CMMC Level 2 (C3PAO): the third-party assessment, suspended since 13 July 2026
Third-party CMMC certification was suspended on 13 July 2026 pending a review; the self-assessment, the SPRS score and the DFARS 252.204-7012 duties it rests on remain in force, and the register is built on those. During the suspension, requiring activities designate only CMMC Level 1 (Self) or CMMC Level 2 (Self); the third-party assessment and Level 3 designations are not used, and contracting officers remove them from existing contracts before the next option or at the next scheduled administrative modification. A subcontractor that already holds a Level 2 (C3PAO) status can declare it; the register reads its dates like any Level 2 status.
The rule sentences
4 citedDoW CIO memorandum, 13 Jul 2026, Attachment 1memorandum, cleared for open publication 13 Jul 2026Per the attached CIO memorandum, during this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments. The cybersecurity requirements outlined in the clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect.
DoW CIO memorandum, 13 Jul 2026, Attachment 1memorandum, cleared for open publication 13 Jul 2026Program Managers and requiring activities may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self).
DFARS 252.204-7021, "current" (2)(ii)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official
32 CFR 170.22(a)codified text, eCFR current to 24 Sep 2026An Affirming Official from each OSA, whether a prime or subcontractor, must affirm the continuing compliance of their respective organizations with the specified security requirement after every assessment, including POA&M closeout, and annually thereafter.
Confirm which deviation your contracting officer's agency has adopted. The register records what a subcontractor declares; it does not look anything up in SPRS.