On July 13, 2026, the Department of Defense suspended the planned rollout of Phase 2 of the Cybersecurity Maturity Model Certification program while a 60-day CMMC Reform Task Force reviews the program.
That announcement may sound like a reason for defense contractors to pause. It is not. Phase 2 was suspended, not CMMC, nor the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), and neither the need for contractors to understand and accurately represent their cybersecurity posture. Phase 1 remains in effect, and the DoD has indicated that self-assessments and selected government-led assessments will continue.
For organizations in the Defense Industrial Base, the message is straightforward: accurate CMMC self-assessment matters now more than ever.
A delay in third-party assessments is not a delay in cybersecurity responsibility.
CMMC Phase 1 took effect on November 10, 2025. Depending on the requirements included in a solicitation or contract, contractors and suppliers may still need to complete a Level 1 or Level 2 self-assessment.
Long-standing DFARS requirements also remain relevant. DFARS 252.204-7012 addresses safeguarding covered defense information and cyber incident reporting. DFARS 252.204-7020 establishes NIST SP 800-171 DoD Assessment requirements, including the handling of assessment scores in the Supplier Performance Risk System (SPRS), DoD access, and applicable flowdown obligations. DFARS 252.204-7021 places CMMC requirements into covered solicitations and contracts, making it the key contractual mechanism behind Phase 1 implementation.
In other words, the Phase 2 suspension changes the near-term rollout of third-party certification requirements. It does not erase the contractual and security obligations that already exist. When third-party certification is delayed, self-assessment does not become optional. For many contractors, it becomes the primary mechanism the DoD is relying on to measure baseline cyber hygiene.
A self-assessment is not a readiness quiz.
An accurate CMMC self-assessment is a present-tense representation of what your organization has implemented—not what it plans to implement, what a policy says should happen, or what a vendor promised to configure. A defensible assessment begins with the correct scope. Organizations must identify the systems, users, facilities, processes, and assets that handle or protect FCI or CUI. From there, each applicable practice or requirement should be evaluated against actual implementation and supported by objective evidence. That evidence may include configurations, access-control records, system-generated logs, screenshots, tickets, training records, procedures, interviews, and other artifacts demonstrating that a safeguard exists and operates as described.
A written policy is useful, but a policy alone does not prove that a control is working. An accurate assessment connects three things:
- What the organization says it does
- What its technology and people actually do
- What evidence can demonstrate to an assessor or customer
If those three do not align, the assessment is not ready to support a reliable SPRS score or withstand outside scrutiny.
Why an inaccurate self-assessment creates real risk:
An overly optimistic score can feel reassuring in the short term, but it can create larger problems later.
First, it creates false confidence. If a requirement is marked as met without sufficient implementation or evidence, the underlying security gap remains open. That can leave CUI exposed while leadership believes the risk has already been addressed.
Second, an unsupported result can collapse under review. A DoD assessor, C3PAO, prime contractor, or customer may ask an organization to substantiate its answers. If the evidence does not support the claimed implementation, the organization may face corrective action, delays, lost opportunities, performance issues, or reputational harm.
Third, inaccurate representations can create legal risk. Knowingly false cybersecurity compliance claims may create exposure under the False Claims Act and the Department of Justice’s Civil Cyber-Fraud Initiative. This is not a reason to panic; it is a reason to assess carefully, document conclusions, and avoid treating compliance as a box-checking exercise.
Your SPRS score must be calculated correctly.
The SPRS score used for a NIST SP 800-171 DoD Assessment is not a percentage or a generic maturity rating. Under the DoD Assessment Methodology, the calculation begins at 110 and subtracts weighted values for requirements that are not met. Depending on the unmet requirements, a score can fall as low as -203. That weighting matters. Two organizations with the same number of unmet requirements can have very different scores because some requirements carry greater value than others. A spreadsheet assembled from memory, or a simple count of completed controls, can therefore produce a misleading result. A reliable score requires accurate scoping, requirement-by-requirement evaluation, correct weighting, and traceable supporting evidence.
NeQter Comply brings the assessment, evidence, and score together
NeQter Comply is purpose-built to help organizations manage the work behind a defensible CMMC self-assessment.
Instead of spreading requirements, responses, evidence, implementation status, and scoring across disconnected spreadsheets and shared drives, teams can manage their compliance effort in one place. NeQter Comply provides current CMMC and NIST SP 800-171 frameworks with assessment objectives, SPRS guidance, structured implementation tracking, and documentation support.As an organization evaluates its environment, NeQter Comply calculates the SPRS score using the applicable weighted methodology. Teams can see how individual gaps affect the overall score, prioritize remediation, and generate an SPRS-focused scorecard and supporting reports. That makes the score easier to understand, review, and defend before it is submitted to SPRS.NeQter Comply also helps transform a one-time assessment into an ongoing compliance process. Requirements can be tied to implementation details and evidence, progress can be tracked over time, and stakeholders can work from a shared source of truth. The result is not merely a number—it is a clearer picture of what is implemented, what remains open, and what should happen next.
Software cannot make compliance claims on an organization’s behalf, and no tool replaces informed judgment or a qualified assessor. What the right platform can do is make the process more consistent, visible, and evidence-driven. That is where NeQter Comply stands apart.