---
title: "When CMMC Phase 2 is paused, what manufacturers should st..."
url: https://trnsfrm.tech/blog/cmmc-phase-2-pause-nist-800-171-sprs-manufacturers
description: "CMMC Phase 2 third-party assessments are on hold. DFARS 7012, NIST 800-171, and honest SPRS scores are not. Here is what manufacturers and DoD suppliers…"
lang: en
---

Back to blog (https://trnsfrm.tech/blog)
Image: When CMMC Phase 2 is paused, what manufacturers should still do on NIST 800-171 and SPRS (https://trnsfrm.tech/blog-covers/cmmc-phase-2-pause-nist-sprs.jpg)

By Jeff Dennis (https://www.linkedin.com/in/jefferydennis), Founder & CEO October 8, 2026

# When CMMC Phase 2 is paused, what manufacturers should still do on NIST 800-171 and SPRS

## What the Phase 2 pause actually changed

In July 2026, the Department of Defense suspended CMMC Phase 2. The big change is about **who assesses you**, not **whether you still have to protect CUI**.

During the suspension, requiring activities may generally include only CMMC Level 1 (Self) or Level 2 (Self) in new procurements. Third-party Level 2 (C3PAO) and Level 3 (DIBCAC) designations for new contract requirements are on hold. The November 2026 Phase 2 transition that many teams were planning around is suspended pending reform review.

What did **not** pause:

- DFARS 252.204-7012 (https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting) safeguarding and 72-hour cyber incident reporting
- Implementation of **NIST SP 800-171 Rev. 2** for covered defense information
- SPRS assessment scores and related self-assessment expectations where your contracts and clauses require them
- Annual affirmations tied to Level 1 / Level 2 self-assessment when your award requires them
- Basic safeguarding of Federal Contract Information under FAR 52.204-21

Official guidance is clear: during the suspension the Department will still enforce baseline compliance with NIST SP 800-171 Rev. 2 through self-assessment and select government-led assessments. If you want the primary source, start with the DoD CIO Implementing Suspension of CMMC Phase II (https://dodcio.defense.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf) memorandum.

## Why manufacturers should not treat this as a free pass

Most manufacturers in the DoD supply chain do not live on certification calendars alone. You live on **prime flow-downs**, **RFQ cybersecurity questionnaires**, and **whether your SPRS number looks real**.

A pause on third-party CMMC designations does not erase:

- Contract language that already requires 7012 / 800-171
- A prime that still demands evidence, an SSP, or a minimum SPRS score before you stay on the bid list
- False Claims Act risk if you affirm a posture you cannot defend

If your drawings, specs, or program data are CUI (or you process Covered Defense Information), the operational work remains the same: scope it, protect it, document it, and score it honestly.

## Keep NIST 800-171 moving: a shop-floor checklist

Treat the pause as time to close real gaps, not as a reason to freeze the program. Use this sequence.

### 1. Reconfirm CUI scope (one page is enough to start)

Write down where CUI enters, where it sits, and where it leaves:

- Email and file shares
- ERP / PLM / MES
- Engineering workstations and CAD vaults
- Shop-floor systems that open drawings or travelers
- Vendor portals and remote access paths

If a CNC controller or tablet opens CUI drawings, it is in scope. "OT is separate" is not a control.

### 2. Refresh the asset inventory against that boundary

You need an authoritative list of in-scope endpoints, servers, SaaS, and network gear. Stale inventories produce stale SPRS scores.

### 3. Score all 110 controls against reality

Use NIST SP 800-171A style objectives. Mark each control YES / PARTIAL / NO based on what exists today, not what is "in progress" without evidence.

Then calculate (or recalculate) your SPRS score with the DoD methodology. Do not invent points you cannot show an assessor, a prime, or a government reviewer.

### 4. Put the gaps in a living POA&M

Every open item needs:

- A named owner
- A target date
- A status someone reviews weekly

An undated POA&M reads as "we will never fix this."

### 5. Lock an SSP that matches the plant you actually run

Your System Security Plan should describe the current environment, the CUI boundary, residual risk, and how each in-scope control is implemented. If the document and the shop disagree, the shop wins in an assessment. Fix the document or fix the control.

For a manufacturer-oriented walkthrough of this sequence, see The Manufacturer's Guide to NIST 800-171 (https://trnsfrm.tech/resources/manufacturers-guide-nist-800-171).

## SPRS: what "good" looks like while Phase 2 is paused

SPRS is still how many primes and programs size you up. A few operator rules:

- **Accuracy beats optimism.** An inflated score creates False Claims Act exposure. An honest lower score with a dated POA&M is defensible. A fiction is not.
- **Keep the submission current.** Know when your last assessment was posted, what score you claimed, and which systems it covered.
- **Align score, SSP, and evidence.** If SPRS says MFA is implemented, your identity reports and admin accounts should prove it.
- **Watch prime thresholds.** Many primes want a positive score. Some want closer to 110. Confirm what *your* primes require in writing, not what a LinkedIn thread claims.

