Self-Assessment Is Not a Lighter Standard
Many defense contractors read the July 13, 2026 suspension of CMMC Phase 2 as relief. For organizations with a small footprint or a simple environment, that reading often goes further. A ten-person machine shop or a two-person engineering consultancy assumes the program was designed for primes, and that a self-assessment is a lighter version of the real requirement. Both assumptions are wrong, and acting on them carries real cost.
Self-assessment did not lower the standard; it moved the burden of proof onto the organization. The Department of War (DoW) suspended third-party certification, not the security requirements behind it, and it now relies on contractor self-assessments and senior-official affirmations as the primary verification mechanism.¹ Every affirmation posted to the Supplier Performance Risk System (SPRS) is a representation the government relies on when it awards and pays a contract. The requirements behind that representation do not scale with headcount, revenue, or the complexity of the network.
The most common failure I see is not unwillingness. Organizations want to protect the information entrusted to them; they often do not know that a gap exists until someone outside the organization finds it. Under a self-assessment model, the organization is the only party positioned to find that gap before it becomes a false representation. That is a governance problem before it is a technical one, and it is the reason this article closes with a governance approach rather than a checklist.
Where CMMC Stands Today
The CMMC acquisition rule took effect in November 2025 under a phased rollout. Phase 1 began November 10, 2025, and introduced Level 1 and Level 2 self-assessment requirements into applicable solicitations.² Phase 2, which would have required Level 2 certification by a Certified Third-Party Assessment Organization (C3PAO) as a condition of award, was scheduled for November 10, 2026. Phase 3 would have added government-led Level 3 assessments in November 2027.³
On July 13, 2026, DoW suspended Phase 2 and all later milestones and directed a 60-day review by a CMMC Reform Task Force.¹ The Department cited cost, administrative burden on small and non-traditional businesses, and limited C3PAO capacity relative to the more than 100,000 contractors that would eventually require assessment.³ It also issued a public Request for Information asking which NIST SP 800-171 controls deliver meaningful risk reduction, which counsel have read as a signal that the Department may consider a narrower control set in the future.³ Department officials declined to rule out cancelling the program outright.³
On September 3, 2026, Revision 3 of DFARS Class Deviation 2026-O0025 wrote the suspension into DFARS Part 240. It permits Level 1 and Level 2 to be satisfied through self-assessment and moves automatic insertion of the CMMC clause into every contract involving Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to November 10, 2028.⁴ Until that date, program offices decide case by case which contracts carry a CMMC requirement. Contracting officers are removing Phase 2 language from existing contracts by modification before the next option period or at the next administrative modification.¹
Two obligations did not change. Phase 1 self-assessment and annual affirmation requirements remain in force, and DFARS 252.204-7012 still requires implementation of the 110 NIST SP 800-171 Rev. 2 security requirements, along with cyber incident reporting and flow-down to subcontractors.¹ ³ During the review, DoW has stated it will enforce the standard through self-assessments and select government-led assessments.¹ The suspension changed how compliance is verified; it did not change what compliance requires.
What Self-Assessment Requires
Self-assessment is a defined process in the CMMC Program rule, 32 CFR Part 170, with specific scoring, documentation, and accountability requirements.⁵ It is not a questionnaire, and it is not a statement of intent.
Level 1 (Self). Organizations that handle only FCI must meet all 15 basic safeguarding requirements of FAR 52.204-21. Every requirement must be fully implemented; Level 1 does not permit a Plan of Action and Milestones (POA&M) for open items. The organization performs the assessment annually, enters the results into SPRS, and affirms compliance annually.² ⁵ The 15 requirements cover access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. They are basic safeguards, but none of them is optional.
Level 2 (Self). Organizations that handle CUI assess against all 110 requirements of NIST SP 800-171 Rev. 2 using the DoD Assessment Methodology. Each requirement carries a weighted value, and the methodology produces a score from -203 to 110.⁶ A score of 110 yields Final status. An organization may hold Conditional status with a minimum score of 88 and a POA&M limited to the items the rule permits, and it must close those items within 180 days. The self-assessment is repeated every three years, and the affirmation is annual.² ⁵ The POA&M closeout assessment must be performed in the same manner as the initial assessment.²
Documentation. A System Security Plan (SSP) must support the self-assessment by describing the assessment scope, the system boundary, and how each requirement is implemented. Any reviewer or investigator will compare the posted score against the SSP and the underlying evidence. A score without supporting artifacts, such as configuration exports, access reviews, training records, and logs, is not defensible.
