There is no official fixed CMMC certification timeline. Most organizations should think in terms of months rather than weeks. For planning purposes, Level 1 readiness may take roughly 1–4 months, Level 2 may take around 6–18 months, and Level 3 preparation may take 18–24 months or longer when the Level 2 prerequisite is included. These are planning estimates, not government-guaranteed timelines. The actual amount of time depends on the required CMMC level, the maturity of the current security environment, how much of NIST SP 800-171 has already been implemented, the size of the CUI environment, the quality of documentation, and the amount of remediation required before assessment. Organizations also need to separate readiness time from assessment time. A company may spend many months preparing its systems, policies, evidence, and assessment scope even though the actual self-assessment or formal assessment represents only a small part of the overall process. There is an additional 2026 consideration. CMMC implementation is currently paused in Phase I following the July 13, 2026 suspension of Phase II requirements. That means formal C3PAO and Level 3 timelines need to be discussed differently from organizational readiness timelines.
In This Guide
- 01
How Does the 2026 CMMC Suspension Affect Certification Timelines? - 02
How Long Does CMMC Level 1 Take? - 03
How Long Does CMMC Level 2 Take? - 04
How Long Does CMMC Level 3 Take? - 05
What Takes the Most Time During CMMC Certification? - 06
What Factors Affect the CMMC Certification Timeline? - 07
How Does a POA&M Affect the CMMC Timeline? - 08
What Common Problems Delay CMMC Readiness? - 09
How Can You Speed Up the CMMC Process? - 10
How Early Should You Start Preparing for CMMC? - 11
How Nexeris Helps Contractors Reduce CMMC Readiness Delays - 12
Frequently Asked Questions
CMMC Timeline at a Glance
| CMMC Requirement | Typical Planning Range | Assessment Type | Current 2026 Status |
|---|---|---|---|
| Level 1 | 1–4 months | Annual self-assessment | Phase I requirement remains |
| Level 2 Self | 6–12+ months depending on readiness | Self-assessment every three years | Phase I requirement remains |
| Level 2 C3PAO | Often 6–18+ months including preparation | C3PAO certification assessment | Phase II requirement suspended |
| Level 3 | Often 18–24+ months including Level 2 prerequisite | DIBCAC government assessment | Future implementation affected by suspension |
These ranges estimate organizational preparation and readiness. Formal assessment scheduling can add additional time and is currently affected by the 2026 CMMC program review.
How Does the 2026 CMMC Suspension Affect Certification Timelines?
The July 2026 suspension is important because many older CMMC articles still describe Phase II, Phase III, and future implementation dates as if they are active deadlines. They are not reliable planning dates today.
What Was Suspended on July 13, 2026?
On July 13, 2026, the Department suspended the planned transition to CMMC Phase II and began a broader review of the program. Phase II had been expected to expand the use of Level 2 C3PAO certification assessments. Because that transition is suspended, contractors should not plan their certification strategy around previously published rollout dates without checking current Department guidance. The better way to plan in 2026 is to separate what an organization can control from what remains uncertain. A contractor can continue improving its security environment, closing gaps, building evidence, correcting its SSP, and validating CUI scope. What it cannot reliably predict today is the exact future timing of broader C3PAO or Level 3 implementation.
Which CMMC Requirements Are Still in Effect?
CMMC remains paused in Phase I. Level 1 annual self-assessment requirements continue to apply where required. Level 2 self-assessments also remain part of the current Phase I framework for applicable organizations. At Level 1, the organization evaluates itself against the 15 safeguarding requirements from FAR 52.204-21. At Level 2, the applicable baseline remains the 110 security requirements from NIST SP 800-171 Revision 2. Annual affirmations and SPRS reporting also remain important where applicable. The suspension does not eliminate underlying contractual cybersecurity obligations. Contractors that are already subject to DFARS 252.204-7012 or related requirements still need to protect covered information and maintain applicable NIST SP 800-171 implementation.
Should Contractors Stop Preparing for CMMC Certification?
No.
The suspension changes rollout timing, not the value of being ready. Organizations can still use this period to improve CUI protection, correct security weaknesses, validate SPRS information, improve documentation, and reduce the amount of future remediation required before certification. The CMMC Phase 2 suspension explains what has changed and what contractors still need to maintain during the current review.
How Long Does CMMC Level 1 Take?
