If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
CMMC Trigger Events: A Triage Guide for Contractors
Nobody reads a compliance article for entertainment. If you are here, one of the nine CMMC trigger events on this page landed on your desk this week. A questionnaire from your prime. A drawing with a CUI banner on it. An award notice carrying a clause you did not price. An email telling you that an eleven year supply relationship is about to end unless you can produce something you have never heard of.
This page triages all of them. Find your situation in the table, make the first move, then read the article that covers it in full. For the contract language sitting underneath all of it, start with DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.
Three things hold true across every one of these CMMC trigger events, and they are worth saying before anything else:
- The clock started before you found out. The obligation attached when the contract was signed or when the data arrived, not when somebody noticed.
- The certification audit is suspended. The liability is not. DFARS 252.204-7012, NIST SP 800-171, SPRS reporting and the annual affirmation are all still live.
- What you say in writing is the risk. A wrong answer on a questionnaire or an inflated SPRS score is a False Claims Act problem. The gap itself usually is not.
What changed in July 2026, and what did not
On July 13, 2026, the Department of War suspended the CMMC Phase 2 assessment requirements that were scheduled to take effect on November 10, 2026, and stood up a CMMC Reform Task Force with a 60 day reporting deadline. The suspension covers the certification assessment mechanism for Levels 2 and 3, meaning the C3PAO audit and the DIBCAC led assessment.
It does not touch the underlying obligations. Here is the split, because almost every panicked call starts with somebody getting this wrong:
| Requirement | Status today |
|---|---|
| C3PAO certification assessment, Level 2 and Level 3 | Suspended, pending the Task Force report |
| New 7021 clauses in solicitations | Paused. Existing clauses stay in existing contracts until modified |
| DFARS 252.204-7012, safeguarding, 72 hour incident reporting, media preservation, cloud requirements | Fully in force |
| NIST SP 800-171 implementation, all 110 requirements | Fully in force |
| DFARS 252.204-7019, current SPRS score as a condition of award | Fully in force |
| DFARS 252.204-7020, government access and verifying your subcontractors | Fully in force |
| FAR 52.204-21, fifteen basic safeguarding requirements for FCI | Fully in force |
| Annual senior official affirmation | Fully in force, and it is a certification |
| Prime contractor flowdown demands | Unaffected. Primes set their own supplier terms |
The practical read is straightforward. You cannot currently be forced to hold a certificate, and you cannot currently obtain one either. Everything that creates legal exposure, meaning the score you posted, the affirmation you signed and the safeguards you claimed, is untouched. The detail on which clause does what is in DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers.
The nine CMMC trigger events, and the first move for each
These are the nine CMMC trigger events that put a small contractor into an urgent compliance decision. Find yours, make the first move today, then read the full article.
| What happened | Your first move, today | Full article |
|---|---|---|
| A prime sent you a cybersecurity questionnaire | Do not answer from memory. Find out what score is posted in SPRS under your CAGE before you write a word. | your prime just sent you a cybersecurity questionnaire |
| CUI marked drawings arrived and you were not expecting them | Stop forwarding. Do not delete. Identify where copies now exist before you touch anything. | CUI-marked drawings you weren’t expecting |
| Your SPRS score expired and a bid is due | Check the assessment date, not the score. Under 7019 the assessment must be no more than three years old to be considered for award, and a solicitation can require less. | your SPRS score expired and a bid is due |
| A prime told you that you will be dropped without CMMC | Get the requirement in writing with the clause cited. Half of these turn out to be supplier policy rather than contract. | a prime told you you’ll be dropped without CMMC |
| You have 90 days to get compliant | Decide scope first. Ninety days is enough for an enclave and a defensible System Security Plan. It is not enough for a whole company remediation. | 90 days to get compliant |
| You won an award, then found the 7021 clause in it | Do not sign a modification quietly. Ask the contracting officer in writing how the Phase 2 suspension applies to your contract. | you won an award and then found the 7021 clause |
| Your MSP says you are already compliant | Ask for the System Security Plan, the score worksheet and the POA&M. If those three do not exist, neither does the compliance. | your MSP says you’re already compliant |
| Your CUI is sitting in commercial Microsoft 365 | Do not start migrating. Establish where the CUI actually is, then move the boundary rather than the whole tenant. | your CUI is sitting in commercial Microsoft 365 |
| An RFP requires a Level 2 certification you do not have | Read the requirement precisely. Certification, self assessment and SPRS score are three different asks and solicitations mix them up constantly. | an RFP requires a Level 2 certification you don’t have |
The first 72 hours
All nine CMMC trigger events share the same opening moves. Do them in this order.
- Establish what you have already said. Pull your SPRS record. Note the score, the assessment date, which must be no more than three years old to be considered for award under 7019, the scope description, and who affirmed it. That record is the government’s version of your security posture, and it is what a prime, a contracting officer or an investigator reads first.