During the pause, self-assessment quality matters more, not less. You may not face a C3PAO on day one of every new award, but you can still face government-led review, prime due diligence, and contract clauses that expect 7012 performance.

## High-leverage controls manufacturers usually underfund

If bandwidth is limited, prioritize work that closes multiple weighted gaps and reduces real incident risk:

- **MFA** on remote access, email, and admin accounts
- **Unique admin IDs** (shared "admin" is a finding waiting to happen)
- **FIPS-validated encryption** for endpoints and removable media where required
- **Centralized logging** with retention and actual weekly review
- **Incident response** that includes 72-hour DoD reporting paths and a recent tabletop
- **Vendor flow-down** for subcontractors who touch your CUI

These are not "CMMC theater." They are the controls that fail quietly on the plant floor and then show up in RFQs.

## What to ask your primes this week

Send a short note (or put it on the next QBRs):

1. Which of our current POs or upcoming bids still require DFARS 252.204-7012 / NIST 800-171 evidence?
2. Do you still require a minimum SPRS score, and what is it?
3. What artifacts do you want on file: SSP, POA&M, SPRS screenshot, policies, or a third-party report?
4. If Phase 2 resumes, what lead time do you expect from us?

Do not assume every prime paused their supplier bar because DoD paused Phase 2 designations.

## A 30-day plan if you froze the program after the announcement

**Week 1:** CUI boundary sketch, asset list refresh, pull your last SPRS submission.

**Week 2:** Control-by-control gap pass on the 110. Recalculate score. Draft or update POA&M owners and dates.

**Week 3:** Close quick wins (MFA coverage, shared admin cleanup, logging retention, removable media encryption).

**Week 4:** SSP revisions, IR tabletop date on the calendar, written confirmation of prime expectations.

If you want a structured self-score first, use the free compliance checklist (https://trnsfrm.tech/compliance-checklist). For the broader CMMC context during the suspension, see our CMMC compliance overview (https://trnsfrm.tech/frameworks/cmmc).

## Bottom line

CMMC Phase 2 timing is uncertain. Your obligation to safeguard Covered Defense Information is not. Manufacturers that keep NIST 800-171 implementation, honest SPRS scoring, and prime-ready evidence moving will be ready whether Phase 2 stays paused, resumes, or reforms.

If you want a senior engineer to walk your current score and the gaps primes notice first, book a free 45-minute Compliance Gap Audit (https://trnsfrm.tech/book). You keep the written snapshot either way.

## Keep exploring

More from the TRNSFRM team.

### All Blog Posts

Browse every cybersecurity and IT article.
https://trnsfrm.tech/blog

### Case Studies

Real CMMC, NIST, and FTC outcomes.
https://trnsfrm.tech/case-studies

### Free Compliance Checklist

Score yourself across 47 controls in 10 minutes.
https://trnsfrm.tech/compliance-checklist

### Compliance Frameworks

CMMC, NIST 800-171, ISO 27001, HIPAA, FTC, ITAR.
https://trnsfrm.tech/governance

### Cybersecurity Operations

24/7 MDR, SOC, and threat response.
https://trnsfrm.tech/cybersecurity

### IT Resilience Framework

Assess, Remediate, Operate, Improve. A continuous lifecycle.
https://trnsfrm.tech/it-resilience-framework

### ITAR Compliance Checklist

Work through ITAR readiness control by control.
https://trnsfrm.tech/frameworks/itar

### MSP Partner Program

White-label security and compliance for MSPs.
https://trnsfrm.tech/partners/msp

### Choosing a Cybersecurity Firm

2026 buying guide and provider directory.
https://trnsfrm.tech/blog/cybersecurity-companies

## More industries we secure

Regulated-industry programs built by TRNSFRM.

### Aerospace & Space

AS9100, CMMC, ITAR programs for aerospace suppliers.
https://trnsfrm.tech/industries/aerospace-space

### Ambulatory Surgery Centers

HIPAA-grade IT for ASCs and outpatient surgery.
https://trnsfrm.tech/industries/ambulatory-surgery-centers

### Automotive Suppliers

TISAX, CMMC, and OEM cyber flow-downs.
https://trnsfrm.tech/industries/automotive-suppliers

### Behavioral Health

HIPAA + 42 CFR Part 2 for behavioral health providers.
https://trnsfrm.tech/industries/behavioral-health

### Defense & DoD Suppliers

CMMC 2.0 & NIST 800-171 for the defense industrial base.
https://trnsfrm.tech/industries/defense-dod-suppliers

### Dental Practices

Real HIPAA compliance for dental groups and DSOs.
https://trnsfrm.tech/industries/dental

## Featured cybersecurity insights

Deeper reads from the TRNSFRM team.

