Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

CMMC Trigger Events: A Triage Guide for Contractors

Nobody reads a compliance article for entertainment. If you are here, one of the nine CMMC trigger events on this page landed on your desk this week. A questionnaire from your prime. A drawing with a CUI banner on it. An award notice carrying a clause you did not price. An email telling you that an eleven year supply relationship is about to end unless you can produce something you have never heard of.

This page triages all of them. Find your situation in the table, make the first move, then read the article that covers it in full. For the contract language sitting underneath all of it, start with DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.

Three things hold true across every one of these CMMC trigger events, and they are worth saying before anything else:

  • The clock started before you found out. The obligation attached when the contract was signed or when the data arrived, not when somebody noticed.
  • The certification audit is suspended. The liability is not. DFARS 252.204-7012, NIST SP 800-171, SPRS reporting and the annual affirmation are all still live.
  • What you say in writing is the risk. A wrong answer on a questionnaire or an inflated SPRS score is a False Claims Act problem. The gap itself usually is not.

What changed in July 2026, and what did not

On July 13, 2026, the Department of War suspended the CMMC Phase 2 assessment requirements that were scheduled to take effect on November 10, 2026, and stood up a CMMC Reform Task Force with a 60 day reporting deadline. The suspension covers the certification assessment mechanism for Levels 2 and 3, meaning the C3PAO audit and the DIBCAC led assessment.

It does not touch the underlying obligations. Here is the split, because almost every panicked call starts with somebody getting this wrong:

RequirementStatus today
C3PAO certification assessment, Level 2 and Level 3Suspended, pending the Task Force report
New 7021 clauses in solicitationsPaused. Existing clauses stay in existing contracts until modified
DFARS 252.204-7012, safeguarding, 72 hour incident reporting, media preservation, cloud requirementsFully in force
NIST SP 800-171 implementation, all 110 requirementsFully in force
DFARS 252.204-7019, current SPRS score as a condition of awardFully in force
DFARS 252.204-7020, government access and verifying your subcontractorsFully in force
FAR 52.204-21, fifteen basic safeguarding requirements for FCIFully in force
Annual senior official affirmationFully in force, and it is a certification
Prime contractor flowdown demandsUnaffected. Primes set their own supplier terms

The practical read is straightforward. You cannot currently be forced to hold a certificate, and you cannot currently obtain one either. Everything that creates legal exposure, meaning the score you posted, the affirmation you signed and the safeguards you claimed, is untouched. The detail on which clause does what is in DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers.

The nine CMMC trigger events, and the first move for each

These are the nine CMMC trigger events that put a small contractor into an urgent compliance decision. Find yours, make the first move today, then read the full article.

What happenedYour first move, todayFull article
A prime sent you a cybersecurity questionnaire Do not answer from memory. Find out what score is posted in SPRS under your CAGE before you write a word. your prime just sent you a cybersecurity questionnaire
CUI marked drawings arrived and you were not expecting them Stop forwarding. Do not delete. Identify where copies now exist before you touch anything. CUI-marked drawings you weren’t expecting
Your SPRS score expired and a bid is due Check the assessment date, not the score. Under 7019 the assessment must be no more than three years old to be considered for award, and a solicitation can require less. your SPRS score expired and a bid is due
A prime told you that you will be dropped without CMMC Get the requirement in writing with the clause cited. Half of these turn out to be supplier policy rather than contract. a prime told you you’ll be dropped without CMMC
You have 90 days to get compliant Decide scope first. Ninety days is enough for an enclave and a defensible System Security Plan. It is not enough for a whole company remediation. 90 days to get compliant
You won an award, then found the 7021 clause in it Do not sign a modification quietly. Ask the contracting officer in writing how the Phase 2 suspension applies to your contract. you won an award and then found the 7021 clause
Your MSP says you are already compliant Ask for the System Security Plan, the score worksheet and the POA&M. If those three do not exist, neither does the compliance. your MSP says you’re already compliant
Your CUI is sitting in commercial Microsoft 365 Do not start migrating. Establish where the CUI actually is, then move the boundary rather than the whole tenant. your CUI is sitting in commercial Microsoft 365
An RFP requires a Level 2 certification you do not have Read the requirement precisely. Certification, self assessment and SPRS score are three different asks and solicitations mix them up constantly. an RFP requires a Level 2 certification you don’t have

The first 72 hours

All nine CMMC trigger events share the same opening moves. Do them in this order.

  1. Establish what you have already said. Pull your SPRS record. Note the score, the assessment date, which must be no more than three years old to be considered for award under 7019, the scope description, and who affirmed it. That record is the government’s version of your security posture, and it is what a prime, a contracting officer or an investigator reads first.
  2. Find the clauses. Search your active contracts and subcontracts for 252.204-7012, 7019, 7020, 7021 and FAR 52.204-21. Note which contracts carry them and which do not. Do this before anyone in your company starts talking about our CMMC requirement, because there may not be one.
  3. Locate the data. Identify where CUI and FCI live right now. Email, file shares, laptops, the ERP, the shop floor PC running the CAM software, the personal Dropbox somebody set up in 2019. You cannot scope what you have not found. The CUI Scoping Workbook walks this.
  4. Hold the line on written statements. Until the first three steps are done, nobody answers a questionnaire, signs an affirmation, updates a score or tells a prime that you are compliant. Written answers are the liability. Three days of quiet are not.
  5. Score yourself honestly. A real NIST SP 800-171 self assessment, all 110 requirements, using the DoD scoring methodology. If the number is ugly, that is information rather than a problem. A low posted score is defensible. An inflated one is not.

