Insights · CMMC Fundamentals
SPRS score vs CMMC: what the Phase 2 pause did not changeTwo obligations, routinely confused. One was suspended in July. The other has been in force since 2020, was never contingent on CMMC, and is the number a contracting officer can look up before deciding whether to award you anything.
Since the Phase 2 suspension in July I have had a version of the same conversation more than once. It goes: CMMC is paused, so we have some breathing room.
Then I ask what their SPRS score is, and the room goes quiet.
Framing
Two obligations, one confusion
These are separate requirements with separate legal bases, separate mechanics and separate consequences. Conflating them is the most common misunderstanding I encounter, and the Phase 2 suspension has made it considerably worse.
Your SPRS score comes from DFARS 252.204-7019 and 7020, in force since November 2020. It is a self-assessment you calculate and post. CMMC comes from 32 CFR Part 170 and the DFARS acquisition rule, and it changes who verifies your implementation and what counts as passing.
One of those was paused. The other was not, and never depended on the first.
Your SPRS score is what you say about yourself. CMMC certification is what someone else confirms.
Mechanics
What the SPRS score actually is
You work through NIST SP 800-171 using the DoD Assessment Methodology, start at 110, and subtract for each requirement not implemented. Deductions are weighted — some requirements cost one point, others three, the highest-impact ones five. There is no partial credit, with narrow exceptions around multifactor authentication and FIPS-validated encryption. The floor is −203, which surprises people the first time they run it honestly.
You post the result to the Supplier Performance Risk System with the assessment date and the date you expect to reach 110. A contractor self-assessment is a Basic assessment; Medium and High assessments are performed by the government.
No assessor is involved. Nobody checks it at the time you submit. That last part is the whole problem.
SPRS score — DFARS 252.204-7019 / -7020
You assess. You post.
no verification at submission
Partial score permitted
Award eligibility, not certification
Visible to contracting officers
Accuracy is a representation
Self-attested. Nobody checks at submission.
CMMC Level 2 — 32 CFR Part 170
A third party confirms.
examine · interview · test
Minimum threshold for conditional
POA&M closeout window
Some requirements cannot be deferred
Three-year term, annual affirmation
Verified. Partial becomes a countdown.
The core problem
A score is not a grade
Because nothing happens at submission, the score gets treated as a number to be managed rather than a measurement to be taken. I have seen scores produced by someone reading the control list and forming an impression. I have seen a 105 in an environment that could not produce audit logs.
Here is what I would want any contractor to sit with. You are not scoring yourself for your own benefit. You are making a representation to the government, in a government system, that a contracting officer will rely on under DFARS 252.204-7019 before award.
The Civil Cyber-Fraud Initiative exists because the Department of Justice decided that misrepresenting cybersecurity posture on federal contracts is worth pursuing under the False Claims Act, and there are settled cases behind that.
A low score is a business problem. An inaccurate score is a legal one. Those are not the same risk, and contractors routinely optimize against the wrong one.
Comparison
What CMMC adds on top
CMMC does not replace any of the above. It sits on top and changes two things: who verifies, and what counts as passing.
| Dimension | SPRS score | CMMC Level 2 |
|---|---|---|
| Legal basis | DFARS 252.204-7019 and -7020 | 32 CFR Part 170, implemented through the DFARS acquisition rule |
| In force since | November 2020 | Program rule December 2024; acquisition rule November 2025 |
| Who assesses | You, using the DoD Assessment Methodology | You for self-assessment; a C3PAO for certification; DIBCAC at Level 3 |
| Method | Calculation against your system security plan | Objectives evaluated by examine, interview and test |
| Partial implementation | Permitted — post the score you have | Threshold applies; closeout window applies; some requirements cannot sit on a POA&M |
| What it produces | A number visible to contracting officers | A status recorded against the contract |
| Ongoing obligation | Keep it current and accurate | Annual affirmation by a senior official |
| Status as of today | Unaffected by the Phase 2 suspension | Phase 1 self-assessment active; Phase 2 certification milestone suspended |
Verify the current conditional-status specifics against 32 CFR 170.21 before planning around them — the thresholds and closeout mechanics are exactly the kind of detail that moves. But understand the direction of travel. Under the DoD Assessment Methodology, partial is a position you can hold. Under CMMC, partial becomes a countdown.
Interactive
What do you owe right now?
Four questions, following the order the obligations actually attach.
Obligation check
DFARS 252.204-7012 / -7019 / -7020 / -7021
Question 1 of 4
The pause
What the pause did and did not suspend
In July the Department suspended Phase 2 — the milestone that would have made third-party Level 2 assessment the standard for applicable CUI contracts from November — and stood up a reform task force to review the program on a sixty-day clock. Public comments closed in mid-August. A report is expected this autumn.
