On July 13, the Department of War (DoW) suspended the CMMC Phase 2 requirement for independent Level 2 assessments, which had been scheduled to begin on Nov. 10, 2026. Phase 2 was part of the DoW’s rollout schedule for CMMC. CMMC Level 2 cybersecurity requirements remain in full force.
The suspension may sound like welcome news for defense contractors and their managed service providers.
- The $30,000 to $100,000 cost of a third-party assessment may disappear.
- Contractors may no longer have to prepare for an intimidating review by a Certified Third-Party Assessment Organization (C3PAO). Smaller companies may feel that the pressure to comply has eased.
That conclusion is dangerous.
What really changed with CMMC and what didn’t
Independent assessments may be suspended, but defense contractors must still comply with the cybersecurity requirements in their contracts and legally attest to their compliance. They must still assess themselves, support their conclusions with evidence, and legally affirm the accuracy of their results.
The biggest change may be that contractors, and the MSPs advising them, will now carry more of the risk themselves.
The assessment requirement changed. The contract requirements did not.
The DoW criticized the existing assessment model for creating “prohibitive compliance costs and bureaucratic burdens” that discouraged innovative and nontraditional companies from participating in the Defense Industrial Base (DIB). It also announced a 60-day review of the program.
As part of the suspension, requirements for assessments by Certified Third-Party Assessment Organizations (C3PAO), are being removed from current and future solicitations.
But the underlying cybersecurity requirements remain.
Defense contractors subject to DFARS 252.204-7012 must still implement the requirements in NIST SP 800-171 Revision 2. They must still:
- Protect Covered Defense Information (CDI), a subset of Controlled Unclassified Information (CUI)
- Only use FedRAMP cloud services for CDI/CUI
- Report qualifying cyber incidents within 72 hours and preserve evidence when required
- Flow applicable requirements down to subcontractors
DFARS 252.204-7012 appears in more than 80% of defense contracts. Changing the CMMC assessment process does not remove the clause or reduce the contractor’s responsibility to comply with it.
CMMC was never the source of the requirements
Many contractors think of CMMC as a new cybersecurity regulation. It is more accurate to describe CMMC as a method for verifying existing contract requirements.
The requirements in DFARS 252.204-7012 have appeared in defense contracts since 2017. Contractors accepting those contracts were already agreeing to protect sensitive information by implementing NIST SP 800-171 and its accompanying assessment guide.
The honor system was not working.
Government assessments found that many contractors claiming compliance had not fully implemented the required safeguards. Some had unsupported self-assessment scores. Others misunderstood the scope of the information and systems they were required to protect.
CMMC added a more structured assessment process, including detailed scoping and assessment guides, 320 assessment objectives, documentation requirements and, for many Level 2 contractors, independent validation.
Suspending independent assessments does not return contractors to a world without accountability. It places more importance on the accuracy and defensibility of their self-assessments.
‘Self-assessment’ does not mean informal
Under the revised approach, solicitations requiring CMMC Level 2 Self will still require contractors to conduct comprehensive assessments using the CMMC Level 2 Scoping Guide and CMMC Level 2 Assessment Guide.
An authorized company official must then affirm the assessment in the Supplier Performance Risk System (SPRS). That is not a casual administrative step.
The affirmation represents that the contractor has accurately assessed its cybersecurity program and can support its conclusions. An incomplete, exaggerated or unsupported assessment can create contractual and legal exposure.
The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) can continue performing random or targeted assessments. Prime contractors may also require subcontractors to validate their SPRS CMMC self-assessment status before awarding or continuing work.
A contractor may avoid a scheduled C3PAO assessment and still face a government review that reveals its self-assessment was wrong.
False Claims Act risk has not been suspended
The Department of Justice’s Civil Cyber-Fraud Initiative has already demonstrated that cybersecurity misrepresentations can lead to False Claims Act cases.
In one recent settlement, Navy contractor LOGZONE agreed to pay $507,144 after reporting a perfect NIST SP 800-171 self-assessment score of 110. A DIBCAC assessment reportedly determined that its actual score was -170, close to the bottom of the scoring range.
The important issue was not simply that the contractor had cybersecurity deficiencies. The government alleged that the contractor fraudulently claimed compliance it could not support.
Eliminating a mandatory independent assessment does not eliminate that risk. Contractors must still prove that each requirement has been implemented. They must also maintain policies, procedures, system configurations, records, logs, screenshots and other objective evidence showing that the safeguards operate as represented.
A self-assessment based on assumptions, verbal assurances or a checklist completed without evidence can expose the company and the person signing the affirmation.
Contractors may be creating protected information
One of the most common mistakes in defense contractor scoping is assuming that information is protected only when the government or a prime contractor sends a file marked as Controlled Unclassified Information (CUI).
