CMMC Phase 2 is paused. Your SPRS score isn't.

A five-question self-assessment for aerospace and defense suppliers, with a scoring key and the next step for each outcome.

On July 13, 2026, the Department of War suspended Phase 2 third-party CMMC certification while a reform task force reviews the program. That single line item is the only thing that stopped.

Phase 1 self-assessment still applies. Your SPRS score still has to be current, and it has to be defensible. All 110 NIST SP 800-171 controls are still the technical baseline, so gaps are still gaps. DFARS 252.204-7012 still carries CUI safeguarding and 72-hour incident reporting. And primes are still writing flow-down requirements into subcontracts on their own timeline.

The result is a supply chain full of suppliers who think the clock stopped. It didn't. Below is a five-question check on where you actually stand, with a scoring key and the next step for each outcome.

Free download

The CMMC Status Check

Five questions, scored out of 10, with three read-your-score bands and the three things to do next in each one. Takes about two minutes.

Download the check (PDF)

No form, no gate. Open it, score yourself honestly, and act on the band you land in.

What the check asks you

  1. Have you submitted a current NIST SP 800-171 self-assessment score to SPRS?
  2. Do you have an SSP and POA&M covering all 110 controls?
  3. Do you know which CMMC level your prime contracts flow down, and where those clauses sit?
  4. Could you produce evidence (policies, configs, logs) for your weakest controls if asked tomorrow?
  5. Do you have a plan to reach full Level 2 certification once third-party assessments resume?

What's suspended, and what never was

One line item paused. Four kept moving.

Requirement Status What it means for you
Phase 1 self-assessment (SPRS) ACTIVE Your score must be current in SPRS, and it must be defensible.
NIST SP 800-171 (110 controls) ACTIVE The technical baseline hasn't changed. Gaps are still gaps.
DFARS 252.204-7012 ACTIVE Safeguarding CUI and 72-hour incident reporting still apply.
Prime flow-down clauses ACTIVE Primes set their own bar and are still writing it into subcontracts.
Phase 2 third-party (C3PAO) certification PAUSED Suspended pending reform. Expect it to return, not disappear.

The exposure isn't a deadline. It's a request you can't answer.

Defense suppliers tend to watch the federal date because it's visible. Prime contractors are more immediate. If a prime is under pressure to protect its own programs, it can set supplier requirements that are stricter or faster than the government's current rollout timeline: questionnaires, attestations, score summaries, or proof that specific controls are in place before you receive data or keep supporting a program.

That's not only a compliance issue. It's a revenue protection issue. A supplier who can't answer basic cybersecurity questions can look risky even when the formal timeline has shifted. Most businesses don't have a technology problem. They have a business problem that's showing up through technology, and here the business problem is clarity: which obligations still apply, which evidence is ready, and which gaps could affect the next contract conversation.

Next step

Book a CMMC readiness call

We'll walk your five answers with you, pressure-test the evidence behind your SPRS score, and give you a written roadmap to Level 2. No jargon, no runaround.

Use the Let's Talk form below, or call us directly at (440) 373-5805.

Monreal IT helps regulated and compliance-driven organizations regain control through cybersecurity and applied AI, enabling secure and confident operations. Our managed cybersecurity practice is built on NIST 800-171, not a cobbled-together product stack. Read the full breakdown of the pause.

Based on the Department of War's published CMMC program status as of August 2026. Program guidance is changing; confirm specific requirements with your contracting officer and prime.

Let's Talk

Tell us where to reach you and we'll be in touch ASAP.