The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CMMC assessments & contract requirements · primary-sourced · last reviewed August 2026

CMMC Voluntary Assessment: Should You Get Certified During the Phase 2 Suspension?

Last updated:

Last verified: against 32 CFR Part 170, DFARS, NIST, Cyber AB, SPRS, and the July 2026 Department CMMC suspension procedures.

Editorial illustration of a CMMC voluntary assessment decision with a readiness checklist, contract document, and proceed or hold pathways

Suspension status — last verified August 29, 2026. CMMC Phase 2 is suspended. During the review, Department of War program managers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self) in new procurement requirements. New Level 2 (C3PAO) and Level 3 (DIBCAC) designations are not permitted, and no waivers are being granted. Level 2 certification assessments remain available on a voluntary basis through authorized or accredited C3PAOs. Official suspension procedures · Cyber AB July 15 statement

By The Defense Compliance Report Editorial Team · Published August 29, 2026 · Last reviewed: August 29, 2026

Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. Educational research, not legal, contractual, or compliance advice. The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.


The 45-second answer

A CMMC voluntary assessment is a formal Level 2 certification assessment you choose to buy from a C3PAO without a current written requirement for Level 2 (C3PAO). It is still available in 2026. The old Joint Surveillance version is not. Whether you should buy one comes down to four questions — and three of them have nothing to do with the Pentagon.

Here's the part that trips people up. On July 13, 2026, the Department suspended the Phase 2 transition that had been scheduled to make third-party certification a broader condition of award starting November 10, 2026. Two days later, the Cyber AB confirmed that the assessment machinery never stopped running. So both of these are true at the same time: Department program managers cannot make a new Level 2 (C3PAO) designation during the suspension, and you can still go get a Level 2 certification assessment this quarter.

There is one paperwork trap inside that sentence. The suspension memo directs active solicitations to be amended and existing contracts to be modified before the next option period or scheduled administrative modification. It does not magically rewrite a solicitation, contract, or subcontract the day the memo is issued. If your controlling document still says Level 2 (C3PAO), clarify the current requirement in writing before you change course.

Availability is not necessity. That gap is the entire decision, and it is why a page that just tells you "CMMC isn't cancelled" doesn't help you.

The four questions that actually decide it:

  1. Does a written requirement exist today — from a solicitation, a contract, a subcontract, a prime, a customer, or a board?
  2. Can you produce assessment-grade evidence right now, or would a C3PAO be discovering your homework?
  3. Will you use the status inside its three-year window, or would you be starting the clock too early?
  4. What does waiting actually cost you in deposits, deferral or cancellation fees, and lost schedule?

Answer those four and you land in one of four places.

If this is you — Your answer
If this is youYour answer
A prime, customer, or board has a written requirement with a date, and your evidence is readyProceed
The suspended November 10, 2026 transition was your only reason to buyHold — compare deferral, rescheduling, and cancellation terms
Your CUI scope, System Security Plan, or evidence isn't stable yetRedirect the spend to readiness
Your solicitation, contract, or subcontract still says Level 2 (C3PAO)Clarify in writing before you touch anything

Cost reality, up front, from the government's own model: the Department's regulatory analysis for the CMMC Program Rule put the initial Level 2 certification assessment and affirmation cycle for a small entity at roughly $101,752, of which about $31,234 is the modeled C3PAO engagement. The remaining $70,518 is organization-side planning, assessment support, reporting, and affirmation — including modeled director, IT-specialist, and external-service-provider time. And the model assumes you have already implemented NIST SP 800-171 Revision 2. It is a burden estimate, not a quote, and it is not a readiness budget. Federal Register cost model

This page separates regulation-stated requirements from The Defense Compliance Report's editorial decision method. Regulatory claims link to primary sources. Proceed, Hold, Redirect, and Clarify are editorial routing judgments, not CMMC statuses or legal conclusions.


What is a "CMMC voluntary assessment" in 2026?

Answer capsule. In 2026, "CMMC voluntary assessment" is being used for several different products. Formal CMMC self-assessments and certification assessments can produce a CMMC Status. Commercial gap assessments and mock assessments do not. The current formal third-party route is a Level 2 certification assessment performed by an authorized or accredited C3PAO — a CMMC Third-Party Assessment Organization — under 32 CFR § 170.17. The historical Joint Surveillance Voluntary Assessment route is closed to new entrants.

We keep seeing the same failure in the market: a contractor budgets six figures for "an assessment," and what they actually buy is a report that produces no official status anywhere. Or the reverse — they pay formal-assessment rates for work a readiness provider should have resolved first.

So before anything else, sort out which product you are being sold.

The Voluntary Assessment Ledger

Every "assessment" a DIB contractor can buy, perform, or receive right now, and what each one actually produces. We built this because no single page we could find distinguishes them cleanly, and the government's small-entity model separates $31,234 of C3PAO cost from $70,518 of organization-side burden. Buying the wrong category can put the expensive people on the wrong job.

What you might be buying — What it actually is — Available now? — Produces or changes a CMMC Status? — Where the result lands — Authority
What you might be buyingWhat it actually isAvailable now?Produces or changes a CMMC Status?Where the result landsAuthority
Level 2 certification assessmentFormal assessment of all 110 NIST SP 800-171 Rev. 2 requirements by an authorized or accredited C3PAOYesYes — Conditional or Final Level 2 (C3PAO)C3PAO → CMMC eMASS → SPRS32 CFR § 170.17
Level 2 self-assessmentYou assess the same 110 requirements using the incorporated NIST SP 800-171A proceduresYesYes — Conditional or Final Level 2 (Self)You → SPRS32 CFR § 170.16
Level 1 self-assessmentThe 15 basic safeguards at FAR 52.204-21(b)(1), for an FCI-only scopeYesYes — Final Level 1 (Self)You → SPRS32 CFR § 170.15
Joint Surveillance Voluntary Assessment (JSVA)The pre-rule joint DCMA DIBCAC and C3PAO pathwayNo — closed to new entrantsOnly qualifying pre-rule DIBCAC High results receive the legacy statusDIBCAC identifies and verifies the SPRS record32 CFR § 170.20
Gap or readiness assessmentA consultant measures the environment and tells you what is missingYesNoNo official CMMC status repositoryCommercial service
Mock assessmentA dress rehearsal against assessment objectivesYesNoNo official CMMC status repositoryCommercial service
POA&M closeout assessmentVerification that eligible open items were remediated within 180 daysYes, after a qualifying Conditional statusYes — can convert Conditional to FinalSame route as the original assessment32 CFR § 170.21
Level 3 certification assessmentDCMA DIBCAC assessment of 24 selected NIST SP 800-172 requirements after Final Level 2 (C3PAO)No new Department procurement designations during the suspensionYes — Conditional or Final Level 3 (DIBCAC)DCMA DIBCAC → CMMC eMASS → SPRS32 CFR § 170.18
DIBCAC Medium or High AssessmentA government-performed NIST SP 800-171 assessment under the DoD Assessment MethodologyGovernment-directed; not a C3PAO product you simply orderNot by itself, outside the narrow § 170.20 legacy pathDIBCAC → SPRS summary scoreDFARS 252.204-7020; 32 CFR § 170.20
Voluntary ESP certificationAn External Service Provider obtains its own certification to reduce repeated participation effort in customer assessmentsYes, subject to the applicable assessment pathwayYes, for the ESP's assessed scopeThe ESP's own CMMC record32 CFR § 170.19

Ledger compiled by The Defense Compliance Report from 32 CFR Part 170, DFARS 252.204-7019, DFARS 252.204-7020, and DFARS 252.204-7021. Last verified August 29, 2026.

