CMMC Phase II is suspended — but DFARS 252.204-7012 and your SPRS score never paused. CMMC status: the straight story

Frameworks · NIST SP 800-171 · DFARS 252.204-7012

110 requirements.
Zero room for guesswork.

If your defense contract includes clause 252.204-7012, the government expects you to protect sensitive information in 110 specific ways — and to post an honest self-grade (your SPRS score) that every prime contractor can see. Companies that guessed at that grade have paid millions in federal penalties. Run your self-assessment honestly in the Cyber Tackle Box™ platform — or bring in Lionfish & partner consultants to assess you, fix the gaps with your team, and hand you paperwork that protects the business instead of exposing it.

110 requirements (Rev 2)SPRS scoringDFARS 7012/7019/7020FCA-proof evidence

Technical evaluator? Skip the pitch — jump to the deep dive ↓

For the technical reader — the deep dive
  • Contractual baseline: Rev 2 — 110 requirements in 14 families, decomposing to ~320 assessment objectives under 800-171A (the evidence grain that matters).
  • Rev 3 (97 requirements, 88 organization-defined parameters; DoD fixed the ODP values April 2025) is published but not yet in DFARS — we track the delta.
  • Clauses: DFARS 252.204-7012 (safeguarding + incident reporting), 7019/7020 (SPRS posting and government assessment rights).
  • SPRS scoring: DoD methodology, range −203 to +110, weighted 1/3/5-point deductions; your posted score is a certified statement under the False Claims Act.
  • CMMC status: Phase II suspended July 13, 2026 pending the reform task force; Phase 1 self-assessments and annual affirmations continue.
  • In the Tackle Box: objective-level evidence, honest SPRS calculator, SSP and POA&M artifacts organized the way 800-171A reads.

Want to go deeper than a web page? Book a call — you'll be talking to a practitioner, not a salesperson.

Self-attestation is now the battlefield

$00K×10
Raytheon's 2025 False Claims Act settlement over 800-171 failures — $8.4M across 29 contracts
0
security requirements in NIST SP 800-171 Rev 2 — still the contractual baseline under DFARS
0 to +110
the SPRS scoring range (−203 floor) — most first assessments land far below passing
0+
assessment objectives under 800-171A — the evidence level where spreadsheets die

Sources: DOJ settlement announcements (Raytheon $8.4M, MORSECORP $4.6M, Georgia Tech $875K — all 2025); DFARS clause requirements; NIST SP 800-171A. Whistleblowers get a cut of FCA settlements — the MORSE relator took home $851K.

Who this is for

For everyone holding a DFARS clause

If 252.204-7012 is in your contract — or your prime's flow-down letter — this is already your obligation, suspension or not.

  • Defense subcontractors handling CUI — machine shops, engineering firms, electronics manufacturers, R&D shops — where the "IT department" is two people and a prayer.
  • Contractors whose primes demand a SPRS score before award — primes are re-ranking supplier lists by security posture right now.
  • MSPs serving the defense industrial base who need to run 800-171 programs for a book of DIB clients without hiring a compliance team per client.

Sound familiar?

The pain we hear on every first call

  • !The score you posted is a legal statement. DOJ settlements in 2025 made a false SPRS score an existential risk — and your former IT admin is a potential whistleblower.
  • !320+ objectives, one spreadsheet. 800-171's 110 requirements decompose into 320+ assessment objectives. Evidence at that grain doesn't fit in Excel.
  • !A moving target. Rev 3 is published, DoD has fixed its parameters, and CMMC is being reformed — you need a system that tracks the change, not a binder that fossilizes.

The platform

How the Cyber Tackle Box™ runs your 800-171 program

The same platform that runs our CMMC Rapid Deployment engagements — because 800-171 is the backbone of both.

SSP & Policy Templates

A System Security Plan built from proven structure, plus the policy set behind every one of the 14 requirement families.

Honest SPRS Scoring

Control-by-control assessment with the real DoD scoring methodology — a number you can post, defend, and improve on a plan.

POA&Ms That Close

Gaps become assigned, dated Plans of Action & Milestones driven to closure — the heart of remediation, managed as living work.

Evidence & the Intel Hub

Artifacts organized by requirement and objective, timestamped and exportable — plus regulatory intel so Rev 3 and CMMC reform never surprise you.

Assessment Playbooks

Runbooks built by instructors who teach the official CCA curriculum — you prepare against the same standard assessors are trained on.

Workforce Training

The awareness and role-based training 800-171 requires (3.2.x), delivered so your people actually finish it — tracked per person.

Software, services, or both

Two ways to work with Lionfish

The Cyber Tackle Box™ is a product you can run yourself. Our consulting team is a service you can add. Take either — or both. They're priced separately, and we'll tell you straight which one you actually need.

The platform — Cyber Tackle Box™

Software you run yourself: framework-mapped controls, policy templates, evidence, POA&Ms, and workforce training in one system of record. Your team (or your MSP) drives; the platform keeps everything organized and audit-ready.

Book a platform demo

The services — Lionfish & partner consultants

Add Lionfish & partner consultants — led by the team that trains certified CMMC assessors, backed by our vetted Trusted Partner Network — to run the gap assessment, drive remediation, and prepare you for the audit, by, with, and through your team, inside the same platform.

Book a readiness call

For MSPs & partners

Multi-tenant by design: run every client's compliance program from one console and add a services line without adding headcount. White-glove onboarding for your first clients.

Partner with us

Straight answers

800-171 questions we answer every week

Does the CMMC suspension change my 800-171 obligations?

No. On July 13, 2026 the Department of War suspended CMMC Phase II pending a reform review — but DFARS 252.204-7012 contractual obligations, 7019/7020 SPRS posting requirements, and Phase 1 self-assessments all continue. If anything, the suspension raises the stakes on self-attestation accuracy, because the False Claims Act is now the primary enforcement vector.

What SPRS score do I actually need?

The scoring range runs from −203 to +110, and a perfect implementation of all 110 requirements scores 110. Practically: primes compare subs against each other, contracting officers can see your number, and posting a score you can't evidence is the fact pattern behind the 2025 DOJ settlements. Get assessed honestly first — then improve on a documented plan.

Rev 2 or Rev 3 — which applies to me?

Rev 2 (110 requirements) remains the contractual baseline under DFARS via DoD's class deviation. Rev 3 (97 requirements, 88 DoD-defined parameters) is published and DoD has fixed its parameter values — a clear signal it's coming. We track your program against Rev 2 today and map the Rev 3 delta so the transition is a diff, not a do-over.

How is this different from your CMMC service?

Same backbone, different destination. 800-171 is the control set; CMMC is the certification program built on top of it. Our CMMC: Rapid Deployment engagements take you through assessment readiness; this program keeps your 800-171 posture and SPRS score defensible in the meantime — and everything done here counts toward whatever the CMMC reform produces.

Get in touch

Get an 800-171 score you can defend

Tell us about your DFARS clauses and your current SPRS posture — or that you don't know it, which is the most common answer. Straight assessment within one business day.

  • 1We reply within one business day — usually faster.
  • 2A 30-minute call with someone who can actually answer your questions.
  • 3A straight recommendation — even if it's that you don't need us yet.

Prefer to skip the form? Book a time directly or call 1-877-732-6772.

Book a Free Call