AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

CMMC in 2026: The Pause Is Not a Pardon

CMMC 2026 status: Phase 2 certification is suspended, but Phase 1 self-assessments, SPRS scores and DFARS 7012 are still in force. What to do now.

Dr. Kashmala KhalidDr. Kashmala Khalid Dr. KashCo-Founder, healthcare and defense programsSeptember 2, 2026 · 6 min read

The letter and the headline arrive the same week

The owner of a 45-person cable assembly manufacturer in Ohio reads two things on a Tuesday. The first is a trade-press headline: CMMC Phase 2 suspended. The second is a letter from the prime contractor's supplier quality manager. It asks for the company's current SPRS score, the date it was posted, and the name of the official who affirmed it, by the 30th.

His nephew runs IT, three days a week, between a contract at the hospital and the family's other business. The nephew reads the headline and says the pressure is off. The owner reads the letter and is not so sure. He calls the prime's supplier quality manager, a woman who has been doing this for twenty years, and asks whether the pause changes anything.

"For you? No. Score, date, name. By the 30th."

He asks what happens if there is no score. She is polite about it. The prime cannot award a purchase order for a contract that requires the score to a supplier who does not have one, and the harnesses on the current program are due to move to a new contract in the spring.

The company has posted a score once, in 2023, and nobody can find the assessment it came from. The drawings from the prime arrive by email and get printed for the shop floor. Some of them are marked CUI. Most of the people who handle them have never heard the term.

The pause, in plain words

CMMC is the Cybersecurity Maturity Model Certification, the Department of Defense's way of checking that contractors actually protect the information the government shares with them.

CUI is controlled unclassified information: not secret, but sensitive enough that the government controls how it is handled. Drawings and specifications on a defense program are the usual examples.

NIST SP 800-171 is the list of 110 security requirements CMMC Level 2 measures against. DFARS 252.204-7012 is the contract clause that has required those 110 since 2017, and it is unchanged.

Phase 1 began on 10 November 2025 under the 48 CFR rule. It requires a self-assessment against 800-171, a score posted to SPRS, and an annual affirmation signed by a senior official.

Phase 2 would have put third-party certification by a C3PAO, a certified assessor firm, into new solicitations from 10 November 2026. On 13 July 2026 the DoD suspended Phase 2 pending a Reform Task Force review.

So the pause removes one thing: the outside examiner. The requirements, the score, the affirmation and the clause all stand. A pause is not a pardon; it is time to prepare while the queue is short.

The numbers that matter

The 48 CFR CMMC rule took effect on 10 November 2025, and Phase 1 requires a self-assessment posted in SPRS with annual affirmation as a condition of award, per the Department of Defense's 2025 rule. That is what the prime's letter is enforcing.

Phase 2, scheduled for 10 November 2026, was suspended by the DoD on 13 July 2026 pending a 60-day Reform Task Force review, according to the Department's 2026 announcement. The third-party assessment moved; the underlying obligations did not.

A defined CUI enclave can cut the scope of compliance from hundreds of endpoints to as few as 20, according to industry MSP estimates published in 2026. Treat that as a range, not a promise, and as the reason most 45-person shops should not try to secure the whole company to 800-171.

What to do this week

  1. Find the CUI. Follow one drawing from the prime's email to the shop floor and back: which inboxes, which shared drives, which printers, which phones. Write down every stop. (CIS 3 Data Protection)
  2. Decide the boundary. Either every system in the company meets 800-171, or CUI lives only inside a defined enclave and the rest of the business stays out of scope. For a company this size, the enclave is nearly always the answer. (CIS 3 Data Protection)
  3. Put MFA on every account that can reach CUI, and restrict access to named people with a reason. "Everyone in engineering" is not a reason. (CIS 6 Access Control Management)
  4. Turn on logging for the systems inside the boundary and keep the logs where the systems' users cannot delete them. An assessor's first question about any requirement is how you know it happened. (CIS 8 Audit Log Management)
  5. Build the asset list for the boundary: every laptop, server, phone and application that touches CUI, with an owner. This list is the scope of your self-assessment. (CIS 1 Inventory and Control of Enterprise Assets)
  6. Score yourself truthfully against the 110, write a plan of action with dates for every gap, post the real number to SPRS, and reply to the prime with the score, the date and the affirming official's name. (CIS 6 Access Control Management)

Where AccuSights fits

We work the CMMC problem the way a surgeon works a case: scope first, then the procedure. Our assessment finds the CUI, draws the enclave boundary and produces the self-assessment and plan of action. Our team implements the controls at a reasonable rate, from data loss prevention and scanning to protecting the assets inside the boundary, and we can stand up a partner enclave with encrypted email for shops that would rather not rebuild their whole network. The Cyber Hygiene Test takes three minutes, and 15 minutes with an engineer will tell you whether an enclave fits.

Questions people ask

Do subcontractors need CMMC? Yes, if contract information or CUI flows down to you. The prime is required to pass the requirement to any subcontractor that will handle that information, and primes are now asking for SPRS scores because their own eligibility depends on the supply chain. A subcontractor that only receives public information and never sees a drawing or specification marked CUI may sit at Level 1, but the prime decides what flows down, not the sub.

What is an SPRS score? SPRS is the Supplier Performance Risk System, the DoD database where contractors post their NIST SP 800-171 self-assessment score. The score starts at 110 and loses one, three or five points for each requirement not met, so it can go negative. Under Phase 1 the score must be current, posted before award, and affirmed each year by a senior official at your company.

Is CMMC Level 2 self-assessment still allowed? Yes. Phase 1, in force since 10 November 2025, works on self-assessment posted to SPRS with annual affirmation. The 13 July 2026 suspension applies to Phase 2, which would have put third-party C3PAO certification into new solicitations from 10 November 2026. For now the self-assessment is the requirement, and the affirmation makes it a signed statement to the government.

The government paused its examiner. It did not pause the people trying to steal the drawings. Prepare for the one who is still working.

Controls this post maps to

CIS 6 Access Control ManagementCIS 8 Audit Log ManagementCIS 3 Data Protection

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the HIPAA and CMMC programs. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.