A Post-Suspension CMMC Compliance Checklist (and Who Should Own It)

Reports to: 
02
Location: 

A Post-Suspension CMMC Compliance Checklist (and Who Should Own It)

If you search for a CMMC compliance checklist right now, you'll probably land on some pages written before the July 13 suspension. The standard checklist items haven't disappeared. You still need to self-assess against your SSP (System Security Plan) and post that score to SPRS (Supplier Performance Risk System). Only the third-party assessment requirements, Phase II and the future Phases III and IV, are suspended; DFARS 252.204-7012 and your incident reporting duties are unaffected. Here’s where to focus now:

1. Check Your Active Contracts for CMMC Level 2 or 3 Language

If a contract you're already performing on requires a Level 2 assessment by a C3PAO (Certified Third-Party Assessor Organization) or a Level 3 assessment by DIBCAC (the Defense Industrial Base Cybersecurity Assessment Center), that language doesn't necessarily disappear. The government must remove it by your next option period or scheduled modification.

Who owns this: Contracts or ops lead. Pull every active contract and flag anything citing CMMC Level 2 (C3PAO) or Level 3. 

2. Confirm What Your Prime Still Requires

CMMC flow-down (requirements passed from your prime's contract down into your subcontract) to subcontractors is written into federal regulation (see B-Q6, page 3, in the DoW's CMMC FAQ, last revised July 13, 2026). That's why primes don't need to wait for federal policy to catch up before deciding what they'll keep requiring from you. At a recent industry conference, one prime said outright that before they'd even consider a potential supplier, that supplier had to show Level 2 self-assessment status and have its SSP ready to share. 

As a subcontractor, what actually governs your compliance obligations is your prime's contract with you, not the federal suspension directly.

Who owns this: Whoever manages the prime relationship. Ask directly: has anything in our flow-down requirements changed since July 13? Get it in writing.

3. Keep Your NIST 800-171 Self-Assessment Current

If you haven't run your NIST 800-171 checklist against your current environment recently, prioritize getting that done. Your SSP, usually 100 to 200 pages, needs to match what is currently implemented. There are financial and legal consequences if the self-assessment is inaccurate. We covered the self-assessment and False Claims Act exposure in more detail in our earlier piece on the suspension.

Who owns this: IT or security lead. Re-run your self-assessment now if it's more than a few months old.

4. Keep Level 2 Prep Moving If It's Already Underway

If you've already started working toward C3PAO certification, continue with the process. The security work behind that prep is what your self-assessment relies on. It's also what keeps you eligible for contract opportunities as primes still have to manage their own compliance risk regardless of the pause.

Part of continuing that prep should include a mock assessment, a practice run of the actual certification review and red-teaming (actively trying to get in the way a real attacker would, rather than just reviewing documents). This can include testing whether an old vendor account still has active access, or whether an unattended, unlocked laptop can still be used to log into your CUI environment. What counts as "Level 2 prep" could shift once the task force reports what’s next in mid-September, so it is recommended to treat that date as a checkpoint to reassess.

Who owns this: Whoever's been driving your CMMC prep (security lead, ops, or an outsourced provider). 

For a lot of small and mid-size subcontractors, there's usually no single owner for these action items. It's one person wearing multiple hats, often an IT generalist, an ops lead, or the founder, now covering contracts and compliance too. Either way, staying on top of these items keeps you prepared for what's next and keeps the door open for future opportunities. If a second set of eyes on any of this would be helpful, let's walk through it together.