Compliance Advisory
CMMC Readiness and NIST 800-171 Support
CMMC Phase 2 was suspended in July 2026, but DFARS 252.204-7012 and 252.204-7021 remain in force. You still owe a NIST SP 800-171 self-assessment, a System Security Plan, a POA&M, an SPRS score and an annual affirmation. APT does that work.
On 13 July 2026 the Department of War suspended CMMC Phase 2 and froze Phases 3 and 4 pending a reform review. A lot of contractors read the headline and stopped.
That is the expensive misreading, so it is worth being precise about what changed.
What paused, and what did not
| Paused | Still in force |
|---|---|
| Level 2 (C3PAO) third-party assessment | NIST SP 800-171 Rev. 2 self-assessment |
| Level 3 (DIBCAC) assessment | System Security Plan |
| CMMC waivers | POA&M and remediation |
| SPRS score posting | |
| Annual affirmation |
32 CFR Part 170, DFARS 252.204-7012 and DFARS 252.204-7021 are unchanged. What stopped is the Department requiring the higher assessment types. During the suspension, contracts may specify only Level 1 (Self) or Level 2 (Self).
So the work did not go away. The audit did. If you are subject to 7012 you still self-assess, still maintain an SSP, still post a score, and still affirm annually. A contractor who downed tools in July is out of compliance today, and the affirmation is signed by a company official who carries that.
Gap assessment
Where most engagements start, and the piece worth doing properly.
Scoping first: which systems handle FCI, which handle CUI, and where the boundary sits. Getting this wrong is the single most expensive mistake in CMMC, because an oversized boundary means securing systems that never needed it and an undersized one means an assessment that fails on scope before it reaches a control.
Then each of the 110 practices against what you actually do, not what a policy says. The output is a scored assessment, an SPRS number you can defend, and a prioritized list of what to fix.
Getting to Level 2
Remediation, documentation, and the evidence that makes both provable.
The SSP is the document everything else hangs off, and most of the ones we see are a template with a company name in it. It needs to describe your system, in enough detail that a stranger could tell whether a control is really in place.
The POA&M is where honesty pays. A plan with real dates and real owners is worth more than a document claiming full compliance that falls apart under a question.
Free tools
Eight of them, no signup, built for exactly this work: readiness check, SPRS calculator, CUI identifier, SSP scaffolder, POA&M builder, practice lookup, asset categorizer, and a flow-down letter generator.
They are on the tools page. Use them without talking to us.
If the review brings CMMC back
Nothing you do now is wasted. The self-assessment work is the same work a certification assessment would check, so a contractor who kept going is ready and one who stopped starts from behind, with less notice.
Scoping is a two-sided risk. Draw the boundary too wide and you pay to secure systems that never needed it. Draw it too narrow and the laptop nobody mentioned is what an assessor finds.
