The question the suspension did not answer
On July 13, 2026, the Department of War suspended advancement to CMMC Phase II. During the suspension, requiring activities may designate only self-assessment for contracts involving Controlled Unclassified Information, a Reform Task Force is conducting a 60-day review, and the signals suggest a material risk that third-party assessment will be reduced or removed from the program rather than repositioned.
The suspension settled the question of mandatory certification for now. It did not answer the harder one. Executives still sign annual affirmations in SPRS. Prime contractors still have to differentiate supplier risk across thousands of subcontractors. Government programs still depend on the security of the small companies that hold their technical data. Suspending the planned expansion removed the immediate barrier, but it also placed the principal scalable, contractor-initiated mechanism for obtaining independent assurance in doubt.
In June 2026, the Department of Justice settled with a defense contractor that had reported a perfect self-assessment score of 110, and that the Defense Contract Management Agency later assessed at negative 170. The settlement resolved allegations rather than adjudicated findings, but the gap illustrates the assurance problem the third-party assessment model was designed to address.
A false binary
The policy choice before the Department should not be framed as continued progression toward broadly mandatory C3PAO assessments versus indefinite reliance on unsupported self-assessment. Both ends of that binary have already demonstrated their failure modes. The mandatory end priced small manufacturers out of the industrial base, which is the Department's own stated reason for the suspension. The unsupported end creates the risk of inflated scores and leaves the government to address material misrepresentations through audits and False Claims Act enforcement after the fact, one settlement at a time.
Both pathways evaluate the same 110 requirements of NIST SP 800-171 against the same assessment methodology. The difference is not the standard. It is who verifies that the standard is met.
The graduated model
The paper proposes that Level 2 Self remain the affordable contractual entry point where the contract designates it, preserving access for small, emerging, and nontraditional contractors, while contractors should be permitted to pursue a voluntary official Level 2 C3PAO assessment when they need greater independent assurance, stronger credibility with prime contractors, or a better evidentiary basis for executive affirmation. The regulatory structure already exists in 32 CFR Part 170, including the rule that Level 2 C3PAO status satisfies Level 2 Self for the same assessment scope. What the model needs is a Department policy determination that voluntary assessments will be accepted into the official systems and recognized.
The paper develops the full architecture: what a defensible self-assessment actually requires, where credentialed practitioners fit and where their role ends, how a voluntary assessment would work under the existing regulation, a verifiable and scope-specific Third-Party Assessed supplier credential modeled conceptually on the aerospace industry's OASIS registry, what the Affirming Official gains and what responsibility remains, a conservative treatment of False Claims Act exposure with a proposed enforcement-credit policy, and guardrails to keep the voluntary pathway from hardening into a hidden mandate imposed through subcontract flowdown.
Why this beats abandoning independent assessment
The assessment infrastructure of authorized C3PAOs, certified assessors, and the accreditation apparatus behind them took years to build, and it will not idle indefinitely without a market. A voluntary pathway preserves much of that capability without requiring the government to build a new assurance structure, keeping independent assessment available for critical programs, high-risk suppliers, or a future policy direction. Eliminating it would trade one mistake for its mirror image.
The twelve recommendations
- Retain Level 2 Self as the baseline entry pathway where designated by the contract.
- Explicitly authorize contractor-initiated voluntary Level 2 C3PAO assessments during and after the current review.
- Ensure voluntary official assessment results are accepted into eMASS, transmitted to SPRS, recorded, and officially recognized.
- Preserve the rule that Level 2 C3PAO status satisfies Level 2 Self for the same assessment scope.
- Create a verifiable, scope-specific Third-Party Assessed supplier designation tied to official C3PAO status.
- Permit primes to accept the credential in place of duplicative reviews of the same requirements when the scope matches.
- Establish formal enforcement credit recognizing good-faith reliance on a current assessment as evidence of due diligence.
- Require annual affirmation, material-change monitoring, and prompt action when compliance is called into question.
- Preserve a meaningful role for RPs, RPAs, and CCPs based on competence rather than mandate.
- Preserve C3PAO independence, including the existing 3-year restriction on preparers participating in the assessment.
- Prevent the voluntary pathway from becoming an automatic universal subcontract requirement.
- Build the program around measurable security operation and evidence rather than possession of documents.
The full paper runs the argument from the contractor's operating reality through the regulatory mechanics, the commercial incentives, and a worked example of how a small aerospace machine shop would use the model, with every material claim cited to the governing sources.