Defense Contracting

CMMC Phase II Is Paused. NIST 800-171 Readiness Still Matters.

Published July 27, 2026

On July 13, 2026 the Department of Defense (referred to in current communications as the Department of War, or DoD/DoW) announced a pause on CMMC Phase II requirements while the program is under review. The announcement does not eliminate the obligation to protect Federal Contract Information (FCI) or Controlled Unclassified Information (CUI); it changes the near-term validation model. Phase I self-assessment obligations remain in place, and NIST SP 800-171 Rev. 2 remains the operative standard behind the DFARS 252.204-7012 safeguarding clause. Contractors should read this as a timing shift, not a policy reversal.

What was announced

The July 13, 2026 announcement suspends the Phase II CMMC requirements that would have introduced third-party assessments at broader scale. It leaves Phase I self-assessment obligations intact. Contract-specific requirements continue to be driven by the solicitation and by clauses in force at the time of award. See the official CMMC program information maintained by the DoD CIO at dodcio.defense.gov/CMMC for the current status of the program.

Language in public communications has shifted; some agencies now refer to the department as the Department of War (DoW). Contractors should track both the CMMC program pages and the DFARS clauses that appear in their own contracts, and should not rely on secondhand summaries for compliance decisions.

Phase I self-assessment remains in place

Nothing about the pause removes the Phase I self-assessment obligations. Level 1 remains an annual self-assessment against the 15 basic safeguarding requirements for FCI derived from FAR 52.204-21. Level 2 self-assessment continues to map to the 110 security requirements in NIST SP 800-171 Rev. 2, with an SSP, evidence, an SPRS score, a POA&M where allowed, and an annual affirmation by a senior official.

Level 1 — FCI safeguarding

Level 1 is the baseline: annual self-assessment against the 15 FCI-focused safeguards. These cover fundamentals like access control, media protection, physical protection, system and information integrity, and identification and authentication for federal contract information. Contractors that only handle FCI can meet Phase I with a documented, credible self-assessment and an SPRS submission.

Level 2 — NIST SP 800-171 Rev. 2

Level 2 self-assessment is tied to the 110 security requirements in NIST SP 800-171 Rev. 2. Contractors handling CUI need:

  • A current, defensible System Security Plan (SSP) describing how each 800-171 requirement is met.
  • Evidence backing each control — logs, configurations, policies, tickets, screenshots — organized so someone else can find it quickly.
  • An SPRS score that reflects the environment as it actually exists today, not a legacy snapshot.
  • A Plan of Action & Milestones (POA&M) for the controls where remediation is permissible, with realistic dates and owners.
  • An annual affirmation of compliance signed by a senior official.

A stale SSP or an SPRS score that no longer matches production is a common finding during prime-contractor due diligence, and it does not become less risky because CMMC Phase II is paused — if anything, it is more visible now.

Why 800-171 readiness still matters

The pause changes the validation model, not the substance. DFARS 252.204-7012 continues to require adequate security measures aligned to NIST SP 800-171, prime contractors continue to ask subcontractors about their posture, and the underlying risks to FCI and CUI — spearphishing, credential theft, misconfigured cloud storage, unmanaged endpoints — do not pause with the program. Contractors that continue to close gaps now will be in substantially better shape when Phase II or its successor becomes active, and they remain competitive for solicitations that reference 800-171 today.

What to do right now

  1. Refresh the SSP against the current 800-171 Rev. 2 requirements and how the environment operates today.
  2. Re-score SPRS honestly and submit updates when the score changes materially.
  3. Continue closing POA&M items on schedule; do not let the pause become an excuse to slow remediation.
  4. Run the annual affirmation process on time with the appropriate senior official.
  5. Read every new solicitation for contract-specific security requirements — assumptions from one contract do not carry to another.
  6. Monitor official DoD/DoW communications for changes to Phase II timing and scope.
Need a fresh readiness view?

Need help validating your NIST 800-171 or CMMC readiness posture? Book a readiness call.

Do not conclude certification is gone for good

The most dangerous interpretation of the announcement is that certification is permanently unnecessary. It is not. The program is under review; obligations to protect FCI and CUI remain; and contract-specific validation requirements are still driven by the solicitations that appear each week. Treat the pause as breathing room to strengthen the underlying 800-171 posture, not a reason to unwind it.

Related ControlSolid resources

Authoritative sources