A practical planning range for Level 1 readiness is approximately 1–4 months, although some organizations may need less or more time depending on their starting point. The biggest factor is not the number of requirements alone. It is whether the organization already has foundational security practices in place.
Level 1 Is a Self-Assessment, Not a Third-Party Certification
Level 1 is an annual self-assessment. The organization evaluates itself against the 15 safeguarding requirements from FAR 52.204-21, records the applicable results, and submits the required information and affirmation. There is no C3PAO certification assessment at Level 1. POA&Ms are also not permitted for achieving Level 1 status, which means the applicable requirements need to be satisfied before the organization can complete the process successfully.
Typical Level 1 Readiness Timeline
A Level 1 project usually begins with confirming which systems and users handle FCI. The organization then reviews the 15 requirements, identifies any missing safeguards, corrects those weaknesses, documents how each requirement is implemented, and completes the self-assessment. An organization that already has managed devices, basic access controls, updated anti-malware protection, physical safeguards, and appropriate user restrictions may move through this relatively quickly. A company with weak endpoint management, inconsistent access controls, outdated devices, or unclear system ownership may need more time. The important point is that Level 1 should still be treated as a structured readiness project rather than a quick annual formality.
How Long Does CMMC Level 2 Take?
Level 2 is where timeline planning becomes much more important. For most organizations that have not recently validated complete NIST SP 800-171 implementation, 6–18 months is a more realistic planning range than a short fixed estimate. Some mature contractors may move faster. Others may require more than 18 months if the assessment uncovers architecture changes, cloud issues, major documentation gaps, or weaknesses across the CUI environment.
Typical Level 2 Readiness Timeline
Level 2 is based on all 110 NIST SP 800-171 Revision 2 requirements. That means the organization needs more than security policies. It must be able to show that its technical safeguards, procedures, people, systems, and evidence collectively support those requirements. The first part of the timeline normally involves defining CUI flows and assessment scope. After that, the organization compares its actual environment against the 110 requirements and identifies gaps. The largest amount of time usually comes after that gap assessment. A mature organization may already have multifactor authentication, managed endpoints, logging, incident response, identity controls, vulnerability management, network segmentation, and a documented SSP. Another contractor may discover that several of those capabilities are missing or only partially implemented. That difference is why two organizations pursuing the same Level 2 requirement can have very different timelines. For more detail on the underlying security baseline, see the CMMC Level 2 requirements.
How Long Does a Level 2 Self-Assessment Take?
The self-assessment itself is normally much shorter than the readiness process that comes before it. Once the scope is confirmed, the SSP is accurate, the applicable requirements are implemented, and objective evidence exists, the organization can move through the assessment activity far more efficiently. The mistake is assuming that completing the assessment form is the main project. It is not. Most of the work happens before the self-assessment, when the organization is correcting control gaps, fixing documentation, validating asset inventories, and gathering evidence. Under the current Phase I framework, applicable Level 2 self-assessments are performed every three years, with annual affirmation requirements where applicable.
How Long Does a Level 2 C3PAO Certification Take?
Under the defined CMMC framework, a Level 2 certification assessment performed by a C3PAO adds several additional stages after readiness work is complete. The organization would normally need to complete remediation, select a qualified C3PAO, coordinate the assessment, undergo the formal evaluation, address any eligible POA&M items, and complete closeout before receiving Final Level 2 status. However, contractors should not treat that as a predictable 2026 end-to-end timeline. The broader Phase II C3PAO implementation requirement is currently suspended. That means organizations can prepare for future certification, but the formal scheduling portion of the CMMC certification timeline depends on what results from the ongoing program review. The most useful planning approach today is to control the readiness side of the timeline first.
How Long Does CMMC Level 3 Take?
Level 3 should generally be treated as a long-term security program rather than a short certification project. Industry planning estimates often reach 18–24 months or longer, especially when the organization has not yet achieved the Level 2 foundation.
Why Level 3 Takes Longer Than Level 2
Level 3 builds on Level 2. Under the defined CMMC framework, an organization must first achieve Final Level 2 status for the applicable assessment scope. Level 3 then adds 24 selected enhanced requirements derived from NIST SP 800-172. Those additional requirements introduce more advanced capabilities involving threat hunting, security operations, incident response, advanced monitoring, supply chain risk, cyber resiliency, and other defenses designed for sophisticated threat environments. This is why Level 3 preparation usually takes longer. The contractor is not simply adding 24 written policies. It is building capabilities that need to operate at a high level of maturity.
