CMMC Phase 2 Is Paused , Your Self-Assessment Is Not: 5 Steps to Get SPRS-Ready Before DIBCAC Shows Up

Page: Cybersecurity and Defense Contracting
Author: Penny Marbel, JPI Worldwide
Revision date: September 17, 2026

The Department of Defense has paused the universal rollout of CMMC Phase 2 third-party assessment requirements. Class Deviation 2026-O0025, Revision 3, effective September 3, 2026, moves the date for a universal CMMC mandate to November 10, 2028.

The pause does not suspend the underlying cybersecurity obligations that apply to contractors and subcontractors handling Controlled Unclassified Information (CUI).

For organizations subject to applicable contract requirements, DFARS 252.204-7012, NIST SP 800-171 Revision 2 controls, current Supplier Performance Risk System (SPRS) information, and cyber incident reporting obligations remain operational requirements. The government also retains authority to conduct independent Medium and High NIST assessments through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) and related DoD assessment processes.

Prime contractors may also impose cybersecurity, documentation, or certification requirements that are more restrictive than the minimum government contracting officer requirement.

Quotable definition: A CMMC pause changes the timing and mechanism of certain assessments. It does not make CUI security, SPRS accuracy, or DFARS compliance optional.

This article provides five practical steps for primes and subcontractors that need to prepare for a potential government assessment while reducing operational friction across the contractor team.

Clean compliance workspace with a redacted System Security Plan and tabbed control families

1. Confirm the Contractual Cybersecurity Baseline

The first step is to identify which cybersecurity requirements apply to each contract, task order, subcontract, and information system.

Do not rely only on the current CMMC phase schedule. Review the contract file and associated flow-down requirements for:

  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.
  • NIST SP 800-171 Revision 2 requirements.
  • DFARS 252.204-7021 or other CMMC language, where incorporated.
  • DFARS 252.240-7997 or other applicable NIST assessment requirements.
  • Prime contractor security addenda and subcontractor representations.
  • Cloud, remote-access, incident-reporting, and system-boundary requirements.
  • Requirements governing the handling of CUI by lower-tier subcontractors.

The applicable system boundary must also be documented. A contractor should be able to identify which devices, users, applications, cloud services, locations, and support processes store, process, or transmit CUI.

This is particularly important for subcontractors. A prime may require a specific system configuration, assessment record, evidence package, or annual affirmation even where the current government solicitation does not require a third-party certification.

The official Class Deviation 2026-O0025 document should be reviewed with the operative contract language. The deviation does not replace contract-specific analysis.

2. Reconcile the SSP, POA&M, and Actual Environment

A System Security Plan (SSP) is not a historical narrative. It should describe the system as it exists during contract performance.

Compare the SSP to the current environment and record discrepancies involving:

  • Network architecture.
  • User accounts and privileged access.
  • Multifactor authentication.
  • Endpoint protection and configuration management.
  • Logging, monitoring, and audit retention.
  • Media handling and removable storage.
  • Remote administration.
  • Cloud service providers.
  • Incident response responsibilities.
  • Physical and environmental safeguards.
  • Personnel termination and access-removal procedures.

Each NIST SP 800-171 requirement should have a defensible implementation statement. The organization should be able to identify the responsible process owner, the supporting evidence, and any limitation or deficiency.

A POA&M should not be used to conceal an unknown condition. It should identify the deficiency, risk, responsible party, milestone, resources, and expected completion date. The status of each item should be consistent with the score entered into SPRS.

NIST describes SP 800-171 as a framework for protecting CUI in nonfederal systems and organizations. Its control families include access control, awareness and training, audit and accountability, configuration management, identification and authentication, media protection, personnel security, and system and communications protection. See the NIST SP 800-171 Revision 2 publication for the source requirements.

3. Validate the SPRS Score and Annual Affirmation

A SPRS score is an official representation of the contractor’s cybersecurity posture. It should not be treated as a one-time administrative entry.

Before submitting or affirming a score, verify that:

  1. The score corresponds to the correct system security plan.
  2. The assessed system boundary is clearly defined.
  3. The applicable NIST version is correctly identified.
  4. The score reflects actual implementation status.
  5. Any POA&M items are accurately represented.
  6. The CAGE code and related system information are correct.
  7. The affirming official understands the basis for the representation.
  8. The annual affirmation is current.

The organization should retain the calculation, supporting evidence, approvals, and change history used to establish the score. The records should be accessible to authorized personnel without disclosing CUI in unnecessary public or internal locations.

A current score does not establish that every control is operating effectively at every moment. It does establish an accountable representation that should be supported by contemporaneous records.

Where a material system change occurs, the contractor should determine whether the SSP, score, POA&M, or affirmation requires review or update. The same principle applies when a new subcontractor, cloud service, remote-access method, or technology platform enters the CUI environment.

