On 3 September 2026 the Office of the Assistant Secretary of War for Acquisition and Sustainment issued Class Deviation 2026-O0025, Revision 3, which directs contracting officers to remove or revise CMMC requirements in new and existing solicitations in line with the Department of War Chief Information Officer's 13 July 2026 memorandum. That memorandum suspended the November 2026 transition to CMMC Phase 2 and told program managers they "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self)."
For a contractor handling Controlled Unclassified Information, that sentence changes who checks the work, not what the work is. The same memorandum states that "during this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments," and that the requirements of DFARS 252.204-7012 "remain in effect." The self-assessed score you post in SPRS is now the only score most contracts will ever ask for, and it is a representation the government relies on. Between June and September 2026 the Department of Justice settled two False Claims Act cases built on exactly that representation.
Quick answer: A CMMC Level 2 self-assessment is a contractor's own scoring of all 110 NIST SP 800-171 Revision 2 requirements using the DoD Assessment Methodology, posted in SPRS and affirmed annually by a senior official. No penetration test is mandated at Level 2. Vulnerability scanning of systems and applications (RA.L2-3.11.2) and periodic assessment of control effectiveness (CA.L2-3.12.1) are mandated, are worth 5 points each, and cannot be deferred to a POA&M. Independent scan results and a penetration test report are the strongest evidence that those controls are effective rather than merely documented, which is what a DIBCAC review or a False Claims Act investigator will test. Where Stingrai fits: Stingrai is a CREST-accredited offensive security company headquartered in Toronto with a London office. Its penetration testers simulate real-world attacks across applications, cloud, networks and people, delivered one-time or continuously through its PTaaS platform, with published pricing from US$3,000 per assessment for one web application and its APIs (pricing) and every other scope quoted.
What changed in 2026, and what did not
Two documents define the current state. Both are primary sources and both are short enough to read in full.
The CIO memorandum of 13 July 2026 (publication case 26-P-1023) suspended "the upcoming November 2026 transition to Phase 2 of CMMC implementation" and, with it, "all pending and future CMMC milestones." Its attachment sets the operating rules for the suspension: only Level 1 (Self) and Level 2 (Self) may be written into requirements documents; program offices must amend active solicitations that carried a C3PAO or DIBCAC requirement; contracting officers must remove such requirements from existing contracts "prior to the exercise of the next option period or during the next scheduled administrative modification"; and "no waivers shall be granted during the review of the program." It also launched a 60-day CMMC Reform Task Force. As of 13 September 2026 the task force's report had not been published; DoD received more than 1,100 public comments before the comment window closed on 14 August, according to Nextgov.
The class deviation of 3 September 2026 turns that policy into contracting instructions. It supersedes Revision 2 of 16 July 2026 and directs contracting officers to "collaborate with requiring activities to remove or revise the Cybersecurity Maturity Model Certification (CMMC) requirements in new and existing solicitations and contracts in accordance with" the CIO memorandum, which the deviation summarises as permitting "CMMC Level 1 (Self) or Level 2 (Self) assessments in all procurement requests," requiring "baseline compliance with NIST SP 800-171 Rev 2 in accordance with the clause at DFARS 252.204-7012," and suspending "the November 2026 CMMC Phase 2 transition."
Item | Status on 13 September 2026 | Source |
|---|---|---|
CMMC Level 2 (C3PAO) and Level 3 (DIBCAC) in new solicitations | Suspended; may not be designated | CIO memorandum, 13 July 2026 |
CMMC Level 1 (Self) and Level 2 (Self) | Permitted in all procurement requests | CIO memorandum; Class Deviation 2026-O0025 Rev 3 |
NIST SP 800-171 Revision 2 (110 requirements) | In force through DFARS 252.204-7012 | CIO memorandum, attachment 1 |
DFARS 252.204-7012 | "Remain in effect" | CIO memorandum, attachment 1 |
NIST SP 800-171 DoD Assessment clause (252.204-7020, carried as 252.240-7997 under the deviation) | In force: Basic, Medium and High assessments, SPRS posting, flow-down | Class Deviation 2026-O0025 Rev 3, DFARS 240 attachment |
DFARS 252.204-7021 CMMC clause | In force where a program office specifies a level; prescribed for every FCI/CUI contract on or after 10 November 2028 | Class Deviation 2026-O0025 Rev 3, 240.371 |
32 CFR part 170 (the CMMC Program rule) | Unamended | eCFR, title 32 part 170 |
Annual affirmation in SPRS by an Affirming Official | Required for every CMMC status, not older than one year | 32 CFR 170.22; DFARS 240.371-2 definition of "current" |
The deviation's own prescription for the CMMC clause is worth reading closely, because it fixes the outer date of the whole program. Until 9 November 2028 the clause goes into a solicitation only "if the program office or requiring activity determines that the contractor is required to have a specific CMMC level." On or after 10 November 2028 it goes into every solicitation and contract, other than those solely for commercially available off-the-shelf items, where the contractor "is required to use contractor information systems in the performance of the contract ... to process, store, or transmit FCI or CUI." Whatever the task force recommends, the deviation as written still puts every CUI contract under the clause in November 2028.