DFARS 252.204-7012 is broader because of its requirement to protect Covered Defense Information (CDI), a subcategory of CUI.
CDI can include documents, drawings, machine code, testing results, reports and other information created by a contractor while performing a defense contract.
A contractor may therefore create protected information even when it never receives a marked CUI document.
This matters because the systems used to create, process, store or transmit that information can become part of the assessment scope. Those systems may include workstations, servers, cloud applications, file-sharing platforms, backup services and remote-access tools.
An inaccurate understanding of the data can lead to an inaccurate scope. An inaccurate scope can invalidate the entire self-assessment.
MSPs remain part of the assessment
MSPs, MSSPs, cloud providers and other external service providers do not automatically fall outside of the assessment merely because C3PAO reviews have been suspended.
When an MSP manages technology that implements or supports a CMMC requirement, its services remain relevant to the contractor’s self-assessment.
The MSP should provide a Customer Responsibility Matrix (CRM) identifying which party is responsible for each applicable assessment objective. The contractor must understand what the MSP performs, what the contractor must perform and where evidence for each responsibility is maintained.
The MSP also needs to participate directly in the client’s self-assessment by producing documentation, demonstrating configurations, explaining processes and providing evidence.
The contractor must be able to show exactly how each requirement is implemented and who is accountable for it at a level that will sustain a random or targeted DIBCAC audit.
For more on this topic, visit the ChannelPro Compliance and Regulations Answer Center.
Not every MSP security tool must be FedRAMP
Another area of confusion involves the cloud services used by contractors and MSPs.
Cloud services that process, store or transmit CDI/CUI must meet FedRAMP Moderate requirements or an accepted equivalent. This includes email, file storage, file sharing, backups, ERP systems, Operational Technology, test equipment and more.
However, tools that MSPs use to process only Security Protection Data (SPD) do not have the same FedRAMP requirement.
SPD may include system configurations, vulnerability results, security alerts, passwords, event logs and other information generated by security products or used to protect the contractor’s environment.
Depending on how they are configured and used, this distinction allowing non-FedRAMP tools may apply to:
- Remote monitoring and management (RMM) platforms.
- Vulnerability scanning tools.
- Documentation systems.
- EDR and MDR services.
- SIEM platforms.
- Other security management tools.
The key question is not simply whether a tool supports security. The contractor and MSP must determine whether the service accesses, processes, stores or transmits CDI contained in client files.
Correctly distinguishing CDI from SPD can reduce unnecessary cost and complexity. Getting the distinction wrong can leave protected information in an unqualified service.
MSPs face a conflict when assessing their own work
The suspension of independent assessments creates a difficult situation for MSPs.

Mike Semel
Contractors may increasingly ask their MSPs to determine whether they comply with CMMC. But the MSP may be evaluating controls that it selected, configured, manages and bills the client to operate.
That creates an inherent conflict.
An MSP may be asked to assess whether its own services meet the requirements and then provide conclusions the client will use to support a legal affirmation.
Should a later DIBCAC assessment determine that the controls were not implemented or the self-assessment was unsupported, the contractor could face penalties, lost contracts or False Claims Act allegations.
The contractor may then claim that it relied on the MSP’s advice. This could cause the MSP to face False Claims penalties if it is determined that the MSP caused its client to attest to misrepresent cybersecurity compliance.
The MSP’s Errors and Omissions (E&O) insurance or master services agreement (MSA) may not provide adequate protection. This is especially true when the MSP performed work resembling a formal CMMC assessment without being certified CMMC assessors.
Independent validation still has value
A government mandate is not the only reason to use an independent certified assessor.
An independent CMMC Certified Assessor can challenge the scope, review the evidence and identify unsupported conclusions before the contractor submits its affirmation. That review can help the contractor distinguish between requirements that are fully implemented and those that are only partially addressed. It can also reduce the risk of an MSP assessing its own performance without independent oversight.
Contractors should not interpret the suspension as permission to stop preparing. They should use the opportunity to verify their scope, strengthen their documentation and complete an evidence-based self-assessment.
MSPs should clearly document their responsibilities, participate in client assessments and recommend independent validation before an executive signs their SPRS affirmation.
The government may change how CMMC compliance is assessed. It has not told defense contractors that cybersecurity is optional.
Independent assessments may be on hold. Contract requirements, government audits and legal accountability are not.
Mike Semel, CEO and founder of Semel Consulting, is a CMMC Certified Assessor. He is the creator of CMMC for MSPs, which provides training, a Customer Responsibility Matrix (CRM), and other templates to help MSPs support CMMC Level 2 compliance. Semel Consulting pays referral fees to MSPs and does not complete with you for products and services. Send your compliance questions to mike@semelconsulting.com.
Featured image: kaliel — stock.adobe.com











