DoD Suspends CMMC Phase II Audits for Small Businesses.
The Department of War recently suspended costly third-party CMMC audits for small businesses, but the legal mandate to protect federal data remains.
To keep winning defense contracts, O&M and facility contractors must still:
Comply with NIST SP 800-171 controls.
Maintain an active System Security Plan (SSP).
Submit an active self-assessment score to SPRS.
We help small businesses achieve rapid, audit-free Phase I compliance to keep your Prime status secure and your business winning bids.
FEDERAL MANDATED DUE DATE:
Currently Active
Required for all contractors handling Federal Contract Information (FCI). Mandates 15 foundational practices and a submitted annual self-assessment.
FEDERAL MANDATED DUE DATE:
Self-Assessment Active
Mandatory for firms handling Controlled Unclassified Information (CUI), requiring strict adherence to 110 NIST 800-171 controls via self-assessment and SPRS score submission.
Note: Costly third-party (C3PAO) audits have been suspended to protect small businesses.
FEDERAL MANDATED DUE DATE:
Under Review
Reserved for high-priority defense programs facing Advanced Persistent Threats (APTs), adding 24 enhanced NIST 800-172 controls. Government-led DIBCAC assessments for this tier will be fully implemented trailing the Level 2 rollout in 2027.