The rules changed. The obligation didn’t.
August Schell is a 35-year federal cybersecurity firm — an Authorized C3PAO and a Registered Practitioner Organization, with Lead CCAs on staff. Whatever the Department decides next, there is a path from where you are to a defensible compliance posture. Start by finding yours.
The suspension pauses the verification mechanism — not the security obligation.
Maintained by August Schell
Authorized C3PAO · Registered RPO
Do not dismantle your compliance program. With the third-party checkpoint suspended, a SPRS score that would not survive a government-led assessment is more exposed than it was before — not less.
Read the full brief →Which path are you on?
Phase II is suspended and the program is under review — which makes the right next step different depending on where you actually stand today. Three doors, and you can walk through more than one.
RPO — Readiness & Advisory
Scoping and boundary definition, readiness assessment, gap analysis against all 110 controls, NIST SP 800-171 remediation, SSP and evidence. Includes a non-certification mock assessment — the same line-by-line diagnostic an assessor would apply, without the certification cost.
C3PAO — Certification Assessment
The formal CMMC Level 2 assessment, performed by our all-W-2, in-house Lead CCAs.
DoW requiring activities may now designate only Level 1 (Self) or Level 2 (Self). C3PAO and DIBCAC designations are off the table for the duration of the review, existing ones are being stripped from active solicitations, and they come out of existing contracts at the next option exercise or scheduled administrative modification.
Stop you from certifying. The Cyber AB confirmed on July 15 that only Phase II implementation was suspended — C3PAO Level 2 assessments, CAICO training, professional exams, Registered Practitioner services, and DIBCAC’s assessment of C3PAOs all remain operational and available.
So the question changed. It is no longer “will a contract require this,” but “is it worth holding anyway.” The Cyber AB’s CEO answered that directly this week: a Level 2 certification “remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk.” There are 110 authorized C3PAOs by the Cyber AB’s count, against a base SBA puts at 120,000+ small businesses — and that math does not improve while everyone waits for the Task Force to report.
Mission Assurance Services
A single managed program across compliance, IT, and security operations — CUI enclave and SSP administration, vCIO/vCISO advisory, continuous monitoring, and incident response — so your compliance posture, your operations, and your security program are run by one accountable team instead of stitched together from three.
Not sure which one you need? Six questions, two minutes, and a straight answer — or talk to a Lead CCA about your specific contract portfolio.
Start the readiness check →Conflict of interest, handled honestly.
If August Schell provided you RPO, advisory, or remediation services in the last three years, Cyber AB rules prevent us from performing your certification assessment — we will coordinate an independent C3PAO on your behalf. A non-certification mock assessment does not establish a consulting relationship under Cyber AB conflict-of-interest rules, so readiness work with us today does not cost you the option to certify with us later. We will tell you which side of that line you are on before you engage, in writing, every time.
Questions we’re getting this week.
Is CMMC cancelled?
No. Phase II — the third-party certification tier — is suspended pending a 60-day review by a CMMC Reform Task Force. For the duration, DoW requiring activities may designate only Level 1 (Self) or Level 2 (Self) assessments. The underlying rules, 32 CFR Part 170 and the DFARS acquisition rule, remain codified law. A CIO memo pauses implementation; it does not repeal the regulation, and any permanent change would require further rulemaking. Phase I self-assessment requirements are untouched. The DoW CIO has pointed industry to Brilliant Basics as the interim emphasis while the review runs.
Can I still get certified?
Yes. The Cyber AB confirmed on July 15 that only Phase II implementation was suspended — C3PAO Level 2 certification assessments remain operational and available, along with CAICO training, professional exams, Registered Practitioner services, and DIBCAC’s assessment of C3PAOs. The requirement paused; the ability did not. Be clear-eyed about what that means: no DoW contract can require a C3PAO certification right now, so certifying today is a commercial and risk decision rather than a compliance one. Their CEO put the value plainly: a Level 2 certificate “remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk.” We are an authorized C3PAO with Lead CCAs on staff, and our assessment calendar is open.
Do I still need a current SPRS score?
Yes. A current NIST SP 800-171 self-assessment posted in SPRS, with annual senior-official affirmation, remains a condition of eligibility on applicable solicitations. And inaccurate affirmations carry False Claims Act exposure — that risk did not pause with Phase II.
Should I pause my compliance program?
No — and this is the most expensive mistake available right now. The technical standard is unchanged. Under the memo, Level 2 (Self) against NIST SP 800-171 Rev. 2 is now the only path DoW can designate — which means your self-assessment is carrying the entire verification load, backed by direct government audit exposure through DIBCAC, and because the regulatory machinery is still standing, a modified program could re-implement quickly once the Task Force reports. Organizations that fully dismantle their programs in July could be caught flat-footed in the fourth quarter.
My prime requires CMMC. Does the suspension change that?
Not automatically. Where DFARS 252.204-7021 already sits in an awarded contract or subcontract, it remains a live obligation until it is formally modified — and the memo directs contracting officers to remove C3PAO and DIBCAC requirements at the next option exercise or scheduled administrative modification, not immediately. Expect a lag, and do not act on the announcement alone. Primes also impose supplier cybersecurity terms as commercial contract requirements independent of the DFARS, and those obligations did not change with this announcement. Do not alter your posture until every party whose terms bind you has confirmed the change in writing.
What happens to my existing certificate, or an assessment already underway?
That is genuinely unknown. The announcement is silent on the status and contractual value of certifications already earned and assessments currently in progress. We are engaging the Cyber AB directly at the executive level and will update our status page as we learn more.
Why can’t my C3PAO also fix my gaps?
Cyber AB independence rules. If a firm provided you RPO, advisory, or remediation services in the last three years, it cannot perform your certification assessment. That is why a non-certification mock assessment matters — it delivers the same line-by-line diagnostic without establishing a consulting relationship, so it doesn’t burn your option to certify with us.
Do you work with smaller businesses?
Yes — and the SBA analysis behind this suspension is precisely about you. SBA found Phase II would have required more than 120,000 DIB small businesses to comply through a system it characterized as supported by only about 100 approved assessors. Its analysis estimates total compliance costs can reach approximately $593,800 per certification for firms requiring third-party assessment, and about $388,600 for firms eligible for self-assessment — the figure that now applies to nearly everyone, since Level 2 (Self) is the ceiling DoW can designate. Most of either number is implementing controls you already owe under DFARS 252.204-7012. We scope to what you actually need.
How soon can you start?
Readiness work can begin immediately — and the pause is the ideal window for it, because you’re doing the work without competing for a scarce assessment slot. Plan for at least three months end-to-end on a full path, longer if a mock surfaces gaps to remediate.
Tell us where you stand.
We’ll come back with a straight read on your situation — which path fits, what it takes, and what it doesn’t. No obligation, and nothing is recorded or sent until you submit.