One visibility distinction matters. Contracting officers verify required CMMC status and affirmations in SPRS. A Level 2 self-assessment is entered directly in SPRS; a C3PAO submits certification results to CMMC eMASS, which transmits the applicable data to SPRS. Do not assume a prime can simply browse another company's entire SPRS record. A prime may require CMMC UID or status evidence under a subcontract, but the direct system-access rules are narrower than the draft market language usually suggests.

Three questions to ask any vendor before you sign anything:

  1. Does this engagement produce a CMMC Status in SPRS — yes or no?
  2. Are you currently listed as authorized or accredited in the Cyber AB Marketplace, and can I verify that listing myself today? The CMMC Assessment Process v2.0 tells organizations to use the live Marketplace listing.
  3. Has any CMMC Ecosystem member who would participate in this assessment served as our consultant to prepare us for any CMMC assessment during the prior three years? That is the conflict rule in 32 CFR § 170.8(b)(17)(ii)(G).

If a vendor can't answer question one in a single word, you're not talking to the right vendor.


Is the Joint Surveillance Voluntary Assessment Program still available?

Answer capsule. No. The Joint Surveillance Voluntary Assessment pathway is closed to new entrants. Under 32 CFR § 170.20, an organization that achieved a perfect score with no open POA&M from a DCMA DIBCAC High Assessment conducted before December 16, 2024 can receive a CMMC Status of Level 2 Final (C3PAO), valid for three years from the date of that original assessment. Eligible assessments include qualifying Joint Surveillance assessments conducted under DCMA Manual 2302-01. You cannot request a new JSVA under § 170.20.

This is the single biggest source of stale information on this topic, and it's not the internet's fault. Before the Program Rule took effect, "voluntary assessment" genuinely meant Joint Surveillance in a lot of industry writing — you hired a C3PAO, DCMA DIBCAC participated, and a clean qualifying result could convert into a Level 2 status once the rule took effect. It was a real on-ramp. A lot of good writing was published about it.

Then the rule took effect and the door closed behind it. Most of that writing is still on page one.

Here is exactly what § 170.20 requires, because the conditions are strict and every one of them has to hold:

Condition — What the rule requires
ConditionWhat the rule requires
Assessment typeA DCMA DIBCAC High Assessment, including an eligible assessment conducted with Joint Surveillance under DCMA Manual 2302-01
TimingConducted before the rule's effective date: December 16, 2024
ScoreA perfect score
POA&MNone open
ScopeThe Level 2 certification scope is identical to the DIBCAC High Assessment scope
ValidityThree years from the date of the original assessment, not from the date the status later appears
Ongoing obligationAn affirmation in SPRS and annually thereafter under § 170.22

The practical implication most people miss: because the clock runs from the original assessment date, qualifying legacy statuses are expiring on a rolling basis through 2026 and 2027. If you converted a 2023 Joint Surveillance result, you may be closer to a renewal decision than you think. Check the actual CMMC Status Date and scope in SPRS before you assume you're covered.

And if a vendor is still selling you "joint surveillance" today, ask them which current section of the rule creates a new-entry pathway. There isn't one.


Can you still get a Level 2 (C3PAO) assessment when no contract requires one?

Answer capsule. Yes. On July 15, 2026, the Cyber AB stated that only Phase 2 implementation requirements were suspended and that all CMMC program elements remain operational and available — including C3PAO Level 2 certification assessments, CAICO-sanctioned training, professional exams, Registered Practitioner services, and DIBCAC's assessment of C3PAOs. The July 2026 suspension procedures constrain what Department program managers and requiring activities may newly designate in procurements. They do not close the Level 2 assessment ecosystem. Cyber AB statement · Department procedures

The mechanics are unchanged, and that matters. A voluntary assessment is not a lesser certificate or a practice run. You engage an authorized or accredited C3PAO. They assess the same 110 security requirements from the specific February 2020 edition of NIST SP 800-171 Revision 2 incorporated into 32 CFR Part 170, organized into 14 requirement families, using the assessment procedures and objectives in the incorporated June 2018 edition of NIST SP 800-171A. Results go into CMMC eMASS, which transmits the applicable data to SPRS. You end up with a Conditional or Final Level 2 (C3PAO) status associated with the covered CMMC Assessment Scope and CMMC UID information, on a three-year assessment cycle, with an annual affirmation by a senior Affirming Official. 32 CFR §§ 170.2, 170.14 and 170.17

Same rulebook. Same CMMC Status. Same obligations afterward.

The ecosystem is not sitting idle

The official July 15 snapshot proves the system is operating. It does not prove that every C3PAO has an open calendar, that market-wide wait times are short, or that pricing is falling.

Official Cyber AB snapshot — July 15, 2026 — Published count
Official Cyber AB snapshot — July 15, 2026Published count
Authorized C3PAOs110
CMMC Certified AssessorsMore than 1,000
Defense contractors at Final Level 2Nearly 2,000

The 2025 DFARS acquisition rule's pre-suspension regulatory model estimated 118,289 entities on the Level 2 certification path by Year 4. Against that modeled population, "nearly 2,000" Final Level 2 contractors is about 1.7%. That comparison is not a current backlog forecast — the rollout has since been suspended — but it shows how early the formal certification market still is. 2025 DFARS final rule

Two honest readings:

  • The verifiable read: formal Level 2 assessments are still being delivered, authorized C3PAOs exist, and issued statuses continue to flow through the program.
  • The boundary: those published counts do not establish spare capacity, a universal lead time, or a market-wide price trend. Only current quotes and calendars can answer those questions for your scope.

What we will not tell you is that assessor capacity is about to vanish or that prices are about to spike. We do not have market-wide data supporting either claim, and vendors who assert it usually do not either.

The honest part, and it costs us money to say it

A voluntary Level 2 (C3PAO) assessment is the wrong purchase for a lot of the people reading this page. Buy it too early and you start a three-year status clock before the opportunity that needed the certificate arrives. Buy it before your scope and evidence are stable and you pay formal-assessment rates to discover readiness work that a separate provider should have resolved first. We route more readers away from an assessment than toward one, and if the deciding factor for you was the suspended November 10 date, that reason no longer exists.

Now the turn, because this is exactly why timing is a variable rather than a coin flip.

The certificate has not lost every use. It has lost the original government Phase 2 deadline that was driving a lot of bookings. Those are different problems, and the second one is solvable. Once you stop asking "is independent verification good?" and start asking "what specific decision will use this status, who makes that decision, and when," the answer usually resolves in about ten minutes. That is what the rest of this page does.