What a Level 2 self-assessment is under 32 CFR part 170
Section 170.16 of 32 CFR part 170 defines the Level 2 self-assessment: the contractor assesses all 110 requirements of NIST SP 800-171 Revision 2 against the assessment objectives in NIST SP 800-171A (June 2018), scores the result with the DoD Assessment Methodology, enters the result in SPRS, and a senior official affirms continuing compliance at the time of assessment and annually thereafter. The status is valid for three years. A Conditional status, available when a plan of action and milestones is permitted, expires after 180 days unless the POA&M is closed out.
Three consequences follow for anyone who thought "self" meant "lighter."
The objectives are the same as a C3PAO's. Section 170.16 points at the same NIST SP 800-171A assessment objectives a C3PAO would use under section 170.17. A self-assessment that skips objectives is not a different assessment method; it is an incomplete one.
The score is arithmetic, not judgement. The DoD Assessment Methodology, version 1.2.1 starts every contractor at 110 and subtracts the value of each requirement not implemented. It states plainly that this "may result in a negative score." Requirements whose absence "could lead to significant exploitation of the network, or exfiltration of DoD CUI" cost 5 points; requirements with "a specific and confined effect" cost 3; the remainder cost 1. Partial implementation earns no credit except where the methodology builds it in, such as multifactor authentication and FIPS-validated encryption.
The affirmation is personal. Section 170.22 requires an Affirming Official, a senior contractor representative, to attest to continuing compliance in SPRS after every assessment and annually thereafter. The class deviation carries the same requirement into the definition of a "current" CMMC status: a Final Level 2 (Self) status is current only with "a corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official."
The scoring trap: the controls that prove effectiveness are all worth 5 points
Cross-referencing the methodology's Annex A against the POA&M rule in section 170.21 produces the single most important table in Level 2 planning. The rule permits a Conditional status only where every requirement on the POA&M is worth 1 point, with one exception for FIPS-validated encryption, and the overall score is at least 0.8 of the total. Everything worth 5 points has to be MET on the day you score yourself.
Requirement | Text (NIST SP 800-171 Rev 2) | Points | POA&M-eligible |
|---|---|---|---|
RA.L2-3.11.1 | Periodically assess the risk to organizational operations, assets and individuals | 3 | No |
RA.L2-3.11.2 | Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified | 5 | No |
RA.L2-3.11.3 | Remediate vulnerabilities in accordance with risk assessments | 1 | Yes |
CA.L2-3.12.1 | Periodically assess the security controls in organizational systems to determine if the controls are effective in their application | 5 | No |
CA.L2-3.12.2 | Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities | 3 | No |
CA.L2-3.12.3 | Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls | 5 | No |
CA.L2-3.12.4 | Develop, document and periodically update system security plans | Not scored: without an SSP "an assessment could not be completed" | No |
SI.L2-3.14.1 | Identify, report, and correct system flaws in a timely manner | 5 | No |
SI.L2-3.14.2 | Provide protection from malicious code at designated locations | 5 | No |
SI.L2-3.14.3 | Monitor system security alerts and advisories and take action in response | 5 | No |
SI.L2-3.14.4 | Update malicious code protection mechanisms when new releases are available | 5 | No |
SI.L2-3.14.5 | Perform periodic scans of organizational systems and real-time scans of files from external sources | 3 | No |
SI.L2-3.14.6 | Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks | 5 | No |
SI.L2-3.14.7 | Identify unauthorized use of organizational systems | 3 | No |

The methodology names 3.11.2 explicitly in its list of 5-point requirements, alongside 3.14.4 and 3.14.6, and it lists 3.14.5 and 3.14.7 among the 3-point requirements. The one requirement in these families that can wait is remediation itself, 3.11.3, at 1 point. Everything that finds, assesses and monitors has to be working before you can honestly post a score above the Conditional threshold.
