Insights / Federal

The CMMC Suspension Didn't Lower Your Risk. It Moved It.

← All insights

On July 13, 2026, the Department of War suspended CMMC Phase II — the third-party assessment piece that was supposed to start this November. Most of the reaction treats this as a break. I'd argue it's the opposite.

Here's what actually happened. The suspension removed a verification step. It didn't touch the obligation underneath it. NIST 800-171 is still the baseline. DFARS 252.204-7012 hasn't changed. SPRS scoring and your annual affirmation are still required. And nothing about this action touches DOJ's separate authority to pursue False Claims Act cases against contractors who misrepresent their cybersecurity posture. DoW can suspend its own assessment program. It can't suspend DOJ's.

What's gone is the independent check. Your obligation to be right about what you attest isn't.

For two years, a C3PAO assessment meant someone outside your organization had looked at your controls before the government relied on your score. That check is paused now.

Why this is a governance issue, not just a cyber one

Every SPRS filing is now a claim to the federal government that nobody outside your walls has verified. Based on how DOJ's Civil Cyber-Fraud Initiative cases have generally been built, the exposure tends to come less from missing controls and more from a gap between what got attested and what an audit would have found. Self-attestation without an outside check widens that gap's room to hide.

So if your read on this suspension is "we can slow down," what you're actually doing is holding onto that gap without the buffer that used to make it smaller.

What I'd be doing instead

  • Pull the evidence behind every control claim in your SPRS score, tied to what's actually running — not what a policy document says should be running.
  • Get clear on who owns the affirmation, and make sure there's a record of what they checked before they signed it.
  • Look hard at whether your CUI scope can shrink. Smaller footprint, easier to defend, easier to keep accurate.
  • Run your own internal testing against the 110 controls, because nobody's scheduling that visit for you anymore.

The compliance calendar just got longer. The liability window didn't move at all. If you sit on a board or in GC and you're looking at cyber risk this quarter, that's the signal: tighten review, don't ease off it.

This is my read on where things stand, not legal advice. FCA exposure is a question for counsel. Note added since publication: the suspension was subsequently confirmed to cover CMMC Phases 3 and 4 and all future milestones, not Phase II alone. The argument above holds — the underlying obligation survives regardless of scope — but the original post understated how broad the suspension was.

Next Step

Start with a working session.

Thirty minutes with the principal. Bring one AI deployment — in use or planned — and leave knowing whether its record would survive review.

Book a Call