← Back to Resources
DCG Blog

CMMC After the Pause: What 30 Days of DoW Solicitations Actually Tell Us

Defense contractor procurement documents, a laptop, and a stopwatch in a precision manufacturing workshop.

There has been a lot of discussion about what happens to CMMC after the pause and after we hear from the Reform Task Force. For defense contractors, the CMMC pause (more precisely the CMMC Level 2 pause, a pause in Level 2 enforcement) has raised a practical question about which CMMC requirements still apply. The answer is also arriving under the broader changes of the Revolutionary FAR Overhaul.

A common assumption seems to be that if CMMC Level 2 certification requirements are delayed, reduced, or removed from solicitations, then the cybersecurity requirements facing defense contractors in the Defense Industrial Base have largely disappeared with them. That is not what we thought would happen, and that is NOT what we are seeing.

Defense Cybersecurity Group recently reviewed a 30-day sample of cyber-relevant Department of Defense solicitations and solicitation amendments published between September 3 and October 3, 2026. We looked specifically at how contracting activities are implementing the Cybersecurity Maturity Model Certification (CMMC) program, NIST SP 800-171, SPRS, Controlled Unclassified Information (CUI) access requirements, and the new FAR/DFARS cybersecurity provisions. The conclusion is increasingly clear:

The CMMC program is not dead, even during the pause. It is a distributed cybersecurity qualification regime being implemented differently by individual contracting activities.

We see consistency inside of contracting activities but a great deal of variation across contracting activities. And there is another complication. Those contracting activities are implementing these requirements while simultaneously navigating an incomplete transition between the legacy DFARS cybersecurity framework and the new FAR/DFARS overhaul. The result is not merely perceived inconsistency. The contractual requirements are inconsistent.

What We Measured

Rather than simply searching solicitations for the word “CMMC,” we evaluated five separate characteristics.

1. Which cybersecurity clause architecture is the solicitation using?

We looked for:

  • legacy DFARS 252.204-7019 and 252.204-7020;
  • DFARS 252.204-7012 and the NIST SP 800-171 Rev 2 security controls it points to;
  • the new DFARS 252.240-7997 assessment clause;
  • CMMC clauses and provisions;
  • combinations of legacy and new language.

This matters because the February 2026 FAR overhaul materially changed the framework. DFARS 252.204-7019 was actually eliminated under the deviation, and the new 252.240-7997 replaced the prior 7020 assessment framework clause. Importantly, the new 7997 does not include the old contractor Basic Assessment requirement. DoW has continued revising the Part 240 deviation during 2026, including Revision 3 issued September 3 which incorporates the CMMC pause language. Simultaneously over 8 months later the legacy clauses and language (7019, give us your SPRS score, etc) remains visible in new RFPs and contracts. That means contractors cannot simply assume that the DFARS text they historically relied upon, the current online regulatory repository, the class deviation, and the language actually appearing in a solicitation will necessarily tell the same story. Once again contractors will need to navigate these shoal filled waters carefully to reduce their risk and meet their increasingly complex and varied cyber compliance obligations.

2. How Is SPRS Being Used?

The answer is: several different ways. Some acquisitions simply incorporate the new assessment framework. Others impose very specific SPRS requirements. USSOCOM, for example, required contractors seeking access to restricted CUI solicitation information to maintain a current NIST SP 800-171 DoW Assessment score of 110 in SPRS before access would be granted. That is not merely a contract-performance requirement. It is an information-access gate.

At Offutt AFB, the approach was different. Contractors seeking three CUI documents were required to have an SPRS self-assessment score of 110. However, if they did not have a 110, the solicitation allowed access where appropriate POA&Ms had been filed in SPRS. This is of course problematic because SPRS does not actually have a functionality to file a POA&M.

Then consider Robins AFB. One current solicitation requires a satisfactory SPRS score of 110 to be considered for award, while simultaneously requiring only CMMC Level 1 Self. That combination is particularly revealing. Someone looking only at the stated CMMC level might reasonably conclude: “This is just a Level 1 procurement.” But the same procurement imposes a 110 NIST SP 800-171 assessment-score requirement. Those are very different cybersecurity obligations.

Fundamentally this boils down to a number of different uses of SPRS. Some consistent with existing regulation, some consistent with old regulation, and some operating in uncharted territory based on the contracting activities outlook.