Read carefully what was suspended.
| Obligation | Status |
|---|---|
| CMMC Phase 2 certification milestone | Suspended pending review |
| 32 CFR Part 170 program rule | Unamended, in force |
| DFARS acquisition rule | Unamended, in force |
| Phase 1 self-assessment requirements | Active in solicitations |
| DFARS 252.204-7012 | Unaffected |
| NIST SP 800-171 implementation | Unaffected |
| SPRS score submission and accuracy | Unaffected |
| C3PAO certification assessments | Still available to anyone who wants one |
Phased rollout status · August 2026
- Phase 1 — ActiveFrom November 2025. Level 1 and Level 2 self-assessment requirements in solicitations.
- Phase 2 — SuspendedC3PAO certification milestone, paused pending review.
- Phase 3 — On holdPending the outcome of the review.
- Phase 4 — On holdPending the outcome of the review.
Reform task force reporting expected autumn 2026.
The program’s history runs one direction. The 2020 interim rule became CMMC 2.0, which became the 2024 program rule, which became the 2025 acquisition rule. Every step slipped its expected timing. None reversed.
Strategy
Why waiting is the expensive option
There is a version of this moment where contractors stop, and a version where they use it.
Consider the assessor math. Something on the order of a hundred authorized C3PAOs exist against a defense industrial base of well over a hundred thousand companies. Whatever Phase 2 eventually looks like, that ratio does not improve by waiting. Organizations that book assessments while demand is low will be certified while others are still in a queue.
Primes do not wait for regulators. Flow-down requirements move on the prime’s schedule, not the Department’s. I have watched subcontractors receive a compliance requirement in a contract months before anything obliged them to have one, because the prime decided their own exposure warranted it.
And the underlying work is the same work. Every requirement you implement improves a score you are already obliged to maintain, and shortens the path to certification if and when it is required. There is no version of the review outcome that makes implemented controls worthless.
The question I would ask your leadership
If a contracting officer pulled your SPRS score this afternoon, and then asked you to walk them through how you arrived at it, how long would that conversation take before someone had to say they would need to check?
That interval is your real compliance position. The number in the system is just the claim.
Action
Three things to do while the review runs
- Re-score honestlyNot the number you posted — the number that is true today. Run it against your actual system security plan, requirement by requirement. If the gap between the two embarrasses you, that is the finding.
- Check the date on your submissionIf your posted score predates a material change to your environment — a migration, a new provider, a new CUI workflow — it describes a company that no longer exists.
- Close the five-point requirements firstThey cost the most in scoring, and they are the ones least likely to be tolerated on a POA&M under CMMC. Highest scoring return and highest certification relevance in the same set.
None of that depends on what the task force recommends.
Primary sources for this brief
- DFARS 252.204-7012, -7019, -7020, -7021
- NIST SP 800-171 DoD Assessment Methodology, v1.2.1
- 32 CFR Part 170 — CMMC Program, § 170.21 assessment findings and POA&M
- DoD CIO memorandum suspending Phase 2, July 2026
- DOJ Civil Cyber-Fraud Initiative — announced October 2021
FAQ
Common questions
Does the Phase 2 suspension affect my SPRS score obligation?
No. The SPRS score requirement comes from DFARS 252.204-7019 and 7020, which have been in force since November 2020 and were never contingent on CMMC. The suspension applies to one phase of the CMMC rollout schedule.
Is an SPRS score of 110 the same as CMMC Level 2 certification?
No. A score of 110 is your own statement that all 110 requirements are implemented. CMMC Level 2 certification is a third party confirming the same thing after examining artifacts, interviewing owners and testing controls. The requirements overlap; the evidentiary standard does not.
Can I still get a CMMC assessment during the suspension?
Yes. Certification assessments remain available. What was suspended is the milestone that would have made them mandatory for applicable contracts, not the ability to obtain one.
How often does my SPRS score need updating?
Scores carry a validity period, but the more useful standard is accuracy. If your environment has changed materially since you calculated it, the posted score no longer describes your system regardless of how recently it was submitted.
What is the actual legal exposure for an inaccurate score?
The score is a representation relied on in the award process. The Department of Justice pursues misrepresented cybersecurity posture under the False Claims Act through the Civil Cyber-Fraud Initiative, and there are settled cases. This is not a hypothetical category of risk.
Should we pause our readiness work until the task force reports?
The work improves a score you are already required to maintain, so it has value under every outcome. The assessor-to-contractor ratio also does not improve by waiting, and primes set flow-down requirements on their own schedule regardless of the Department’s calendar.
Related reading
- CMMC readiness: why companies think they’re readyPublished
- CMMC scope: what the rule says and where it breaksPublished
- SPRS score vs CMMC: what the pause did not changeYou are here
- Identifying CUI: markings, categories and contract clausesNext
- The SSP that survives an assessmentComing
This brief reflects program status as of 31 August 2026. The reform task force review was ongoing at the time of writing. Verify current requirements against your contract clauses and published DoD guidance before making compliance decisions.
Cyber DSC · Insights · Compliance brief · 31 Aug 2026