If you already know your scope isn't stable, skip ahead. You don't need an assessor yet — you need a readiness engagement or readiness checklist, and buying the wrong category first is one of the most expensive mistakes on this topic.

Which provider category fits — and which doesn't

The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO or RP, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your required level and assessment type, not a checklist. Because a general answer can't resolve those facts for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the provider category to compare before you request quotes — and do not submit CUI, drawings, or sensitive contract details.


Should you proceed, hold, redirect, or clarify?

Answer capsule. Proceed with a voluntary Level 2 (C3PAO) assessment only when a written requirement or a named business use, assessment-ready evidence, and a useful three-year timing window all line up. Hold when the suspended November 10, 2026 transition was your only reason. Redirect the spend when CUI scope, documentation, implementation, or evidence is unfinished. Clarify in writing whenever your controlling contract document still says something the current Department procedures direct officials to remove or change.

Four outputs. Not "yes" and "no," because the real answers in this market are rarely binary.

  • Proceed — a real party will rely on this status, on a date you can name, and you can produce the evidence today.
  • Hold — the purchase might still make sense later, but nothing today justifies starting the clock. Compare the economic effect of deferral, rescheduling, and termination before you choose one.
  • Redirect — the money is better spent on the thing that would have caused you to fail anyway.
  • Clarify — you don't have a spending problem, you have a paperwork problem, and the first move is free.

The CMMC Voluntary Assessment Decision Matrix

This is our editorial decision method. It combines the controlling written requirement, formal amendment status, CUI scope, evidence readiness, three-year timing, cancellation economics, and assessor independence. It is not a score, a ranking, a CMMC requirement, or compliance advice, and it routes to a category, never to a named provider.

Your situation — Readiness and timing — Our read — What to do next
Your situationReadiness and timingOur readWhat to do next
A named prime, customer, board, lender, or acquirer requires current independent Level 2 statusScope and evidence are stable; the event falls inside three yearsProceedVerify the C3PAO's live Marketplace status and independence, normalize the quote, then schedule
No government designation, but leadership can name a concrete commercial use — a specific bid, teaming arrangement, or transactionReady, with a dated opportunity and named decision-makerProceed as a business decisionDocument who will rely on it, when, for what scope, and what evidence they will accept
An active solicitation still states Level 2 (C3PAO) and no amendment has been issuedReadiness may be anywhereClarifyAsk the contracting officer for the amendment and current requirement, in writing
An awarded contract or executed subcontract still contains Level 2 (C3PAO)No modification has been issuedClarifyGet the controlling party's written position; involve qualified counsel if the obligation is disputed
The suspended November 10, 2026 transition was the only reason you bookedNo other written demand; a delay is economically practicalHoldCompare deferral, rescheduling, deposit, and cancellation terms; monitor formal Department action
CUI scope, SSP, asset inventory, or network diagram is unstableThe assessor would be discovering basic gapsRedirectEngage an RPO/RP or readiness specialist first
Controls are not implemented or operating consistentlyThe need is architecture and operations, not verificationRedirectCompare an MSSP, managed-compliance provider, or CUI enclave category
Controls are largely in place but evidence is scatteredThe assessment date is not justified yetRedirectBuild an evidence workflow; evaluate a GRC platform only if the workflow problem is real
A proposed assessment participant helped prepare you for CMMC during the prior three yearsThe § 170.8 conflict rule may bar participationRedirect or replaceGet a written conflict determination and separate the roles
You handle FCI only and no CUI in the relevant environmentYour facts do not support Level 2 by themselvesDo not buy Level 2 from this pageConfirm the written requirement and scope, then start at Level 1
Your question is about an old Joint Surveillance resultIt may qualify only under the § 170.20 conditionsVerify the historical statusCheck SPRS for scope, original date, score, POA&M state, affirmation, and expiry
You're an MSP, MSSP, or other ESP serving multiple CUI clients§ 170.19 may make voluntary certification operationally usefulSeparate decisionUse the ESP analysis below rather than a buyer-only rule

Notice what this matrix does not do. It does not tell you the assessment is always worth it, and it does not tell you to cancel. Both of those answers are being sold right now by people with an interest in the outcome.

▶ Not sure which row you're in?

The Defense Compliance Report's Find My CMMC Path tool takes your required level, FCI/CUI handling, assessment type, cloud and IT environment, and contract timeline and maps them to the provider category to compare first. Free, about two minutes, no obligation, educational triage only.

Map my situation to the right provider category →

Do not submit CUI, drawings, export-controlled content, credentials, or sensitive contract details.


What does a CMMC voluntary assessment cost — and what does the official estimate actually include?

Answer capsule. The Department's regulatory impact analysis for the CMMC Program Rule models the initial Level 2 certification assessment and affirmation cycle at approximately $101,752 for a small entity and $112,345 for an other-than-small entity, rising to roughly $104,670 and $117,768 across the full three-year cycle. Only about $31,234 of the small-entity figure is the modeled C3PAO engagement. The model assumes NIST SP 800-171 Revision 2 is already implemented, so it is a regulatory burden estimate, not a market quote and not a readiness budget. Federal Register, October 15, 2024

Almost every article on this topic quotes a single six-figure number and moves on. That number is the reason contractors panic, and it is being used incorrectly.

Here is the model, taken apart.

DoD's Level 2 certification cost anatomy

Modeled component — Small entity — Other-than-small entity
Modeled componentSmall entityOther-than-small entity
Organization planning and preparation$20,699$26,264
Organization support during the assessment$45,509$28,600
Organization reporting support$2,851$2,712
Initial affirmation$1,459$2,712
Modeled C3PAO engagement$31,234$52,056
Modeled initial total$101,752$112,345
Modeled three-year total$104,670$117,768
Technical implementation included?NoNo

Source: the regulatory impact analysis published with the CMMC Program Rule, 32 CFR Part 170, Federal Register, October 15, 2024. Figures are the government's modeled burden estimates, not quotes.

Three things fall out of that table that change how you should read every price you're quoted.

First, the assessor is not the biggest modeled line item. In the small-entity model, the C3PAO engagement is about 31% of the initial total. The remaining 69% is organization-side planning, participation, reporting, and affirmation. That does not mean all $70,518 is employee payroll: the government's line items include modeled director, IT-specialist, and external-service-provider hours. It does mean a discount on the assessment fee leaves most of the modeled burden untouched.

Second, the model assumes you're already compliant. It prices verification, not implementation. If you have not implemented all 110 requirements, none of the engineering, licensing, enclave, architecture, or remediation cost appears anywhere in that $101,752. This is the single most misread number in the CMMC market, and it is why "the assessment costs a hundred grand" and "CMMC costs a hundred grand" are wildly different statements.

Third, the model assigns small entities higher organization-support cost during the assessment than other-than-small entities — $45,509 against $28,600. That is not a typo. The Federal Register does not say every small contractor will experience the same burden or explain every operational reason for the difference. The decision implication is still clear: budget the opportunity cost of pulling a small team into interviews, evidence production, remediation decisions, and assessor support.

