The DoD Suspended CMMC Phase 2: What Defense Contractors Need to Do Next

The Department of Defense (DoD) recently announced the official suspension of CMMC Phase 2 requirements, halting mandatory third-party C3PAO audits while a newly formed Task Force reviews the program.

For many defense contractors, this brings a welcome sigh of relief regarding immediate audit costs. However, it is critical not to mistake a suspension of the audit process for a suspension of the laws imposing the security requirements.

What Has Changed?

  • C3PAO Audits are Paused: You are no longer required to undergo or pay for third-party CMMC Phase 2 assessments for the foreseeable future.
  • Contract Solicitations: The DoD is actively modifying current and pending contract solicitations to remove Phase 2 requirements.

What Remains Exactly the Same?

  • NIST SP 800-171 Compliance: The legal obligation to protect Controlled Unclassified Information (CUI) under DFARS 252.204-7012 remains fully active.
  • Phase 1 Self-Assessments: Contractors must still maintain accurate, honest self-attestations and submit their scores to the Supplier Performance Risk System (SPRS).

How We Are Helping Our Clients Navigate the Shift

As an MSP and compliance partner staffed with certified Registered Practitioners (RP) and Certified CMMC Professionals (CCP), our strategy is pivoting to give you the ultimate competitive advantage:

  1. Eliminating Audit Stress: We are shifting our focus away from audit preparation and entirely onto functional, robust cyber hygiene and risk mitigation.
  2. Securing Executive Liability: We ensure your mandatory Phase 1 self-attestations are fully defensible, protecting your leadership from False Claims Act risks.
  3. Optimizing Your Stack: Your security infrastructure remains your shield against real-world cyber threats, keeping your business eligible for DoD contracts without the overhead of third-party audits.

The requirement to protect our nation’s defense data hasn’t vanished, the timing around requirement for 3rd party audits and its associated cost have shifted.

Contact us here to start the conversation or if you have any questions about this update!

Frequently Asked Questions About CMMC Phase 2

If Phase 2 is suspended, can we stop implementing NIST SP 800-171 controls?

Absolutely not. The DoD suspended the third-party assessment mechanism (the C3PAO audit requirement), not the underlying security standard. Your active defense contracts still contain DFARS clause 252.204-7012, which legally mandates the protection of CUI via NIST SP 800-171.

Do we still need to submit scores to the Supplier Performance Risk System (SPRS)?

Yes. Phase 1 requirements, which govern basic self-assessments and SPRS score submissions, remain fully in effect. The government is also continuing select government-led assessments (such as DIBCAC audits).

Why should we keep paying for a certified RP or CCP if there is no official CMMC audit?

Because your executive team must still sign off on Phase 1 self-attestations. Signing a self-attestation without a certified expert ensuring your technical stack actually meets the controls opens your company up to massive legal liability under the False Claims Act.

What happens to the work we have already done toward Phase 2?

None of it is wasted. Every piece of documentation, policy, and technical control we implemented mapped directly to NIST SP 800-171. This work forms the exact foundation required for your mandatory Phase 1 compliance and ongoing data protection.

Can businesses still get a certification if they want to?

Yes, you can still audit, its just the requirement for audit that is shifted, if you want to certify, the program remains intact and no one is stopping you from moving forward and being prepared for all eventualities.