### Building an Incident Response Plan You'll Actually Use

A pragmatic IR playbook, not a shelf binder.
https://trnsfrm.tech/blog/building-an-incident-response-plan-you-ll-actually-use

### Cloud Misconfigurations: The #1 Cause of Data Breaches

Where teams get cloud wrong — and how to fix it.
https://trnsfrm.tech/blog/cloud-misconfigurations-the-1-cause-of-data-breaches

### CMMC 2.0: What Defense Contractors Must Do Now

The DIB compliance clock is ticking.
https://trnsfrm.tech/blog/cmmc-2-0-compliance-what-defense-contractors-must-do-now

### Deepfake Fraud in the Boardroom: The New CEO Scam

Why voice and video attacks now target execs.
https://trnsfrm.tech/blog/deepfake-fraud-in-the-boardroom-the-new-ceo-scam

### MFA Bypass Techniques and How to Stop Them

Attackers are getting past MFA — here's how.
https://trnsfrm.tech/blog/mfa-bypass-techniques-and-how-to-stop-them

### Quantum Computing and the Cryptography Apocalypse

Start planning your post-quantum crypto migration.
https://trnsfrm.tech/blog/quantum-computing-and-the-cryptography-apocalypse

Call Now: +18777776855

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "name": "TRNSFRM",
    "legalName": "Bitboyz LLC",
    "alternateName": [
      "TRNSFRM Technology",
      "Bitboyz",
      "Bitboyz LLC",
      "Bitboyz LLC DBA TRNSFRM"
    ],
    "url": "https://trnsfrm.tech",
    "logo": "https://trnsfrm.tech/wp-content/uploads/2021/11/trnsfrm-logo.svg",
    "image": "https://trnsfrm.tech/og-image.png",
    "description": "Cybersecurity, compliance, and managed IT services for manufacturers, construction, automotive, and healthcare organizations.",
    "foundingDate": "2008",
    "telephone": "+1-877-777-6855",
    "email": "info@trnsfrm.tech",
    "founder": {
      "@type": "Person",
      "name": "Jeff Dennis",
      "jobTitle": "Founder & CEO",
      "url": "https://trnsfrm.tech/",
      "sameAs": [
        "https://www.linkedin.com/in/jefferydennis"
      ]
    },
    "areaServed": [
      {
        "@type": "Country",
        "name": "United States"
      },
      {
        "@type": "City",
        "name": "Cleveland",
        "containedInPlace": {
          "@type": "State",
          "name": "Ohio"
        }
      },
      {
        "@type": "City",
        "name": "Columbus",
        "containedInPlace": {
          "@type": "State",
          "name": "Ohio"
        }
      }
    ],
    "address": [
      {
        "@type": "PostalAddress",
        "streetAddress": "10143 Royalton Rd Suite J",
        "addressLocality": "North Royalton",
        "addressRegion": "OH",
        "postalCode": "44133",
        "addressCountry": "US"
      },
      {
        "@type": "PostalAddress",
        "addressLocality": "Columbus",
        "addressRegion": "OH",
        "addressCountry": "US"
      }
    ],
    "contactPoint": {
      "@type": "ContactPoint",
      "contactType": "customer service",
      "telephone": "+1-877-777-6855",
      "email": "info@trnsfrm.tech",
      "areaServed": "US",
      "availableLanguage": "English"
    },
    "knowsAbout": [
      "CMMC",
      "NIST 800-171",
      "ISO 27001",
      "HIPAA",
      "FTC Safeguards",
      "ITAR",
      "Managed IT",
      "vCISO",
      "vCIO",
      "Cybersecurity",
      "Microsoft GCC High"
    ],
    "makesOffer": [
      {
        "@type": "Offer",
        "itemOffered": {
          "@type": "Service",
          "name": "Cybersecurity",
          "url": "https://trnsfrm.tech/cybersecurity",
          "provider": {
            "@type": "Organization",
            "name": "TRNSFRM"
          }
        }
      },
      {
        "@type": "Offer",
        "itemOffered": {
          "@type": "Service",
          "name": "Governance & Compliance",
          "url": "https://trnsfrm.tech/governance",
          "provider": {
            "@type": "Organization",
            "name": "TRNSFRM"
          }
        }
      },
      {
        "@type": "Offer",
        "itemOffered": {
          "@type": "Service",
          "name": "Managed IT",
          "url": "https://trnsfrm.tech/managed-it",
          "provider": {
            "@type": "Organization",
            "name": "TRNSFRM"
          }
        }
      },
      {
        "@type": "Offer",
        "itemOffered": {
          "@type": "Service",
          "name": "vCISO",
          "url": "https://trnsfrm.tech/vciso",
          "provider": {
            "@type": "Organization",
            "name": "TRNSFRM"
          }
        }
      },
      {