Typical Level 3 Planning Timeline
An organization preparing for Level 3 may first spend substantial time completing Level 2 remediation and assessment readiness. Once that foundation is mature, it still needs to evaluate the additional NIST SP 800-172-based requirements, build the necessary advanced security capabilities, document those capabilities, collect evidence, and prepare for the government-led DIBCAC assessment. That is why an 18–24+ month planning horizon can be more realistic than assuming Level 3 is only a small extension of Level 2.
Why the Current Level 3 Completion Date Is Difficult to Predict
The 2026 CMMC program review makes it difficult to predict a formal Level 3 completion date. The regulatory framework still defines Level 3 and its government-led assessment model, but the broader implementation timeline is affected by the current suspension. Organizations that expect to support higher-risk programs should therefore focus on Level 2 maturity and advanced security readiness rather than building plans around old Phase III deadlines.
What Takes the Most Time During CMMC Certification?
The formal assessment is rarely the biggest source of delay. The longest parts of the process usually occur while the organization is determining scope, identifying weaknesses, remediating technical issues, updating documentation, and building evidence.
Step 1: Determine Your Required CMMC Level
The first step is understanding the actual acquisition requirement. A contractor should review the relevant solicitation, contract, flow-down obligations, FCI and CUI requirements, and assessment type before beginning major remediation. Choosing the wrong level can waste months. For example, not every contractor handling CUI needs Level 3, and not every Level 2 organization currently requires a C3PAO assessment during Phase I.
Step 2: Define the CMMC Assessment Scope
Scoping can become a substantial project in complex organizations. The team needs to understand where FCI or CUI enters the business, where it is stored, which systems process it, how it is transmitted, which security services protect it, and which people can access it. That can involve endpoints, cloud applications, networks, external service providers, security protection assets, specialized assets, facilities, and remote users. Poor scoping creates major timeline risk. If the scope is too broad, the organization may remediate far more systems than necessary. If it is too narrow, overlooked assets can create serious problems later.
Step 3: Conduct a CMMC Gap Assessment
The gap assessment compares the actual environment against applicable CMMC and NIST requirements. Its purpose is not simply to produce a list of missing controls. A useful gap assessment identifies which deficiencies are technical, which are procedural, which involve documentation, and which may require architecture or vendor changes. The environment’s complexity matters more than the number of requirements alone.
Step 4: Remediate Technical and Process Gaps
Remediation is usually the longest and most variable part of the CMMC certification timeline. Some gaps can be corrected quickly. Others can take months. For example, changing an incomplete procedure may be relatively simple. Migrating a legacy application, implementing FIPS-validated cryptography, redesigning identity architecture, deploying centralized logging, segmenting a network, or replacing a cloud service may require planning, procurement, testing, and user migration. This is where many aggressive CMMC timelines begin to slip. The earlier these long-lead technical issues are identified, the more realistic the project becomes.
Step 5: Build and Update CMMC Documentation
Documentation needs to describe the environment as it actually operates. At Level 2, the System Security Plan is especially important because it connects security requirements to the real systems, boundaries, responsibilities, and protections used by the organization. Other supporting documentation can include policies, procedures, asset inventories, network diagrams, data flows, roles, incident response documentation, and applicable POA&M records. The fastest way to create problems is to write documentation that describes controls the organization does not really use.
Step 6: Collect Objective Evidence
CMMC assessments are evidence-driven. A control may exist technically but still create assessment problems if the organization cannot demonstrate its operation. Objective evidence can include configurations, logs, access records, security reports, training records, system output, approved policies, change records, testing results, and other artifacts that show a requirement is implemented and consistently followed. Evidence collection should happen while controls operate rather than immediately before assessment.
Step 7: Perform an Internal Readiness Assessment
Before relying on a formal assessment or self-assessment, the organization should test whether its implementation can withstand independent review. That means checking whether documentation matches reality, control owners understand their responsibilities, technical safeguards can be demonstrated, evidence is current, and known gaps have truly been closed. This stage often catches problems that look complete in a spreadsheet but are not assessment-ready.