3. Where Is the Self-Assessment Requirement Coming From?

Historically, that question was relatively straightforward. Under the old architecture, DFARS 252.204-7019 and 7020 provided the Basic Assessment and SPRS mechanism. That architecture has now changed. But contractor self-assessment obligations have not disappeared. Instead, we are seeing them originate from several places:

  • CMMC Level 1 Self requirements;
  • CMMC Level 2 Self requirements;
  • solicitation-specific instructions;
  • SPRS requirements for information access;
  • controlled-document release procedures;
  • program-office acquisition policies;
  • and, in some cases, legacy DFARS language that remains in solicitation templates.

This is important because it means the practical requirement facing a contractor can no longer be understood simply by reading one clause. You have to look at the entire acquisition to see what you are contractually obligated to do.

4. What CMMC Levels Are Actually Appearing?

Our 30-day cyber-relevant sample contained numerous Level 1 and Level 2 Self requirements. What was largely absent was Level 2 certification through a C3PAO, the third party assessments. CMMC Level 1 is appearing on relatively ordinary acquisitions. CMMC Level 2 Self, however, is increasingly being used where CUI or controlled technical information enters the acquisition, although overall explicit CMMC requirements appeared in fewer than 20% of the broader recent-acquisition sample we reviewed. One current Air Force Minuteman III connector procurement requires offerors to submit evidence of an active CMMC Level 2 Self assessment with the proposal itself rather than at contract award. If the company does not have the required cybersecurity status when it submits its proposal, it has a procurement problem.

That absence matters because CMMC Phase II, scheduled for November 2026, is the point at which new contracts were expected to require Level 2 third party assessments to be complete before award. Many contractors have been planning around the CMMC Phase II requirements. What we are seeing in solicitations suggests they should plan around the buying activity instead.

We are seeing the same general model in NAVAIR and other organizations where contractors need CMMC Level 2 Self status before receiving CUI technical-data packages or drawings. This is effectively moving the testing point from at contract award to at contract solicitations. Many have continued to point out the regulatory check point as being at contract award, and this is absolutely correct. It just does not match what we are seeing in execution. Increasingly in some form, cyber compliance is needed before you can even receive RFP materials, or at least at RFP submission, rather than waiting until contract award.

5. At What Point Is Cybersecurity Being Enforced?

This may be the most important measurement of all. The answer is no longer simply: “During contract performance.” We observed cybersecurity requirements being enforced at multiple points in the acquisition lifecycle: before access to RFP information, at the proposal stage, at contract award, and during contract execution.

Before the Contractor Can Access the Solicitation Information

USSOCOM requires the appropriate SPRS posture before releasing restricted CUI. Other buying activities are similarly using CMMC status, SPRS information, JCP registration, or combinations of those requirements before releasing controlled technical data. This means cybersecurity readiness can determine whether a company can even obtain enough information to decide whether to bid.

At Proposal Submission

The Minuteman III solicitation requires evidence of CMMC Level 2 Self status with the proposal. Cybersecurity has become part of proposal responsiveness.

Before Award

Robins AFB explicitly requires an SPRS score of 110 before an offeror can be considered for award. Cybersecurity has become an award-eligibility criterion.

During Contract Performance

CMMC status requirements also continue through performance. Robins, for example, requires the contractor to maintain its CMMC Level 1 status for the duration of the contract. So the emerging model is not one cybersecurity checkpoint.

The Most Important Pattern: Implementation Is Local

Perhaps the most interesting observation from the sample is that cybersecurity implementation appears to cluster by contracting activity and program office. NAVAIR Lakehurst appears to have developed a recognizable approach for controlled technical data. DLA Maritime frequently uses Level 1 Self on routine supply acquisitions. Hill AFB is using Level 2 Self as a proposal requirement in some acquisitions. Robins AFB has explicitly combined a 110 SPRS requirement with Level 1 CMMC. USSOCOM has used a 110 SPRS score as an access gate to CUI. Other organizations allow lower SPRS scores accompanied by POA&Ms.

These are not minor drafting differences. They determine who gets access to information, who can submit an acceptable proposal, and who can receive an award. This suggests that the wrong question may be: “What is DoW doing with CMMC?” A more useful question is: “What is the particular buying activity I care about doing with cybersecurity qualification?” That distinction will matter enormously.

