoD
CMMC Phase 2 is Paused

(844) MYISOPRO

PO Box 4372

Crestline, CA 92325

We service the entire United States and most countries, but we consider the following areas of California, Arizona, Texas and Nevada "Local" to us: San Bernardino County, Riverside County, Los Angeles County, Orange County, San Diego County, Ventura County, Sacramento County, San Jose, Santa Clara County, Fresno County, Phoenix Area, San Antonio, Austin, Reno and Las Vegas areas

© 2025 by My ISO Consultants

bottom of page