CMMC Is Suspended — But NIST 800-171 Isn’t: What DoD Suppliers Still Owe

CMMC suspended — a machine shop manager reviews a NIST 800-171 compliance checklist on a laptop on the CNC production floor

CMMC is suspended, not canceled. CMMC suspended still leaves every control in force. The Department of Defense (DoD) paused the Phase 2 third-party audit mandate on July 13, 2026 for a 60-day review — but DFARS 252.204-7012, all 110 NIST SP 800-171 controls, your SPRS score, and annual affirmations still apply today. If a defense contract clause reaches your shop, your obligations did not change this month.

CMMC suspended — what exactly did the DoD pause?

On July 13, 2026, the DoD suspended the rollout of CMMC Phase 2 and Phase 3 through an internal memorandum (implemented by the USD(A&S) memo, sometimes cited as Memorandum 26-P-1023 — and, in a change worth noting once, now issued under the renamed Department of War). What got frozen is specific and narrow: the Phase 2 mandate that would have made a third-party C3PAO Level 2 certification a condition of contract award starting November 10, 2026. That deadline is now on hold.

In its place, the DoD opened a 60-day reform review. Responses to the Request for Information were due August 14, 2026, and a report is expected around mid-September 2026. No outcome has been announced. Here is the part contractors keep missing: the pause is on the third-party audit gate, not on the underlying security requirements. During the review, contracting officers may still designate Level 1 (Self) or Level 2 (Self) — the self-attestation machinery stays fully live.

So when you read “CMMC suspended,” read it precisely: the outside auditor is paused; the standard you are audited against is not.

Does this apply to your shop?

If you are a subcontractor or supplier to a defense prime — a machine shop, a tooling or molding house, a contract manufacturer, an engineering firm — the answer is usually yes, through flow-down. When a prime’s purchase order or contract carries DFARS 252.204-7012, that clause flows down to you. You do not have to hold a direct DoD contract to be on the hook; you only have to be in the chain that handles the covered information. CMMC suspended does nothing to loosen that flow-down.

The covered information comes in two flavors, and the difference sets your level:

  • FCI (Federal Contract Information) — information provided by or generated for the government under a contract that is not public. Protecting it is Level 1, and it is self-assessed.
  • CUI (Controlled Unclassified Information) — the sensitive stuff: technical drawings, specifications, CAD files, process data, anything marked or export-controlled. Protecting it is Level 2 and maps to all 110 NIST SP 800-171 controls.

In plain English: if the prime hands you a drawing marked CUI to make a part, you are handling CUI. A lot of small manufacturers assume “we just cut metal” exempts them — it does not. If you protect defense drawings and engineering IP, that data determines your obligations. (We cover the data-protection side of this in how to protect CAD files and engineering IP.)

What still applies — and what is actually paused

This is the whole point of the suspension: a small slice is frozen, and the rest is exactly as binding as it was in June. Here is what changed and what did not. CMMC suspended freezes the audit, not the standard underneath it.

RequirementStatus during the suspensionWhat it means for you Monday
DFARS 252.204-7012 (safeguard covered defense information + 72-hour incident reporting)Still in forceNothing changed. You must still protect CDI and report a cyber incident to the DoD within 72 hours.
All 110 NIST SP 800-171 Rev. 2 controls (14 families)Still in forceEvery control you owe at Level 2, you still owe. The technical standard did not move.
SPRS self-assessment score (DFARS 252.204-7019 / 7020)Still in forceYou must have a current score posted in SPRS to be eligible for award. Scoring runs from -203 to a maximum of 110.
Annual affirmation (DFARS 252.204-7021, self)Still in forceA senior official still affirms compliance annually — a signed statement with legal weight.
DIBCAC government-led assessmentsContinueThe government’s own assessors can and do assess you during the suspension. This audit path never paused.
Third-party C3PAO Level 2 certification (the Phase 2 Nov 10, 2026 mandate)Paused / frozenYou are not required to pass a C3PAO audit to win award — for now. Contracting officers use Level 1 (Self) or Level 2 (Self) instead.
Phase 3 rolloutPausedThe later phases are on hold pending the review outcome.

Read the table top to bottom and the pattern is obvious: five obligations stayed, two paused. The paused two are both about the third-party auditor. Everything about what you actually have to do to secure the data is untouched.

Why an honest SPRS score matters more now, not less

Here is the counterintuitive part. With the third-party audit paused, the only thing standing between your claimed compliance and reality is your own signature. You post your SPRS score yourself, and a senior official affirms it annually. No outside assessor is checking the math right now. That is exactly why CMMC suspended raises the stakes on your self-reported score rather than lowering them.

That makes a guessed or inflated score the real exposure of this period. The SPRS methodology starts at 110 and subtracts points for each control you have not fully implemented — some controls are worth 1 point, others 3 or 5, so a shop that is genuinely early can land well into the negatives. Posting a 110 when you are actually at 47 is not optimism; when you affirm it, it becomes a false statement to the federal government. That is False Claims Act territory, and it is precisely the gap the government is watching while formal audits pause.

