Subcontractor CMMC Tracker

CMMC Level 2 (C3PAO): the third-party assessment, suspended since 13 July 2026

Third-party CMMC certification was suspended on 13 July 2026 pending a review; the self-assessment, the SPRS score and the DFARS 252.204-7012 duties it rests on remain in force, and the register is built on those. During the suspension, requiring activities designate only CMMC Level 1 (Self) or CMMC Level 2 (Self); the third-party assessment and Level 3 designations are not used, and contracting officers remove them from existing contracts before the next option or at the next scheduled administrative modification. A subcontractor that already holds a Level 2 (C3PAO) status can declare it; the register reads its dates like any Level 2 status.

The rule sentences

4 cited
DoW CIO memorandum, 13 Jul 2026, Attachment 1memorandum, cleared for open publication 13 Jul 2026

Per the attached CIO memorandum, during this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments. The cybersecurity requirements outlined in the clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect.

Threshold read: self-assessment and DFARS 252.204-7012 stay in force during the suspension. Source
DoW CIO memorandum, 13 Jul 2026, Attachment 1memorandum, cleared for open publication 13 Jul 2026

Program Managers and requiring activities may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self).

Threshold read: only Level 1 (Self) or Level 2 (Self) designated during the suspension. Source
DFARS 252.204-7021, "current" (2)(ii)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official

Threshold read: Final Level 2: not older than 3 years, affirmation not older than 1 year. Source
32 CFR 170.22(a)codified text, eCFR current to 24 Sep 2026

An Affirming Official from each OSA, whether a prime or subcontractor, must affirm the continuing compliance of their respective organizations with the specified security requirement after every assessment, including POA&M closeout, and annually thereafter.

Threshold read: affirmation after every assessment and annually thereafter. Source

Confirm which deviation your contracting officer's agency has adopted. The register records what a subcontractor declares; it does not look anything up in SPRS.