{
 "slug": "interim-supplier-assurance",
 "topic_id": "TOPIC-206",
 "cluster": "Defense Industrial Base, CUI & Export-Control Identity",
 "tier": "Tier B",
 "title": "Buying identity assurance when CMMC is paused: a procurement guide for primes",
 "summary": "The 13 July 2026 suspension removed the third-party assessment mechanism and left safeguarding obligations and flow-down duties intact. Primes have reverted to the questionnaires CMMC existed to replace.",
 "lede": "Primes built supplier assurance plans around certification dates that no longer apply. The obligation to protect controlled information did not pause, which leaves a gap that has to be filled with something — and the default is the thing that did not work.",
 "date": "2024-06-13",
 "category": "Compliance",
 "author_id": "margot-reyes",
 "tags": [
  "CMMC suspension",
  "supplier assurance",
  "prime contractor",
  "flow down",
  "procurement",
  "DFARS"
 ],
 "image_title": "Interim Supplier Assurance",
 "schema": "Article",
 "key_takeaways": [
  "Assurance was outsourced to a certification regime. With the regime suspended, the default fallback is self-assessment questionnaires — the mechanism certification was created to replace.",
  "The useful distinction for interim requirements is attested versus verifiable, and only the second gives a prime something to sample.",
  "Requirements language should be scenario-neutral, because the suspension's duration is unknown and nobody should forecast it."
 ],
 "body": [
  {
   "type": "h2",
   "text": "What primes actually did in the weeks after"
  },
  {
   "type": "diagram",
   "kind": "compare",
   "alt": "Certification-shaped versus evidence-shaped procurement",
   "caption": "One depends on programme timing. The other does not.",
   "nodes": [],
   "left": {
    "title": "Certification-shaped",
    "items": [
     "Wait for assessment cadence",
     "Binary status per supplier",
     "Point in time",
     "Stops when the programme pauses"
    ]
   },
   "right": {
    "title": "Evidence-shaped",
    "items": [
     "Per-access and per-change records",
     "Measurable coverage",
     "Continuous",
     "Survives any programme change"
    ]
   }
  },
  {
   "type": "p",
   "html": "Three responses, observable across the sector."
  },
  {
   "type": "ol",
   "items": [
    "<strong style=\"font-weight:600\">Pause.</strong> Supplier assurance activity deferred pending clarity. Lowest effort, highest exposure, and the most common.",
    "<strong style=\"font-weight:600\">Revert.</strong> Return to self-assessment questionnaires and SPRS score collection. Familiar, cheap, and known not to work — which is why the certification programme was created.",
    "<strong style=\"font-weight:600\">Substitute.</strong> Build an interim requirement set. Highest effort, and the only one that actually maintains assurance."
   ]
  },
  {
   "type": "p",
   "html": "This article is about the third, and specifically about what to put in a supplier agreement when you cannot point to a certificate."
  },
  {
   "type": "h2",
   "text": "Attested versus verifiable"
  },
  {
   "type": "p",
   "html": "The organising distinction. An attested requirement produces a claim; a verifiable requirement produces an artefact the prime can check without an audit visit."
  },
  {
   "type": "table",
   "head": [
    "Requirement",
    "Attested form",
    "Verifiable form"
   ],
   "rows": [
    [
     "Safeguarding implementation",
     "Supplier states its SPRS score",
     "Supplier provides a signed control-state record with a scope hash"
    ],
    [
     "Access to our CUI",
     "Supplier states access is limited to authorised personnel",
     "Supplier provides per-access receipts naming individuals"
    ],
    [
     "Incident reporting readiness",
     "Supplier states it has a process",
     "Supplier demonstrates a signed test-report from an exercise"
    ],
    [
     "Flow-down to sub-tiers",
     "Supplier states it flows down",
     "Supplier provides delegation artefacts issued to sub-tiers"
    ],
    [
     "Affirmation basis",
     "Supplier provides its affirmation",
     "Supplier provides the signed control-state record the affirmation covered"
    ]
   ]
  },
  {
   "type": "p",
   "html": "The right column costs the supplier more and costs the prime less. That is the trade, and it should be negotiated as one rather than imposed."