Our take: use the suspension to make your score true, not to make it look good. A defensible, evidenced score — even a low one with a real plan of action behind it — is worth far more than a round number you cannot support.

What could change after the review?

Nobody knows yet — the report is not out. Plausible outcomes range from a revised, simpler certification model, to a phased restart with new deadlines, to reinstatement close to the original plan. What is not on the table is the one thing hopeful contractors want to hear: that the 110 controls go away. Read CMMC suspended as a timing change, not a reprieve — the security baseline underneath it never moved.

The controls trace back to NIST SP 800-171 and DFARS 7012, both of which predate CMMC by years and exist independently of it. CMMC was always the enforcement wrapper, not the requirement. Betting your shop on “CMMC suspended means canceled” is betting against a standard the DoD has reaffirmed every step of the way. Don’t bet the shop on cancellation.

What an MSP owns vs. what stays yours

Compliance work splits into pieces, and honesty about the split matters — especially because parts of it are not ours to do. Here is where QOS MSP fits and where it does not.

  • We implement and evidence the technical controls. Access control, MFA, encryption, logging and monitoring, patching, incident response, backup and recovery — the majority of the 110 are configurable, provable technical measures. We deploy them and produce the artifacts an assessor asks for.
  • We support your SPRS self-assessment and submission. We help score each control honestly against the objectives, build the System Security Plan and Plan of Action & Milestones, and assemble the evidence behind the number you post.
  • Many of these are network controls. Boundary protection, segmentation, and separating your covered environment from the rest of the business is a large share of Level 2 — the same discipline we describe in IT/OT network segmentation for manufacturers.
  • What stays with others: we are not a C3PAO or assessor — when third-party certification returns, an accredited assessor conducts it, not us. And we are not your attorney — whether a specific clause applies, how to read a flow-down, and any False Claims Act question is for qualified counsel. We route both, deliberately.

The practical starting point is a cyber risk and gap assessment that scores you against the 110 controls and hands you an honest number and a roadmap. From there, ongoing security administration keeps the controls running and the evidence current between affirmations.

When you can actually relax

Not everyone reading this needs to act on CMMC suspended right now. You can genuinely set this aside if:

  • You do no defense work — no DoD contracts and no subcontracts feeding a defense prime.
  • No DFARS clause appears in any purchase order or contract you hold. If 7012 isn’t there and never flows to you, you are outside this regime.
  • You handle FCI only, no CUI — then Level 1 (self) is your ceiling, which is a much shorter list than the full 110.

If none of those describe you, the suspension is a gift of time, not a reprieve. Use it.

Frequently asked questions

Is CMMC canceled?

No. CMMC is suspended, not canceled. On July 13, 2026 the DoD paused the Phase 2 and Phase 3 rollout for a 60-day review, and no outcome has been announced. Self-assessment continues during the pause, and CMMC is widely expected to return in some form.

Do I still need a NIST 800-171 self-assessment?

Yes. DFARS 252.204-7019 and 7020 still require a current SPRS self-assessment score to be eligible for a defense contract award. The suspension paused the third-party audit, not the self-assessment obligation.

Does DFARS 252.204-7012 still apply?

Yes, fully. You must still safeguard covered defense information and report any cyber incident to the DoD within 72 hours. Nothing about 7012 changed on July 13, 2026.

Can the DoD still audit me during the suspension?

Yes. Third-party C3PAO certification audits are paused, but government-led DIBCAC assessments continue during the suspension. The government can still assess your NIST 800-171 implementation directly.

What happens if my SPRS score is inflated?

You affirm your score annually, and a knowingly false score is potential False Claims Act exposure. The DOJ has recovered significant sums through its Civil Cyber-Fraud Initiative by settling cases where contractors misrepresented their cybersecurity compliance. Any specific False Claims Act question is for qualified counsel, not an MSP.

Should I stop preparing for CMMC?

No. The 110 NIST 800-171 controls are the same whether or not the audit is paused, and preparation work you do now counts under any reformed program. Stopping only means redoing it later under a deadline.

Our take

“CMMC suspended” is not “CMMC canceled,” and treating it as canceled is the one move that can genuinely hurt you — because the audit paused while the liability did not. If you supply the defense industrial base, the smart play during this window is to get an honest read on where you stand against the 110 controls, fix the gaps that are yours to fix, and post a score you can defend under your own signature.

QOS MSP implements and evidences the technical controls and supports your SPRS self-assessment — we are not a C3PAO and not your counsel, and we route those clearly. If you want a straight answer on your NIST 800-171 gaps, start with a cyber risk and gap assessment or just talk to us.

Put this to work in your business

Talk with a QOS engineer about what you read here — practical answers, no sales pressure.
Schedule Introductory Meeting
There is no cost or obligation.