What NIST SP 800-171A actually asks for
The assessment objectives are the test. Below are the determination statements, quoted from NIST SP 800-171A, for the four requirements that matter most to a security testing programme. A self-assessor marks a requirement MET only when every objective is satisfied.
RA.L2-3.11.2, vulnerability scanning. Determine if: [a] "the frequency to scan for vulnerabilities in organizational systems and applications is defined"; [b] "vulnerability scans are performed on organizational systems with the defined frequency"; [c] "vulnerability scans are performed on applications with the defined frequency"; [d] "vulnerability scans are performed on organizational systems when new vulnerabilities are identified"; and [e] "vulnerability scans are performed on applications when new vulnerabilities are identified."
Objectives [c] and [e] are the ones most contractors miss. A quarterly network scan satisfies [b]. It says nothing about the applications you develop or operate, which are assessed separately under [c] and [e]. The Revision 2 discussion, reproduced in DoD's assessment guide, adds that "vulnerability analyses for custom software applications may require additional approaches such as static analysis, dynamic analysis, binary analysis, or a hybrid of the three approaches."
RA.L2-3.11.3, remediation. Determine if: [a] "vulnerabilities are identified"; and [b] "vulnerabilities are remediated in accordance with risk assessments." The CMMC Level 2 Assessment Guide, version 2.13 adds: "Not all vulnerabilities captured in a vulnerability scanner may pose the same level of risk to an organization. Prioritize mitigation efforts to close the most critical vulnerabilities first."
CA.L2-3.12.1, security control assessment. Determine if: [a] "the frequency of security control assessments is defined"; and [b] "security controls are assessed with the defined frequency to determine if the controls are effective in their application." The assessment guide's own consideration for objective [a] is blunt: "Are security controls assessed at least annually?" Its further discussion warns against "a 'set it and forget it' mentality" and lists the expected outputs: "documented assessment results; proposed new controls, or updates to existing controls; remediation plans; and newly identified risks."
SI.L2-3.14.1, flaw remediation. Determine if the time to identify, report and correct system flaws is specified, and whether flaws are identified, reported and corrected within those times, six objectives in all. A scanning cadence without a documented fix window fails half of them.
The assessment methods in 800-171A are examine, interview and test. Appendix D lists among typical test actions "conducting penetration testing of key system components." That phrase is why a penetration test is a legitimate way to satisfy the TEST method for 3.12.1 without the framework ever mandating one: it is an assessment technique the standard already contemplates.
Scanning versus penetration testing: what each one proves
The two activities answer different questions, and the objectives above assign them different jobs.
Scanning answers "what is exposed and unpatched?" It is the named mechanism for 3.11.2, it feeds 3.11.3 and 3.14.1, and the assessment guide expects it to cover "all devices connected to the network including servers, desktops, laptops, virtual machines, containers, firewalls, switches, and printers," including "assets such as laptop computers that may not routinely connect to an organization's network." Its output is a dated, tool-generated list with CVE identifiers and CVSS scores.
Penetration testing answers "are the controls effective in their application?" That is the wording of 3.12.1. A scan reports that a web server is missing a patch. A test reports that an authenticated low-privilege user in your custom procurement portal can read another supplier's CUI attachments because an object identifier is not authorised, that the segmentation between the CUI enclave and the corporate network can be crossed from a compromised workstation, or that the MFA you scored as MET can be bypassed through a legacy protocol. None of those show up in a scanner.
DoD's assessment guide says as much in the discussion of 3.11.2: "Perform reviews of your organization's custom-developed software. Vulnerability analysis of a custom-made solution may require a penetration tester to properly test and validate findings. Automated vulnerability scanners may not be as thorough when scanning custom developed applications."
