CMMC Phase 2 is suspended. Your obligations are not.
What the 13 July 2026 CMMC Phase 2 suspension changed, who it affects, and what defense suppliers should do now. The safeguarding obligations are unchanged.
August 10, 2026
Under 32 CFR Part 170, a Level 2 assessment is valid for three years and a senior official has to affirm continued compliance in the Supplier Performance Risk System (SPRS) every year in between. All 110 requirements assessed against your real environment, an SPRS package built from the findings, and the same engineer keeping both current when the affirmation comes due.
You start at 110 and subtract. These three are each worth 5 points — the heaviest weighting the methodology assigns.
Score after these three
110 / 110
Answer all three to see the deduction.
Three of 110. Almost every requirement is met or it is not — only multifactor authentication and FIPS-validated encryption carry partial credit. The other 107 carry the rest of the points at risk.
In the order they actually happen, not the order that makes a proposal look tidy. Stage three produces the System Security Plan and the Plan of Action and Milestones the submission is built from. Stage four has no end date, because the obligation does not have one either.
Read The CMMCg Method in fullStage 01 · Week 1
Before anything is assessed, we establish where CUI actually lives: which systems process it, which people touch it, and which of your networks can honestly be excluded. Scope determines the size of everything downstream, which is why it is the highest-return hour in the engagement and the one most often skipped.
Who is involved: Whoever handles CUI day to day, plus IT
You receive
Scope statement and boundary diagram
A boundary diagram and written scope statement, in the form a Certified Third-Party Assessment Organization (C3PAO) expects to receive it.
A supplier who submits a 110 in March and changes identity providers in June has changed their score, and usually does not know it. When the annual affirmation comes due, a senior official signs their name to a number nobody has checked in eleven months.
We monitor the controls that drift, refresh the evidence behind them, and reconcile the SPRS entry before anyone has to sign it.
SPRS score
−128
at intake
110
held since
Fourteen families. Each square is one requirement. Pick a family to read what it covers and where suppliers usually lose the points.
Who can reach CUI, from where, and what they can do once they are in. The largest family, and it touches every system you own.
A common way to lose points here
Remote access is allowed but not routed through managed access control points.
Requirement text and counts are taken from NIST SP 800-171 Rev 2, the same index this site’s assistant answers from. Point values are the Department of Defense Assessment Methodology’s own lists (Version 1.2.1, 24 June 2020, §3.a): an unmet requirement deducts 5, 3, or 1 point from a starting 110. Multifactor authentication (3.5.3) and FIPS-validated encryption (3.13.11) are the two that carry partial credit, and are counted here at their maximum.
Large enough to hold Controlled Unclassified Information (CUI) and a prime’s attention. Small enough that compliance lands on someone who already has a full job.
and a prime has started asking what your SPRS score is, with a date attached.
and the IT director who would own this already has a full job.
and nobody who owns the number they produce or the evidence they generate.
The reference section is the product before it is a funnel. Every one of the 110 requirements is published with its text, every topic is cited to a primary source you can open, and none of it sits behind a form.
A supplier who reads this and decides they can handle it themselves has been given something useful. That is the trade. It starts where your obligation does: the Defense Federal Acquisition Regulation Supplement (DFARS) clause in your contract.
Open the knowledge baseLevels, scoping, and the current model version
Read →All 110 requirements, by family
Read →How the methodology works and how points are lost
Read →Safeguarding obligations and the 72-hour reporting rule
Read →Fourteen families, each with the requirement text for every requirement in it.
Thirty minutes with an engineer who does the assessments, not a sales rep. You leave with your scoping boundary sketched and the requirements costing you the most points named.
NDA signed before anything technical. No cost, no obligation.