As if an election year, record heatwaves, and all the CMMC acronyms weren't enough, the Department of War's recent decision to pause mandatory CMMC Phase II assessments has caused even more confusion across the Defense Industrial Base.
When the dust settles, it will be apparent that this decision actually adds risk for businesses.
On the surface, there's a perception that things just got easier.
CMMC Phase II would have required a third party to assess a DIB company's controls against NIST SP 800-171 before it could earn a Level 2 certificate. And these aren't just any third parties. Certified Third-Party Assessment Organizations (C3PAOs) must pass rigorous inspection by the Department of War, complete specialized training, and staff their engagements with specially trained experts for the privilege of assessing DIB and supply chain companies.
Now, the DIB companies are on the hook to review and score themselves against the 320 assessment objectives.
That responsibility carries real risk.
The Real Risk
Most organizations believe they are compliant. Far fewer can prove it.
Executives are being asked to certify compliance with a complex cybersecurity framework, often without experienced CMMC assessors reviewing their evidence. Internal IT teams may be highly capable, but many have never been through a formal CMMC assessment and may not recognize where documentation falls short.
The greatest risk is no longer the self-assessment. It's the self-attestation. Once an executive certifies compliance, the organization owns that representation and the responsibility that comes with it.
Without experienced guidance, organizations often overestimate the strength of their evidence, misunderstand documentation requirements, or assume that implemented technical controls are sufficient without demonstrating them appropriately. The result is uncertainty at precisely the moment confidence matters most.
Is Your Business Ready to Attest?
MNS Group developed Ready to Attest to address this challenge. Rather than conducting a formal assessment, our Certified CMMC Assessors perform a comprehensive, documentation-based evidence review using the same disciplined approach developed through years of performing CMMC assessments.
Every control is evaluated against the evidence submitted, resulting in a clear Met or Not Met determination. Every gap identified is paired with clear, actionable remediation guidance and access to our CMMC experts, giving your team a practical path to strengthening its evidence before submitting a self-attestation.
Unlike many review programs, the service includes two complete review cycles. After implementing improvements, organizations resubmit updated evidence for a second comprehensive review, receiving revised findings and an updated SPRS score before finalizing their self-attestation.
The objective is not simply to produce another report. It is to help organizations sign their self-attestation with confidence rather than assumption.
Self-Attest with Confidence
The suspension of mandatory assessments may have changed the compliance process, but it has not reduced the importance of cybersecurity or the expectation that contractors accurately represent their security posture.
When your organization signs its self-attestation, that confidence should be based on evidence, not hope.
Submit Your SPRS Score With Confidence
We offer two levels of support, built around the same disciplined review our Certified CMMC Assessors use in the field.
Evidence Review & SPRS Score
An independent, evidence-based review of your CMMC Level 2 posture.
Guided Review & Remediation
Everything in Tier 1, plus hands-on support and a second look after you remediate.
+ Includes everything in Tier 1