Question | Scanning | Penetration test |
|---|---|---|
Which objectives it primarily evidences | 3.11.2 [a] to [e], 3.11.3 [a], 3.14.1 [b] | 3.12.1 [b], 3.11.2 [c] and [e] for custom applications, scoping boundary under 170.19 |
What it finds | Known CVEs, missing patches, exposed services, misconfigurations | Authorisation flaws, business logic abuse, chained weaknesses, segmentation failures, real exploitability |
Independence | Tool output; who runs it matters less | The Revision 2 discussion for 3.12.1 asks for results "obtained with the appropriate level of assessor independence" |
Cadence the evidence supports | Defined frequency plus on new vulnerabilities; quarterly is the guide's own example | Defined frequency for 3.12.1; the guide asks whether controls are assessed "at least annually" |
Typical artefact | Scan configuration, scope list, dated results, remediation tickets | Scope and rules of engagement, methodology, findings with reproduction steps, retest results, attestation letter |
Neither replaces the other. A programme that scans quarterly but never tests has documented exposure without evidence of effectiveness. A programme that tests annually but never scans cannot satisfy objective [d] or [e], which require action when new vulnerabilities are identified.
Why "self" does not mean unverified: the False Claims Act cases of 2026
Two Department of Justice settlements this summer explain why the evidence behind a self-assessment matters more than the score itself.
On 18 June 2026 DOJ announced that LOGZONE Inc. of Huntsville, Alabama, agreed to pay US$507,144 to resolve allegations that it "failed to implement certain cybersecurity controls" on two Navy contracts. The release records that DIBCAC assessed the company's systems at a score of negative 170 on a range of negative 203 to 110. DefenseScoop reported that the company had earlier submitted a self-assessment score of 110, the maximum.
On 1 September 2026 DOJ announced that Honeywell Aerospace Inc. agreed to pay US$2,042,518 to resolve allegations that, between April 2020 and December 2023, a business unit "submitted false claims for payment by failing to comply with the controls in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 on one of its networks." A former employee who filed the case will receive US$375,823. The release notes there has been no determination of liability.
Both matters predate the suspension, and both were resolved after it. That is the point. The suspension removed the C3PAO from the picture; it did not remove DIBCAC's Medium and High assessments under the NIST SP 800-171 DoD Assessment clause, which the class deviation carries forward as 252.240-7997, and it did not touch the False Claims Act. The CIO memorandum itself preserves "select Government-led assessments." A contractor's self-assessment is therefore a number that can be checked against reality by the government at any time during the contract, with a whistleblower incentive attached.
The defensive question is not "did we score ourselves?" It is "what would we hand DIBCAC to show that the 5-point controls were genuinely effective on the date of the affirmation?" Independent scan output and an independent penetration test report are the two artefacts that answer it without relying on the contractor's own word.
Building the evidence pack: objective by objective
The following map is what we recommend defense contractors assemble before scoring themselves. Every artefact is one that 800-171A lists as an assessment object or that the CMMC assessment guide names as an expected output.
Objective | Artefact that evidences it | Produced by |
|---|---|---|
3.11.2[a], 3.12.1[a], 3.14.1[a][c][e] | Written, dated, approved frequency and time windows in the SSP or a vulnerability management standard | Contractor |
3.11.2[b][d] | Scanner configuration showing authenticated scans, asset scope matching the 170.19 asset inventory, dated results, evidence of signature updates | Contractor or managed provider |
3.11.2[c][e] | Application scan results plus, for custom software, static or dynamic analysis and penetration test findings against the applications that handle CUI | Contractor plus independent tester |
3.11.3[a][b] | Risk-ranked remediation tickets tied to scan and test findings, with rationale for any accepted risk | Contractor |
3.12.1[b] | Security assessment plan, assessment report, penetration test report with methodology and results, retest confirming fixes | Independent tester or internal team with documented independence |
3.12.2[a][b][c] | POA&M entries for every deficiency found, with owners and dates | Contractor |
3.12.3 | Continuous monitoring outputs: dashboards, recurring reports, evidence they reach decision makers | Contractor |
3.14.1[b][d][f] | Patch records and change tickets showing flaws closed within the specified windows | Contractor |
170.19 scope boundary | Test evidence that CUI cannot be reached from assets declared out of scope or Contractor Risk Managed | Independent tester |
Two practical rules make this pack hold up under review.
Freeze the artefacts on the assessment date. Section 170.17 requires a hashed artefact list for C3PAO assessments. Nothing stops a self-assessor from adopting the same discipline, and it is the cleanest way to prove later that a given scan result or test report existed when the score was posted rather than being assembled after a DIBCAC notice.
