Obligations · 2026-08-15

What the CMMC Pause Does and Doesn't Change About Your Obligations

CMMC Phase II is suspended. DFARS 7012, SPRS scores, self-assessments, the annual affirmation, and False Claims Act exposure are not. Here is what still binds you.

Nicolas Cano · Founder, Valontirsecurity researcher with a background in vulnerability analysis2026-08-15

The suspension of CMMC Phase II changed one thing: for now, no DoD contract will require you to pass a third-party assessment as a condition of award. It changed nothing else. If your company handles controlled unclassified information (CUI), you are still bound by DFARS 252.204-7012 to implement all 110 requirements of NIST SP 800-171, still required by DFARS 252.204-7019 to keep a current self-assessment score in SPRS, still subject to CMMC Phase I self-assessment and annual affirmation requirements in new awards, and still exposed under the False Claims Act if what you post does not match what you run. This article separates the news from the obligations, so that whatever the review concludes, you know exactly what still binds you today.

What was suspended, and why

Status as of this writing (August 15, 2026; this section will be updated when the review reports). On July 13, 2026, the Department of War announced the immediate suspension of the transition to CMMC Phase II, which had been scheduled to take effect on November 10, 2026, along with pending and future CMMC implementation milestones across its solicitations and contracts. Phase II would have made a certification assessment by an authorized third-party assessment organization (C3PAO) a condition of award for contracts involving CUI. The stated rationale was cost: the Department's release said the program had created "prohibitive compliance costs and bureaucratic burdens," citing Small Business Administration reporting that compliance was pushing companies out of the defense industrial base. The Department CIO established a CMMC Reform Task Force to conduct a top-to-bottom review and deliver recommendations to the CIO within 60 days, informed by a public request for information. Sixty days from July 13 is September 11, 2026; a report in mid-September is the working expectation. The Department has said the review's outcome could range from a restructured assessment model to something else entirely, and has not committed to a result.

That paragraph is the news. Everything below it is the same on any outcome.

The Department's own release was careful about the boundary. It said all Phase I self-assessment requirements "remain firmly in place," that during the interim it "will enforce cybersecurity compliance with the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments," and, in its own words, that this action does not eliminate the requirement to protect federal data: contractors and subcontractors "remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012."

Read that as a plain statement of what a suspension is. CMMC is a verification program. It was built to check whether contractors had done what a separate, older set of rules already required. Suspending part of the verification does not suspend the rules being verified. Those rules are the substance of your obligations, and each one is still in force.

DFARS 252.204-7012: the requirement itself

This is the clause that puts NIST SP 800-171 in your contracts, and it has been there since 2017. If your contract involves covered defense information, 7012 requires you to provide "adequate security" on the systems that process, store, or transmit it, defined at minimum as implementing the security requirements of NIST SP 800-171. It also carries the cyber incident reporting obligation (72 hours to DoD, via the DIBNet portal) and the flow-down obligation to your own subcontractors.

Nothing in the July 13 action touched 7012. It is not a CMMC clause; it predates CMMC by years and would remain in your contracts if CMMC were cancelled tomorrow. Every one of the 110 requirements you must implement under 7012 is the same requirement CMMC Level 2 would have assessed. The work is identical. The only thing that moved is who checks it and when.

DFARS 252.204-7019 and 7020: the SPRS score

DFARS 252.204-7019 requires that, to be considered for award, you have a NIST SP 800-171 DoD Assessment score no more than three years old posted in SPRS. DFARS 252.204-7020 gives the government the right to conduct Medium and High assessments of your implementation, and prohibits you from awarding subcontracts involving CUI to subcontractors who lack a current score of their own.

Both clauses remain in force. The score is computed the same way it always was, from the DoD Assessment Methodology's weights (the arithmetic is covered in Your SPRS Score, Explained). And the score is a representation to the government, made by you, in a system of record. That was true before July 13 and it is true now. Under Phase II, a C3PAO would eventually have tested that representation. Under the suspension, the government tests it directly through DIBCAC assessments, and the Department of Justice tests it after the fact. The score has, if anything, more weight during the pause, because it is the primary evidence the government has about your posture.

