Edit Template

CMMC Phase II Suspension: What the Pause Didn’t Change

CMMC Is Paused. False Claims Act Exposure Isn’t.

On June 18, 2026, a defense contractor called LOGZONE agreed to pay $507,144 to settle a False Claims Act case. There was no breach and nobody stole anything. The government’s position was that LOGZONE performed Navy work while overstating how well it met the cybersecurity requirements written into its contracts, and that the distance between the claim and the reality was enough to trigger liability. What’s worth noting is that this case was brought forward by a government assessment.

Ironically, three weeks later the Department of War paused the exact program built to catch problems like LOGZONE’s.

On July 13, 2026, the Department suspended CMMC Phase II, the requirement that contractors handling controlled unclassified information pass a third-party assessment at Level 2 before an award. That milestone had been fixed for November 10, 2026. The reason given was logistical. Around 100,000 contractors would eventually need an assessment, and around 100 accredited assessors exist to perform them. The numbers did not reconcile, so the Department stopped the clock and opened a 60-day review focused on cost and on the burden the program was placing on smaller suppliers.

To a lot of contractors, that read like relief. Two months on, it is starting to read like a trap.

What has actually happened since July

The pause did not stay a policy statement. On September 3, 2026, the Office of the Assistant Secretary of War issued a class deviation, tracking number 2026-O0025, Revision 3, that wrote the suspension straight into contract terms. A class deviation carries weight a memo does not. It directs contracting officers to pull third-party assessment language out of new and existing contracts and substitute revised text, effective on issuance. The pause is now a binding acquisition instruction, and reversing a binding instruction is slower and more procedural than lifting a suspension.

The review that set all this in motion is still open. Industry filed comments with the CMMC Reform Task Force by the August 14 deadline. The Task Force owed recommendations to the Department CIO around mid-September, with a public report expected in late September or early October. The range of outcomes runs from Phase II returning on a new timeline to a longer stretch under self-assessment while the program is redesigned. Every contractor weighing whether to keep investing is doing it without the document that would settle the question.

The Department has been candid about why it stepped in. Officials pointed to a program that had grown expensive and slow, with the heaviest weight falling on the small and mid-sized suppliers the defense base cannot afford to lose. The review is weighing cheaper routes to the same security outcome, which is why the plausible endings run from a trimmed-down return of third-party assessment to a model that leans on self-assessment for a long stretch. None of those endings lightens the record a contractor has to keep today.

What keeps getting overlooked is that the class deviation paused C3PAO assessments. It left DIBCAC, the government’s own assessment arm, fully in place. The third party audits are on hold but government audits are not.

Security risks are still at the forefront. 

Take out third-party verification and one mechanism is left standing: the self-assessment. A contractor scores itself against the 110 controls in NIST SP 800-171, posts that score to the Supplier Performance Risk System, and a senior official signs an annual affirmation that the score is accurate. None of that changed on July 13. The affirmation is not a checkbox. A named senior official signs it, personally, every year, and that signature is the representation the government tests when it decides whether a claim was false.

The C3PAO assessment was the check that would have caught an inflated self-score before it hardened into a submitted claim. Remove the check and the inflated number stays on file with nothing between it and an enforcement action.  This is the same representation carrying more weight with less standing behind it.

Justice has signaled where that leads. In fiscal year 2025 it recovered $52 million across nine cybersecurity False Claims Act settlements, a run its own leadership described as a significant upward trajectory. This pattern is consistent. In September 2025, a Georgia Tech research affiliate paid $875,000 over allegations it fell short of the same NIST requirements on Air Force and DARPA work. The per-claim structure is what converts a paperwork gap into a balance-sheet event. Each false claim carries a civil penalty between $14,308 and $28,619, with damages trebled on top. Ten invoices tied to one bad certification clear six figures before the trebling begins.

What still applies, in plain terms

The underlying obligation did not move an inch. Handle covered defense information and you still implement the 110 controls in NIST SP 800-171. You still safeguard that information under DFARS 252.204-7012, report a cyber incident within 72 hours, and flow the clause down to your subcontractors. You still post an SPRS score and sign the affirmation behind it. And primes do not wait on the Department. A prime can demand certification before it shares CUI with you, pause or no pause.

Some contractors have taken the pause as a stop sign. Trade coverage has captured contractors saying openly that they will not spend another dollar on compliance until the rules are settled. That is a fair reading of the certification timeline. It is a dangerous reading of the enforcement one.

What still applies after the CMMC Phase 2 Pause

The discipline the pause rewards

The contractors who come out of this ahead treat the pause as time, not as an exit. The work that holds its value under every outcome is the work that was always the point. A self-assessment score you can defend against evidence, one control at a time. Documentation clean enough to hold up in front of a government reviewer who arrives with no C3PAO in the room.

That is a records problem before it is a technology problem. A score is only as strong as the artifacts under it, and an affirmation is only as safe as the trail that supports it. How you capture, correct, and defend your own records is what stands up when someone with subpoena authority reads them back to you.

This is the discipline AutoTime is built on. The platform runs on CMMC-aligned architecture and the same documentation-first rigor that DCAA timekeeping has demanded for 30 years, because the organizations that keep defensible records do not lose sleep over the audit, whoever sends it. 

Contact

Copyright 2026 AutoTime Solutions. All rights reserved.