        "@type": "Offer",
        "itemOffered": {
          "@type": "Service",
          "name": "AI Integration & Implementation",
          "url": "https://trnsfrm.tech/services/ai",
          "provider": {
            "@type": "Organization",
            "name": "TRNSFRM"
          }
        }
      },
      {
        "@type": "Offer",
        "itemOffered": {
          "@type": "Service",
          "name": "Microsoft GCC / GCC High",
          "url": "https://trnsfrm.tech/services/microsoft-gcc",
          "provider": {
            "@type": "Organization",
            "name": "TRNSFRM"
          }
        }
      }
    ],
    "aggregateRating": {
      "@type": "AggregateRating",
      "ratingValue": "5.0",
      "reviewCount": "176",
      "bestRating": "5",
      "worstRating": "1"
    },
    "sameAs": [
      "https://www.linkedin.com/company/trnsfrmtech",
      "https://www.linkedin.com/in/jefferydennis",
      "https://clutch.co/profile/trnsfrm",
      "https://maps.google.com/?cid=0x8830ed5d3a6900c5:0xe344c24d13357f96",
      "https://www.goodfirms.co/company/trnsfrm",
      "https://www.bestitmsps.com/company/trnsfrm/"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "name": "TRNSFRM",
    "url": "https://trnsfrm.tech",
    "publisher": {
      "@type": "Organization",
      "name": "TRNSFRM"
    },
    "potentialAction": {
      "@type": "SearchAction",
      "target": "https://trnsfrm.tech/blog?q={search_term_string}",
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "ProfessionalService",
    "name": "TRNSFRM",
    "legalName": "Bitboyz LLC",
    "alternateName": [
      "TRNSFRM Technology",
      "Bitboyz",
      "Bitboyz LLC",
      "Bitboyz LLC DBA TRNSFRM"
    ],
    "url": "https://trnsfrm.tech",
    "image": "https://trnsfrm.tech/og-image.png",
    "telephone": "+1-877-777-6855",
    "email": "info@trnsfrm.tech",
    "address": {
      "@type": "PostalAddress",
      "streetAddress": "10143 Royalton Rd Suite J",
      "addressLocality": "North Royalton",
      "addressRegion": "OH",
      "postalCode": "44133",
      "addressCountry": "US"
    },
    "areaServed": [
      {
        "@type": "Country",
        "name": "United States"
      },
      {
        "@type": "City",
        "name": "Cleveland",
        "containedInPlace": {
          "@type": "State",
          "name": "Ohio"
        }
      },
      {
        "@type": "City",
        "name": "Columbus",
        "containedInPlace": {
          "@type": "State",
          "name": "Ohio"
        }
      }
    ],
    "priceRange": "$$",
    "sameAs": [
      "https://www.linkedin.com/company/trnsfrmtech",
      "https://www.linkedin.com/in/jefferydennis",
      "https://clutch.co/profile/trnsfrm",
      "https://maps.google.com/?cid=0x8830ed5d3a6900c5:0xe344c24d13357f96",
      "https://www.goodfirms.co/company/trnsfrm",
      "https://www.bestitmsps.com/company/trnsfrm/"
    ]
  },
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "BlogPosting",
        "headline": "When CMMC Phase 2 is paused, what manufacturers should still do on NIST 800-171 and SPRS",
        "description": "CMMC Phase 2 third-party assessments are on hold. DFARS 7012, NIST 800-171, and honest SPRS scores are not. Here is what manufacturers and DoD suppliers should keep doing while the timeline is uncertain.",
        "author": {
          "@type": "Person",
          "name": "Jeff Dennis",
          "jobTitle": "Founder & CEO",
          "url": "https://www.linkedin.com/in/jefferydennis",
          "sameAs": [
            "https://www.linkedin.com/in/jefferydennis"
          ],
          "worksFor": {
            "@type": "Organization",
            "name": "TRNSFRM",
            "url": "https://trnsfrm.tech"
          }
        },
        "datePublished": "2026-10-08T16:00:00+00:00",
        "publisher": {
          "@type": "Organization",
          "name": "TRNSFRM",
          "url": "https://trnsfrm.tech"
        },
        "image": "https://trnsfrm.tech/blog-covers/cmmc-phase-2-pause-nist-sprs.jpg"
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://trnsfrm.tech/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Blog",
            "item": "https://trnsfrm.tech/blog"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "When CMMC Phase 2 is paused, what manufacturers should still do on NIST 800-171 and SPRS",
            "item": "https://trnsfrm.tech/blog/cmmc-phase-2-pause-nist-800-171-sprs-manufacturers"
          }
        ]
      }
    ]
  }
]
```