Defense & Government

The CMMC third-party mandate is paused. Your obligations are not.

In July 2026 the DoD paused CMMC Phase 2 — the rollout that would have made third-party (C3PAO) assessments mandatory in solicitations — pending a program review. The obligations underneath did not move: contractors and subcontractors must still implement NIST SP 800-171 and complete annual Level 1 and Level 2 self-assessments posted to SPRS. Pistos builds and maintains that evidence record continuously — and now guides subcontractors through their self-assessments.

Defense Primes Subcontractors IT Service Providers Research Institutions Aerospace & Defense Federal Civilian Contractors
Request a defense briefing

On July 13, 2026 the DoD suspended CMMC Phase 2 — the expansion that would have made third-party (C3PAO) assessments mandatory in solicitations from November 2026 — and opened a review of the program. The third-party rollout is paused; the obligations underneath it are not. Level 1 and Level 2 self-assessments, posted and affirmed in SPRS, remain required today — and DFARS 252.204-7012 still requires you to implement NIST SP 800-171 Rev 2. Both the self-assessment today and any future C3PAO assessment evaluate evidence of 110 practices across 14 domains derived from NIST SP 800-171. A subcontractor that lets its evidence lapse will scramble when the third-party mandate returns.

Regulatory landscape

The defense compliance framework.

Defense contractors operate under the most rigorous cybersecurity requirements in any commercial sector. The framework is not optional — it is baked into contract language.

CMMC 2.0

Cybersecurity Maturity Model Certification — DoD

Level 1 (17 practices) applies to FCI — Federal Contract Information. Level 2 (110 practices) applies to CUI — Controlled Unclassified Information. With Phase 2 paused, Level 2 is met today through self-assessment posted to SPRS; third-party (C3PAO) assessment resumes when the DoD lifts the pause. Pistos supports both paths, built around the Level 2 practice set derived from NIST SP 800-171 Rev 2 and Rev 3.

NIST SP 800-171 Rev 3

Protecting CUI in Nonfederal Systems

The technical foundation for CMMC Level 2. 110 security requirements across 14 families — access control, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, system and information integrity, and awareness and training.

DFARS 252.204-7012

Defense Federal Acquisition Regulation Supplement

Requires contractors to implement NIST SP 800-171 security requirements, report cyber incidents to DoD within 72 hours, provide access to systems for damage assessment, and maintain a current System Security Plan and Plan of Action and Milestones.

CMMC practice domains

All 14 CMMC practice domains. All tracked in PCS.

PCS maps all 110 CMMC Level 2 practices to CIS Controls v8.1 safeguards. Skopein reads the technical configuration state. Mathisi satisfies the training domain. Every practice carries a control record, a dated evidence status, and a remediation path.

AC — Access Control

22 practices. User access, remote access, mobile device management, CUI access limitations.

AT — Awareness & Training

3 practices. Security awareness, role-based training, insider threat awareness.

AU — Audit & Accountability

9 practices. Audit log creation, review, retention, and protection.

CA — Security Assessment

4 practices. System assessment, plan of action, continuous monitoring, internal system connections.

CM — Configuration Mgmt

9 practices. Baseline configurations, system change control, least functionality, unauthorized software.

IA — Identification & Auth

11 practices. User identification, MFA, password management, replay-resistant authentication.

IR — Incident Response

3 practices. Incident response capability, reporting, and testing.

MA — Maintenance

6 practices. System maintenance controls, maintenance tools, remote maintenance.

MP — Media Protection

9 practices. Media access, marking, storage, transport, sanitization, and disposal.

PS — Personnel Security

2 practices. Personnel screening and termination procedures.

PE — Physical Protection

6 practices. Physical access authorization, monitoring, and visitor control.

RA — Risk Assessment

3 practices. Risk assessment, vulnerability scanning, and risk response.

SC — System & Comms Protection

16 practices. Boundary protection, encryption in transit, network segmentation, CUI in public cloud.

SI — System & Info Integrity

7 practices. Malware protection, security alerts, software and firmware integrity, security architecture.

New — subcontractor self-assessment

Now: we run your self-assessment.

With third-party assessments paused, the annual self-assessment is what the DoD is actually looking for — and for most subcontractors it always was. Pistos runs it end to end, so your SPRS score is current, defensible, and ready the day a prime or a contracting officer asks.

Level 1 self-assessment

Federal Contract Information (FCI)

The 17-practice annual self-assessment and affirmation. We implement the controls, gather the evidence, and post the result to SPRS — then keep it current year over year.

Level 2 self-assessment

Controlled Unclassified Information (CUI)

The 110-practice NIST SP 800-171 self-assessment: a scored System Security Plan, a Plan of Action & Milestones, and the SPRS submission — maintained between reviews, not rebuilt each year.

Ready for what’s next

When Phase 2 returns

The same evidence record that satisfies your self-assessment is what a C3PAO will ask to see. Build it once with Pistos and you are ready either way.

Your CMMC assessment starts with your evidence record.

Request a briefing and we will walk you through PCS against the CMMC Level 2 practice set for your organization.

Request a defense briefing
Also in scope
Financial Services Defense Healthcare PCS Aegis Platform Insights