CMMC Navigator
All insights
compliance
assurance
nist-800-171
interim-rule
7/15/2026

Maintaining Continuous Cyber Assurance During CMMC Implementation Pauses

While formal CMMC assessments may experience administrative delays, defense contractors remain obligated to maintain baseline cybersecurity standards and continuous assurance.

Understanding the challenge

Despite ongoing administrative adjustments to the Cybersecurity Maturity Model Certification (CMMC) program, particularly affecting CMMC Level 2 assessments, defense contractors must remain vigilant in upholding robust cybersecurity practices. The Department of Defense (DoD) has consistently emphasized that the underlying cybersecurity requirements, codified in DFARS clause 252.204-7012 and detailed within NIST SP 800-171, are not paused (DoD CIO). Contractors are still obligated to maintain all 110 controls, develop and update System Security Plans (SSPs), and actively manage Plans of Action and Milestones (POAMs). Furthermore, the interim DFARS rule 252.204-7019 and 252.204-7020 mandates annual self-assessments and submission of current NIST SP 800-171 scores to the Supplier Performance Risk System (SPRS), regardless of CMMC assessment availability (DoD CMMC FAQs). This continuous reporting requirement underscores the DoD's expectation for persistent cyber assurance, rather than a "check-the-box" approach tied solely to external audits, ensuring a foundational security posture even as the CMMC ecosystem matures (32 CFR Part 170).

Key takeaways
  • Maintain all 110 NIST 800-171 controls and System Security Plans regardless of CMMC phase delays.
  • Update SPRS scores regularly to reflect current security posture and ensure contract eligibility.
  • Perform required annual self-assessments and affirmations for CMMC Level 1 and Level 2.
  • Focus on continuous monitoring instead of treating compliance as a one-time event.
Evidence-backed answer

Administrative pauses in the CMMC rollout do not alleviate a contractor's duty to secure sensitive information. While the DoW CIO has suspended Phase 2 implementation and temporarily restricted procurement requirements to Level 1 and Level 2 self-assessments, existing cybersecurity mandates remain fully active [2][4]. The underlying obligations found in DFARS 252.204-7012 continue to require the protection of Covered Defense Information and rigorous cyber incident reporting [4].

Contractors handling CUI must maintain all 110 NIST SP 800-171 requirements, a System Security Plan (SSP), and up-to-date scores in the Supplier Performance Risk System (SPRS) [3]. The shift toward CMMC 2.0 emphasizes continuous monitoring and ongoing compliance rather than treating cybersecurity as a point-in-time evaluation [1][5]. Failing to maintain these standards during administrative delays creates significant regulatory and business risks, including potential exclusion from future DoD procurement opportunities [1].

During this suspension period, program managers are prohibited from designating C3PAO or DIBCAC-led assessments, but the requirement for annual self-assessments and affirmations for Level 1 and Level 2 remains a prerequisite for contract award [4][6]. Organizations must use this time to ensure their daily activities promote open communication regarding security and formalize their internal review processes to meet the scalable requirements of the three-level CMMC framework [5][6].

Citations

  1. [2] MEMORANDUM FOR SENIOR PENTAGON LEADERSHIP: Implementing Suspension CMMC-Phase II — In alignment with Pillar 3
    Tier 1
    https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf
  2. [4] Cybersecurity Maturity Model Certification Procedures — Suspension of Phased Implementation Schedule
    Tier 1
    https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf

Discussion(0)

Sign in to join the discussion.Sign in