  },
  {
   "type": "h2",
   "text": "Interim requirements language"
  },
  {
   "type": "p",
   "html": "Scenario-neutral, so it survives whatever happens to the programme:"
  },
  {
   "type": "blockquote",
   "text": "During any period in which third-party certification under the Cybersecurity Maturity Model Certification programme is not required or not available, Supplier shall provide, annually and upon material change, a cryptographically signed control-state record covering the systems within the scope of this agreement, verifiable by Buyer against Supplier's published verification key, together with the signed affirmation to which that record relates. Supplier shall provide equivalent records from any sub-tier supplier to which covered defense information is disclosed."
  },
  {
   "type": "p",
   "html": "Note what it does not say. It does not predict the programme's return, does not reference a date, and does not become obsolete if certification resumes — it simply stops applying."
  },
  {
   "type": "h2",
   "text": "A verification protocol a supply chain team can run"
  },
  {
   "type": "ol",
   "items": [
    "On receipt, verify the signature against the supplier's published key. Minutes, using open-source tooling.",
    "Check the scope hash against the boundary document the supplier provided. A record covering a narrower boundary than your work is the most common finding.",
    "Record three observations: coverage of in-scope systems, POA&M open item count, and change since the prior record.",
    "Sample sub-tier delegations for the suppliers who disclose onward. This is where flow-down assurance currently disappears entirely."
   ]
  },
  {
   "type": "h2",
   "text": "What to do about suppliers who cannot comply"
  },
  {
   "type": "p",
   "html": "Small suppliers — machine shops, specialty fabricators, single-product component makers — may have no capability to produce any of this, and they are frequently irreplaceable."
  },
  {
   "type": "p",
   "html": "Two workable approaches. Tier the requirement by the sensitivity of what they hold, so a supplier who never receives covered defense information is not asked for records about protecting it. And offer assistance: a prime that helps a critical small supplier stand this up has bought assurance and goodwill for less than the cost of qualifying an alternate source."
  },
  {
   "type": "h2",
   "text": "Do not rebuild twice"
  },
  {
   "type": "p",
   "html": "The strongest argument for the interim requirement set is that it is not interim. A control-state record and access receipts remain useful if certification resumes — they are what a certified supplier would produce anyway, and they cover the 364 days a year on which no assessor is present."
  },
  {
   "type": "p",
   "html": "A prime that builds this now builds it once. A prime that waits builds questionnaires now and something else later."
  },
  {
   "type": "h2",
   "text": "What to ask a supplier for"
  },
  {
   "type": "table",
   "caption": "Four asks, in order of acceptability to a supplier",
   "head": [
    "Ask",
    "Why they can usually agree"
   ],
   "rows": [
    [
     "A correlation identifier that round-trips",
     "Cheap, and it makes reconciliation possible"
    ],
    [
     "Receipts for a defined access class",
     "Bounded, not general logging"
    ],
    [
     "Retention matching your contract",
     "A contract term rather than engineering work"
    ],
    [
     "Verification without contacting them",
     "Reduces their support burden too"
    ]
   ]
  },
  {
   "type": "h2",
   "text": "Objections and honest limits"
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“Suppliers will resist anything extra during a pause.”</strong> Frame it as reducing their assessment burden later, and bound the ask to a defined access class. A scoped ask is agreeable in a way that ‘send us your logs’ is not."
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“We should just wait for the programme.”</strong> The affirmation is annual and the clauses are in force. Waiting means signing statements about facts you cannot evidence."
  },
  {
   "type": "p",
   "html": "A prime that has been collecting this through the pause is also the prime that can complete an assessment quickly when the cadence resumes."
  }
 ],
 "faq": [
  {
   "q": "When will CMMC Phase II return?",
   "a": "Nobody knows, and this article deliberately does not forecast it. The requirements language is written to be scenario-neutral for that reason."