Step 8: Complete the Required Formal Assessment or Self-Assessment
The assessment method depends on the required CMMC level and current implementation phase. Level 1 uses an annual self-assessment. Applicable Level 2 requirements in the current Phase I environment use self-assessment. The broader framework also defines Level 2 C3PAO certification and Level 3 DIBCAC assessment, but those future rollout elements need to be considered in light of the current 2026 suspension. This is why contractors should always verify the assessment type required for their specific acquisition.
Step 9: Close Eligible POA&M Items
Where conditional status is permitted, post-assessment remediation can extend the timeline. Eligible deficiencies may need to be corrected through a POA&M closeout process before Final status is achieved. The regulatory closeout period can extend up to 180 days for applicable conditional statuses. This makes POA&M planning important, but it should not be treated as an automatic six-month extension of the preparation timeline.
What Factors Affect the CMMC Certification Timeline?
The same CMMC level can take very different amounts of time for two different organizations. The starting environment is usually the biggest reason.
Your Current NIST SP 800-171 Compliance
Organizations that genuinely implement NIST SP 800-171 Revision 2 will normally need less Level 2 remediation. However, a previous SPRS score does not automatically prove that the current environment still meets every requirement. Systems change over time. Vendors change, employees leave, cloud services are added, and security settings drift. A contractor should validate present implementation rather than assuming an older assessment is still accurate.
Size and Complexity of the CUI Environment
A larger CUI environment usually means more coordination. More applications, users, sites, vendors, cloud environments, networks, and systems create more scope to assess and more evidence to maintain. Company size alone does not determine complexity, though. A large business with CUI isolated inside a tightly controlled enclave may have an easier assessment boundary than a smaller business where CUI moves across every major system.
Accuracy of Your CMMC Scope
Scope directly affects both cost and time. An unnecessarily broad CUI boundary increases remediation work and evidence requirements. An incorrectly narrow boundary creates a different problem because overlooked systems may have to be brought into scope later. The goal should be an accurate scope that reflects real CUI movement and security dependencies.
Number and Severity of Security Gaps
The type of gap matters more than the total number. A missing procedure might take days to correct. Replacing unsupported infrastructure or redesigning authentication can take months. Organizations should rank deficiencies by technical complexity, dependency, cost, and implementation lead time rather than treating every gap equally.
Internal Staffing and Leadership Support
CMMC projects move more quickly when ownership is clear. Leadership support matters because teams may need budget, procurement approvals, architecture decisions, new services, staffing, and operational changes. Projects often slow down when nobody has authority to resolve cross-functional issues. CMMC is easier to manage when each requirement has an accountable owner and one person or team is responsible for coordinating the full program.
Documentation and Evidence Quality
Weak documentation can delay an otherwise strong technical environment. An assessor needs to see how the system works and how security requirements are implemented. Outdated network diagrams, incomplete inventories, conflicting policies, missing records, and unclear ownership can all slow down readiness. Good evidence should be built into the operating process rather than recreated immediately before an assessment.
External Service Providers and Cloud Dependencies
Third-party providers can affect the CMMC timeline because the contractor may depend on them for technical safeguards, security evidence, system information, or contract terms. Cloud providers, MSPs, MSSPs, SaaS providers, and other external services can all influence scope and shared responsibility. A dependency that is discovered late may force the contractor to change vendors, renegotiate responsibilities, or find a different technical solution.
Assessor Availability
When a formal C3PAO certification assessment applies, assessor availability can become part of the end-to-end timeline. However, contractors should avoid planning around a specific 2026 waiting-time estimate. The current Phase II suspension means future C3PAO scheduling will depend partly on how the CMMC implementation review develops. Readiness is therefore the part of the timeline organizations can control most directly.
How Does a POA&M Affect the CMMC Timeline?
A Plan of Action and Milestones can extend the time between an initial assessment and Final CMMC status, but its use is limited.
Can You Get CMMC Status With Open Gaps?
In some Level 2 situations, conditional status may be available when regulatory conditions are satisfied. That does not mean every deficiency can be deferred. Minimum scoring requirements still apply, and certain higher-value security weaknesses cannot simply be left open. Level 1 does not allow POA&M use for achieving the required status.
How Long Is the CMMC POA&M Closeout Period?
Applicable conditional statuses use a 180-day POA&M closeout period. During that time, eligible deficiencies need to be remediated and the required closeout assessment completed. For Level 2 Self, the organization handles the applicable self-assessment closeout. For a Level 2 C3PAO certification, the C3PAO conducts the applicable closeout assessment. If the required remediation is not successfully completed within the allowed period, conditional status can expire.