For a fuller treatment of these figures against the rest of a real implementation budget, see our CMMC Level 2 cost guide. For the work the government's assessment estimate expressly excludes, see who to hire first for NIST SP 800-171 implementation.

Did the pause make certification cheaper?

Not according to one dated seller-side report.

At an AFCEA TechNet Augusta workshop on August 17, 2026, representatives from three assessment organizations pushed back on the SBA's half-million-dollar figure as conflating implementation with assessment. In the same session, Fernando Machado of Cybersec Investments said the pause was producing layoffs and cancellations among assessment organizations and was, at least temporarily, driving assessment prices up because lower volume works against price reduction. Other participants quoted small-business assessment fees in the $30,000 to $70,000 range. Those are attributed practitioner statements, not a market survey. National Defense Magazine, August 17, 2026

We're publishing that because it cuts against the obvious assumption, and against our own routing interest. Two separate things can happen at the same time:

  • Cancellations may open slots at some firms. That does not prove market-wide availability or a short lead time for your scope.
  • Price may not fall with the cancellations. One named practitioner and other assessment-side participants said the opposite.

That is one dated workshop report, not a market trend, and we're labeling it as one. Get real quotes. Don't assume a discount, and don't accept an urgency pitch built on a price increase nobody has documented across the market.

Normalize the quote before you sign it

Two C3PAO quotes are almost never comparing the same work. Before you accept one, break it into these lines and make each bidder fill them in:

  • C3PAO assessment fee
  • Travel and on-site costs
  • Scope assumptions, in writing
  • Number of CAGE codes and information systems covered
  • Re-evaluation allowance for NOT MET findings during the permitted window
  • POA&M closeout assessment cost, if you land Conditional
  • Rescheduling fee and notice period
  • Deposit refundability and credit-forward terms
  • Evidence transfer and format requirements
  • Assessment team size and duration
  • Expected hours from your staff and outside support
  • Post-assessment deliverables
  • Readiness or remediation work explicitly excluded because of independence rules
  • The date you verified the C3PAO's Cyber AB Marketplace status

▶ Test readiness before you compare assessment quotes

The CMMC Readiness Checklist tests scope, SSP, asset inventory, evidence, POA&M eligibility, ESP documentation, and assessment type before you put an assessment date on the calendar. Free, no email gate.

Open the CMMC Readiness Checklist →


Does a voluntary certification actually count right now?

Answer capsule. Yes, for the same CMMC Assessment Scope — and this is the most important connection on the page. 32 CFR § 170.17 says a Level 2 (C3PAO) status also satisfies Level 1 (Self) and Level 2 (Self) for that same scope. DFARS 252.204-7021 requires the contractually specified CMMC level or higher. During the suspension, the only new Department designations permitted are Level 1 (Self) and Level 2 (Self). A current same-scope Level 2 (C3PAO) status, with the required affirmation, can satisfy either one.

Read that twice, because it is the part of this decision almost nobody has connected, and it is what separates a voluntary certificate from a purely speculative bet.

During the suspension, program managers and requiring activities may newly designate Level 1 (Self) or Level 2 (Self). If you hold a current Level 2 (C3PAO) status for the relevant scope and maintain the required affirmation, you are above both permitted designations under the rule's status hierarchy. You are not waiting for Phase 2 to return before the status can do any work.

So the framing "am I gambling on the program returning?" is incomplete. The real question is whether the same-scope status covers a requirement or named business use you have now, whether you expect a later Level 2 (C3PAO) use inside the three-year cycle, and whether your environment is stable enough to justify starting that cycle.

What it does not do

We are not going to oversell this. A Level 2 (C3PAO) status does not:

  • Exempt you from a government assessment. Under § 170.17, the Department reserves the right to conduct a DCMA DIBCAC assessment, and if that assessment finds requirements were not achieved or maintained, the DIBCAC result takes precedence over the existing CMMC Status.
  • Immunize you under the False Claims Act. A certificate is evidence, not immunity. It says nothing about representations made before it, requirements not maintained after it, or conduct outside the assessed scope. Any vendor telling you certification "protects you from the FCA" is selling something the governing sources do not say.
  • Waive the annual affirmation. A senior Affirming Official still attests to continuing compliance in SPRS after the assessment and annually thereafter under § 170.22.
  • Follow you automatically to a materially different boundary. The status attaches to the assessed CMMC Assessment Scope, covered information systems, CAGE-code associations, and CMMC UID information. A major boundary change requires a real scope analysis, not an assumption that the old record follows the new environment.
  • End at the certificate. The organization must retain the hashed assessment artifacts for six years from the CMMC Status Date under § 170.17. This is a six-year evidence-retention commitment wearing a three-year assessment-cycle label.

How the three-year clock changes the timing

Answer capsule. Level 2 (C3PAO) runs on a three-year assessment cycle with annual affirmations under 32 CFR § 170.17. Because the Department has published no replacement Phase 2 date, an assessment completed too early can burn part of that cycle before the opportunity it was meant to serve arrives. The CMMC Status Date is a real decision variable, not an administrative detail.

Match your status window to your opportunity window. That's the whole section, but the details matter.

When the status will actually get used — Our read
When the status will actually get usedOur read
A named award, option exercise, prime decision, or transaction inside 6–12 monthsStrong timing case
A credible opportunity 12–24 months outEvaluate scope stability and business value first
No named use, or only a speculative event more than 36 months awayWeak timing case — hold or redirect

What can make a valid status less useful before the cycle ends

  • A major redesign of the CUI boundary
  • Standing up a different enclave or moving the work to a different information system
  • An acquisition or divestiture
  • Material changes in CAGE-code or system associations
  • A significant change in External Service Providers or inherited responsibilities
  • Failing to maintain the requirements
  • Missing a required annual affirmation
  • A Conditional status you do not close inside 180 days
  • A later DIBCAC assessment that finds the requirements were not achieved or maintained

One date worth putting on the calendar

Under NIST's Cryptographic Module Validation Program, FIPS 140-2 module validations remain on the Active List through September 21, 2026. On September 22, 2026, they move to the Historical List and only FIPS 140-3 validations remain active. NIST expressly says Historical does not mean revoked: agencies may continue using FIPS 140-2 modules in existing systems, while new systems should use active FIPS 140-3 modules. NIST CMVP transition guidance · NIST CMVP FAQ

Why that matters here: SC.L2-3.13.11 requires FIPS-validated cryptography to protect the confidentiality of CUI. Under § 170.24, if encryption is employed but is not FIPS-validated, three points come off; if encryption is not employed, five points come off, and the no-encryption condition is not POA&M-eligible. But a module does not become nonvalidated merely because its certificate moves from Active to Historical.

The assessment question is narrower and more technical: can you document the exact cryptographic module, certificate, version, operating environment, and approved mode supporting the in-scope use? The September transition is a procurement and architecture planning date, not an automatic assessment failure date.

That is not a reason to rush. It is a reason to know your crypto posture before you pick a date.


What happens if the Reform Task Force changes the program?