CMMC Phase I: self-assessment and the annual affirmation

CMMC Phase I took effect on November 10, 2025, and the Department was explicit that it remains fully in place. Under Phase I, contracting officers may include CMMC Level 1 (Self) and Level 2 (Self) requirements in solicitations and contracts. For a contractor handling CUI, Level 2 (Self) means: a self-assessment against all 110 requirements of NIST SP 800-171 Rev 2, entered in SPRS, with results and any plan of action items reported; and an annual affirmation of continuing compliance by an Affirming Official, a named senior official at your company, entered in SPRS under 32 CFR 170.22.

The affirmation deserves particular attention during the pause. It is a personal attestation, by a named individual, that your organization "has implemented and will maintain implementation of" every applicable requirement for every system in scope. That attestation is the subject of its own article. The relevant point here is that the pause removed the third-party assessment that would have sat between your affirmation and the government. It did not remove the affirmation. Your senior official is now signing without an assessor's finding behind the signature, which means the evidence behind the signature is entirely your own.

The False Claims Act: enforcement continued through the pause

The False Claims Act (31 U.S.C. § 3729) makes it unlawful to knowingly submit false claims for payment to the federal government. A claim for payment on a contract that incorporates 7012, made while you know you have not implemented what 7012 requires, is the fact pattern the Department of Justice has pursued repeatedly since its Civil Cyber-Fraud Initiative launched in October 2021. Whistleblowers can bring these cases and share in the recovery. Damages are trebled.

Nothing in the July 13 action affects any of that. FCA liability attaches to the representations you make and the claims you submit under existing DFARS clauses. It does not depend on CMMC, and the cases that established the pattern all predate any CMMC clause in a contract.

The most recent settlement makes the point concretely, and it involves a company much closer in size to a small supplier than to a prime. On June 18, 2026, less than a month before the pause, DOJ announced that LOGZONE Inc., a Huntsville, Alabama logistics contractor, agreed to pay $507,144 to resolve allegations that it knowingly submitted claims for payment on two Navy contracts while not in compliance with the contracts' cybersecurity requirements. Per the DOJ release, the government alleged that from May 2021 to March 2025 the company had failed to implement certain NIST SP 800-171 controls, including ones whose absence could lead to significant exploitation of the system or exfiltration of sensitive defense information; the deficiencies were identified when the Defense Contract Management Agency assessed the company's implementation and scored it −170. The settlement agreement, published by DOJ, adds the detail that the company had posted a self-assessment score of 110 in SPRS in October 2021, and that the −170 came from a DIBCAC Medium Assessment completed in February 2024. Total payments under the two contracts through March 2025 were about $682,000; the settlement recovered roughly three-quarters of that. The claims resolved are allegations only, and there has been no determination of liability.

Notice what the case did not need. It did not need CMMC. It did not need a C3PAO. It needed a 7012 clause, a posted SPRS score, a government assessment that contradicted it, and invoices submitted in between. Every one of those mechanisms is fully operational during the pause. If a small contractor is looking for the risk the suspension actually changed, this is not it.

Why the pause creates no relief from any of these

It helps to name the reasoning directly, because the headlines invite the wrong conclusion.

The obligation and the verification are different things. 7012 says implement 800-171. CMMC Level 2 certification was a mechanism to confirm you had. The Department suspended a mechanism. The instruction stands, and the Department said so in the release announcing the suspension.

The government kept the verification tools it already had. DIBCAC Medium and High assessments under 7020 continue. Self-assessment scores in SPRS continue and remain government-reviewable. The Department's release said explicitly it will enforce the standard "through self-assessments and select government-led assessments." The LOGZONE case is what a government-led assessment does to a posted score that cannot be substantiated.

Your primes did not change their flow-downs. Under 7020, a prime cannot award you a subcontract involving CUI without confirming your current score. Prime questionnaires and portal attestations asking for your SPRS score, your SSP status, and your affirmation date are unaffected, and many primes had already written 800-171 compliance into supplier terms independent of any government deadline.

