The assessors left the room. The rules did not.
Bottom Line Up Front
- CMMC Phase II requirements are suspended. DFARS 252.204-7012 is not. The verification mechanism is under review. The security requirement is unchanged.
- A defensible program is not a certificate. It is the ability to demonstrate, with consistent documentation and operating evidence, that your organization protects CUI as represented.
- The False Claims Act never depended on CMMC. In June 2026, one contractor paid $507,144 over the gap between a self-reported SPRS score and what a government assessment found.
What Changed Under the CMMC Phase II Suspension
On July 13, 2026, the Department of War (DoW) announced the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II. The action was memorialized in a July 10 memorandum signed by DoW Chief Information Officer Kirsten Davies.
Phase II would have required Level 2 assessments by Certified Third-Party Assessment Organizations (C3PAOs) beginning November 10, 2026. That transition is off. Phase III and Phase IV milestones are held in abeyance until further notice. DoW established a CMMC Reform Task Force to deliver recommendations within 60 days and issued a public Request for Information seeking industry input on cost drivers and program burden.
During the suspension, contracting officers may include only CMMC Level 1 (Self) or Level 2 (Self) assessment requirements in contracts. They may not impose Level 2 C3PAO assessments or Level 3 DIBCAC assessments as contract requirements. Solicitations and contracts containing those requirements are to be amended or modified under DoW guidance.
The 60-day deadline does not mean the suspension ends on day 61. Current direction pauses milestones until further notice. DoW could extend the pause, restructure CMMC, or replace broad third-party certification with a risk-based model built on self-assessments and select government audits.
What Did Not Change: DFARS 7012 and NIST SP 800-171
DFARS 252.204-7012 remains in applicable contracts. Contractors must continue safeguarding covered defense information, providing adequate security, and reporting covered cyber incidents. NIST SP 800-171 Revision 2 remains the contractual security baseline for affected systems during the review.
Three separate obligations survive, and they come from three different places:
- SPRS score reporting flows from DFARS 252.204-7019 and 252.204-7020.
- The annual affirmation flows from the CMMC clause at DFARS 252.204-7021, which remains in force under Phase I.
- Flowdown to subcontractors continues wherever the underlying clauses apply.
Contractors handling only Federal Contract Information (FCI) also have to meet Level 1 self-assessment and annual affirmation requirements remain firmly in place.
DoW says it will continue enforcing NIST SP 800-171 through self-assessments and select government-led assessments. DIBCAC remains the department's primary NIST SP 800-171 assessment capability and conducts Medium and High assessments under the DoD Assessment Methodology.
The False Claims Act Is Unaffected
In June 2026, LOGZONE agreed to pay $507,144 to resolve cybersecurity-related allegations. The settlement agreement states that the company submitted an SPRS score of 110, a perfect result on a scale that runs from -203 to 110. A later DIBCAC Medium Assessment produced a score of -170.
The allegations were settled without an adjudication of liability. The case still demonstrates the risk plainly: report a score your environment and evidence cannot support, and the government has a mechanism to act on it. That mechanism never required CMMC to exist.
How to Prepare for a DIBCAC Medium or High Assessment
Document what you are going to do. Do it. Have evidence to prove you do it.
A defensible compliance program lets an assessor trace each claimed requirement from the SPRS score, through the System Security Plan (SSP), to implementation evidence in the operating environment.
Evidence typically includes:
- System configurations and inventories
- Access-control records
- Vulnerability scan results
- Tickets and change records
- Logs
- Policies and procedures
- Training records
- Incident-response exercise artifacts
- Interviews and technical demonstrations
The documentation must agree with the architecture and with actual practice. A polished SSP describing controls the organization has not implemented is not defensible, and it will produce a lower score.
Use NIST SP 800-171A Revision 2 and the DoD Assessment Methodology to run an evidence-based internal assessment. Mark an assessment objective satisfied only when adequate, current, attributable evidence supports it. Explicitly document your assumptions, inherited controls, service-provider responsibilities, enclave boundaries, and data flow.
Then recalculate the SPRS score from validated results. Accurately describe, prioritize, assign, and track POA&M items. Management should understand exactly what the score represents before submitting or reaffirming it.
Organizations seeking additional assurance may ask their contracting officer, program office, or DCMA contact whether a voluntary government-led NIST SP 800-171 assessment is available. DIBCAC controls selection and scheduling, so a request does not guarantee an assessment. Even when one is unavailable, preparing to the Medium or High Assessment standard tests whether your compliance position holds.
7 Steps Defense Contractors Should Take Now
- Keep remediation moving. Continue closing deficiencies in access control, multifactor authentication, logging, configuration management, vulnerability management, incident response, and CUI protection.
- Confirm the assessment boundary. Identify where CUI enters, resides, is processed, is transmitted, and exits. Include electronic and physical data. Document external connections, service providers, remote access, administrative systems, and subcontractor dependencies.
- Validate the SSP against the environment. Confirm that diagrams, inventories, data flows, control descriptions, and inherited-control statements are current. Remove aspirational language unsupported by implementation.
- Reperform the assessment using evidence. Test the NIST SP 800-171A objectives, retain supporting artifacts, and make results reproducible. Someone other than the original control owner should challenge the evidence and the scoring assumptions.
- Reconcile the SPRS score and POA&M. Correct unsupported conclusions before a government assessor discovers them. Coordinate material corrections or disclosures with qualified counsel and contracting professionals.
- Establish continuous compliance. Review controls periodically, preserve evidence, assess significant changes, monitor subcontractor obligations, and treat the annual affirmation as a formal management representation.
- Respond to the RFI. DoW is actively soliciting industry input on cost drivers and program design. The reformed program will be shaped by the contractors who show up during the review window.
Conclusion
DoW may leave CMMC Phase II suspended. It could narrow the program or replace it entirely.
Either way, the obligation is the same one it has been since 2017. Build a documented NIST SP 800-171 program that supports an accurate SPRS score and can withstand a DIBCAC Medium or High Assessment.
Frequently Asked Questions
Is CMMC cancelled? No. Phase II third-party assessment requirements are suspended pending a 60-day review. Phase I self-assessment and affirmation requirements remain in effect, and contracting officers may still include Level 1 (Self) and Level 2 (Self) requirements in contracts.
Do I still need to report an SPRS score? Yes. SPRS score reporting under DFARS 252.204-7019 and 252.204-7020 was not suspended. Contractors handling covered defense information must maintain a current, supportable self-assessment score.
Can I still face False Claims Act liability? Yes. FCA exposure arises from the accuracy of representations made to the government, not from CMMC. Recent enforcement has focused on gaps between self-reported SPRS scores and what government assessments find.
The RubinBrown Cyber Security Services and Technology Consulting teams help organizations identify risks, strengthen defenses, and build lasting cybersecurity resilience through proactive strategy, education, and technical expertise.
Preparing for a DIBCAC assessment or validating your SPRS score? Contact our Cyber Security Services team for a readiness review.
Published: 07/29/2026
Readers should not act upon information presented without individual professional consultation.
Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.