Insights · CMMC Fundamentals

SPRS score vs CMMC: what the Phase 2 pause did not change

Two obligations, routinely confused. One was suspended in July. The other has been in force since 2020, was never contingent on CMMC, and is the number a contracting officer can look up before deciding whether to award you anything.

Since the Phase 2 suspension in July I have had a version of the same conversation more than once. It goes: CMMC is paused, so we have some breathing room.

Then I ask what their SPRS score is, and the room goes quiet.

Framing

Two obligations, one confusion

These are separate requirements with separate legal bases, separate mechanics and separate consequences. Conflating them is the most common misunderstanding I encounter, and the Phase 2 suspension has made it considerably worse.

Your SPRS score comes from DFARS 252.204-7019 and 7020, in force since November 2020. It is a self-assessment you calculate and post. CMMC comes from 32 CFR Part 170 and the DFARS acquisition rule, and it changes who verifies your implementation and what counts as passing.

One of those was paused. The other was not, and never depended on the first.

Your SPRS score is what you say about yourself. CMMC certification is what someone else confirms.

Mechanics

What the SPRS score actually is

You work through NIST SP 800-171 using the DoD Assessment Methodology, start at 110, and subtract for each requirement not implemented. Deductions are weighted — some requirements cost one point, others three, the highest-impact ones five. There is no partial credit, with narrow exceptions around multifactor authentication and FIPS-validated encryption. The floor is −203, which surprises people the first time they run it honestly.

You post the result to the Supplier Performance Risk System with the assessment date and the date you expect to reach 110. A contractor self-assessment is a Basic assessment; Medium and High assessments are performed by the government.

No assessor is involved. Nobody checks it at the time you submit. That last part is the whole problem.

SPRS self-assessment compared with CMMC certification Left panel: SPRS score, self-calculated, posted by the contractor, partial scores permitted. Right panel: CMMC Level 2 certification, verified by a third party, with a threshold and a closeout window. SPRS SCORE — DFARS 252.204-7019 / -7020 CMMC LEVEL 2 — 32 CFR PART 170 You assess. You post. no verification at submission · Partial score permitted · Award eligibility, not certification · Visible to contracting officers · Accuracy is a representation A third party confirms. examine · interview · test · Minimum threshold for conditional · POA&M closeout window · Some requirements cannot be deferred · Three-year term, annual affirmation

SPRS score — DFARS 252.204-7019 / -7020

You assess. You post.

no verification at submission

Partial score permitted
Award eligibility, not certification
Visible to contracting officers
Accuracy is a representation

Self-attested. Nobody checks at submission.

CMMC Level 2 — 32 CFR Part 170

A third party confirms.

examine · interview · test

Minimum threshold for conditional
POA&M closeout window
Some requirements cannot be deferred
Three-year term, annual affirmation

Verified. Partial becomes a countdown.

Figure 1 — The same 110 requirements, two different claimsAn SPRS score of 88 and a CMMC Level 2 certification are not equivalent statements about your environment, even where the underlying requirements are identical.

The core problem

A score is not a grade

Because nothing happens at submission, the score gets treated as a number to be managed rather than a measurement to be taken. I have seen scores produced by someone reading the control list and forming an impression. I have seen a 105 in an environment that could not produce audit logs.

Here is what I would want any contractor to sit with. You are not scoring yourself for your own benefit. You are making a representation to the government, in a government system, that a contracting officer will rely on under DFARS 252.204-7019 before award.

The Civil Cyber-Fraud Initiative exists because the Department of Justice decided that misrepresenting cybersecurity posture on federal contracts is worth pursuing under the False Claims Act, and there are settled cases behind that.

A low score is a business problem. An inaccurate score is a legal one. Those are not the same risk, and contractors routinely optimize against the wrong one.

Comparison

What CMMC adds on top

CMMC does not replace any of the above. It sits on top and changes two things: who verifies, and what counts as passing.

DimensionSPRS scoreCMMC Level 2
Legal basis DFARS 252.204-7019 and -7020 32 CFR Part 170, implemented through the DFARS acquisition rule
In force since November 2020 Program rule December 2024; acquisition rule November 2025
Who assesses You, using the DoD Assessment Methodology You for self-assessment; a C3PAO for certification; DIBCAC at Level 3
Method Calculation against your system security plan Objectives evaluated by examine, interview and test
Partial implementation Permitted — post the score you have Threshold applies; closeout window applies; some requirements cannot sit on a POA&M
What it produces A number visible to contracting officers A status recorded against the contract
Ongoing obligation Keep it current and accurate Annual affirmation by a senior official
Status as of today Unaffected by the Phase 2 suspension Phase 1 self-assessment active; Phase 2 certification milestone suspended

Verify the current conditional-status specifics against 32 CFR 170.21 before planning around them — the thresholds and closeout mechanics are exactly the kind of detail that moves. But understand the direction of travel. Under the DoD Assessment Methodology, partial is a position you can hold. Under CMMC, partial becomes a countdown.

Interactive

What do you owe right now?

Four questions, following the order the obligations actually attach.

Obligation check

DFARS 252.204-7012 / -7019 / -7020 / -7021

Question 1 of 4

The pause

What the pause did and did not suspend

In July the Department suspended Phase 2 — the milestone that would have made third-party Level 2 assessment the standard for applicable CUI contracts from November — and stood up a reform task force to review the program on a sixty-day clock. Public comments closed in mid-August. A report is expected this autumn.

Read carefully what was suspended.