The FAR Overhaul Makes the Situation Even More Complicated

The Revolutionary FAR Overhaul introduced a new cybersecurity clause structure. For example, FAR 52.240-93 now provides the Basic Safeguarding framework, and DFARS 252.240-7997 provides the new NIST SP 800-171 DoW Assessment requirements under the deviation. DoW continues to maintain and revise the Part 240 class deviation separately from the ordinary codified DFARS structure. This creates a practical ground-truth problem. Contractors have historically been told: “Go read the FAR and DFARS.” That is no longer necessarily enough. The operative requirement may depend on:

  • the codified regulation;
  • an active class deviation;
  • the solicitation;
  • an amendment;
  • a program-office instruction;
  • an SPRS requirement;
  • a CMMC requirement;
  • or some combination of all of them.

That is a messy environment. But it is the environment contractors actually have to operate in.

What the 30-Day Sample Does Not Tell Us

Our sample was intentionally focused on solicitations where there was enough publicly available cybersecurity information to analyze actual implementation. It was not a statistically random sample of every DoW procurement issued during the period. Therefore, percentages observed within this cyber-relevant sample should not be interpreted as saying, for example: “X percent of all DoW solicitations require Level 2 Self.” That would require a much larger and more rigorously constructed acquisition dataset. Earlier sampling suggested that approximately 15 percent of a small group of recently posted DoW solicitations contained an identifiable explicit CMMC requirement. That number is interesting and worth further research. It is not yet a DoW-wide statistic. The stronger conclusion is qualitative, and it is supported by repeated examples across multiple services and contracting activities.

So What Does the Sample Actually Tell Us?

  1. CMMC did not disappear.
    • Level 1 Self and Level 2 Self continue to appear in active procurements.
  2. The underlying NIST SP 800-171 qualification ecosystem did not disappear either.
    • SPRS remains commercially important even though the regulatory architecture supporting it has changed.
  3. Cybersecurity is increasingly being enforced before contract performance begins.
    • It may determine whether a company gets the drawings, sees the CUI, submits a responsive proposal, or receives an award.
  4. Implementation requirements differ materially between buying activities.
    • Contractors should expect different approaches from DLA, NAVAIR, Air Force program offices, Army contracting activities, USSOCOM, Space Force, USACE, and others.
  5. The FAR overhaul has added another layer of uncertainty.
    • Legacy language, new deviation language, CMMC requirements, and local acquisition practices are currently mixed together in varying ways by different contracting activities.

What This Means for Defense Contractors

The practical implication is straightforward. Do not build your cybersecurity strategy around the question: “When will CMMC Level 2 certification come back?” That question is too narrow. Instead ask: “What cybersecurity qualification will I need to pursue the contracts I want?” Depending on the customer, that answer might be:

  • CMMC Level 1 Self;
  • CMMC Level 2 Self;
  • a CMMC UID;
  • a particular SPRS status;
  • a 110 SPRS score;
  • a lower score supported by POA&Ms;
  • JCP registration plus CMMC status;
  • compliance with the new DFARS 252.240-7997 assessment regime;
  • or some combination of these.

This matters most for small and medium sized businesses, where prohibitive compliance costs are a real worry and a wrong guess about which qualification a customer will ask for is expensive.

And you may need it before the RFP ever reaches the proposal-writing stage. That is the larger lesson from the last 30 days. CMMC may be changing. The FAR and DFARS may be changing. The method by which the Government measures contractor cybersecurity may be changing. But the Government is still using cybersecurity posture to decide who gets access, who gets to compete, and who gets the work. The CMMC program is not dead. It is a distributed cybersecurity qualification regime being implemented differently by individual contracting activities. For the Defense Industrial Base, that distinction matters.

Working Source Links

← All posts

Know What Your Next Solicitation Requires

DCG helps defense contractors interpret changing CMMC, SPRS, FAR, and DFARS requirements and turn them into a practical readiness plan.

Explore consulting for defense contractors
Ready to Talk?

The First Conversation Is Free.
And It Will Tell You the Truth.

If this raised a question about your specific situation, the next step is a conversation with DCG. We will tell you honestly what we see before we tell you anything about our services.

Book a Free Consultation