Make the test scope match the SSP scope. A penetration test of the public website when CUI lives in an internal file share and a custom engineering portal proves little about the boundary that matters. Scope the test to the CUI assets, the Security Protection Assets that defend them, and the paths from everything else into them.
A 12-month evidence calendar for a Level 2 (Self) contractor
The cadence below satisfies the objectives with figures DoD's own guide uses as examples: quarterly scanning and at least annual control assessment. Adjust the intervals if your documented risk assessment justifies something different, but document the justification, because objective [a] of both 3.11.2 and 3.12.1 is about a defined frequency that is then honoured.
When | Activity | Evidence produced |
|---|---|---|
Month 1 | Confirm the 170.19 asset inventory and scope; update the SSP frequencies; hash and file the artefact list from last year | Updated SSP, asset inventory, artefact list |
Months 1, 4, 7, 10 | Authenticated vulnerability scans of every in-scope system and application; ad hoc scans on new critical CVEs | Dated scan results, tickets, patch records |
Month 2 | Independent penetration test of the CUI enclave, the applications that process CUI, and the boundary from corporate and remote assets | Scope, methodology, findings, POA&M entries |
Month 3 | Remediation and retest of test findings | Retest report, closed tickets, attestation letter |
Month 6 | Mid-year control assessment review: are monitoring outputs reaching decision makers; are new systems in scope | Assessment review record |
Month 11 | Re-score all 110 requirements against 800-171A; update SPRS; Affirming Official affirmation | SPRS entry, affirmation record |
Continuous | Security alerts and advisories monitored and actioned (3.14.3); system monitoring (3.14.6) | Alert logs, response records |
If your Level 2 (Self) status is already posted, the annual affirmation is the natural anchor for the calendar: run the test and the remediation cycle in the quarter before the affirmation date so the official is signing on current evidence.
What a DIBCAC Medium or High assessment looks for
The NIST SP 800-171 DoD Assessment clause, DFARS 252.204-7020 in the codified DFARS and 252.240-7997 under the class deviation, requires the contractor to have a Basic assessment not more than three years old posted in SPRS, and it gives the government the right to conduct Medium and High assessments. For those, "the Contractor shall provide access to its facilities, systems, and personnel necessary for the Government to conduct" the assessment. A High assessment "requires a thorough on-site or virtual verification/examination/demonstration of the Contractor's system security plan and implementation of the NIST SP 800-171 security requirements," in the methodology's words.
Demonstration is the operative word. An assessor asking to see 3.11.2 in operation will expect to watch a scan run against the in-scope range, open the last results, and follow one finding through to a closed ticket. An assessor testing 3.12.1 will want the assessment plan, the report, and someone who can speak to the findings. A penetration test report from a firm that can be reached for questions, with reproduction steps an assessor can verify, is the artefact that survives that conversation. A scan export with no remediation trail is the one that does not.
How Stingrai supports a Level 2 self-assessment
Stingrai's penetration testers, credentialed with OSCE3, OSCP, OSWE, CREST CRT and CISSP among others, deliver human-led penetration testing for regulated industries, including defense contractors preparing or maintaining a CMMC Level 2 status. Stingrai is a CREST-accredited penetration testing service provider at firm level, was founded in 2021, and holds 5.0 out of 5.0 across 19 Clutch reviews.
For the objectives in this guide, an engagement is scoped to produce evidence rather than a generic report: internal and external network testing of the CUI enclave and its boundary, testing of the applications that process CUI with every role exercised against every other role, cloud configuration and identity review where the enclave is hosted, and a documented methodology that maps findings to the 800-171A objectives they touch. Findings are published to the PTaaS portal as they are confirmed, with reproduction steps and remediation guidance, so the remediation trail for 3.11.3 and 3.12.2 starts during the test rather than after it. Retesting is included, and the engagement closes with a report and a signed attestation letter that state scope, methodology and retest results.
Stingrai delivers both one-time annual penetration tests and continuous testing programmes. For web applications, Snipe, Stingrai's autonomous AI agent for web application penetration testing, works concurrently with the penetration testers, who direct its focus and extend its attack paths; every other scope is human-led. Scope drives price far more than framework does; the pricing page lists the published web application packages and the get a quote form covers network, cloud and combined CMMC scopes.
Frequently Asked Questions
Does a CMMC Level 2 self-assessment require a penetration test?
