About Partners Contact Client Portal
LinkedIn Twitter
Services Industries Insights & Events Careers & Culture
Insights & Events

Services

RubinBrown specializes in providing a comprehensive range of services to meet business and personal needs. Whether you require expert tax, strategic business consulting, audit services or more, RubinBrown's team of experienced professionals are here to support you.

View All Our Services
Assurance Services
Benefit Plan Audit Services Public Company Services SOC Examinations, IT Audit, & Third-Party Risk
Consulting Services
AI & Data Services Business Process Improvement Services Business Restructuring & Bankruptcy Services Cyber Security Services Independent ERP Selection Consultants Fraud & Forensics Healthcare Consulting Services SOC Examinations, IT Audit, & Third-Party Risk Information Technology Services Litigation Services Mergers & Acquisitions Services Risk & Internal Audit Services Valuation Services
Entrepreneurial Services
Outsourced Accounting & Advisory Services
Tax Services
Federal Tax Services Private Client Services Credits & Incentives Services State & Local Tax Services
Wealth Management Services by RubinBrown Advisors RubinBrown Corporate Finance

Industries

At RubinBrown, we bring experience across a range of industries. Our experience enables our professionals to offer tailored solutions catering to the intricacies of each sector. Our professionals have years of focused engagement and skills, allowing them to navigate industry-specific challenges to benefit our clients.

View All Our Industries
Colleges & Universities Construction Financial Institutions Gaming Healthcare Law Firms Life Sciences & Technology Manufacturing & Distribution Not-For-Profit Private Equity Public Sector Real Estate Transportation & Dealerships

Careers & Culture

At RubinBrown, we are inspired team members, working as one firm, living our core values, and Being Our Best for Others while delivering totally satisfied clients. We invite you to learn more about the Firm's culture, the Be Your Best for Others mentality, and explore the available opportunities at RubinBrown.

Discover Our Culture
Baker Tilly International Campus Recruiting Diversity & Inclusion Experienced Recruiting RubinBrown Charitable Foundation Join The Team
Back to Insights

CMMC Phase II Suspended: Defense Contractors Still Must Comply with NIST SP 800-171

Contact Us

CMMC Phase II Suspended: Defense Contractors Still Must Comply with NIST SP 800-171

Contact Us

The assessors left the room. The rules did not.

Bottom Line Up Front

  • CMMC Phase II requirements are suspended. DFARS 252.204-7012 is not. The verification mechanism is under review. The security requirement is unchanged.
  • A defensible program is not a certificate. It is the ability to demonstrate, with consistent documentation and operating evidence, that your organization protects CUI as represented.
  • The False Claims Act never depended on CMMC. In June 2026, one contractor paid $507,144 over the gap between a self-reported SPRS score and what a government assessment found.

What Changed Under the CMMC Phase II Suspension

On July 13, 2026, the Department of War (DoW) announced the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II. The action was memorialized in a July 10 memorandum signed by DoW Chief Information Officer Kirsten Davies.

Phase II would have required Level 2 assessments by Certified Third-Party Assessment Organizations (C3PAOs) beginning November 10, 2026. That transition is off. Phase III and Phase IV milestones are held in abeyance until further notice. DoW established a CMMC Reform Task Force to deliver recommendations within 60 days and issued a public Request for Information seeking industry input on cost drivers and program burden.

During the suspension, contracting officers may include only CMMC Level 1 (Self) or Level 2 (Self) assessment requirements in contracts. They may not impose Level 2 C3PAO assessments or Level 3 DIBCAC assessments as contract requirements. Solicitations and contracts containing those requirements are to be amended or modified under DoW guidance.

The 60-day deadline does not mean the suspension ends on day 61. Current direction pauses milestones until further notice. DoW could extend the pause, restructure CMMC, or replace broad third-party certification with a risk-based model built on self-assessments and select government audits.

What Did Not Change: DFARS 7012 and NIST SP 800-171

DFARS 252.204-7012 remains in applicable contracts. Contractors must continue safeguarding covered defense information, providing adequate security, and reporting covered cyber incidents. NIST SP 800-171 Revision 2 remains the contractual security baseline for affected systems during the review.

Three separate obligations survive, and they come from three different places:
  • SPRS score reporting flows from DFARS 252.204-7019 and 252.204-7020.
  • The annual affirmation flows from the CMMC clause at DFARS 252.204-7021, which remains in force under Phase I.
  • Flowdown to subcontractors continues wherever the underlying clauses apply.
Contractors handling only Federal Contract Information (FCI) also have to meet Level 1 self-assessment and annual affirmation requirements remain firmly in place.

DoW says it will continue enforcing NIST SP 800-171 through self-assessments and select government-led assessments. DIBCAC remains the department's primary NIST SP 800-171 assessment capability and conducts Medium and High assessments under the DoD Assessment Methodology.

The False Claims Act Is Unaffected

In June 2026, LOGZONE agreed to pay $507,144 to resolve cybersecurity-related allegations. The settlement agreement states that the company submitted an SPRS score of 110, a perfect result on a scale that runs from -203 to 110. A later DIBCAC Medium Assessment produced a score of -170.

The allegations were settled without an adjudication of liability. The case still demonstrates the risk plainly: report a score your environment and evidence cannot support, and the government has a mechanism to act on it. That mechanism never required CMMC to exist.