Affirmation. A senior official, the Affirming Official, must attest in SPRS that the organization meets the requirements and will continue to meet them. That affirmation is required at each assessment, after POA&M closeout, and every year in between.⁵ It is a personal accountability mechanism, not an administrative formality, and the official who signs it should understand the evidence behind it.
These requirements are identical whether the organization is a prime with a dedicated security operations center or a subcontractor whose IT is managed part-time by an office manager. The rule specifies what must be true; it does not adjust that standard for the resources available to make it true.
Why Size and Complexity Do Not Change the Requirement
The CMMC rule contains no small-business tier, no reduced control set for simple environments, and no materiality threshold. The requirements attach to the information, not to the organization. An organization that processes, stores, or transmits CUI must implement the same 110 requirements whether it employs 12 people or 12,000.
Scope is the legitimate lever. Size and complexity affect the assessment scope, not the standard. A small organization with a well-defined enclave may have fewer assets in scope, which can reduce implementation cost. The organization must document and defend that boundary in its SSP. Scoping does not allow an organization to mark a requirement as not applicable because the environment is small or the team lacks a dedicated security function.
Outsourcing does not transfer the obligation. Smaller organizations often rely on a managed service provider or commercial cloud tools, and that reliance does not reduce what must be true. DFARS 252.204-7012 requires the contractor to ensure that a cloud service provider storing covered defense information meets security requirements equivalent to the FedRAMP Moderate baseline.⁸ The contractor, not the provider, makes the representation in SPRS. A simple environment built on the wrong service can still fail the requirement.
The obligations travel down the supply chain. DFARS 252.204-7012 must be included in applicable subcontracts without alteration, and prime contractors remain responsible for flowing cybersecurity requirements to suppliers that handle FCI or CUI.³ ⁸ A small subcontractor inherits the same requirements as the prime it supports. Incident obligations travel with them: the clause requires reporting within 72 hours of discovering a cyber incident and preserving images of affected systems for at least 90 days.⁸ Those obligations assume capabilities to detect and document an incident that many small organizations have not built.
Enforcement history follows the same logic. MORSECORP, Inc., a Cambridge, Massachusetts defense contractor, agreed in March 2025 to pay $4.6 million to resolve False Claims Act allegations tied to its cybersecurity obligations.⁶ The company had posted an SPRS score of 104; a third-party consultant later calculated a score of -142, and the company did not correct its posted score for almost a year.⁷ The Department of Justice continues to pursue inaccurate cybersecurity representations through its Civil Cyber-Fraud Initiative, and counsel have noted that reliance on self-attestation may increase that exposure.³
The Phase 2 suspension removed the independent check that would have identified an inflated score before award. That change places more responsibility on the Affirming Official at every organization, regardless of size.
The Governance Gap Behind Inaccurate Affirmations
An inaccurate SPRS score rarely begins as a deliberate misstatement. It usually begins as a governance gap: the people who score the controls, the people who operate them, and the official who affirms them are working from different pictures of the environment.
In larger organizations, that gap takes the form of siloed functions. Privacy may sit with the legal team, risk management with a GRC team or a separate enterprise risk management program, and security may operate in isolation from the parts of the organization deploying new technology. Each function holds a piece of the evidence; no single function holds the complete picture. When a self-assessment is assembled from those pieces independently, a missing control may not surface until an investigator or a whistleblower finds it.
Smaller organizations face the same gap in a different form. The silos are not separate departments; they are separate responsibilities held by a few people, often without a documented owner for each one. The office manager provisions accounts, an outside provider manages the firewall, and the owner signs the affirmation. Responsibility shifts with the size of the organization, but every organization must still understand who is responsible for each component and how those responsibilities fit together.
The second gap is timing. A self-assessment is a point-in-time measurement, while the environment it describes changes continuously. A new cloud application, a departed administrator, or a lapsed configuration can invalidate a posted score within weeks. Annual affirmation cycles were not designed to detect that drift; an organization must build that detection into its own governance program.