What you can actually fix in the time you have

The honest version, because urgency makes people buy the wrong thing.

Time availableRealistic outcome
One weekAn accurate SPRS score, a scoping decision, and a written answer to whoever is asking. Nothing technical.
30 daysThe above, plus a defensible System Security Plan and a POA&M with real dates and named owners.
90 daysA CUI enclave stood up, the data moved into it, the plan written against that boundary, and a score that reflects reality. Whole company remediation is not on this list.
6 to 12 monthsFull 800-171 implementation across a general purpose environment, evidence accumulated, and readiness for an assessment if and when assessments resume.

The single biggest lever on all of these is scope. Reducing the number of systems that touch CUI is faster and cheaper than hardening every system you own, and it is the difference between a 90 day answer and a two year program.

Four questions that decide your path out of any of these

  1. Do you actually have CUI, or only FCI? FCI puts you at FAR 52.204-21 and fifteen requirements. CUI puts you at DFARS 252.204-7012 and 110. People assume the harder answer and spend accordingly. Check the markings and the contract before you assume. See What is Controlled Unclassified Information (CUI)?
  2. Is the requirement contractual or commercial? A clause in your contract is a legal obligation. A prime’s supplier policy is a business relationship. Both can end your revenue, and they are negotiated in completely different ways.
  3. Is your CUI in a place that can ever be compliant? Commercial Microsoft 365 was not built to meet the 7012 cloud conditions. If that is where your CUI lives, no amount of policy writing fixes it. The data has to move.
  4. Who signs the affirmation? Identify that person now. They are personally attesting, and they should see the score, the plan and the POA&M before their name goes on anything.

The mistakes that turn CMMC trigger events into real problems

  • Answering fast to look responsive. A prime would rather get an accurate answer on Friday than a wrong one on Tuesday.
  • Posting a score you cannot document. The score is only as good as the assessment behind it. No worksheet, no defense.
  • Assuming the suspension cancelled something. It suspended the audit. Your 7012 obligations, your posted score and your affirmation are unchanged.
  • Letting the service provider answer for you. The obligation belongs to the contractor. A provider saying you are covered is not evidence, and it does not transfer liability.
  • Deleting CUI you should not have received. Destroying data that arrived in error can turn a paperwork issue into a spoliation issue. Isolate first, then ask the sender in writing.
  • Buying a tool before deciding scope. Tooling bought before scoping gets thrown away after scoping.

Next step

Every one of these CMMC trigger events starts from the same place, which is a number you can actually defend. The SPRS Score Calculator walks all 110 NIST SP 800-171 requirements using the DoD scoring methodology and gives you a score with the worksheet behind it. It is free, and nothing you enter leaves your browser.

If you already have a score posted and you are not confident it would survive scrutiny, run the SPRS Score Reality Check instead.

Frequently asked

Questions about this topic

Does the CMMC Phase 2 suspension mean I can ignore a prime’s questionnaire?
No. The suspension paused the government’s certification assessment mechanism. It did nothing to a prime’s ability to set supplier requirements, and nothing to DFARS 252.204-7020(d), which obligates primes to verify that their subcontractors have current SPRS scores. Questionnaires have increased since the suspension rather than decreased, because primes lost the certificate as an easy proxy for supplier risk.
My contract already has DFARS 252.204-7021 in it. Is it still binding?
A clause in an executed contract stays in that contract until the contracting officer modifies it. The suspension pauses the requirement going forward. It does not retroactively strike existing clauses. Ask your contracting officer in writing how the suspension applies to your specific contract, and keep the answer on file.
What is the fastest legitimate path if I have 90 days?
Reduce scope, then remediate. Stand up a dedicated enclave for CUI, move the data into it, and write the System Security Plan against that boundary. Ninety days is realistic for that. Ninety days is not realistic for bringing an entire general purpose corporate network to 110 requirements.
Can I post a low SPRS score without losing the contract?
Usually yes. DFARS 252.204-7019 requires a current score, not a high one. A score of 42 with a credible POA&M and a real implementation plan is a survivable position. A score of 110 you cannot evidence is a False Claims Act exposure. Contractors get into trouble for the second one far more often than the first.
Do I have to report anything if CUI arrived by mistake?
It depends on what happened to it after it arrived. Receiving mismarked or misdirected CUI is not automatically a reportable cyber incident. If that CUI landed in a system that does not meet the safeguarding requirements, you may be in incident territory under DFARS 252.204-7012, which carries a 72 hour reporting obligation to DIBNet. Isolate it, document the timeline, and get the determination made before you decide it is nothing. See 72-Hour DoD Breach Notification: DFARS Reporting Requirements.
Who is legally on the hook, us or our service provider?
You. The clauses flow to the contractor holding the contract. You can delegate the work to a service provider, and you should hold them to it in writing, but the affirmation is signed by your senior official and the liability sits with your company.
How long will the suspension last?
Unknown, and it does not change how you handle any of the CMMC trigger events on this page. The CMMC Reform Task Force was given 60 days from July 13, 2026 to report recommendations. A report is not a rule, and any structural change to the program would still require rulemaking. Plan on the underlying 800-171 obligations continuing regardless of what the certification mechanism ends up looking like.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents