DoW pauses CMMC Phase II implementation
On Monday, July 13, the Department of War issued guidance pausing the CMMC C3PAO assessment requirement for 60 days.
This action only impacts C3PAO assessments. Companies are required to comply with DFARS 252.204-7012 and current requirements.
This action was taken in part due to the shrinking DIB and feedback concerning the time, cost, and difficulty in meeting CMMC requirements.
In response to these concerns, the DoW paused the C3PAO assessment requirement and posted a Request for Information to SAM.gov.
See: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view. Responses are due by August 14, 2026 12:00 ET. An attachment to the RFI provides background and outlines the types of information being requested. Information being requested includes both what are the most costly and problematic requirements and what tools are being used that have made the journey easier. For details concerning both submission format and content please review the document titled – RFI – CMMC – FINAL 7-13-2026.docx
From these actions it is obvious that DoW is attempting to understand the root causes of the issue – why companies are having so much difficulty in meeting the requirements and the costs involved.
Many companies have been frustrated with the process and concerned over the time, effort and costs involved. For these companies, this is an excellent opportunity to identify impediments and a better path forward. DoW needs the DIB to provide feedback that can be reviewed and used to better the program.
What is required to comply with current DoW cybersecurity requirements?
All requirements of DFARS 252.204-7012 remain in effect. This DFARS requires companies to provide adequate security and at a minimum to comply with the requirements of NIST SP 800-171 r2. Note, there is a revision 3 to NIST 800-171 but for purposes of current DoW cybersecurity r2 is being used. In addition to meeting the requirements of NIST 800-171 r2, companies must adhere to other requirements listed in this clause.
Paragraph (l) reminds companies that there are compliance requirements beyond those listed in DFARS 252.204-7012. Different types of information may have specific security requirements. Companies must be aware of the information that is being handled and the associated security requirements. For example JCP-enhanced information must be handled and secured in accordance with JCP-enhanced requirements and if ITAR information is being handled, that information must be handled in accordance with those requirements. Paragraph (m) identifies this clause as a flowdown clause. Therefore, the clause, including paragraph (m) must be flowed down to subcontractors if Covered Defense Information will be shared/used.
As a result of this pause, there are two possible levels of certification that can be identified in solicitations/awards. They are CMMC L1 (Self) and CMMC L2 (Self). Both levels require a company to have developed a System Security Plan (SSP) and perform an assessment. Plans of Action (POA) are authorized in limited instances. Assessment scores are then posted to the Supplier Performance Risk System (SPRS). See: https://www.sprs.csd.disa.mil/
Access to SPRS requires an Active SAM, CAGE, and an individual who has a Cyber Role established.
Additionally, in addition to posting the company’s assessment score to SPRS, an Affirming Letter which is electronically submitted is required. The Affirming Letter is required by 32 CFR §170.22 and it represents that the company (organization seeking assessment – OSA) has implemented and will maintain all required CMCM security requirements to their CMMC status. The Affirming Official is “is the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA’s compliance with the CMMC Program requirements and has the authority to affirm the OSA’s continuing compliance with the specified security requirements for their respective organizations.”
The specific requirements copied from 32 CRF §170.22 are:
- Level 1 self-assessment. At the completion of a Level 1 self-assessment and annually thereafter, the Affirming Official shall submit a CMMC affirmation attesting to continuing compliance with all requirements of the CMMC Status Level 1 (Self).
- (2) Level 2 self-assessment. At the completion of a Level 2 self-assessment and annually following a Final CMMC Status Date, the Affirming Official shall submit a CMMC affirmation attesting to continuing compliance with all requirements of the CMMC Status Level 2 (Self). An affirmation shall also be submitted at the completion of a POA&M closeout self-assessment.
Companies that have questions about this change or cybersecurity requirements in general should contact the Wisconsin Procurement Institute (WPI) for assistance.