No. CMMC Level 2 is identical to NIST SP 800-171 Revision 2, and none of its 110 requirements mandates a penetration test. Level 2 does mandate vulnerability scanning of systems and applications (RA.L2-3.11.2) and periodic assessment of whether controls are effective (CA.L2-3.12.1), both worth 5 points and both ineligible for a POA&M. A penetration test is the strongest evidence for 3.12.1 and, for custom-developed applications, DoD's Level 2 Assessment Guide states that vulnerability analysis "may require a penetration tester." The test is evidence, not a control.
Can I still self-assess for CMMC Level 2 after the 2026 suspension?
Yes, and for most contracts it is now the only option. The 13 July 2026 CIO memorandum limits program offices to CMMC Level 1 (Self) and Level 2 (Self) designations, and Class Deviation 2026-O0025 Revision 3 of 3 September 2026 directs contracting officers to remove C3PAO and DIBCAC requirements from solicitations and contracts. The self-assessment itself follows 32 CFR 170.16: score all 110 requirements against NIST SP 800-171A, post the result in SPRS and affirm annually.
How often does NIST SP 800-171 require vulnerability scanning?
NIST SP 800-171 leaves the frequency to the organisation, but assessment objective 3.11.2[a] requires that frequency to be defined, and objectives [b] to [e] require scans of both systems and applications at that frequency and whenever new vulnerabilities are identified. The CMMC Level 2 Assessment Guide uses quarterly scanning as its worked example and mentions continuous passive scanning as an option. Whatever interval you choose, it must be written down and honoured.
What score do I need for a CMMC Level 2 self-assessment?
A Final Level 2 (Self) status requires every requirement to be MET. A Conditional status is possible under 32 CFR 170.21 only if the score is at least 0.8 of the total, and only if no requirement on the POA&M is worth more than 1 point, with a single exception for non-FIPS-validated encryption at 3 points. RA.L2-3.11.2, CA.L2-3.12.1, CA.L2-3.12.3 and SI.L2-3.14.1 are each worth 5 points, so they must be MET on the day you score. The Conditional status expires after 180 days if the POA&M is not closed.
Did the 2026 suspension change DFARS 252.204-7012 or the SPRS requirements?
No. The CIO memorandum states that the requirements of DFARS 252.204-7012 "remain in effect" and that DoD will enforce baseline NIST SP 800-171 Rev 2 compliance through self-assessments and select government-led assessments. The NIST SP 800-171 DoD Assessment clause, 252.204-7020 in the codified DFARS and 252.240-7997 under the class deviation, still requires a Basic assessment not more than three years old in SPRS and still allows DIBCAC Medium and High assessments.
What is DFARS 252.240-7997?
It is the number the September 2026 class deviation assigns to the NIST SP 800-171 DoD Assessment Requirements clause, previously 252.204-7020, within the reorganised DFARS part 240 used under the Revolutionary FAR Overhaul. Its content is the same: a current Basic assessment posted in SPRS, government access for Medium and High assessments, and flow-down to subcontractors that handle covered defense information.
Can vulnerability scanning go on a CMMC POA&M?
No. RA.L2-3.11.2 is worth 5 points under the DoD Assessment Methodology, and 32 CFR 170.21 bars any POA&M item worth more than 1 point, other than the FIPS-validated encryption exception. The same applies to CA.L2-3.12.1, CA.L2-3.12.3 and SI.L2-3.14.1. Only remediation, RA.L2-3.11.3, at 1 point, can be deferred.
What evidence does DIBCAC ask for on vulnerability scanning and security assessment?
NIST SP 800-171A lists the assessment objects. For 3.11.2 they include the vulnerability scanning procedures, the scanning tools and their configuration documentation, the scan results, and patch and vulnerability management records, plus interviews with the people who scan and remediate and a test of the scanning process. For 3.12.1 they include the security assessment policy, the assessment plan, the SSP, interviews with assessment personnel, and a test of the mechanisms that support assessment and reporting. A penetration test report and retest record are the natural artefacts for that last item.
Does the CMMC Reform Task Force change any of this?
Not yet. The task force was given 60 days from 13 July 2026, and its report had not been published as of 13 September 2026. A report is advice; only a further class deviation, a DFARS rule or an amendment to 32 CFR part 170 changes an obligation. Until one of those is issued, the self-assessment, the SPRS score, the annual affirmation and the underlying NIST SP 800-171 requirements stand as described here.