ObligationStatus
CMMC Phase 2 certification milestoneSuspended pending review
32 CFR Part 170 program ruleUnamended, in force
DFARS acquisition ruleUnamended, in force
Phase 1 self-assessment requirementsActive in solicitations
DFARS 252.204-7012Unaffected
NIST SP 800-171 implementationUnaffected
SPRS score submission and accuracyUnaffected
C3PAO certification assessmentsStill available to anyone who wants one
CMMC phased rollout status Phase 1 active from November 2025. Phases 2 through 4 suspended pending the reform task force review announced in July 2026. PHASE 1 NOV 2025 · ACTIVE self-assessment PHASE 2 SUSPENDED C3PAO certification PHASE 3 ON HOLD PHASE 4 ON HOLD PHASED ROLLOUT STATUS · AUGUST 2026 Reform task force reporting expected autumn 2026.

Phased rollout status · August 2026

  • Phase 1 — ActiveFrom November 2025. Level 1 and Level 2 self-assessment requirements in solicitations.
  • Phase 2 — SuspendedC3PAO certification milestone, paused pending review.
  • Phase 3 — On holdPending the outcome of the review.
  • Phase 4 — On holdPending the outcome of the review.

Reform task force reporting expected autumn 2026.

Figure 2 — One phase paused, the rules unamendedAn administrative pause on a rollout phase is not a repeal. The program rule and the acquisition rule both remain in force.

The program’s history runs one direction. The 2020 interim rule became CMMC 2.0, which became the 2024 program rule, which became the 2025 acquisition rule. Every step slipped its expected timing. None reversed.

Strategy

Why waiting is the expensive option

There is a version of this moment where contractors stop, and a version where they use it.

Consider the assessor math. Something on the order of a hundred authorized C3PAOs exist against a defense industrial base of well over a hundred thousand companies. Whatever Phase 2 eventually looks like, that ratio does not improve by waiting. Organizations that book assessments while demand is low will be certified while others are still in a queue.

Primes do not wait for regulators. Flow-down requirements move on the prime’s schedule, not the Department’s. I have watched subcontractors receive a compliance requirement in a contract months before anything obliged them to have one, because the prime decided their own exposure warranted it.

And the underlying work is the same work. Every requirement you implement improves a score you are already obliged to maintain, and shortens the path to certification if and when it is required. There is no version of the review outcome that makes implemented controls worthless.

The question I would ask your leadership

If a contracting officer pulled your SPRS score this afternoon, and then asked you to walk them through how you arrived at it, how long would that conversation take before someone had to say they would need to check?

That interval is your real compliance position. The number in the system is just the claim.

Action

Three things to do while the review runs

  1. Re-score honestlyNot the number you posted — the number that is true today. Run it against your actual system security plan, requirement by requirement. If the gap between the two embarrasses you, that is the finding.
  2. Check the date on your submissionIf your posted score predates a material change to your environment — a migration, a new provider, a new CUI workflow — it describes a company that no longer exists.
  3. Close the five-point requirements firstThey cost the most in scoring, and they are the ones least likely to be tolerated on a POA&M under CMMC. Highest scoring return and highest certification relevance in the same set.

None of that depends on what the task force recommends.

Primary sources for this brief

  • DFARS 252.204-7012, -7019, -7020, -7021
  • NIST SP 800-171 DoD Assessment Methodology, v1.2.1
  • 32 CFR Part 170 — CMMC Program, § 170.21 assessment findings and POA&M
  • DoD CIO memorandum suspending Phase 2, July 2026
  • DOJ Civil Cyber-Fraud Initiative — announced October 2021

FAQ

Common questions

Does the Phase 2 suspension affect my SPRS score obligation?

No. The SPRS score requirement comes from DFARS 252.204-7019 and 7020, which have been in force since November 2020 and were never contingent on CMMC. The suspension applies to one phase of the CMMC rollout schedule.

Is an SPRS score of 110 the same as CMMC Level 2 certification?

No. A score of 110 is your own statement that all 110 requirements are implemented. CMMC Level 2 certification is a third party confirming the same thing after examining artifacts, interviewing owners and testing controls. The requirements overlap; the evidentiary standard does not.

Can I still get a CMMC assessment during the suspension?

Yes. Certification assessments remain available. What was suspended is the milestone that would have made them mandatory for applicable contracts, not the ability to obtain one.

How often does my SPRS score need updating?

Scores carry a validity period, but the more useful standard is accuracy. If your environment has changed materially since you calculated it, the posted score no longer describes your system regardless of how recently it was submitted.

What is the actual legal exposure for an inaccurate score?

The score is a representation relied on in the award process. The Department of Justice pursues misrepresented cybersecurity posture under the False Claims Act through the Civil Cyber-Fraud Initiative, and there are settled cases. This is not a hypothetical category of risk.

Should we pause our readiness work until the task force reports?

The work improves a score you are already required to maintain, so it has value under every outcome. The assessor-to-contractor ratio also does not improve by waiting, and primes set flow-down requirements on their own schedule regardless of the Department’s calendar.

Related reading

  1. CMMC readiness: why companies think they’re readyPublished
  2. CMMC scope: what the rule says and where it breaksPublished
  3. SPRS score vs CMMC: what the pause did not changeYou are here
  4. Identifying CUI: markings, categories and contract clausesNext
  5. The SSP that survives an assessmentComing

This brief reflects program status as of 31 August 2026. The reform task force review was ongoing at the time of writing. Verify current requirements against your contract clauses and published DoD guidance before making compliance decisions.

Nabiha Sofia Herradi

Principal · Cyber DSC

Sofia advises defense and technology companies on CMMC readiness, NIST SP 800-171 implementation and privacy programs, with a focus on the parts of compliance that only work when people outside IT own them. She holds CMMC-CCP, CISM, CIPP/E and CIPP/US.

Cyber DSC · Insights · Compliance brief · 31 Aug 2026