The CMMC Pause Is Not a Pass: The Legal Risk of Lying on Your Self-Assessment
CMMC Phase 2 is paused. Your NIST 800-171 obligations are not. Contractors who use this window to inflate their SPRS scores or ignore their security posture are taking on False Claims Act exposure that makes the cost of a C3PAO assessment look small.
The DoD suspended CMMC Phase 2 on July 13, 2026. Within hours, some defense contractors were privately asking whether this meant they could stop worrying about cybersecurity compliance. Some were already behind on their NIST 800-171 implementation. The pause felt like relief.
It is not relief. It is a delayed reckoning - and for contractors who use the pause as an excuse to inflate their SPRS scores or ignore their compliance posture, the reckoning will be considerably more expensive than the assessment they were trying to avoid.
What the Pause Actually Suspended
The Phase 2 suspension is narrow. It paused one specific thing: the requirement for mandatory C3PAO third-party assessments, which were scheduled to begin appearing in contracts after November 10, 2026.
What it did not suspend:
- DFARS 252.204-7012 - the clause in your contract requiring compliance with NIST SP 800-171. Still there. Still enforceable.
- NIST SP 800-171 obligations - the 110 practices you agreed to implement when you accepted contracts with that clause. Still required.
- SPRS score submission - you are still required to submit an accurate self-assessment score to the Supplier Performance Risk System.
- Phase 1 self-assessments - CMMC Level 1 and the Level 2 self-assessment track remain fully in effect.
- Annual affirmation - senior officials must continue to affirm compliance annually.
The assessment was paused. The requirement was not. If you handle CUI and you have DFARS 252.204-7012 in your contracts, your obligation to implement NIST SP 800-171 is unchanged. The only thing that changed is how that implementation gets verified.
The False Claims Act Is Not Paused
Here is the part that some contractors are not taking seriously enough.
The Department of Justice has been actively pursuing False Claims Act cases against defense contractors who submitted inflated SPRS scores - claiming compliance levels they had not actually achieved. These are not theoretical cases. They are settled, with dollar amounts attached, and they are accelerating.
MORSECORP Inc. - $4.6 Million Settlement (April 2025)
Submitted a SPRS score of 104 out of 110 in January 2021. A third-party gap analysis 18 months later found the actual score was negative 142. The gap between claimed and actual compliance was 246 points. DoJ characterized this as a knowing false claim under the False Claims Act.
LOGZONE Inc. - $507,144 Settlement (June 2026)
Failed to implement required NIST SP 800-171 controls on two Navy contracts from 2021 to 2025. A Defense Contract Management Agency assessment put their actual SPRS score at negative 170. Settled one month before the Phase 2 pause - which means DoJ enforcement continued even as the program was under review.
University Research Institution - $875,000 Settlement (September 2025)
Submitted a false SPRS score and failed to install anti-malware tools on systems in a research lab handling CUI. Research institutions handling defense contracts are not exempt from NIST 800-171 obligations or FCA exposure.
In FY2025 alone, DoJ cybersecurity fraud recoveries exceeded $52 million across nine cases. Five of those nine cases were initiated by whistleblowers - meaning they started with someone inside the organization, or close to it, who filed a qui tam complaint.
The Whistleblower Risk Is Real
Under the False Claims Act, whistleblowers who report fraud can receive 15 to 30 percent of the government's recovery. In a $4.6 million settlement, that is up to $1.38 million for the person who filed the complaint.
Think about who in your organization knows the gap between what your SPRS score says and what your actual security posture is. Your IT administrator knows. Your MSP knows. Any consultant who has done a gap assessment knows. A former employee who was involved in the self-assessment knows.
The FCA qui tam mechanism exists precisely to incentivize people with insider knowledge to report fraud. It works. Five of the nine FY2025 cybersecurity cases came from whistleblowers. The pause does not reduce this risk - if anything, it creates a longer window during which inflated scores remain in the system without being corrected by an independent C3PAO assessment.
The SPRS score is a legal representation. When a senior official submits or affirms an SPRS score, they are making a representation to the federal government about the organization's cybersecurity posture. A materially false representation, made knowingly, is a False Claims Act violation. The pause does not change this.
What Prime Contractors Will Ask For
Even if the federal government's enforcement mechanisms feel distant, your prime contractors are a more immediate concern. Primes have their own CMMC obligations, and those obligations flow down. When you are a subcontractor handling CUI on a prime's contract, the prime has a vested interest in your cybersecurity posture - because if you have a breach, it is their contract and their reputation on the line.
Expect primes to increasingly ask subcontractors for:
- Their current SPRS score and date of last assessment
- A copy of their SSP or at minimum confirmation that one exists
- Evidence of specific controls - MFA, endpoint protection, backup and recovery
- Contractual representations about NIST 800-171 compliance
A prime who discovers that a sub materially misrepresented their security posture has both a legal obligation to report it and a strong business incentive to terminate the relationship. The pause does not change what primes can and will ask for.
When Phase 2 Resumes, Preparation Compounds
The CMMC Reform Task Force report is due around mid-September 2026. Whatever comes out of that review - revised timelines, modified assessment tracks, tiered requirements by contractor size - Phase 2 will resume in some form. The DoD has been consistent: cybersecurity requirements for CUI-handling contractors are not optional.
Organizations that use the pause to get their documentation in order, close gaps in their technical controls, and build the evidence packages assessors will eventually review will enter Phase 2 - whenever it resumes - in a strong position.
Organizations that treat the pause as a reprieve from compliance will face exactly the same gaps they have today, plus additional time elapsed during which they remained non-compliant and submitted SPRS scores that may not have been accurate.
What to Do Right Now
If you handle CUI and have DFARS 252.204-7012 in your contracts, the productive use of the Phase 2 pause is:
- Conduct or update your gap assessment - know your actual NIST 800-171 implementation score, not your optimistic one
- Correct your SPRS score if it does not accurately reflect your current posture
- Build or update your SSP - the master documentation document that describes how you implement each of the 110 practices
- Document your POA&M - gaps with realistic remediation timelines and owners
- Close the highest-risk gaps first - MFA, audit logging, encryption - these are the practices that produce the most assessment failures and the most obvious evidence of non-compliance
- Get your domain policies in place - written policies for each domain create the governance layer that technical controls sit under
Use the Pause to Get Your Documentation Right
The CMMC Level 2 Certification Kit includes the SSP (all 110 practices), POA&M, and all 12 domain policies. The right time to get compliant is before the assessors come back - not after.
View the Certification Kit - $299