- Find the clauses. Search your active contracts and subcontracts for 252.204-7012, 7019, 7020, 7021 and FAR 52.204-21. Note which contracts carry them and which do not. Do this before anyone in your company starts talking about our CMMC requirement, because there may not be one.
- Locate the data. Identify where CUI and FCI live right now. Email, file shares, laptops, the ERP, the shop floor PC running the CAM software, the personal Dropbox somebody set up in 2019. You cannot scope what you have not found. The CUI Scoping Workbook walks this.
- Hold the line on written statements. Until the first three steps are done, nobody answers a questionnaire, signs an affirmation, updates a score or tells a prime that you are compliant. Written answers are the liability. Three days of quiet are not.
- Score yourself honestly. A real NIST SP 800-171 self assessment, all 110 requirements, using the DoD scoring methodology. If the number is ugly, that is information rather than a problem. A low posted score is defensible. An inflated one is not.
What you can actually fix in the time you have
The honest version, because urgency makes people buy the wrong thing.
| Time available | Realistic outcome |
|---|---|
| One week | An accurate SPRS score, a scoping decision, and a written answer to whoever is asking. Nothing technical. |
| 30 days | The above, plus a defensible System Security Plan and a POA&M with real dates and named owners. |
| 90 days | A CUI enclave stood up, the data moved into it, the plan written against that boundary, and a score that reflects reality. Whole company remediation is not on this list. |
| 6 to 12 months | Full 800-171 implementation across a general purpose environment, evidence accumulated, and readiness for an assessment if and when assessments resume. |
The single biggest lever on all of these is scope. Reducing the number of systems that touch CUI is faster and cheaper than hardening every system you own, and it is the difference between a 90 day answer and a two year program.
Four questions that decide your path out of any of these
- Do you actually have CUI, or only FCI? FCI puts you at FAR 52.204-21 and fifteen requirements. CUI puts you at DFARS 252.204-7012 and 110. People assume the harder answer and spend accordingly. Check the markings and the contract before you assume. See What is Controlled Unclassified Information (CUI)?
- Is the requirement contractual or commercial? A clause in your contract is a legal obligation. A prime’s supplier policy is a business relationship. Both can end your revenue, and they are negotiated in completely different ways.
- Is your CUI in a place that can ever be compliant? Commercial Microsoft 365 was not built to meet the 7012 cloud conditions. If that is where your CUI lives, no amount of policy writing fixes it. The data has to move.
- Who signs the affirmation? Identify that person now. They are personally attesting, and they should see the score, the plan and the POA&M before their name goes on anything.
The mistakes that turn CMMC trigger events into real problems
- Answering fast to look responsive. A prime would rather get an accurate answer on Friday than a wrong one on Tuesday.
- Posting a score you cannot document. The score is only as good as the assessment behind it. No worksheet, no defense.
- Assuming the suspension cancelled something. It suspended the audit. Your 7012 obligations, your posted score and your affirmation are unchanged.
- Letting the service provider answer for you. The obligation belongs to the contractor. A provider saying you are covered is not evidence, and it does not transfer liability.
- Deleting CUI you should not have received. Destroying data that arrived in error can turn a paperwork issue into a spoliation issue. Isolate first, then ask the sender in writing.
- Buying a tool before deciding scope. Tooling bought before scoping gets thrown away after scoping.
Next step
Every one of these CMMC trigger events starts from the same place, which is a number you can actually defend. The SPRS Score Calculator walks all 110 NIST SP 800-171 requirements using the DoD scoring methodology and gives you a score with the worksheet behind it. It is free, and nothing you enter leaves your browser.
If you already have a score posted and you are not confident it would survive scrutiny, run the SPRS Score Reality Check instead.
Frequently asked
Questions about this topic
Does the CMMC Phase 2 suspension mean I can ignore a prime’s questionnaire?
My contract already has DFARS 252.204-7021 in it. Is it still binding?
What is the fastest legitimate path if I have 90 days?
Can I post a low SPRS score without losing the contract?
Do I have to report anything if CUI arrived by mistake?
Who is legally on the hook, us or our service provider?
How long will the suspension last?
Keep reading
More in Trigger Events & Urgent Situations
- 90 Days to CMMC Compliance: What Is Really Possible →
- CMMC Compliant MSP? How to Verify What Yours Claims →
- CMMC Level 2 Certification an RFP Wants? Bid Anyway →
- CUI in Commercial Microsoft 365: What to Do Now →
- CUI Marked Drawings You Were Not Expecting? Do This →
- Cybersecurity Questionnaire From Your Prime? Do This →
- DFARS 7021 Clause Found After Award? Read This First →
- Dropped Without CMMC? What a Prime Can Actually Do →
- Expired SPRS Score and a Bid Due? Fix It This Week →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
- DoD CIO, Cybersecurity Maturity Model Certification
- 32 CFR Part 170, Cybersecurity Maturity Model Certification Program
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- NIST SP 800-171, Protecting Controlled Unclassified Information
- Supplier Performance Risk System
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5