Answer capsule. Nobody knows yet, and any page that tells you otherwise is guessing. The CMMC Reform Task Force established with the July 13, 2026 suspension was directed to deliver its final report to the Department CIO within 60 days — by September 11, 2026. Officials have not published the recommendations or a replacement Phase 2 date as of this page's August 29 verification. A certificate purchased today could turn out to be a credential the government uses differently after the review. Department announcement

We're not going to soften that. It is the material program-change risk in this decision and you should weigh it.

Now the three things that sit on the other side of the scale. All three are dated and sourced.

1. The July action did not withdraw issued statuses. The suspension procedures changed implementation policy; they did not amend § 170.17 or declare existing CMMC statuses void. The Cyber AB's July 15 statement said the program elements and assessment pipeline remained operational. Existing validity remains governed by the current rule, including the three-year cycle and annual affirmation.

2. The memo does not rewrite a subcontract. It directs Department officials to amend active solicitations and modify existing contracts on the stated schedule. It does not execute a bilateral subcontract change between a prime and subcontractor, and it does not prevent a prime, customer, board, lender, or acquirer from asking for independent evidence for its own risk decision. Only the written position that controls your relationship answers your question.

3. The federal small-business advocate asked for protection for early investors. In an August 17, 2026 comment letter on the reform effort, the SBA Office of Advocacy recommended stability and safe harbors for early investors, alongside clearer CUI identification, tighter flow-down, and a graduated path to Level 2. SBA Office of Advocacy comment

That is a recommendation, not policy. We are labeling it that way on purpose. But it is a formal federal comment showing that sunk investment and transition protection are part of the reform record.

What would actually change the controlling requirements

The July action is an implementation memorandum. Different instruments can change different layers of the program:

  • A class deviation can change how acquisition requirements or clauses are used before the DFARS text is formally amended.
  • A DFARS rule can amend the acquisition provisions and clauses that put CMMC into solicitations, contracts, and subcontracts.
  • An amendment to 32 CFR Part 170 can change the CMMC Program Rule itself, including the incorporated NIST editions and the phased schedule in § 170.3(e).

Watch those instruments, not press coverage.

Separately, the Department has a CMMC rulemaking at Final Rule Stage in the Unified Agenda — RIN 0790-AM01 — intended to define a transition from NIST SP 800-171 Revision 2 to Revision 3. It is an agenda entry, not an effective rule. CMMC Level 2 is still assessed against the specific Revision 2 and 800-171A editions incorporated in 32 CFR Part 170 until the Department amends the rule. Unified Agenda entry

That incorporation point matters beyond Level 2. NIST has marked SP 800-171 Revision 2 and SP 800-171A as withdrawn and superseded, and in May 2026 it also superseded the February 2021 SP 800-172 and March 2022 SP 800-172A editions. CMMC still incorporates those named editions for Level 2 and Level 3. A newer NIST publication does not silently amend a regulation.

The FAR Council has also proposed a separate governmentwide CUI rule that would move governmentwide contract CUI requirements toward Revision 3. That proposal does not amend CMMC today. Federal Register proposed rule, June 23, 2026 For the full authority map, see our NIST 800-171 Rev. 2 vs. Rev. 3 comparison.

The two-week discipline

The Task Force report is due by September 11, 2026. There is no good reason to sign a six-figure assessment engagement in the days before that date unless a prime, customer, counterparty, or controlling document has already put a date and requirement in writing, or your cancellation economics make delay more expensive than the program-change risk. If a written deadline exists, your immediate decision is driven by that document and your readiness — not by the government's calendar alone.

Everything else on this page is free and improves your position either way.


Are you actually ready to be assessed?

Answer capsule. Assessment-ready means your CUI boundary is stable; your System Security Plan, asset inventory, and network diagram accurately describe the environment as it exists today; your External Service Provider relationships and Customer Responsibility Matrices are documented; and you can produce final evidence against the applicable NIST SP 800-171A assessment objectives without building it during the assessment. If a C3PAO would be discovering basic scope or implementation gaps, engage a readiness category first. 32 CFR §§ 170.17, 170.19, 170.21 and 170.24

This is the gate that decides whether a voluntary assessment is an investment or a very expensive gap assessment.

The pass-or-redirect checklist

You should be able to answer yes to all of these. Honestly. Out loud. In front of the person who signs the affirmation.

  • We know where CUI enters, moves, rests, and leaves our environment.
  • We can identify every CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, and Specialized Asset in scope.
  • Our SSP matches the environment as it exists today, not as it existed at the last audit.
  • The asset inventory and network diagram agree with the SSP.
  • Every External Service Provider that touches CUI or Security Protection Data is documented, with a service description and Customer Responsibility Matrix.
  • We can retrieve final evidence for each applicable assessment objective without assembling it on the fly.
  • We have evaluated known deficiencies against the actual POA&M rules — not our hopes about them.
  • Leadership is prepared to affirm continuing compliance after the assessment and annually thereafter.
  • The proposed C3PAO and every participating CMMC Ecosystem member pass the independence check.

Any "no" on that list is a Redirect until it becomes yes, not a reason to pay a C3PAO to discover it formally.

A Conditional status is not a plan for unfinished work

Contractors talk about POA&Ms as if they buy time. They buy a narrow, rule-bound window. Under 32 CFR § 170.21:

  • you need at least 88 of 110 to earn a Conditional Level 2 status;
  • only 1-point requirements are generally eligible for a POA&M;
  • SC.L2-3.13.11 is the narrow exception when encryption is employed but is not FIPS-validated;
  • six requirements may never appear on a Level 2 POA&M: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5; and
  • everything on the POA&M must be closed through the applicable closeout assessment within 180 days of the Conditional CMMC Status Date or the status expires.

The SSP one catches good companies. Section 170.24 says the absence of an up-to-date SSP means the assessment cannot be completed due to incomplete information and noncompliance with DFARS 252.204-7012. Because CA.L2-3.12.4 cannot go on the POA&M, an SSP that is still "in progress" on assessment day is not a harmless documentation issue.

The independence wall

The exact rule is in 32 CFR § 170.8(b)(17)(ii)(G): the Accreditation Body's ethics requirements must prohibit CMMC Ecosystem members from participating in a Level 2 certification assessment when they previously served as a consultant to prepare that organization for any CMMC assessment within the prior three years.

In plain terms: the people who fixed you cannot then participate in grading you inside that window.

Do not assume a company's dual Marketplace listings or internal organizational chart make an engagement clean. The legal question is whether any CMMC Ecosystem member participating in the assessment served as your preparation consultant during the prior three years. The CAP also requires the C3PAO to manage impartiality and conflicts before the assessment proceeds. Ask for the written conflict determination before you sign. If the conflict cannot be mitigated, the CAP says the assessment should not proceed. CMMC Assessment Process v2.0

Formal assessment vs. readiness assessment

Formal C3PAO assessment — Readiness or gap assessment
Formal C3PAO assessmentReadiness or gap assessment
Produces a CMMC StatusProduces findings and a work plan
Independence restrictions applyMay include consulting and remediation guidance
Comes after readinessComes before formal assessment
The assessor evaluates your evidenceThe provider helps you build the environment and evidence
Not the place to design your environmentOften where scope, architecture, and operations get decided

▶ If you answered "no" to anything on that checklist

Your next call is a readiness category, not an assessor. Compare what an RPO/RP, an MSSP, a GRC platform, and a CUI enclave each actually do, what to verify before hiring one, and which one fits the gap you have.

