CMMC Compliance & Mission Assurance — August Schell
CMMC Compliance & Mission Assurance

The rules changed. The obligation didn’t.

August Schell is a 35-year federal cybersecurity firm — an Authorized C3PAO and a Registered Practitioner Organization, with Lead CCAs on staff. Whatever the Department decides next, there is a path from where you are to a defensible compliance posture. Start by finding yours.

CMMC Program Status

The suspension pauses the verification mechanism — not the security obligation.

Last updatedJuly 16, 2026
Maintained by August Schell
Authorized C3PAO · Registered RPO
Next deadline
FAR CUI Rule — public comment period closes
July 23, 2026 · Unaffected by the suspension. Applies immediately on finalization, with no phased on-ramp.
Days
Hrs
Min
Sec
CMMC Phase II — third-party C3PAO certification
Suspended effective immediately per USD(A&S) Memorandum 26-P-1023, implementing the DoW CIO’s suspension. Pending and future implementation milestones are paused across DoW solicitations and contracts.
Suspended
CMMC assessment levels DoW may require
For the duration of the review, Program Managers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self). Level 2 (C3PAO) and Level 3 (DIBCAC) designations are not permitted, and no waivers will be granted. Existing C3PAO and DIBCAC requirements are being removed from active solicitations, and from existing contracts at the next option exercise or scheduled administrative modification.
Self-assessment only
CMMC Phase I — self-assessment, Levels 1 & 2
A current NIST SP 800-171 self-assessment in SPRS, with annual senior-official affirmation, remains a condition of eligibility.
Still required
DFARS 252.204-7012
In full force. Safeguarding covered defense information and 72-hour incident reporting are unchanged.
In full force
NIST SP 800-171 Rev. 2
The enforced technical baseline — verified through self-assessments and select government-led DIBCAC assessments.
Enforced
32 CFR Part 170 & the DFARS acquisition rule
The CIO memo pauses implementation; it does not repeal the regulation.
Codified law
The CMMC ecosystem — assessments, training, exams
Per the Cyber AB (July 15): only Phase II implementation is suspended. C3PAO Level 2 certification assessments, CAICO training, professional exams, Registered Practitioner services, and DIBCAC assessments all remain operational and available. You can still get certified — though no DoW contract can require it during the suspension.
Fully operational

Do not dismantle your compliance program. With the third-party checkpoint suspended, a SPRS score that would not survive a government-led assessment is more exposed than it was before — not less.

Read the full brief →
01Choose your path

Which path are you on?

Phase II is suspended and the program is under review — which makes the right next step different depending on where you actually stand today. Three doors, and you can walk through more than one.

Path 01 · Prepare

RPO — Readiness & Advisory

“I think we’re compliant — but I couldn’t prove it under an audit.”

Scoping and boundary definition, readiness assessment, gap analysis against all 110 controls, NIST SP 800-171 remediation, SSP and evidence. Includes a non-certification mock assessment — the same line-by-line diagnostic an assessor would apply, without the certification cost.

Best if: your SPRS score is stale, unproven, or you’ve never validated it against real evidence.
CMMC RPO & Readiness Advisory →
Assessments still available — not DoW-designatable
Path 02 · Certify

C3PAO — Certification Assessment

“A prime is asking for my certificate.”

The formal CMMC Level 2 assessment, performed by our all-W-2, in-house Lead CCAs.

What the memo did

DoW requiring activities may now designate only Level 1 (Self) or Level 2 (Self). C3PAO and DIBCAC designations are off the table for the duration of the review, existing ones are being stripped from active solicitations, and they come out of existing contracts at the next option exercise or scheduled administrative modification.

What it didn’t do

Stop you from certifying. The Cyber AB confirmed on July 15 that only Phase II implementation was suspended — C3PAO Level 2 assessments, CAICO training, professional exams, Registered Practitioner services, and DIBCAC’s assessment of C3PAOs all remain operational and available.

So the question changed. It is no longer “will a contract require this,” but “is it worth holding anyway.” The Cyber AB’s CEO answered that directly this week: a Level 2 certification “remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk.” There are 110 authorized C3PAOs by the Cyber AB’s count, against a base SBA puts at 120,000+ small businesses — and that math does not improve while everyone waits for the Task Force to report.

Best if: a prime requires your certificate as a commercial term, you want the FCA posture, or you would rather be in the queue than behind it when a verification model returns.
C3PAO Assessment →
Path 03 · Operate

Mission Assurance Services

“I don’t want to manage vendors — I want one team accountable for all of it.”

A single managed program across compliance, IT, and security operations — CUI enclave and SSP administration, vCIO/vCISO advisory, continuous monitoring, and incident response — so your compliance posture, your operations, and your security program are run by one accountable team instead of stitched together from three.