Compliance team reviewing a dated risk register and an abstract SPRS readiness dashboard

4. Build Evidence That an Assessor Can Verify

An assessment is not satisfied by policy titles alone. Assessors may examine documents, interview personnel, review configurations, and seek demonstrations of how controls operate.

Prepare an evidence index that maps each NIST requirement to objective evidence, such as:

  • Approved policies and procedures.
  • Access-control and account-review records.
  • Configuration baselines.
  • Vulnerability and patch reports.
  • Training records.
  • Incident response exercises.
  • Backup and recovery test results.
  • System-generated logs.
  • Change-management records.
  • Physical access reviews.
  • Supplier and cloud-service documentation.
  • Security assessment reports.
  • POA&M records and closure evidence.

The evidence should be dated, attributable, and connected to the system described in the SSP. Screenshots without context may not demonstrate sustained implementation. Policies without records may not demonstrate execution.

Personnel should also understand their responsibilities. An assessor may ask an administrator how privileged access is approved, an employee how incidents are reported, or a manager how overdue remediation is escalated.

Training should therefore include controlled interviews. The purpose is not to script answers. The purpose is to ensure that personnel can accurately describe established procedures without disclosing information beyond the assessment scope.

5. Prepare for Government and Prime Contractor Review

DIBCAC or another authorized DoD assessment team may conduct a Medium or High NIST assessment independent of a contractor’s self-assessment. The assessment may include document review, discussions with personnel, verification of the SSP, and examination of how controls are implemented.

The contractor should establish a formal assessment-readiness process that includes:

  • A designated assessment lead.
  • A controlled evidence repository.
  • A document request and response log.
  • A system-boundary diagram.
  • A current asset and account inventory.
  • A schedule for control-owner interviews.
  • A process for responding to findings.
  • Legal and contractual review of disclosures.
  • Coordination with the prime contractor where flow-down requirements apply.

The organization should not provide more information than is required for the assessment. It should also avoid modifying records solely to improve appearance. Assessment records must remain accurate and traceable.

The SPRS system and applicable DoD assessment procedures should be treated as part of the contractor’s continuing compliance process, not as a final administrative step.

Prime contractors should apply the same discipline to subcontractor oversight. A prime may need evidence that a subcontractor has identified its CUI system, maintained an appropriate score, completed required affirmations, and reported incidents through the required chain of communication.

What Does the CMMC Phase 2 Pause Mean for Contractors?

The pause means that the universal Phase 2 requirement for third-party CMMC assessments is delayed. It does not remove existing contract obligations or prevent a program office, contracting officer, or prime contractor from imposing specific cybersecurity requirements where permitted.

The universal CMMC mandate is now scheduled for November 10, 2028, subject to applicable future rulemaking and contract language. Until then, each contractor should review the requirements that apply to its specific contracts and systems.

Does a Current SPRS Score Protect a Contractor From DIBCAC Review?

No. A current SPRS score documents a self-assessment position. It does not prevent the government from conducting an independent Medium or High NIST assessment where authorized.

The government may compare the score, SSP, POA&M, evidence, interviews, and observed implementation. A material inconsistency may create contractual, performance, or eligibility consequences.

What Should a Subcontractor Do When a Prime Requires More Than the Government Clause?

The subcontractor should obtain the requirement in writing, identify the affected information system, and confirm the required evidence, timing, and responsible party.

Prime requirements may include additional security controls, specific reporting formats, independent reviews, or certification expectations. The subcontractor should not assume that the current CMMC pause invalidates those requirements.

Practical Readiness Component: Five-Item SPRS and DIBCAC Checklist

Before the next assessment request, confirm that the organization can answer “yes” to each question:

  • Is the applicable contract and subcontract cybersecurity language documented?
  • Does the SSP accurately describe the current CUI environment?
  • Does the SPRS score match the SSP, POA&M, and actual implementation status?
  • Can each control owner produce dated objective evidence?
  • Can the organization explain how it will respond to a government or prime contractor assessment?

If any answer is “no,” the issue should be assigned, documented, and managed through a corrective-action process.

JPI Worldwide supports government agencies, prime contractors, and subcontractors with cybersecurity architecture, secure network implementation, access-control design, system hardening, monitoring, technical staffing, and infrastructure integration. As a subcontractor, JPI can support defined technical work packages and help reduce operational friction between program, technical, and compliance teams. Review JPI cybersecurity capabilities, government support capabilities, or use the JPI contact page to discuss the requirements applicable to your business, agency, or department.

This article is provided for informational purposes and does not constitute legal, contractual, or regulatory advice. Contractors should review their specific contract language and obtain qualified advice where applicable.

Sources