
CMMC Phase 2 is suspended. NIST 800-171 is still in force.
Contributors
Brian Dawson, Director of Product Management
Defense contractors hold the same compliance baseline today that they held before July 13. NIST SP 800-171 remains the control standard in contracts covered by the Defense Federal Acquisition Regulation Supplement (DFARS), and Phase 1 self-assessments continue. What DoD suspended is the layer above: CMMC Phase 2, the third-party certification requirement, is on hold pending a reform review.
Know what DoD suspended and what continues
On July 13, 2026, DoD suspended CMMC Phase 2 and launched a 60-day reform review under a new CMMC Reform Task Force. Phase 2 would have phased in third-party certification for many contractors handling controlled unclassified information (CUI), with assessments beginning November 10. The department kept Phase 1 self-assessments in place and opened a request for information (RFI) with responses due August 14. DoD pointed to compliance costs and to a Small Business Administration finding that the program's burden had pushed some companies out of the defense industrial base.
DoD suspended the certification layer but the security requirements of NIST SP 800-171 remain in force in DFARS contracts.
Three obligations survive the suspension untouched:
- DFARS 252.204-7012 still requires contractors that handle CUI to implement NIST SP 800-171.
- DFARS 252.204-7019 and 252.204-7020 still require a current self-assessment score posted in the Supplier Performance Risk System (SPRS).
- Phase 1 of CMMC, the self-assessment phase, continues on its existing terms.
The contractors in the strongest position in 2027 will be the ones whose 800-171 posture kept improving while the program office deliberated.
Anchor your program on NIST 800-171
CMMC has always been an assessment mechanism layered on controls that exist independently of it. The task force can change who assesses, how often, and at what cost. The 800-171 requirements themselves sit in DFARS clauses that stay in contracts regardless of what the review produces.
That stability makes the near-term guidance concrete:
- Keep evidence collection running. Configuration records, scan results, and POA&M (plan of action and milestones) updates gathered now count under any assessment regime the task force designs.
- Keep your SPRS score current. A stale self-assessment score is a contract risk today, suspension or not.
- Treat the pause as schedule relief, not scope relief. Remediation scheduled now lands before assessors return.
A control you implement during the pause counts under every version of CMMC the task force could produce.
Map your 800-171 controls faster. RLC Pro Hardened ships STIG-ready profiles and FIPS 140-3 validated cryptography for federal environments.
Use the pause to close control shortfalls
The system-hardening families in 800-171 (configuration management, system and communications protection, and system and information integrity) reward preparation time because they touch every server in the environment. They are also the families where the operating system itself carries much of the load.
Federal contractors deploying RLC Pro Hardened address those families at the OS layer from first boot. STIG-ready profiles align configuration baselines with published federal hardening guidance. FIPS 140-3 validated cryptographic modules cover the encryption requirements. LKRG (Linux Kernel Runtime Guard) adds real-time kernel integrity monitoring, which detects kernel-level exploitation attempts as they happen. Security teams running it typically save 1–3 FTE annually on hardening work that would otherwise be manual.
Contractors running RLC Pro Hardened start audits from STIG-ready profiles and FIPS 140-3 validated cryptography instead of a bare install.
Compliance leads can use the reform window to re-check each in-scope system against the 800-171 families, log the shortfalls, and schedule remediation while no assessor is on the calendar.
Send DoD your cost data by August 14
The reform review will run on the record it receives. The RFI closes August 14, and contractors with documented compliance costs, assessor scheduling problems, or subcontractor flow-down pain have a dated window to put those specifics in front of the program office. A two-page response with specific numbers carries more weight than a position paper.
The task force will report, and the assessment mechanism will likely change shape. The requirements underneath it will still be NIST SP 800-171. This week, that means four actions: confirm your SPRS score is current, keep the evidence pipeline running, draft the RFI response, and review which 800-171 families your operating system already covers.
Talk with CIQ about mapping RLC Pro Hardened to your 800-171 requirements.
Built for scale. Chosen by the world’s best.
2.75M+
Rocky Linux instances
Being used world wide
90%
Of fortune 100 companies
Use CIQ supported technologies
250k
Avg. monthly downloads
Rocky Linux
Have questions about your infrastructure?
Talk to a CIQ engineer about Rocky Linux, HPC, and AI infrastructure.