Compare CMMC provider categories →

Or start self-serve with the CMMC Readiness Checklist, mapped to all 14 NIST SP 800-171 Rev. 2 requirement families.


What if your solicitation, contract, or prime still requires Level 2 (C3PAO)?

Answer capsule. Do not treat the July 2026 announcement as an amendment to your paperwork. The implementation procedures direct officials to amend active solicitations containing Level 2 (C3PAO) or Level 3 requirements and to remove those requirements from existing contracts through a modification before the next option period or during the next scheduled administrative modification. Until the controlling instrument actually changes, get the responsible party's current position in writing before you change your bid or performance strategy. Official implementation procedures

This is where we see contractors make unforced errors in both directions. Some keep spending against a requirement that has already been amended out. Others stand down against a requirement that is still sitting in a signed subcontract.

The authority ladder

Four different things, and people collapse them into one:

  1. An announcement or press release. Policy signal. It does not amend your instrument.
  2. Direction to contracting officers and requiring activities. Internal implementation instruction. It directs an action but is not itself your issued amendment or modification.
  3. An issued solicitation amendment or contract modification. Now the federal instrument changed.
  4. An executed subcontract change. A separate action between the prime and subcontractor; the government's instruction to its own officials does not execute it for them.

You need the rung that applies to you. Not the one on the news.

What to ask, by instrument type

Active federal solicitation — ask for the amendment number, the revised provision or clause, the current required CMMC status, the date by which it must be achieved, and how the relevant CAGE codes and information systems are treated.

Awarded prime contract — ask whether the modification has been issued, whether it affects the current period or the next option, which information systems and CMMC UIDs remain associated, and whether the requirement survives anywhere else in the contract.

Executed subcontract — the government's procedures do not directly rewrite a signed prime-to-subcontractor instrument. Get the prime's written position, and get qualified federal-contracts counsel involved if the obligation is disputed.

A prime's supplier requirement outside a Department designation — a prime may impose a separate contractual or supplier-risk requirement, subject to the subcontract and applicable law. That is not the same thing as a new Department CMMC designation. Ask the prime to state the exact status requested, the required date, the systems or CAGE codes covered, whether equivalent evidence will be accepted, and whether the request is contractual or a supplier preference.

Copy this and send it today

Subject: Confirmation of current CMMC status requirement — [instrument number]

We are reviewing the CMMC requirement associated with [solicitation / contract / subcontract number] following the July 2026 suspension of CMMC Phase 2. Please confirm in writing:

  1. The current required CMMC level and assessment type.
  2. The clause, provision, amendment, modification, or subcontract term that establishes it.
  3. The date by which the status must be achieved.
  4. The CAGE codes and information systems to which it applies.
  5. Whether any prior Level 2 (C3PAO) requirement has been removed, deferred, or retained.

We are not transmitting CUI, export-controlled content, or sensitive technical details with this request.

Two notes on using it. Send it in writing, not only on a call — you want the record. And silence from a prime is not permission to stop. If they do not answer, follow up in writing and keep both messages with the subcontract file.

For the full status of the phased rollout, see CMMC deadlines in 2026 after the Phase 2 suspension.


What if you're an MSP, MSSP, or another External Service Provider?

Answer capsule. That is a different question with a different rule behind it. 32 CFR § 170.19 addresses how External Service Providers fit into a customer's CMMC Assessment Scope and expressly notes that an ESP may voluntarily undergo a CMMC certification assessment to reduce the ESP's participation effort during customer assessments. The customer's SSP and Customer Responsibility Matrix still matter, and the customer's written requirement still sets the minimum level and assessment type that applies to the customer environment.

If you're an MSP with fifteen DIB clients, you already know the problem: you sit through fifteen assessments, answer the same questions fifteen times, and hand over the same artifacts fifteen times.

What voluntary ESP certification can do:

  • Reduce repeated participation effort across customer assessments for the controls covered by the ESP's assessed scope
  • Create a reusable, formally assessed body of evidence
  • Clarify the shared-responsibility boundary before a dispute, not after

What it cannot do:

  • Make your customers compliant
  • Remove each customer's obligation to document your service in its SSP and CRM
  • Override what a customer's solicitation, contract, or subcontract requires
  • Turn a service that should not touch CUI into one that should
  • Eliminate the need to prove the customer's own configuration and responsibilities

There's also a distinction worth keeping straight. A Cloud Service Provider that processes, stores, or transmits CUI must meet the FedRAMP Moderate baseline or equivalent under DFARS 252.204-7012. A non-cloud ESP sits under different scoping treatment and may be assessed inside the customer's scope. CSP and ESP are not interchangeable labels, and vendors blur them constantly.

If this is your situation, the ESP question deserves its own analysis rather than a paragraph on a page about buyer decisions. Start with our CMMC External Service Provider assessment guide.


Which CMMC provider category should you talk to next?

Answer capsule. Engage a C3PAO for a formal Level 2 certification assessment only once the environment is assessment-ready. Use an RPO/RP or readiness specialist for scoping, documentation, and evidence preparation; an MSSP for implementation and continuous operations; a GRC platform for evidence workflow; and a CUI enclave provider for boundary architecture. Contract interpretation belongs with your contracting officer, your prime, or qualified federal-contracts counsel — not a vendor.

The most expensive mistake on this topic isn't choosing the wrong vendor. It's choosing the right vendor from the wrong category.

The problem you actually have — First category to call — Don't confuse it with
The problem you actually haveFirst category to callDon't confuse it with
A formal Level 2 certification assessmentC3PAO — CMMC Third-Party Assessment OrganizationReadiness consulting
Scope, SSP, POA&M analysis, and evidence preparationRPO / RP — Registered Provider Organization / Registered Practitioner — or a readiness specialistA certifying assessor
Security implementation and day-to-day operationsMSSP or managed-compliance providerA substitute for your own accountability or affirmation
Evidence organization, control mapping, and continuous workflowGRC platformProof that controls are actually implemented
Shrinking and operating the CUI boundaryCUI enclave providerA shortcut that erases scope or inherited responsibilities
Ambiguous contract languageContracting officer, prime, or qualified attorneyA vendor's sales interpretation

The CMMC Path Framework is our named editorial decision logic: it maps a contractor's required CMMC level, FCI versus CUI handling, assessment type, IT and cloud environment, evidence state, and contract timeline to the provider category needed next. It routes to a category, not a named provider, and it is not a score, ranking, or compliance determination.

Why we don't rank named providers on this page. You haven't established which category you need yet. Publishing a "best provider" list before that question is resolved would put monetization ahead of fit, and it would make this page worse at the only job it has.

▶ Get matched with source-checked provider options

Tell us your level, scope, environment, assessment type, and timeline. We route by provider category — readiness/RPO, MSSP, GRC platform, CUI enclave, or C3PAO — based on the requirement you report and where you actually are.

