Executive Brief
The Cybersecurity Maturity Model Certification (CMMC) Reform Task Force is reviewing the certification program. It isn't reviewing your annual affirmation obligation, and it isn't reviewing the 72-hour window to report a cyber incident once you discover one.
It's worth being clear on what CMMC is: a requirement to be independently assessed against the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 standard. The underlying requirement to implement that standard has been in effect since December 31, 2017, under Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, and it hasn't paused, changed, or gone anywhere.
These two clocks run under different authority. Incident reporting is written into most Department of Defense (DoD) contracts involving covered defense information. Annual affirmation only kicks in once your organization already holds a CMMC status, self-assessed or certified. Neither depends on whether a Certified Third-Party Assessment Organization (C3PAO) is currently required to certify anyone.
- Your annual CMMC affirmation, required under Title 32 of the Code of Federal Regulations (32 CFR) 170.22, applies once your organization holds a CMMC status. It's a personal certification signed by a named individual, and it runs on its own calendar
- Your cyber incident reporting duty under Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 gives you 72 hours from discovery, and that clock has nothing to do with certification status
- The 72-hour incident reporting duty predates CMMC by years. The annual affirmation is a requirement the CMMC Program Rule itself created, but neither is part of what the C3PAO pause addresses
- If you already hold a CMMC status, your certification milestones don't disappear during the pause: your certification stays valid for its full term, a Conditional status still has to close out within 180 days, and your annual affirmation is still due on schedule
- The organizations most exposed right now are the ones who assume every CMMC-adjacent deadline moved when only one specific requirement did
Dig deeper below to learn more.
Why This Distinction Matters
The pause covers a specific thing: mandatory third-party certification for CMMC Level 2 and related Level 3 milestones. It is a narrow, well-defined change, and we broke down exactly what moved in our earlier post on why CMMC Phase II is paused, not canceled.
Read literally, that's all it says. It doesn't mention affirmations. It doesn't mention incident reporting. Yet both are showing up in the same conversations as if they were part of the same pause. See CMMC Phase II Is Paused, Not Canceled for the full breakdown of what changed.
- Affirmations are a CMMC Program Rule requirement under 32 CFR 170.22, separate from the certification assessment process itself
- Incident reporting is a DFARS contract clause that predates CMMC by years and applies regardless of your certification status
The Clock That Doesn't Stop: Your Annual Affirmation
If your organization has ever submitted a CMMC self-assessment or completed a certification assessment, a named Affirming Official at your company is on the hook for an annual affirmation in the Supplier Performance Risk System (SPRS), whether that status is Level 1 (Self), Level 2 (Self), or Level 2 (C3PAO).
- It's due annually, on a fixed clock. The requirement runs from your CMMC Status Date, not from any federal rollout milestone, and it's also triggered at the completion of a POA&M closeout assessment.
- It's personal, not corporate. The Affirming Official is a named senior representative, and the affirmation statement in SPRS explicitly warns that misrepresentation can bring criminal exposure under 18 U.S.C. § 1001, in addition to civil exposure under the False Claims Act (FCA).
- It lapses visibly if missed. SPRS automatically flips a Final CMMC Status to "No CMMC Status (Expired Assessment)" after a year without a renewed affirmation, which is a public, visible change to your status, not a quiet administrative gap.
- It applies whether the C3PAO pause affects your certification path. If you already hold a Level 2 (C3PAO) status, that certification remains valid on its existing cycle, and your Affirming Official still owes an annual affirmation to keep it active.
ISI Insight: Know who your current Affirming Official is, confirm they understand what they are certifying, and calendar the date against your actual CMMC Status Date rather than any date tied to the federal rollout timeline.
The Clock That Doesn't Stop: 72-Hour Incident Reporting
DFARS 252.204-7012 requires contractors to report a cyber incident affecting covered defense information within 72 hours of discovery, and this obligation has no connection to CMMC certification status at all. It's triggered by an event in your environment, not by a federal policy calendar.
- Reporting goes through the DCISE portal. DIBNet was decommissioned in 2025, and dibnet.dod.mil now redirects to the Defense Industrial Base Collaborative Information Sharing Environment (DCISE) Incident Collection Format (ICF) portal. You still need a DoD-approved medium assurance certificate to file, and that certificate needs to be in place before an incident happens. You can't apply for one for the first time in the middle of a 72-hour clock.
- Evidence preservation runs 90 days. You're required to preserve images of affected systems and relevant monitoring data for at least 90 days from your report submission, which means containment and remediation can't come at the expense of forensic evidence.
- Malicious code has its own path. Any isolated malware tied to the incident must be submitted to the DoD Cyber Crime Center (DC3), separate from the incident report itself.
- Subcontractors have a parallel duty. If you're a subcontractor, notifying your prime contractor runs alongside your DCISE reporting obligation, not instead of it.
None of this is new because of the pause, and none of it is paused. It's been sitting in these contracts since long before CMMC existed as a program.
Why These Two Deserve Attention Right Now
Both obligations are easy to overlook precisely because attention is focused on the certification news cycle.
- A missed affirmation date is a visible status change in SPRS, not a private oversight, and it can surface during a bid evaluation or a prime's vendor review
- An incident response plan that has never been tested against the 72-hour clock is the wrong thing to discover mid-incident
- Neither requirement is currently part of the CMMC Reform Task Force review, though that could shift. If the program moves toward machine-readable submissions down the line, the affirmation process itself could eventually change
- A pause in one requirement is a reasonable moment to confirm the requirements that were never paused are being tracked
A Short Operational Checklist
This is deliberately narrow. It isn't a full readiness plan; it's the handful of items tied specifically to these two clocks.
- Confirm who your current Affirming Official is, and that the role is assigned to someone still with the company
- Calendar your next affirmation date against your actual CMMC Status Date in SPRS
- Verify your DoD-approved medium assurance certificate is active and your team knows the current DCISE reporting process, not the retired DIBNet steps
- Walk your incident response plan through the 72-hour timeline on paper, including who submits the DCISE report and who owns evidence preservation
- Confirm your System Security Plan (SSP) names a specific, responsible party for DFARS 252.204-7012 reporting. Our guide on what should be in your SSP for CMMC Level 2 covers where this belongs in your documentation.
FAQs
Does the C3PAO pause affect the annual affirmation requirement?
No. The annual affirmation under 32 CFR 170.22 is a separate Program Rule requirement tied to your CMMC Status Date, not to whether new C3PAO certifications are currently being issued. If you hold a status of any kind, self-assessed or certified, the affirmation clock is still running.
Who is personally responsible if an affirmation is inaccurate?
The named Affirming Official, the senior representative who signs the affirmation in SPRS. The affirmation statement itself warns of both criminal exposure under 18 U.S.C. § 1001 and civil exposure under the False Claims Act, so this isn't a role to assign casually or leave unfilled after someone leaves the company.
Do we still need to report a cyber incident within 72 hours if our C3PAO assessment is on hold?
Yes. DFARS 252.204-7012 incident reporting is a contract clause, not a CMMC certification requirement, and it isn't affected by the pause. The 72-hour clock, the report submission through the DCISE portal, and the 90-day evidence preservation window all still apply.
Helpful ISI Links
Reference Resources