Related Reading
Does CMMC Require a Penetration Test? Level 1, 2 and 3 (2026), the level-by-level reading of the regulatory text.
CMMC vs CPCSC for Canadian Defence Suppliers (2026), for suppliers selling into both the US and Canadian defence markets.
Penetration test evidence auditors accept for SOC 2, ISO 27001, PCI DSS and CMMC.
How to scope a penetration test (2026) and the penetration test cost calculator.
Internal and external network penetration testing and web application penetration testing.
Talk to Stingrai
Scoping a penetration test against the objectives in this guide takes one short conversation. Stingrai is a CREST-accredited offensive security company headquartered in Toronto with a London office. Its penetration testers simulate real-world attacks across applications, cloud, networks and people, delivered one-time or continuously through its PTaaS platform, with documented findings, remediation guidance and retesting included. Book a free scoping call, get a quote, or read the published pricing.
References
Department of War Chief Information Officer. _Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of Cybersecurity Maturity Model Certification Requirements_, with Attachment 1, _Cybersecurity Maturity Model Certification Procedures_. Publication case 26-P-1023, 13 July 2026. https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf. The suspension memorandum and the operating rules for the suspension period.
Office of the Assistant Secretary of War for Acquisition and Sustainment. _Class Deviation 2026-O0025, Revision 3: Revolutionary FAR Overhaul Part 40, DFARS Part 240_. 3 September 2026. https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_Rev3_TAB_A_Deviation_Memo.pdf. The binding contracting instructions implementing the suspension, the DFARS 240.371 CMMC policy and the clause prescriptions.
Department of Defense. _32 CFR part 170, Cybersecurity Maturity Model Certification (CMMC) Program_. https://www.ecfr.gov/current/title-32/part-170. Sections 170.16 (Level 2 self-assessment), 170.19 (scoping), 170.21 (POA&M), 170.22 (affirmation) and 170.24 (scoring).
Department of Defense. _NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1_. 24 June 2020. https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf. Point values, scoring rules, and the Basic, Medium and High assessment definitions.
National Institute of Standards and Technology. _NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information_. June 2018. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171A.pdf. The assessment objectives and methods quoted in this guide.
Department of Defense Chief Information Officer. _CMMC Assessment Guide, Level 2, Version 2.13_. September 2024. https://dodcio.defense.gov/Portals/0/Documents/CMMC/AssessmentGuideL2v2.pdf. Discussion, examples and assessment considerations for RA.L2-3.11.2, RA.L2-3.11.3, CA.L2-3.12.1 and CA.L2-3.12.3.
Acquisition.gov. _DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements_ and _DFARS 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements_. https://www.acquisition.gov/dfars/252.204-7020-nist-sp-800-171dod-assessment-requirements. and https://www.acquisition.gov/dfars/252.204-7021-cybersecurity-maturity-model-certification-requirements. The codified clause texts.
United States Department of Justice. _Alabama Defense Contractor Agrees to Pay $507,144 to Resolve False Claims Act Liability Relating to Cybersecurity Violations_. 18 June 2026. https://www.justice.gov/opa/pr/alabama-defense-contractor-agrees-pay-507144-resolve-false-claims-act-liability-relating. The LOGZONE settlement, including the DIBCAC score of negative 170.
United States Department of Justice. _Honeywell Aerospace Inc. Agrees to Pay Over $2M to Settle False Claims Act Allegations of Failing to Comply with Cybersecurity Requirements in a U.S. Department of Defense Contract_. 1 September 2026. https://www.justice.gov/opa/pr/honeywell-aerospace-inc-agrees-pay-over-2m-settle-false-claims-act-allegations-failing.
DefenseScoop. _Defense contractor settles cybersecurity False Claims Act allegations_. 18 June 2026. https://defensescoop.com/2026/06/18/defense-contractor-settles-cybersecurity-false-claims-act-allegations/. Reporting on the self-assessed score submitted in the LOGZONE matter.
Nextgov/FCW. _CMMC's Phase 2 suspension locked in with binding regulation_. 9 September 2026. https://www.nextgov.com/acquisition/2026/09/cmmcs-phase-2-suspension-locked-binding-regulation/415890/. Reporting on the class deviation and the task force comment count.
Federal News Network. _Pentagon suspends CMMC phase two requirements, launches review of program_. 13 July 2026. https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/.