Get matched with source-checked provider options →

Do not submit CUI, drawings, export-controlled content, credentials, or sensitive contract details. This intake is for provider-category routing only.

Already know the category and scope you need? Request scoped CMMC quotes without sending CUI.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our Editorial & Advertising Policy.


What we actually verified

We don't ask you to take our word for any of this. Here's what we read and cross-checked, and what each source supports.

Verified August 29, 2026:

Source — What it supports
SourceWhat it supports
32 CFR Part 170 — current eCFRLevel definitions; incorporated NIST editions; Level 1/2/3 requirements; assessment mechanics; status hierarchy; scoping; POA&M; affirmations; scoring; retention
32 CFR § 170.8(b)(17)(ii)(G)Three-year consultant-to-assessment participation prohibition for CMMC Ecosystem members
32 CFR §§ 170.16–170.18Level 2 self-assessment, Level 2 C3PAO, and Level 3 mechanics; eMASS-to-SPRS flow; three-year cycles; higher-status satisfaction; DIBCAC precedence
32 CFR § 170.19CMMC Assessment Scope, CSP/ESP treatment, CRM/SSP documentation, and voluntary ESP certification language
32 CFR § 170.20Qualifying pre-December 16, 2024 DIBCAC High and Joint Surveillance acceptance conditions
32 CFR §§ 170.21–170.2488-of-110 threshold; POA&M eligibility and barred requirements; 180-day closeout; affirmations in SPRS; FIPS scoring; SSP requirement
DFARS 252.204-7012Continuing safeguarding, incident-reporting, and covered-cloud duties that remain in effect
DFARS 252.204-7019Offeror verification and posting of NIST SP 800-171 DoD Assessment summary scores in SPRS
DFARS 252.204-7020Government access for Medium/High Assessments and posting of DoD Assessment results in SPRS
DFARS 252.204-7021Required CMMC level or higher, annual affirmations per CMMC UID, and flow-down duties
DFARS 252.204-7025Solicitation notice of required CMMC level or higher and proposal-stage CMMC UID information
July 2026 implementation proceduresPhase 2 suspension; permitted Level 1 (Self)/Level 2 (Self) designations; amendment/modification direction; continuing DFARS 252.204-7012 duties; no waivers
Department July 13 releaseSuspension date, continuing Phase 1 self-assessments, Reform Task Force, and 60-day report deadline
Cyber AB July 15 statementContinued availability of Level 2 C3PAO assessments and the official July ecosystem snapshot
CMMC Assessment Process v2.0Live Marketplace verification, preliminary scope/SSP/CRM checks, evidence procedures, impartiality, conflict management, and no guaranteed outcomes
2024 CMMC Program Rule analysisModeled cost components and the assumption that NIST SP 800-171 Rev. 2 implementation is already complete
2025 DFARS acquisition final ruleNovember 10, 2025 effective date, original phased acquisition rollout, and the pre-suspension Level 2 certification population model
NIST SP 800-171 Rev. 2 and SP 800-171APublication dates, withdrawal status, and the source documents specifically incorporated into CMMC for Level 2
NIST SP 800-172 and SP 800-172AFebruary 2021 and March 2022 editions, their May 13, 2026 supersession, and the editions CMMC still incorporates for Level 3 until amended
NIST CMVP and CMVP FAQSeptember 21/22, 2026 FIPS 140-2 Active-to-Historical transition and the existing-system distinction
Unified Agenda, RIN 0790-AM01Planned — not current — transition from NIST SP 800-171 Revision 2 to Revision 3
Proposed FAR CUI rule, June 23, 2026Proposed governmentwide CUI contract framework using NIST SP 800-171 Revision 3; proposal only, not a current CMMC amendment
SBA Office of Advocacy commentRecommendation for stability and safe harbors for early investors; recommendation only
National Defense Magazine, August 17, 2026Dated secondary reporting of assessor-side claims about cancellations, layoffs, assessment prices, and prime pressure

One version-control point worth preserving: NIST's catalog now marks SP 800-171 Rev. 2, SP 800-171A, SP 800-172, and SP 800-172A as withdrawn or superseded. CMMC still incorporates the named editions in 32 CFR § 170.2. NIST publication status and CMMC legal applicability are not the same thing.

What we did not verify, and won't claim:

  • That a voluntary certificate creates a competitive advantage for every contractor. We found no evidence supporting that as a general statement.
  • That certification protects anyone from False Claims Act liability. No controlling source creates immunity.
  • That C3PAO prices, wait times, or availability will move in one direction market-wide. The public evidence is fragmented and seller-heavy.
  • That any specific contractor should cancel, defer, or preserve a booked assessment. That depends on written requirements and signed commercial terms we cannot see.
  • What refund, deposit, rescheduling, or cancellation terms apply to you. Those live in your agreement.
  • What the Reform Task Force will recommend or when the Department will implement any recommendation.
  • That a prime has direct access to browse another contractor's full SPRS record. Verify the evidence and access mechanism the prime actually requires.

Who wrote this. The Defense Compliance Report Editorial Team. This is editorial research, not formally reviewed by a CMMC Subject Matter Advisor. Verify scope and applicability with a CMMC Registered Practitioner (RP/RPO) or a qualified federal-contracts attorney before making compliance decisions. Read our methodology, editorial standards, editorial review process, and corrections policy.

How often we refresh this page. Weekly while the CMMC Reform Task Force review remains open, then monthly. Any Federal Register publication, class deviation, change to the official suspension procedures, amendment to 32 CFR Part 170, or change to the incorporated NIST editions triggers an immediate re-review.


Frequently asked questions about CMMC voluntary assessments

Is CMMC voluntary now?

No. The July 2026 suspension changed which CMMC assessment types Department program managers and requiring activities may newly designate during the review. It did not make CMMC or the underlying safeguarding obligations voluntary. DFARS 252.204-7012 remains in effect, Phase 1 Level 1 (Self) and Level 2 (Self) designations remain active, and your specific solicitation, contract, or subcontract still has to be read on its own terms.

What are the active Phase 1 dates?

The DFARS acquisition rule became effective November 10, 2025. Under the original phased schedule, Phase 1 runs from November 10, 2025 through November 9, 2026. The July 13, 2026 action suspended the transition to Phase 2 and later milestones while leaving Phase 1 self-assessment requirements in place. The original November 10, 2026 Phase 2 date is not currently operative.

Can I still get a voluntary Level 2 (C3PAO) assessment?

Yes. The Cyber AB stated on July 15, 2026 that all CMMC program elements remain operational and available, including C3PAO Level 2 certification assessments, training, exams, Registered Practitioner services, and DIBCAC's assessment of C3PAOs. That is a dated statement from the Accreditation Body, not a government mandate to obtain one.

Should I cancel my scheduled C3PAO assessment?

Not on the headline alone. Check five things first: the written requirement driving it, whether an amendment or modification has actually been issued, your evidence readiness, whether a named business use falls inside the three-year cycle, and your cancellation, credit-forward, and deferral terms. Rescheduling may preserve a deposit or relationship in some agreements; cancellation may be cleaner in others. There is no honest blanket answer without the documents.

