Status note, updated September 2026
In July 2026 the Department of Defense suspended the transition to CMMC Phase 2, and that suspension is still in effect. New solicitations are limited to Level 1 (Self) and Level 2 (Self) assessments, third-party Level 2 and Level 3 assessments are on hold, and contracts that had called for them are being amended to remove the requirement. No resumption date has been announced.
What has not changed is the obligation underneath. DFARS 252.204-7012 remains in force, NIST SP 800-171 is still the standard it points to, and an accurate self-assessment score in SPRS is still required. Read the rest of this article with that distinction in mind: the certification regime is paused, the duty to protect CUI is not. Our guide to where CMMC Level 2 stands right now covers the suspension in more detail.
The Short Version
NIST SP 800-171 is a set of 110 cybersecurity controls published by the National Institute of Standards and Technology. CMMC 2.0 is the Department of Defense's program for verifying that defense contractors have actually implemented those controls. NIST 800-171 tells you what to do. CMMC 2.0 is how the Department intends to confirm that you did it.
NIST SP 800-171
NIST 800-171 defines requirements for protecting CUI in non-federal systems. It has been required for DoD contractors via DFARS clause 252.204-7012 since 2017. Contractors self-assess against its 110 controls and submit a score to the Supplier Performance Risk System (SPRS).
There is no routine third-party audit attached to 800-171 itself — your score is self-reported. That does not make it unverifiable: DFARS 252.204-7020 allows the government to conduct its own Medium and High assessments of a contractor's score, and those have continued throughout the CMMC suspension. Self-reported is not the same as unchecked.
CMMC 2.0
CMMC 2.0 was developed because the DoD found that self-reported SPRS scores were unreliable. Under the program as designed, the same 110 NIST 800-171 controls form the basis of Level 2, and compliance is verified by an accredited C3PAO (third-party assessment organization) for most CUI contracts rather than self-attested. Level 1 covers 15 basic safeguarding requirements and allows self-attestation. Level 3 adds 24 practices from NIST 800-172 for the most sensitive programs.
That third-party step is precisely the part now suspended. While the pause holds, new solicitations use Level 1 (Self) and Level 2 (Self), and annual affirmations continue.
Do You Need Both?
The question is really about sequence rather than choice. CMMC Level 2 does not replace NIST 800-171 — it validates it. Implementing the 110 controls is the work; the assessment is the check on that work. A contract that ultimately calls for Level 2 requires all 110 controls either way. What the suspension changes is who confirms them, and when.
If your contract references DFARS 252.204-7012 without a CMMC clause, you are required to implement and self-assess against NIST 800-171 and to maintain an accurate SPRS score. That was true before the suspension and it is true now.
Where to Start
The practical starting point for any defense contractor is a gap assessment against NIST 800-171. It gives you your current SPRS score, identifies your remediation priorities, and forms the foundation of your System Security Plan — which you will need whether your path ends in self-attestation or, once assessments resume, a C3PAO.
The pause is worth using rather than waiting out. The preparation is unchanged, and the queue for assessors will not get shorter when they restart.
Not sure which requirements actually apply to the contract in front of you? Book a confidential deal-readiness call.