Best if: you’d rather own the mission than the infrastructure behind it — compliance, IT, and security included.
Mission Assurance Services →

Not sure which one you need? Six questions, two minutes, and a straight answer — or talk to a Lead CCA about your specific contract portfolio.

Start the readiness check →
02Independence

Conflict of interest, handled honestly.

Legal notice

If August Schell provided you RPO, advisory, or remediation services in the last three years, Cyber AB rules prevent us from performing your certification assessment — we will coordinate an independent C3PAO on your behalf. A non-certification mock assessment does not establish a consulting relationship under Cyber AB conflict-of-interest rules, so readiness work with us today does not cost you the option to certify with us later. We will tell you which side of that line you are on before you engage, in writing, every time.

03FAQ

Questions we’re getting this week.

Is CMMC cancelled?

No. Phase II — the third-party certification tier — is suspended pending a 60-day review by a CMMC Reform Task Force. For the duration, DoW requiring activities may designate only Level 1 (Self) or Level 2 (Self) assessments. The underlying rules, 32 CFR Part 170 and the DFARS acquisition rule, remain codified law. A CIO memo pauses implementation; it does not repeal the regulation, and any permanent change would require further rulemaking. Phase I self-assessment requirements are untouched. The DoW CIO has pointed industry to Brilliant Basics as the interim emphasis while the review runs.

Can I still get certified?

Yes. The Cyber AB confirmed on July 15 that only Phase II implementation was suspended — C3PAO Level 2 certification assessments remain operational and available, along with CAICO training, professional exams, Registered Practitioner services, and DIBCAC’s assessment of C3PAOs. The requirement paused; the ability did not. Be clear-eyed about what that means: no DoW contract can require a C3PAO certification right now, so certifying today is a commercial and risk decision rather than a compliance one. Their CEO put the value plainly: a Level 2 certificate “remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk.” We are an authorized C3PAO with Lead CCAs on staff, and our assessment calendar is open.

Do I still need a current SPRS score?

Yes. A current NIST SP 800-171 self-assessment posted in SPRS, with annual senior-official affirmation, remains a condition of eligibility on applicable solicitations. And inaccurate affirmations carry False Claims Act exposure — that risk did not pause with Phase II.

Should I pause my compliance program?

No — and this is the most expensive mistake available right now. The technical standard is unchanged. Under the memo, Level 2 (Self) against NIST SP 800-171 Rev. 2 is now the only path DoW can designate — which means your self-assessment is carrying the entire verification load, backed by direct government audit exposure through DIBCAC, and because the regulatory machinery is still standing, a modified program could re-implement quickly once the Task Force reports. Organizations that fully dismantle their programs in July could be caught flat-footed in the fourth quarter.

My prime requires CMMC. Does the suspension change that?

Not automatically. Where DFARS 252.204-7021 already sits in an awarded contract or subcontract, it remains a live obligation until it is formally modified — and the memo directs contracting officers to remove C3PAO and DIBCAC requirements at the next option exercise or scheduled administrative modification, not immediately. Expect a lag, and do not act on the announcement alone. Primes also impose supplier cybersecurity terms as commercial contract requirements independent of the DFARS, and those obligations did not change with this announcement. Do not alter your posture until every party whose terms bind you has confirmed the change in writing.

What happens to my existing certificate, or an assessment already underway?

That is genuinely unknown. The announcement is silent on the status and contractual value of certifications already earned and assessments currently in progress. We are engaging the Cyber AB directly at the executive level and will update our status page as we learn more.

Why can’t my C3PAO also fix my gaps?

Cyber AB independence rules. If a firm provided you RPO, advisory, or remediation services in the last three years, it cannot perform your certification assessment. That is why a non-certification mock assessment matters — it delivers the same line-by-line diagnostic without establishing a consulting relationship, so it doesn’t burn your option to certify with us.

Do you work with smaller businesses?

Yes — and the SBA analysis behind this suspension is precisely about you. SBA found Phase II would have required more than 120,000 DIB small businesses to comply through a system it characterized as supported by only about 100 approved assessors. Its analysis estimates total compliance costs can reach approximately $593,800 per certification for firms requiring third-party assessment, and about $388,600 for firms eligible for self-assessment — the figure that now applies to nearly everyone, since Level 2 (Self) is the ceiling DoW can designate. Most of either number is implementing controls you already owe under DFARS 252.204-7012. We scope to what you actually need.

How soon can you start?

Readiness work can begin immediately — and the pause is the ideal window for it, because you’re doing the work without competing for a scarce assessment slot. Plan for at least three months end-to-end on a full path, longer if a mock surfaces gaps to remediate.

04Request

Tell us where you stand.

We’ll come back with a straight read on your situation — which path fits, what it takes, and what it doesn’t. No obligation, and nothing is recorded or sent until you submit.

Submit request
Prefer email? cmmc@augustschell.com · or call (301) 838-9470
Routed automatically to the right team based on your answers.