Does a Level 2 (C3PAO) status replace a Level 2 self-assessment?

For the same CMMC Assessment Scope, yes. Section 170.17 says Level 2 (C3PAO) also satisfies Level 1 (Self) and Level 2 (Self), and DFARS 252.204-7021 requires the specified level or higher. It does not remove your annual affirmation, continuing-compliance obligation, or requirements tied to a different scope.

Who can look up my CMMC status in SPRS?

Contracting officers use SPRS to verify required CMMC status and affirmations. Level 2 self-assessment results are submitted directly to SPRS; C3PAO results flow from CMMC eMASS to SPRS. DFARS 252.204-7019 separately limits NIST SP 800-171 DoD Assessment summary-score access to authorized Department personnel and the contractor's authorized representatives. Do not assume a prime can directly browse your full record. Ask what CMMC UID, status evidence, representation, or subcontract deliverable the prime requires.

Is a voluntary certification still valid for three years?

It is on a three-year assessment cycle under § 170.17, measured from the CMMC Status Date associated with the Conditional status if there was one, with annual affirmations required. That is exactly why the intended-use date belongs in the decision — starting the clock early spends part of the cycle before anyone needs the result.

Is a voluntary assessment the same thing as a JSVA?

No. Joint Surveillance was the earlier joint DCMA DIBCAC and C3PAO pathway. A current voluntary Level 2 certification assessment follows § 170.17 and is performed by a C3PAO. Section 170.20 addresses acceptance of qualifying past DIBCAC High results, including eligible Joint Surveillance assessments conducted before December 16, 2024. It does not create a new Joint Surveillance pathway.

What happened to my old Joint Surveillance result?

If it was a DCMA DIBCAC High Assessment conducted before December 16, 2024, with a perfect score, no open POA&M, and an identical scope, § 170.20 provides for a Final Level 2 (C3PAO) status valid three years from the original assessment date. Check SPRS for the actual status date, scope, affirmation, and expiry, because the clock runs from the assessment, not from when the status later appeared.

Can the firm that prepared us also assess us?

A CMMC Ecosystem member cannot participate in your Level 2 certification assessment if it served as a consultant to prepare your organization for any CMMC assessment within the prior three years. That is the rule in § 170.8(b)(17)(ii)(G). Do not rely on a verbal assurance or on the fact that one company holds multiple Marketplace designations. Get the conflict determination in writing.

Does certification protect us from a DIBCAC assessment?

No. Section 170.17 reserves the Department's right to conduct a DCMA DIBCAC assessment, and if that assessment shows the requirements were not achieved or maintained, the DIBCAC result takes precedence over the pre-existing CMMC Status.

Does certification protect us from False Claims Act exposure?

No, and be skeptical of anyone who says it does. An independent assessment can create useful evidence about the state and scope of an environment on a given date. It is not immunity from inaccurate representations, failing to maintain requirements afterward, or conduct outside the assessed scope.

Can an MSP or other External Service Provider get certified voluntarily?

Yes, subject to the applicable assessment pathway, and it can make operational sense when the ESP repeatedly lands inside customer assessment scopes. Section 170.19 expressly notes that an ESP may voluntarily undergo certification to reduce its effort during customer assessments. It does not make customers compliant or change what their written requirements demand.

What does a voluntary CMMC assessment cost?

The Department's regulatory model puts the initial small-entity Level 2 certification assessment and affirmation cycle at roughly $101,752, with about $31,234 being the modeled C3PAO engagement. The model assumes NIST SP 800-171 Revision 2 is already implemented, so it excludes engineering and remediation. Real quotes vary by scope, CAGE-code and system complexity, travel, team size, closeout terms, and organization readiness. Normalize every quote against the line items above.

Should we spend the money on readiness instead?

If your CUI boundary, SSP, asset inventory, network diagram, ESP documentation, control operation, or evidence is not stable, yes. A formal assessor is the wrong category to discover basic readiness gaps, and independence rules limit the remediation help assessment participants can provide. Readiness first, verification second, in that order.

What if our prime still requires Level 2 (C3PAO)?

A prime may impose a separate contractual or supplier-risk requirement, subject to your subcontract and applicable law. The Department's suspension procedures do not automatically rewrite that instrument. Get the prime's current position in writing, including the exact status, date, systems, CAGE codes, evidence expected, and whether the requirement is contractual or a preference.

Is CMMC moving to NIST SP 800-171 Revision 3?

A transition is on the Unified Agenda, but it is not in effect. CMMC Level 2 is currently assessed against the specific NIST SP 800-171 Revision 2 and NIST SP 800-171A editions incorporated in 32 CFR Part 170. NIST's publication of newer editions did not amend the rule. Do not let a vendor sell a Revision 3 package for CMMC Level 2 as though it were today's controlling CMMC requirement.

What does NIST's withdrawal of SP 800-172 mean for CMMC Level 3?

It does not silently replace CMMC's Level 3 baseline. NIST marked the February 2021 SP 800-172 edition withdrawn and superseded on May 13, 2026, but 32 CFR Part 170 still incorporates that edition and the March 2022 SP 800-172A edition. Level 3 uses 24 selected requirements from the incorporated edition until the Department amends the rule.

When will we know what happens to Phase 2?

The Reform Task Force was directed to deliver its final report to the Department CIO within 60 days of July 13, 2026 — by September 11, 2026. A report or recommendation is not automatically a rule, clause change, or contract modification. Watch for the report, then for a class deviation, DFARS action, amendment to 32 CFR Part 170, and actual changes to your written instrument.


The bottom line

A voluntary CMMC assessment can absolutely be the right call in 2026. But "available" and "necessary" are two different words, and the market keeps using them interchangeably.

Proceed when a real party will rely on the status, on a date you can name, and your evidence is ready today. Hold when the suspended November 10 deadline was your only reason — compare deferral, rescheduling, and cancellation on the actual contract terms. Redirect when the honest problem is scope, implementation, or evidence, because an assessor is the wrong category to discover that. Clarify whenever your paperwork has not caught up with the current procedures, which starts with an email rather than a purchase order.

Do that, and whatever the Reform Task Force recommends in September, you'll have made the decision on your facts instead of on someone else's headline.

Need help deciding what type of CMMC provider you need?

Tell us your level, scope, assessment type, environment, and timeline, and we'll map you to source-checked CMMC provider options.

Find My CMMC Path → · Open the CMMC Readiness Checklist → · Request scoped quotes →

Free path tool · about two minutes · no obligation · educational triage only.

Do not submit CUI, drawings, export-controlled content, credentials, or sensitive contract details. The intake is for provider-category routing only. Provider matching may generate referral or lead-routing compensation, disclosed at the point of recommendation.


The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. This page is educational research, not legal, contractual, or compliance advice. We are not affiliated with the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. CMMC requirements vary by contract, scope, assessment type, and CUI handling. Confirm scope and applicability with a CMMC Registered Practitioner (RP/RPO) or a qualified federal-contracts attorney before making compliance decisions.

Byline: The Defense Compliance Report Editorial Team. Last verified: August 29, 2026.