The Department of War suspended CMMC Phase 2 on July 13, 2026. But your obligation to protect sensitive data wasn’t suspended with it. If you wait for a mandate to force your hand, it’s going to cost you a lot more than fixing the gaps you already know about. These are the risks you’re facing in the CMMC program today.
Key Takeaways
- CMMC Phase 1 self-assessment, DFARS 252.204-7012, and annual SPRS affirmations remain mandatory even though Phase 2 is paused.
- Self-reported SPRS scores are often inflated, and that gap often doesn’t surface until someone else checks it.
- A single False Claims Act settlement costs far more than the security controls that would have prevented it.
Table of Contents
The Phase 2 Suspension Does Not Change Your Security Obligations
If you looked at the CMMC pause and thought, “Good, guess I dodged that one,” I’ve got bad news for you.
Your legal obligation to protect CUI and FCI has never depended on CMMC assessments.
That’s because of DFARS clause 252.204-7012 – which has required that contractors protect covered defense information since 2017- and NIST SP 800-171. Neither of those was suspended.
While Phase 2 was suspended for at least 60 days (while the CMMC Reform Task Force reviews the certification program), you are still required to:
- Self-assess against NIST SP 800-171
- Submit your score to SPRS
- Sign an annual affirmation that your SPRS score is accurate.
Failure to meet standards, and you’re looking at a costly cyber incident – or worse – a False Claims Act case. More on that below.
Overconfidence is Almost as Risky as Skipping Layered Cybersecurity
Well-meaning business leaders often feel more confident about their security than the facts support.
Case in point, we took on a new client who thought he was in decent shape. He believed his SPRS score was around 80, but when we got into the environment, it was closer to 60.
I see this frequently with defense contractors. Overconfidence puts your business at risk just as fast as neglect does. Lost contracts, exposed CUI – take your pick.
What a False Claims Act Settlement Can Cost You
In June 2026, the Department of Justice reached a $507,144 settlement with an Alabama defense contractor that had certified NIST SP 800-171 controls on two Navy contracts that it had not actually implemented.
In 2025, Raytheon and Nightwing Group paid $8.4 million to resolve similar allegations tied to 29 Department of War contracts.
The False Claims Act does not require proof that you meant to lie. If you make a compliance claim without checking whether it’s true, that can be enough to prosecute you.
Add up the legal fees, the DoW investigation, and the contracts you lose while under review, and the security controls you skipped start looking cheap by comparison.
How to Move Forward during the Phase 2 Pause
The suspension bought contractors time on third-party assessments. It didn’t buy you an exemption from NIST SP 800-171 or DFARS. Keep your cybersecurity foundation solid, and you won’t be scrambling if the assessments resume. Nor will you have to write a check to the DOJ.
The bottom line is this, staying eligible for your next contract protects you whether Phase 2 comes back next month or next year. That means protecting your data now.




