APTSecurity Management

Compliance Advisory

CMMC Readiness and NIST 800-171 Support

CMMC Phase 2 was suspended in July 2026, but DFARS 252.204-7012 and 252.204-7021 remain in force. You still owe a NIST SP 800-171 self-assessment, a System Security Plan, a POA&M, an SPRS score and an annual affirmation. APT does that work.

On 13 July 2026 the Department of War suspended CMMC Phase 2 and froze Phases 3 and 4 pending a reform review. A lot of contractors read the headline and stopped.

That is the expensive misreading, so it is worth being precise about what changed.

What paused, and what did not

Paused Still in force
Level 2 (C3PAO) third-party assessment NIST SP 800-171 Rev. 2 self-assessment
Level 3 (DIBCAC) assessment System Security Plan
CMMC waivers POA&M and remediation
SPRS score posting
Annual affirmation

32 CFR Part 170, DFARS 252.204-7012 and DFARS 252.204-7021 are unchanged. What stopped is the Department requiring the higher assessment types. During the suspension, contracts may specify only Level 1 (Self) or Level 2 (Self).

So the work did not go away. The audit did. If you are subject to 7012 you still self-assess, still maintain an SSP, still post a score, and still affirm annually. A contractor who downed tools in July is out of compliance today, and the affirmation is signed by a company official who carries that.

Gap assessment

Where most engagements start, and the piece worth doing properly.

Scoping first: which systems handle FCI, which handle CUI, and where the boundary sits. Getting this wrong is the single most expensive mistake in CMMC, because an oversized boundary means securing systems that never needed it and an undersized one means an assessment that fails on scope before it reaches a control.

Then each of the 110 practices against what you actually do, not what a policy says. The output is a scored assessment, an SPRS number you can defend, and a prioritized list of what to fix.

Getting to Level 2

Remediation, documentation, and the evidence that makes both provable.

The SSP is the document everything else hangs off, and most of the ones we see are a template with a company name in it. It needs to describe your system, in enough detail that a stranger could tell whether a control is really in place.

The POA&M is where honesty pays. A plan with real dates and real owners is worth more than a document claiming full compliance that falls apart under a question.

Free tools

Eight of them, no signup, built for exactly this work: readiness check, SPRS calculator, CUI identifier, SSP scaffolder, POA&M builder, practice lookup, asset categorizer, and a flow-down letter generator.

They are on the tools page. Use them without talking to us.

If the review brings CMMC back

Nothing you do now is wasted. The self-assessment work is the same work a certification assessment would check, so a contractor who kept going is ready and one who stopped starts from behind, with less notice.

Scoping is a two-sided risk. Draw the boundary too wide and you pay to secure systems that never needed it. Draw it too narrow and the laptop nobody mentioned is what an assessor finds.

Tell us what triggered the search.

An audit, a renewal, a customer questionnaire, or plain curiosity about what an attacker would find.