CMMC · NIST SP 800-171 · DFARS 252.204-7012

You certified your cybersecurity to the DoD.
The False Claims Act assumes you meant it.

In July 2026 the DoD suspended CMMC Phase II — the mandatory third-party audit — after small-business cost concerns, and opened a reform review. Plenty of contractors read that as "CMMC doesn't matter yet." But your self-assessment obligation never paused: your SPRS score and annual affirmation are still binding representations to the government. If they overstate your real NIST 800-171 posture, that isn't a missed audit — it's potential False Claims Act liability. We tell you where you actually stand, before someone else does.

Grounded in NIST SP 800-171 (110 controls) DFARS 252.204-7012 / 7019 / 7020 SPRS scoring DOJ Civil Cyber-Fraud Initiative
What Changed — And What Didn't

Phase II was suspended. The obligation didn't move.

In July 2026 the DoD paused CMMC Phase II and stood up a reform task force — a real change, widely reported as cost relief for small business. It's easy to read that as "CMMC doesn't matter yet." That's the expensive misread. Contractors can even shape the reformed program through the reform RFI comment window (open until August 14, 2026). Here's the honest split.

Suspended · July 2026

What was paused

  • CMMC Phase II — the mandatory third-party (C3PAO) assessment that would have begun Nov 10, 2026 — is suspended, along with the later phases
  • A 60-day CMMC Reform Task Force is reviewing the whole program, with a report due to the DoD CIO around mid-September 2026
  • The driver was cost to small business — SBA analysis put third-party certification near $593,800 per firm and warned it was pushing companies out of the defense base
Still Fully Enforced

What never paused

  • DFARS 252.204-7012 — safeguard covered defense information and report cyber incidents within 72 hours
  • A current NIST SP 800-171 self-assessment score posted in SPRS (DFARS 7019/7020)
  • Annual affirmation that your score and posture are accurate — signed by a senior official
  • These arise outside the CMMC program, so the Phase II pause doesn't touch them — DoD has said the self-assessment obligation continues during the pause
  • False Claims Act liability for representations that overstate your security
This page is educational and reflects the compliance landscape generally. It is not legal advice, and it is not a certification. For legal determinations about your specific contracts, consult qualified counsel; for formal CMMC certification, engage an accredited C3PAO.
Why "Self-Attestation" Is The Trap

Self-assessment isn't lower stakes. It's higher personal stakes.

When a third party assesses you, they own the finding. When you self-attest, you own it — and the chain from a spreadsheet estimate to federal liability is short.

01

You self-assess

Someone scores your posture against the 110 NIST 800-171 controls — often optimistically, often without evidence behind each control.

02

The score goes in SPRS

That number becomes a representation to the DoD that primes and contracting officers rely on to award and keep work.

03

A senior official affirms it

An annual affirmation says the score and posture are accurate — a personal certification, not a checkbox.

04

Every invoice relies on it

If the score was materially wrong, each payment can be recast as a false claim — the theory behind DOJ's cyber-fraud cases.

The Real Exposure

This is a liability question, not a paperwork question.

The DOJ Civil Cyber-Fraud Initiative exists specifically to pursue contractors who misrepresent their cybersecurity. The mechanics are what make it serious.

⚖️

Treble damages

The False Claims Act allows recovery of up to three times the government's damages, plus a civil penalty attached to each individual claim. On a multi-year contract, that compounds fast.

🧑‍⚖️

Whistleblower (qui tam) suits

An employee, ex-employee, or competitor can file on the government's behalf and share in the recovery. Your own IT staff often know exactly which controls aren't real.

📉

Loss of contracts & standing

Beyond dollars: suspension, debarment, and a damaged SPRS record can quietly end your ability to win defense work — including as a subcontractor to primes who now screen their supply chain.

🏢

Prime-driven flow-down

Even if you're a small sub, primes are pushing 800-171 and SPRS requirements down their chain. A weak score can get you dropped long before any regulator gets involved.

Who This Is For

If "CUI" or "DFARS 7012" is in your contracts, this is you.

  • Prime contractors and any tier of subcontractor handling covered defense information
  • Manufacturers and machine shops in the defense industrial base
  • Engineering, R&D, and professional-services firms on DoD work
  • IT / MSP providers supporting defense contractors' environments
  • Companies that posted an SPRS score once and haven't revisited it
  • Firms told by a prime to "show us your 800-171 score" and unsure it holds up
How We Help

Find the gap between your score and your reality — first.

We don't certify you; a C3PAO does that. We make sure that when the assessment (or the affirmation, or the whistleblower) comes, there are no surprises.

STEP 01

800-171 gap analysis

We map your current posture against all 110 controls, flag the ones you're claiming without evidence, and separate quick wins from real projects.

STEP 02

SPRS score reality-check

We recompute what your honest self-assessment score should be and show the delta from what's posted — the exact gap that creates exposure.

STEP 03

POA&M + affirmation readiness

A prioritized plan of action & milestones and an evidence checklist, so your next affirmation is one you can actually defend.

Start With a Free Readiness Scan
FAQ

The questions defense contractors actually ask.

Not cancelled — suspended and under review. In July 2026 the DoD paused CMMC Phase II (the mandatory third-party assessment that would have begun Nov 10, 2026) and launched a 60-day reform review, driven largely by small-business cost. But the baseline obligations live outside the CMMC program: DFARS 252.204-7012, the 110 NIST 800-171 controls, 72-hour incident reporting, a current SPRS self-assessment score, and annual affirmations all remain in force. DoD has said the self-assessment obligation continues during the pause — so the requirement to protect CUI, and the liability for misstating your posture, haven't gone anywhere.

SPRS is the DoD's Supplier Performance Risk System. Under DFARS 252.204-7019/7020, contractors handling covered defense information must post a NIST 800-171 self-assessment score there. That score isn't internal paperwork — it's a representation the government and your primes rely on. If it overstates reality, it can support a False Claims Act claim.

Because you own the statement. In a self-assessment, there's no external assessor between your optimistic scoring and a federal representation. A senior official personally affirms it, and every subsequent invoice can be tied back to it. That's exactly the fact pattern DOJ's Civil Cyber-Fraud Initiative targets.

No — formal CMMC certification is performed by an accredited C3PAO, and we'd be wary of anyone claiming otherwise. We do the readiness and gap work that gets you prepared and reduces self-attestation risk. Our scan is a readiness check, not a certification, audit, or legal advice.

Yes. DFARS and 800-171 requirements flow down the supply chain, and primes are increasingly screening subs on their SPRS scores before awarding work. Small size doesn't remove the obligation — and it often means fewer internal resources to back up the score you posted.

A high-level readiness summary: where your 800-171 posture likely has gaps, whether your SPRS score looks defensible, and the highest-priority next steps — with an initial response within 24 hours. No sensitive documents required to start.

Before The Affirmation Comes Due

Know your real score before you sign your name to it.

Free readiness scan for defense contractors. No credit card. Initial response within 24 hours.

Readiness check · Not a certification or legal advice · No sensitive documents at first step