With CMMC Phase 2 suspended, a dangerous idea is circulating in the defense industrial base: that cybersecurity compliance is on pause. It isn't. The certification ceremony is paused. The requirements — the ones actually written into your contracts — never moved.
This guide explains the stack of obligations that applies to you today: NIST SP 800-171, the DFARS clauses that enforce it, and SPRS, the database where your score lives.
The stack, from the bottom up
NIST SP 800-171: the standard
NIST Special Publication 800-171 defines 110 security requirements across 14 families — access control, awareness and training, audit and accountability, incident response, and so on — for protecting Controlled Unclassified Information (CUI) on non-federal systems. If CUI touches your network, this is the standard you are measured against.
DFARS 252.204-7012: the contract clause
This clause, present in essentially every defense contract involving covered defense information since 2017, requires you to implement all 110 requirements and to report cyber incidents within 72 hours. It is not new, not suspended, and not optional.
DFARS 252.204-7019 and -7020: the proof
Since late 2020, -7019 requires a current NIST 800-171 self-assessment score posted in SPRS — no more than three years old — for you to be considered for award. Its companion, -7020, requires you to let the government verify that assessment and to flow the requirement down to your subcontractors. No score in SPRS, no award. It is that direct.
CMMC: the audit layer (currently in flux)
CMMC was designed to add independent verification on top of this stack — a third-party assessor confirming that what you attest in SPRS is true. Phase 2 of that rollout was suspended on July 13, 2026 pending a reform review. The audit layer is paused; everything beneath it stands.
What SPRS actually is
The Supplier Performance Risk System is the Department's database of supplier risk information. For cybersecurity, it holds your self-assessment: your score, the date of the assessment, the scope (which system it covers), and the date you expect to reach full implementation.
The score comes from the DoD Assessment Methodology: start at 110 and subtract a weighted deduction — 1, 3, or 5 points — for every requirement not fully implemented. The deductions sum to 313, so scores run from 110 down to −203.
A negative first score is normal. Most small contractors doing their first honest assessment land somewhere between −50 and −150. The methodology measures distance from full implementation. What the Department — and increasingly, your primes — care about is whether the score is truthful and whether it is moving up.
Why honesty is the whole game now
With third-party certification paused, your self-reported score is the primary signal of your compliance. That cuts two ways. There is no assessor to fail — and no assessor to hide behind. The Department of Justice's Civil Cyber-Fraud Initiative has already produced False Claims Act settlements against contractors that certified cybersecurity postures they didn't have. Every score posted in SPRS is a representation to the government, made under the same rules as any other certification in your contracts.
The safe position is unglamorous: an accurate score, a written System Security Plan describing what is actually implemented, and a Plan of Action & Milestones with real dates for what isn't. That package satisfies the clauses in force today, and it's the raw material for whatever CMMC becomes after the review.
Getting from zero to posted, step by step
- Scope your environment. Decide which systems store, process, or transmit CUI. A small, well-defined boundary makes everything downstream cheaper.
- Assess all 110 requirements honestly. Met, not met, or not applicable — with a note on why.
- Calculate the weighted score. Apply the 1/3/5-point deductions to everything not met.
- Write the SSP and POA&M. The SSP describes your environment and implementations; the POA&M lists gaps, owners, and target dates.
- Post the score in SPRS via PIEE (the Procurement Integrated Enterprise Environment) — score, assessment date, scope, and full-implementation date.
- Work the plan and re-score. MFA, encryption, and written policies are typically the highest-value early wins.
The assessment is the hard part. We made it free.
CMMC Map walks you through all 110 requirements in plain English, calculates your DoD-weighted SPRS score live, and keeps your evidence organized. When you need the documents — SSP, POA&M, all 14 policies — they're $149/month. No trial, no clock.
Get your SPRS score — free