FCA exposure never ran through CMMC. It runs through the claims you submit and the representations you make in SPRS. Those are the same today as they were on July 12.

The affirmation still carries a name. Whatever the task force recommends, 32 CFR 170.22 is a published rule, and the Phase I requirements that invoke it were expressly kept in place.

What to actually do during the review

The useful response to the pause is not to wait for September. It is to treat the pause as time to make the representations you have already made true and defensible.

  1. Reconcile your posted SPRS score with reality. If your score was set once and never revisited, recompute it from honest requirement statuses using the official weights. A score that has drifted from your actual implementation is the exact fact pattern in the LOGZONE settlement, and correcting it before a DIBCAC assessment or a prime's inquiry is a very different position from correcting it after.
  2. Confirm your SSP describes your current system, not the one you had when it was written. Requirement 3.12.4 requires it to be periodically updated, and it is the document any assessment starts from.
  3. Put real dates and owners on the POA&M. Under 7019 the projected completion date is posted next to your score in SPRS, and under 32 CFR 170.21 the Level 2 POA&M rules (which items are eligible, the 180-day closeout) still govern Phase I self-assessments.
  4. Prepare the affirmation as if it will be tested, because it can be. Every requirement marked implemented should have current evidence behind it before your Affirming Official signs.
  5. Ignore the vendor noise in both directions. Anyone telling you the pause means you can stop, and anyone telling you it changes nothing about the eventual assessment model, is guessing. What is knowable is the list above, and it is not affected by the review's outcome.

This is precisely the work Valontir was built to make continuous rather than episodic: every 800-171 requirement tracked against its 800-171A objectives, evidence stored with timestamps, the SPRS score computed from the official weights as statuses change, and the SSP and POA&M generated from that living record, so the number in SPRS and the affirmation above it describe the company you actually run.

FAQ

Is NIST SP 800-171 still required if CMMC is paused? Yes. NIST SP 800-171 is required by DFARS 252.204-7012, which has been in DoD contracts since 2017 and is unaffected by the CMMC suspension. The Department's July 13, 2026 release stated that contractors remain contractually obligated to safeguard covered defense information under 7012.

Do I still need an SPRS score? Yes. DFARS 252.204-7019 still requires a current NIST SP 800-171 DoD Assessment score, no more than three years old, in SPRS to be considered for award. Nothing in the pause changed that clause.

Is the annual affirmation still required? Yes, under CMMC Phase I, which the Department expressly kept in place. Level 2 (Self) requirements in contracts include a self-assessment in SPRS and an annual affirmation of continuing compliance by an Affirming Official under 32 CFR 170.22.

Can I still be assessed by the government during the pause? Yes. DFARS 252.204-7020 gives the government the right to conduct Medium and High assessments, and the Department said it will enforce the standard through self-assessments and select government-led assessments during the review.

Does the pause reduce False Claims Act risk? No. FCA liability attaches to claims for payment and representations made under existing DFARS clauses, not to CMMC. DOJ announced a NIST SP 800-171 cybersecurity FCA settlement with a small defense contractor on June 18, 2026, weeks before the pause.

When will we know the outcome of the review? The task force was directed to report to the Department CIO within 60 days of July 13, 2026. This article will be updated when the outcome is announced. Nothing in the obligations described above depends on it.


Valontir is a compliance workspace for small defense contractors: every 800-171 requirement, every piece of evidence, and your live SPRS score in one place, so your annual affirmation has evidence behind it. Book a demo or request access.

Sources: Department of War release, July 13, 2026: Department of War Suspends CMMC Phase II Requirements · DFARS 252.204-7012 · DFARS 252.204-7019 · DFARS 252.204-7020 · 32 CFR Part 170 · 31 U.S.C. § 3729 (False Claims Act) · DOJ: LOGZONE Inc. settlement (June 18, 2026) · LOGZONE settlement agreement (DOJ) · NIST SP 800-171 DoD Assessment Methodology, v1.2.1 · SBA statement, July 13, 2026

Put evidence behind your signature.

Valontir keeps your requirements, evidence, and score in one place, ready whenever a prime asks. We’re onboarding early customers deliberately.