Back to Blog

CMMC's Third-Party Assessment Just Got Paused. Your Liability Did Not.

BomberJacket Networks
5 min read
CMMC's Third-Party Assessment Just Got Paused. Your Liability Did Not.

Watch the Short: CMMC's Third-Party Assessment Is Paused. Your Liability Isn't.

On July 13, 2026, the Department of War did three things at once. It suspended the transition to the CMMC Phase 2 rollout that had been scheduled to begin November 10, 2026. It paused the mandatory requirement for contractors to carry a C3PAO third-party assessment certification for Level 2, the requirement that was set to appear in new contracts this November. And it opened a 60-day, top-to-bottom review of the CMMC program.

If your compliance team read that and exhaled, this article is for them.

What the pause actually does

The headline is real: the mandatory requirement to carry third-party certification, set to appear in new contracts this November, is on hold. But the relief is far narrower than most people are treating it.

The suspension applies only to contracts awarded directly between the Department of War and the awarded contractor. It does not touch the flow-down requirements a prime contractor pushes to its subcontractors. If you are a sub, your obligations live in your prime's contract, and those did not move.

And every safeguarding and reporting clause already in your active contracts remains in full force:

  • 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
  • 252.240-7997 (the former 7020), NIST SP 800-171 DoD Assessment Requirements
  • 252.204-7021, Cybersecurity Maturity Model Certification Requirements
  • 252.204-7024, Notice on the Use of the Supplier Performance Risk System
  • 252.204-7025, Notice of CMMC Level Requirements

What you are still required to do

During the suspension, contractors must continue to meet their contract requirements, including the CMMC Level 1 and Level 2 self-assessments. The Supplier Performance Risk System remains open, and contractors are expected to submit their self-assessment results there.

Read that again. The third-party check is paused. The self-assessment is not. Which means the score you put into SPRS is now the standard the government holds you to, with nothing between your word and your contract.

The exposure nobody is talking about

A self-assessment score submitted to SPRS is not a formality. It is a representation to the federal government, and one the government has been actively enforcing.

The Department of Justice's Civil Cyber-Fraud Initiative treats an inaccurate cybersecurity attestation as a potential False Claims Act violation. This is civil liability, and it is expensive: treble damages plus penalties, and whistleblowers who bring a case can collect 15 to 30 percent of the recovery.

This is not theoretical.

  • In fiscal year 2025, cyber-related matters accounted for roughly 52 million dollars across nine settlements, and DOJ has reported that cybersecurity fraud resolutions have more than tripled two years running.
  • In September 2025, a research institution paid 875,000 dollars to resolve allegations that it submitted a false SPRS score.
  • In December 2025, a precision machining subcontractor settled for about 421,000 dollars. That case started as a whistleblower complaint filed by the company's own former quality manager.

An insider does not need the program to be in Phase 2 to file a complaint. They need a gap between what you claimed and what you actually did.

If you are confident, why aren't you already assessed?

Here is the uncomfortable question. If a contractor is certain its compliance is in order, a real assessment holds no fear. The organizations feeling relief right now are, more often than not, the ones that were never ready.

And the reason they believe they are fine is usually the same: they were told so by internal staff, a consultant, or an MSP that has never sat on the assessor's side of the table. Good intentions are not the same as knowing what an assessment actually examines. Bad advice feels comfortable right up until a DIBCAC assessment or a whistleblower turns it into a claim.

What to do now

A pause in the Phase 2 rollout is not permission to pause cybersecurity or contract compliance. Contractors should continue to:

  • Implement and maintain the applicable NIST SP 800-171 requirements
  • Keep system security plans, policies, evidence, and risk assessments current
  • Maintain accurate self-assessments and affirmations
  • Review prime contractor and subcontract flow-down requirements
  • Prepare for the possibility of a DIBCAC 252.240-7997 or 252.204-7012 assessment
  • Monitor the results of the Department of War's 60-day review

Where this is heading

Two paths are on the table. The administration may take the 60-day review into formal rulemaking to amend 32 CFR Part 170 and 48 CFR Parts 204, 212, 217, and 252. Federal rulemaking runs a minimum of six months and often eighteen, which would land near the end of this administration's term. Or the Level 2 assessment pause simply holds until the program is rebuilt or leadership changes.

Either way, the self-assessment obligation and the liability behind it are not going anywhere. Betting your company on a pause that could reverse with a single memo is not a compliance strategy.

The reasonable move

Before you stake a treble-damages lawsuit on your own math, have your self-assessment validated by an organization that runs CMMC assessments for a living. Independent validation tells you where you actually stand and lets you close the gap on your terms, without the cost and commitment of a full certification assessment.

BomberJacket Networks is Minnesota's C3PAO. We support organizations across the defense industrial base with independent validation and mock assessments, managed CMMC services, and, when your contract requires it, formal C3PAO certification assessments, matched to your business, your customers, and your prime's requirements.

The audit got paused. Your liability did not. Putting knowledge into action.

Need Help with CMMC Compliance?

BomberJacket Networks is Minnesota's only C3PAO-authorized MSP with 25 years of expertise. Get a free consultation to assess your CMMC compliance readiness.

Continue Reading