  },
  {
   "q": "Can we require more than the contract flows down?",
   "a": "Primes routinely impose requirements beyond the minimum flow-down through their own terms. Whether to do so is a commercial decision informed by counsel."
  },
  {
   "q": "What about suppliers who refuse?",
   "a": "Tier the requirement by what they actually hold. A supplier who never receives covered defense information should not be asked for records about protecting it."
  },
  {
   "q": "Is this wasted if certification resumes?",
   "a": "No. The artefacts are what a certified supplier produces anyway, and they cover the period between assessments, which is most of the time."
  },
  {
   "q": "Does a programme pause remove the obligation?",
   "a": "No. Safeguarding clauses sit in the contract and the annual affirmation continues. Sequencing changed, not the requirement."
  },
  {
   "q": "What is realistic to ask a supplier for?",
   "a": "A correlation identifier, receipts for a bounded access class, contractual retention, and verification that does not require contacting them."
  },
  {
   "q": "How should suppliers be ranked?",
   "a": "By what they can reach, not by spend. Data access is the exposure."
  }
 ],
 "sources": [
  {
   "t": "CMMC program — DoD CIO",
   "u": "https://dodcio.defense.gov/CMMC/"
  },
  {
   "t": "NIST SP 800-171 Rev. 3 — Protecting CUI",
   "u": "https://csrc.nist.gov/pubs/sp/800/171/r3/final"
  },
  {
   "t": "Published prime contractor supplier assurance programme practice."
  }
 ],
 "related": [
  {
   "slug": "affirmation-evidence-standard",
   "title": "CMMC Phase II is suspended",
   "category": "Compliance"
  },
  {
   "slug": "cross-boundary-cui-access",
   "title": "Who touched the CUI?",
   "category": "Compliance"
  },
  {
   "slug": "software-attestation-evidence",
   "title": "The secure software development attestation",
   "category": "Compliance"
  }
 ],
 "image": "https://cdn.twc.sh/images/igcache/Interim%20Supplier%20Assurance/1200_630/blog.jpg",
 "wordcount": 955,
 "url": "/blog/interim-supplier-assurance.html",
 "reading_time": "4 min read",
 "seo_title": "Buying identity assurance while CMMC is paused",
 "meta_description": "The 13 July 2026 suspension removed the third-party assessment mechanism and left safeguarding obligations and flow-down duties intact.",
 "hub": {
  "slug": "topics/dib-identity",
  "title": "Defense industrial base identity"
 },
 "answer": "Evidence, not certification. The programme's sequencing changed; the safeguarding clauses in the contract did not, and neither did the annual affirmation. A prime that buys per-access and per-change records from its critical suppliers has something that survives whatever the programme does next.",
 "answer_q": "What should a prime buy while CMMC is paused?",
 "glossary": [
  {
   "term": "Flow-down",
   "def": "The contractual mechanism passing safeguarding obligations to suppliers, which operates independently of assessment programme timing."
  },
  {
   "term": "Coverage",
   "def": "The proportion of in-scope access or changes that produced evidence. More informative than a binary compliance status."
  },
  {
   "term": "Critical supplier",
   "def": "One whose access to your data or systems would matter if abused, which is rarely the same ranking as spend."
  }
 ],
 "checklist": {
  "title": "Interim supplier assurance",
  "id": "interim",
  "desc": "Four steps.",
  "steps": [
   {
    "name": "Rank suppliers by what they can reach.",
    "text": "Not by spend. The data they touch is the exposure."
   },
   {
    "name": "Scope the ask to a defined access class.",
    "text": "Bounded asks get agreed."
   },
   {
    "name": "Put retention in the contract.",
    "text": "Not in a policy either side can change."
   },
   {
    "name": "Measure coverage, not status.",
    "text": "A percentage tells you more than a binary certification flag."
   }
  ]
 },
 "cta": {
  "title": "Where this fits in Manav",
  "html": "Manav binds the authorising individual to the exact record being released or approved, and produces a receipt a prime, a government customer or an auditor can verify without access to your systems.",
  "href": "../docs.html",
  "label": "See approval receipts"
 }
}