Why You Should Not Build Your Timeline Around a POA&M
A POA&M should not become a strategy for postponing difficult security work. Some requirements may not be eligible. The organization still needs to meet applicable scoring thresholds. Complex remediation can also take longer than expected. It is safer to treat the POA&M as a limited exception rather than a planned extension of the project.
What Common Problems Delay CMMC Readiness?
Most CMMC delays are predictable once the organization understands where they usually come from.
Incorrectly Scoping the CUI Environment
Scope errors can create some of the most expensive delays. Commonly overlooked areas include remote users, cloud storage, collaboration platforms, external service providers, personal or unmanaged devices, backups, email, and untracked data flows. Discovering one overlooked system late in the project can force the organization to revisit remediation, documentation, and evidence collection.
Waiting Too Long to Address Technical Debt
Unsupported systems, flat networks, weak authentication, old applications, poor logging, and unmanaged devices can become serious schedule blockers. These problems often require technical redesign rather than paperwork. The later they are found, the more likely the organization is to miss its intended readiness date.
Writing Policies That Do Not Match Reality
CMMC assessments focus on actual implementation. A policy saying access is reviewed monthly is useful only if the organization can show those monthly reviews. The same applies to logging, incident response, vulnerability management, training, and other processes. Documentation needs to reflect what the organization actually does.
Collecting Evidence at the Last Minute
Evidence is much easier to manage when it is generated and retained as part of normal security operations. Waiting until the final weeks before assessment often exposes missing records or controls that were never operating consistently. A continuous evidence process reduces this risk.
Treating CMMC as an IT-Only Project
CMMC often involves more than the security or IT team. Human resources, procurement, facilities, leadership, contracts, legal, and operational teams may all own part of the compliance process. Projects slow down when these groups are brought in too late.
Waiting Until the Contract Deadline to Start
A solicitation deadline is usually too late to begin serious CMMC readiness work. If Level 2 preparation may require 6–18 months, starting only after a major opportunity appears can leave too little time for remediation. Organizations should plan backward from expected opportunities rather than from the assessment date alone.
How Can You Speed Up the CMMC Process?
There is no safe shortcut around applicable security requirements, but there are several ways to avoid unnecessary delay.
Start With Accurate Scoping
An accurate CUI boundary can reduce unnecessary technical and assessment complexity. Where operationally appropriate, organizations may be able to limit where CUI is stored and processed. That should only be done when the architecture genuinely supports it. A smaller but inaccurate scope creates more risk, not less.
Conduct the Gap Assessment Early
The gap assessment should happen before leadership commits to a tight certification target. If a major cloud migration or network redesign is required, the organization needs to know that early. Finding it late can turn a realistic project into an emergency.
Prioritize Long-Lead Technical Changes
The most complex technical projects should begin first. Cloud migration, encryption changes, identity redesign, centralized logging, MFA, security monitoring, and segmentation can all take time. Smaller documentation tasks can often be handled in parallel while those projects are underway.
Assign Owners to Every Requirement
Every requirement should have someone responsible for implementation, documentation, evidence, and ongoing operation. Clear ownership prevents controls from remaining partially complete because everyone assumed someone else was handling them.
Build the SSP Alongside Implementation
The SSP should evolve with the environment. Updating it while changes are being made helps prevent a large documentation backlog at the end of the project. It also makes inconsistencies between policy and reality easier to identify.
Collect Evidence Continuously
Evidence should be part of normal operations. For each requirement, the organization should know what demonstrates implementation, where that evidence is stored, who owns it, and how often it changes. This reduces assessment preparation time and helps identify weak controls before formal review.
Perform an Independent Readiness Review
An independent review can identify gaps internal teams may no longer notice. It can be particularly useful for validating scope, SSP accuracy, evidence quality, technical implementation, and assessment preparedness. Organizations that need additional support can use CMMC consulting for readiness planning, gap analysis, remediation, documentation, evidence preparation, and assessment support.
How Early Should You Start Preparing for CMMC?
The right starting point depends on the expected CMMC level and how mature the current environment is.
If You Need Level 1
Start early enough to confirm the FCI environment, assess the 15 FAR requirements, fix any gaps, and complete the required annual self-assessment before the contractual need arises. For many organizations, 1–4 months may be a useful planning range, but it should not be treated as a guaranteed timetable.