How to Prepare for a DIBCAC Medium or High Assessment

Document what you are going to do. Do it. Have evidence to prove you do it.

A defensible compliance program lets an assessor trace each claimed requirement from the SPRS score, through the System Security Plan (SSP), to implementation evidence in the operating environment.

Evidence typically includes:
  • System configurations and inventories
  • Access-control records
  • Vulnerability scan results
  • Tickets and change records
  • Logs
  • Policies and procedures
  • Training records
  • Incident-response exercise artifacts
  • Interviews and technical demonstrations
The documentation must agree with the architecture and with actual practice. A polished SSP describing controls the organization has not implemented is not defensible, and it will produce a lower score.

Use NIST SP 800-171A Revision 2 and the DoD Assessment Methodology to run an evidence-based internal assessment. Mark an assessment objective satisfied only when adequate, current, attributable evidence supports it. Explicitly document your assumptions, inherited controls, service-provider responsibilities, enclave boundaries, and data flow.

Then recalculate the SPRS score from validated results. Accurately describe, prioritize, assign, and track POA&M items. Management should understand exactly what the score represents before submitting or reaffirming it.

Organizations seeking additional assurance may ask their contracting officer, program office, or DCMA contact whether a voluntary government-led NIST SP 800-171 assessment is available. DIBCAC controls selection and scheduling, so a request does not guarantee an assessment. Even when one is unavailable, preparing to the Medium or High Assessment standard tests whether your compliance position holds.

7 Steps Defense Contractors Should Take Now

  1.  Keep remediation moving. Continue closing deficiencies in access control, multifactor authentication, logging, configuration management, vulnerability management, incident response, and CUI protection.
  2. Confirm the assessment boundary. Identify where CUI enters, resides, is processed, is transmitted, and exits. Include electronic and physical data. Document external connections, service providers, remote access, administrative systems, and subcontractor dependencies.
  3. Validate the SSP against the environment. Confirm that diagrams, inventories, data flows, control descriptions, and inherited-control statements are current. Remove aspirational language unsupported by implementation.
  4. Reperform the assessment using evidence. Test the NIST SP 800-171A objectives, retain supporting artifacts, and make results reproducible. Someone other than the original control owner should challenge the evidence and the scoring assumptions.
  5. Reconcile the SPRS score and POA&M. Correct unsupported conclusions before a government assessor discovers them. Coordinate material corrections or disclosures with qualified counsel and contracting professionals.
  6. Establish continuous compliance. Review controls periodically, preserve evidence, assess significant changes, monitor subcontractor obligations, and treat the annual affirmation as a formal management representation.
  7. Respond to the RFI. DoW is actively soliciting industry input on cost drivers and program design. The reformed program will be shaped by the contractors who show up during the review window.

Conclusion

DoW may leave CMMC Phase II suspended. It could narrow the program or replace it entirely.

Either way, the obligation is the same one it has been since 2017. Build a documented NIST SP 800-171 program that supports an accurate SPRS score and can withstand a DIBCAC Medium or High Assessment.

Frequently Asked Questions

Is CMMC cancelled? No. Phase II third-party assessment requirements are suspended pending a 60-day review. Phase I self-assessment and affirmation requirements remain in effect, and contracting officers may still include Level 1 (Self) and Level 2 (Self) requirements in contracts.

Do I still need to report an SPRS score? Yes. SPRS score reporting under DFARS 252.204-7019 and 252.204-7020 was not suspended. Contractors handling covered defense information must maintain a current, supportable self-assessment score.

Can I still face False Claims Act liability? Yes. FCA exposure arises from the accuracy of representations made to the government, not from CMMC. Recent enforcement has focused on gaps between self-reported SPRS scores and what government assessments find.

The RubinBrown Cyber Security Services and Technology Consulting teams help organizations identify risks, strengthen defenses, and build lasting cybersecurity resilience through proactive strategy, education, and technical expertise.
Preparing for a DIBCAC assessment or validating your SPRS score? Contact our Cyber Security Services team for a readiness review.
 
 

Published: 07/29/2026

Readers should not act upon information presented without individual professional consultation.

Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.

 

Contact Us:

Talk to Our Experts

Ivy Dai Consultant Ivy.Dai@RubinBrown.Com 303.952.2386
Mal Hansen, CISSP Manager Mal.Hansen@RubinBrown.Com 314.290.3226
Robert Rudloff, CISSP, CISA, QSA, CMMC RPA Partner rob.rudloff@rubinbrown.com 303-952-1220

Be Your Best for Others at RubinBrown

At RubinBrown, our firm fosters a culture built upon five vision points, and are guided by our philosophy of Being Our Best for Others. Discover how you can be your best at RubinBrown today by visiting our Careers & Culture Overview for available opportunities and more.

Discover Our Culture

Join Our Mailing List

RubinBrown periodically sends breaking regulatory updates, technical summaries, industry-specific information and event (in-person and virtual) invitations through electronic newsletters.

Sign Up for Our Communications
1-800-678-3134 Certified Public Accountants & Business Consultants

Ranked a Top 50 Accounting Firm by Inside Public Accounting

Firm News Disclaimers Privacy Policy Client Payment © 2026 RubinBrown LLP
RubinBrown Executive Recruiting RubinBrown Advisors RubinBrown Corporate Finance