Applying the ARISE Framework™ to Self-Assessment
The ARISE Framework™ is a unifying governance framework that brings cybersecurity, privacy, AI, and ethics into one common operating picture. It does not replace NIST or ISO requirements, and it does not change what NIST SP 800-171 or CMMC requires. Its purpose is to give every function responsible for those requirements the same view of the environment, so the organization can uncover gaps that may exist before it affirms that none do.
ARISE formalizes work that effective security leaders already perform: determining which controls are in place, where each one fits, and which pieces are missing. When an organization has the complete picture, it can see when a piece is missing. When it examines each piece independently, it may not know one is missing until the end, which in a self-assessment model may be after the affirmation has been signed.
ARISE organizes governance into seven domains. Applied to a CMMC self-assessment, each domain poses a specific question the organization should be able to answer before its Affirming Official signs.
| ARISE domain | What it asks of a CMMC self-assessment |
|---|---|
| GOVERN | Who owns each requirement, and does the Affirming Official understand the evidence behind the attestation? |
| MANAGE | Are open items tracked to closure within the POA&M window, and are resources allocated to close them? |
| IDENTIFY | Where does FCI or CUI enter, move, and reside, and which systems, people, and service providers are in scope? |
| PROTECT | Is each of the 15 or 110 requirements implemented as written, including through cloud and managed service providers? |
| DETECT | How will the organization know when a control lapses or the environment changes between assessments? |
| RESPOND | Can the organization report a cyber incident within 72 hours, preserve affected images, and correct its SPRS score promptly? |
| VALIDATE | Is every score supported by evidence an outside reviewer could examine, and is it re-validated when the environment changes? |
The value of this structure is not additional documentation. It assigns ownership across functions that otherwise score their own pieces in isolation, and it replaces a once-a-year scoring event with a continuous feedback loop. For a small organization, the seven domains may be held by three people; for a large one, by seven teams. In both cases, the question is whether those people are working from the same picture when the affirmation is signed.
What Organizations Should Do Now
The Phase 2 suspension gives organizations time; it does not give them a different target. Organizations should treat the current period as preparation for verification that will return in some form, whether through a reinstated Phase 2, a successor program, or the November 10, 2028 universal insertion date.⁴ The organizations that use this period well will not face a compressed remediation timeline when third-party assessment returns.
- Define the scope first. Inventory where FCI and CUI enter, move, and reside before scoring any requirement, because an assessment that precedes the inventory measures the wrong environment.
- Assign an owner to every requirement. Name the person responsible for each control, including controls operated by an outside provider, and record that ownership in the SSP.
- Score against evidence. Assess each requirement against artifacts an outside reviewer could examine, and reconcile the SPRS score with the SSP.
- Verify service providers. Confirm that cloud and managed service providers meet the requirements the contract imposes, and retain the documentation that shows it.
- Correct inaccurate scores promptly. Update SPRS whenever an internal review or third-party gap analysis produces a different result.
- Build detection between assessments. Establish a review cadence that identifies configuration drift, personnel changes, and new systems before the next annual affirmation.
- Prepare the Affirming Official. Brief the senior official on what the affirmation represents and the evidence behind it before each annual attestation.
- Monitor contract changes. Track solicitation amendments and modifications that remove or revise CMMC requirements, and confirm the DFARS 252.204-7012 obligations in each agreement.
Compliance performed this way is an enabler for continued work in the defense industrial base, not a burden imposed by it. Proactive governance costs less than responding to an investigation, a lost award, or a compromised program. A self-assessment conducted with the rigor of a certification assessment, inside a governance program that keeps the picture current, is the most logical investment available today, and that holds for an organization of any size.
References
- WilmerHale. (2026, July 20). Pentagon Suspends CMMC Phase 2 Requirements and Launches Review of Cybersecurity Certification Program.
- Department of War, Office of the CIO. About CMMC.
- Jenner & Block. (2026, July 14). Department of War Suspends CMMC Phase II, But Compliance Obligations Remain, As Does Enforcement Risk.
- Kiteworks. (2026). DFARS Class Deviation 2026-O0025, Revision 3: What It Actually Changes for CMMC.
- Cybersecurity Maturity Model Certification (CMMC) Program, 32 CFR Part 170.
- U.S. Department of Justice. (2025, March 26). Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations.
- Fox Rothschild. (2025, April). Government Contractors Beware: Failure to Comply with DoD Cybersecurity Requirements Can Trigger Civil FCA Liability.
- Defense Federal Acquisition Regulation Supplement. 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.


