CMMC Self Assessment: Your Signature Is Now the Audit
With CMMC Phase 2 paused, the C3PAO is gone but the self assessment is not. It is still required, it still posts to SPRS, and an executive at your company still signs it. Here is what you now have to do.
In This Article
On July 13, 2026, the Department of War paused CMMC Phase 2, the requirement that a Certified Third Party Assessment Organization certify your Level 2 compliance. A lot of contractors read that headline and heard "the assessment is cancelled."
The assessment is not cancelled. The auditor is.
The CMMC self assessment is still required, it still gets posted to SPRS, and an executive at your company still signs it. What the pause actually did was remove the one person who would have checked your work before the government saw it.
That is a bigger deal than it sounds, and this post is about what you now have to do.
What Is a CMMC Self Assessment?
It is your own evaluation of your company against the NIST SP 800-171 Rev 2 security requirements, scored, documented, and submitted to the Supplier Performance Risk System.
For contractors handling Controlled Unclassified Information, that means all 110 controls across 14 families. You assess each one as met or not met, you calculate a score, you record the gaps you have not closed yet in a Plan of Action and Milestones, and you post the result.
None of that changed on July 13. The only thing that changed is that no C3PAO is going to independently verify it.
Who Signs It, and What That Means
Your affirming official signs it. That is a senior company representative, and their affirmation is a statement to the United States government that what you submitted is true.
False Claims Act Exposure
The Department of Justice, through its Civil Cyber-Fraud Initiative, has spent years pursuing contractors under the False Claims Act for misrepresenting their cybersecurity posture, with settlements running into the millions. That initiative is untouched by this week's news.
Before July 13, an inflated SPRS score would likely have been caught by a C3PAO during certification, embarrassingly but privately, and you would have fixed it.
Now there is no C3PAO. The next party to independently examine your score may well be the government, and by then it is not a correction. It is an allegation.
The pause did not reduce your risk. It removed the safety net underneath it.
What a CMMC Self Assessment Actually Requires
If you are doing this properly, you need four things, and most contractors are missing at least two.
- A defined scope. Which systems, people, and facilities touch CUI. If you cannot draw the boundary, you cannot assess against it, and an over-broad scope is the single most expensive mistake in CMMC.
- A System Security Plan. The SSP describes how each of the 110 controls is implemented in your environment. Not how it would be implemented in a generic environment. Yours.
- An honest score. The NIST 800-171 scoring methodology starts at 110 and subtracts for every unmet control, weighted 1, 3, or 5 points. Scores can go negative. A negative score is not a disaster. A fictional positive one is.
- A Plan of Action and Milestones. The POA&M records what is not yet met and when it will be. It is evidence of good faith, and its absence is evidence of the opposite.
Can I Still Be Audited?
Yes, and this is the question most people get wrong.
The Department kept select government led assessments. In practice that means DIBCAC, the Defense Industrial Base Cybersecurity Assessment Center. DIBCAC did not go anywhere, it was never bound by the C3PAO pipeline, and it has never been the gentler option.
So the honest position is this. You have swapped a scheduled, predictable, purchasable audit for an unscheduled one you do not control, plus personal exposure on the affirmation. If that sounds like a relaxation of pressure, read it again.
Does the Pause Mean I Can Stop?
We have run this experiment before, and we know how it ends.
CMMC 1.0 was paused in 2021. A lot of organizations treated that as permission to wait. Years later, many of them are still struggling with the foundational requirements of NIST 800-171, because the pause ended, the requirements came back, and nothing had been built in the meantime.
Cybersecurity does not get easier because a deadline moves. Deferring the work does not delete it. It converts it into technical debt, and that debt gets repaid on a compressed schedule, at a higher price, under someone else's timeline.
The contractors who come out of this well will be the ones who treat the next 60 days as build time.
What to Do in the Next 60 Days
- Scope it. Know exactly where CUI lives. Everything else depends on this.
- Write or fix the SSP. If your SSP is a template with your logo on it, you do not have an SSP.
- Re-score honestly. If your SPRS score was aspirational, correct it now, while correcting it is a decision and not a defense.
- Build the POA&M. Dates and owners, not intentions.
- Skip the C3PAO booking. That is the one cost you can genuinely defer while the review runs.
- Close the 5 point controls first. They move the score most and they are the ones that tend to be genuinely load-bearing for security, not just for scoring.
Free Resource
Know Where You Actually Stand Against All 110 Controls
If you want an honest read on where you stand, that is what a gap assessment is for. Start with our free NIST 800-171 guide to see where the gaps usually hide before an assessor does the checking for you.
Get the Free NIST 800-171 GuideFrequently Asked Questions
Is the CMMC self assessment still required?
Yes. The pause of CMMC Phase 2 removed the third party certification requirement. It did not remove the self assessment, the SPRS submission, or the affirmation.
What is a CMMC self assessment?
An evaluation of your organization against the NIST SP 800-171 Rev 2 requirements, 110 controls across 14 families for contractors handling CUI, scored and submitted to SPRS with a supporting System Security Plan and a Plan of Action and Milestones.
Who signs a CMMC self assessment?
A senior company representative, the affirming official. Their signature is an affirmation to the government that the submission is accurate.
What happens if my SPRS score is wrong?
An inaccurate score is a potential False Claims Act exposure. The Department of Justice has pursued contractors for cybersecurity misrepresentation through its Civil Cyber-Fraud Initiative. With no C3PAO reviewing the submission, an error is now far more likely to surface as an allegation than as a correction.
Can I still be audited with Phase 2 paused?
Yes. The Department retained select government led assessments, which means DIBCAC can still assess you.
Should I stop preparing for CMMC?
No. DFARS 252.204-7012 and NIST SP 800-171 Rev 2 remain in force, and CMMC completed federal rulemaking. The timeline moved. The obligation did not.
Sources
- Department of War release, "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements," July 13, 2026
- Department of War CIO, implementation memo on the pause of CMMC Phase II
- NIST SP 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- U.S. Department of Justice, Civil Cyber-Fraud Initiative
