Phase 2 Is Paused: Your Attestation Is Not.
TLDR: The C3PAO assessment requirement is paused, but your obligation to implement NIST SP 800-171 and to report a defensible score in SPRS is not. In other words, the bar for evidence has not moved, only who checks it.
What's Actually Paused
When the Department of War suspended CMMC Phase 2 in July, it suspended the mandate for third-party (C3PAO) certification assessments scheduled for November 10th, 2026.
That's the pause.
What's Not Paused
-
DFARS Clause 7012 is not paused
-
NIST 800-171 is not paused
-
Self-assessment and attestation are not paused
- The requirement of proving your controls match your SPRS score
Remember Why CMMC Exists
CISEVE has been around since before the inception of the CMMC program, and self-assessments have a track record. Too often, we saw that the reported scores in SPRS did not match reality.
The solution: require an objective third-party review to affirm an OSC's NIST 800-171 implementation.
This is why the CMMC program exists.
What is Required
What many seem to be unaware of is that pausing the C3PAO requirement moves the validation process, and the liability, squarely on to the OSC.
For those familiar, the process is quite involved.
A C3PAO assessment requires:
-
documentation of your control implementations in a System Security Plan (SSP)
-
policies/procedures that support the implementation statements
-
and artifacts/evidence (screenshots, sample logs, etc.) that demonstrate the implementation of the controls.
This may seem like a lot; however, these are required because the C3PAO and OSC need to defend the assessment conclusion against scrutiny from any possible DoW review.
Guess what is still required for an annual self-assessment?
The exact same things.
Is Your SPRS Defensible?
At the end of the day, the OSC still needs to defend its SPRS attestation. An indefensible SPRS score exposes your organization to loss of contracts and/or False Claims Act.
CMMC assessment requires the OSC to "Hash" all the documents, evidence, and reports at the end of the assessment. Therefore, we strongly recommend that an OSC does the same for their self-assessments.
Defensibility reduces risk to the organization.
Next Steps
Don't feel overwhelmed; we can help. Contact us today to learn how we can help you through the self-assessment process.
We can help you defend your SPRS attestation while you stay focused on defending our warfighters.
