If a prime contractor or a contracting officer has asked about your SPRS score, your System Security Plan, or your NIST 800-171 status, this is the page. It is documentation and readiness work — not certification, which by design has to come from someone else.
Call (909) 454-7076, book a consultation, or use our contact form.
Where CMMC actually stands
On July 13, 2026 the Department suspended CMMC Phase II requirements, which had been scheduled to take effect on November 10, 2026, and convened a reform task force to review the program over 60 days with a public Request for Information. Leadership described the program as imposing prohibitive compliance costs and pushing innovative companies out of the defense industrial base.
What remains in force:
- Phase I self-assessment requirements continue to apply.
- NIST SP 800-171 Rev 2 remains the compliance baseline for covered defense information.
- DFARS clause 252.204-7012 safeguarding obligations are unchanged.
- SPRS scores must be posted and maintained, with annual affirmation by a senior official.
- New procurement designations during the suspension are limited to Level 1 (Self) and Level 2 (Self).
The practical consequence is that nothing a small subcontractor is actually being asked for today has gone away. What changed is the deadline pressure behind third-party certification — which makes this a good period to get the documentation right rather than a reason to stop.
What we prepare
System Security Plan
A document describing how your organization satisfies each applicable control — what is configured, who is responsible, and how it is verified. The failure mode we see most often is an SSP describing an environment that does not exist, usually because it was written from a template. It has to describe your actual systems.
Plan of Action and Milestones
The controls you do not yet meet, what closing each requires, who owns it and by when. Open items are normal and expected. Undated items, or dates that have all silently passed, are what make a POA&M worse than useless in front of a prime.
Self-assessment and SPRS submission
Working through the 110 controls under the DoD Assessment Methodology, producing a defensible score, and posting it in SPRS with the supporting record behind it. A defensible score with open items beats an optimistic score you cannot substantiate.
Policies and evidence
The written policies and procedures the controls require, plus the evidence that they are followed — access reviews, training records, incident response procedures, media handling. Evidence collection is usually the part that is missing, and it is the part an assessor will ask for first.
Where our work stops
GERC is not an accredited CMMC Third-Party Assessment Organization and does not perform certification assessments. Any required Level 2 certification assessment must be conducted by an accredited C3PAO, and the organization that prepares your documentation cannot also assess it. We also do not provide managed IT services or implement technical controls on your network — where remediation requires an IT provider or a security engineer, we scope the work and hand it to yours, or to one of our referral partners.
What we do is the documentation, the assessment preparation and the ongoing maintenance, which is where most small companies stall.
Common questions
Do we still need to do anything now that CMMC Phase II is suspended?
Yes. The suspension announced on July 13, 2026 paused Phase II, which had been scheduled for November 10, 2026. It did not touch the underlying obligations. Phase I self-assessment requirements remain in effect, NIST SP 800-171 Rev 2 still applies, DFARS 252.204-7012 still governs safeguarding of covered defense information, and your SPRS score is still what primes and contracting officers look at.
What is an SPRS score and how is it calculated?
It is a self-assessed score against the 110 controls in NIST SP 800-171, using the DoD Assessment Methodology, which weights controls by security impact. The scale runs from 110 down into negative territory. A low or missing score is visible to contracting officers and to primes evaluating you as a subcontractor, and ‘we have not done one’ is the worst of the available answers.
What is the difference between an SSP and a POA&M?
The System Security Plan describes how you meet each control — the actual configuration and practice, not an intention. The Plan of Action and Milestones documents the controls you do not yet meet, with the specific steps and dates to close them. Having open items in a POA&M is normal. Having neither document is the problem.
Can GERC certify us?
No, and be careful with anyone who says they can. Certification assessments must be performed by an accredited CMMC Third-Party Assessment Organization, and a consultant who prepares your documentation cannot also assess you. We do the readiness and documentation work, and we will tell you when you are ready for an assessor.
A prime is asking about our cybersecurity posture. What do they actually want?
Usually three things: a current SPRS score, an SSP that exists and reflects reality, and a POA&M with dates that have not all quietly passed. Many small subcontractors lose opportunities at exactly this point, not because their security is poor but because they have nothing written down.
What should we do during the suspension period?
Treat it as time rather than reprieve. A reform task force is reviewing the program and requirements will land in some form. Companies that keep their documentation current will be ready; companies that stopped will be doing this under deadline pressure later, which is more expensive and worse.
If a prime is waiting on an answer
Send us what they asked for. We will tell you what you actually need to produce, how long it will take, and whether anything in it is urgent.
Call (909) 454-7076, book a consultation, or use our contact form.
GERC is a woman-led advisory firm led by Dr. Shirley Ayangbah, a PhD legal economist with more than 14 years of experience. Based in downtown San Bernardino, delivering nationwide. CAGE code 11SD2, registered and active in SAM.gov, certified California Small Business (Micro) and for Public Works.
GERC provides consulting, research, administrative, proposal, procurement and organizational support services. GERC is not a law firm, an accredited CMMC Third-Party Assessment Organization (C3PAO), or a provider of legal or tax advice. Where a matter requires an attorney, CPA or accredited assessor, we say so and work alongside the professional you choose.