If You Expect Level 2
Organizations that have not recently validated complete NIST SP 800-171 implementation should consider 6–18 months as a realistic planning horizon. Those with significant technical debt, weak documentation, multiple locations, large CUI environments, or complex cloud dependencies should begin even earlier. A mature environment may move faster, but it should still validate current implementation rather than relying on historical assumptions.
If You Expect Level 3
Start well in advance. Final Level 2 is a prerequisite under the defined Level 3 framework, and the additional NIST SP 800-172 capabilities can require significant operational maturity. Level 3 should therefore be treated as a long-term program rather than an extension that can be completed immediately after Level 2.
Why You Should Prepare During the CMMC Pause
The current pause creates uncertainty around future formal assessment timing, but it also creates additional preparation time. Contractors can use that period to close NIST SP 800-171 gaps, improve CUI protection, correct SPRS information, strengthen documentation, reduce technical debt, and build repeatable evidence processes. Those improvements reduce future assessment risk regardless of exactly when the next CMMC implementation phase begins.
How Nexeris Helps Contractors Reduce CMMC Readiness Delays
Nexeris helps contractors build a realistic path from their current cybersecurity environment to CMMC readiness. Support can include identifying applicable requirements, defining the CUI scope, conducting NIST SP 800-171 gap assessments, building remediation roadmaps, improving SSP documentation, planning POA&M remediation, addressing technical gaps, organizing evidence, and preparing internal teams for assessment. The goal is to find schedule risks early rather than discovering major architecture, scope, or evidence problems immediately before a contract opportunity.
Frequently Asked Questions
1. How long does CMMC Level 1 take?
Level 1 readiness may take approximately 1–4 months for planning purposes, although there is no official fixed timeline. The organization must review and satisfy the 15 safeguarding requirements from FAR 52.204-21, complete the annual self-assessment, and submit the applicable results and affirmation. Organizations with significant basic security gaps may need longer.
2. How long does CMMC Level 2 certification take?
A planning range of roughly 6–18 months is often more realistic than promising a specific certification date. The actual timeline depends on the organization’s NIST SP 800-171 maturity, CUI scope, technical remediation needs, documentation, evidence, and applicable assessment type. Formal C3PAO certification timing is also affected by the current Phase II suspension.
3. Can you get CMMC certified in three months?
It may be possible for an organization that already has a mature security environment, accurate documentation, a tightly controlled scope, and very few remaining gaps. However, three months should not be treated as a normal CMMC certification timeline. Most organizations with significant Level 2 remediation needs will require much more time.
4. What part of CMMC certification takes the longest?
Remediation is usually the longest and most variable part of the process. Technical changes involving identity, logging, cloud platforms, encryption, network architecture, legacy systems, and external providers can take months. The formal assessment itself is often only one part of a much larger readiness effort.
5. How long does a C3PAO assessment take?
There is no universal official C3PAO assessment duration. The time depends on the size of the scope, number of systems, organizational complexity, quality of evidence, assessment findings, and whether POA&M closeout is required. In 2026, contractors should also avoid relying on fixed C3PAO scheduling assumptions because Phase II implementation remains suspended.
6. How much time can a CMMC POA&M add to the process?
Applicable conditional statuses can create a closeout period of up to 180 days. Eligible deficiencies must be remediated and the required closeout activity completed within that period. Organizations should not assume the full 180 days will always be available or that every deficiency can be placed on a POA&M.
7. How early should contractors start preparing for CMMC?
Contractors should begin before a specific contract makes the requirement urgent. Level 1 may require a few months of preparation. Level 2 should generally be treated as a 6–18 month readiness project when the organization has not recently validated full NIST SP 800-171 implementation. Level 3 should be planned even further in advance because it builds on Final Level 2 and introduces more advanced security capabilities.
8. Does the 2026 CMMC Phase II suspension change certification timelines?
Yes.
The July 13, 2026 suspension paused the planned transition beyond Phase I and created uncertainty around future C3PAO and Level 3 implementation timing. However, Phase I requirements remain in place, and applicable NIST SP 800-171, DFARS, SPRS, CUI protection, and self-assessment obligations continue to matter. The suspension changes rollout timing, not the need for contractors to maintain strong cybersecurity readiness.
