Table of Contents
When the Department of War paused CMMC Phase 2 in July, plenty of contractors read it as a reason to ease off. That reading has it backwards. The pause lifted the one outside check that could catch a wrong SPRS score and left every other requirement in place, so the number you report yourself is now the main thing the government judges you on.
TestPros is an independent cybersecurity assessment firm, and in our NIST 800-171 readiness work the gap between a contractor’s self-reported score and its real control posture is the finding we see most often.
Is CMMC Cancelled, or Just Paused?
No. It is paused, not cancelled. On July 13, 2026, the Department of War (formerly the Department of Defense) used a policy memo to suspend Phase 2, the third-party assessment milestone, and stood up a CMMC Reform Task Force to review the program. A memo can be revised as easily as it was issued, and however that review lands, it changes who verifies your compliance while the requirements underneath stay in force. Phase 1 self-assessments, the DFARS 252.204-7012 safeguarding clause, and full NIST SP 800-171 implementation all still apply.
What You Still Owe While the Audit Is Paused
One thing moved. Everything else held. The third-party certification step is on hold, while every self-driven obligation underneath it, from the safeguarding duty to the score you post, stays active and enforceable. Here is the split.
| Requirement | Status after the July 2026 pause | What it means for you |
|---|---|---|
| Third-party C3PAO assessment (Phase 2) | Paused | Certification by an accredited assessor is on hold and is not currently a condition of award. |
| CMMC Phase 1 self-assessment | Still required | If your contract calls for a Level 1 or Level 2 self-assessment, you must still complete it. |
| SPRS score posting | Still required | You must still calculate and post a current NIST 800-171 self-assessment score. |
| DFARS 252.204-7012 safeguarding | Still in force | The contractual duty to safeguard covered defense information is unchanged. |
| NIST SP 800-171 implementation | Still the baseline | All 110 requirements remain the standard your score is measured against. |
| Annual affirmation of compliance | Still required | A senior official still affirms the accuracy of what your company reported. |
The government took away the outside check and kept everything it was checking for. Your obligations are the same as they were, and now they rest almost entirely on a number you calculate and report yourself.
Why a Paused Audit Makes Your SPRS Score Riskier
With the third-party assessment on hold, your self-reported SPRS score carries the full weight of your compliance claim, and nobody outside your company is checking it. Most contractors read that as breathing room. In practice it cuts the other way, because the Department paused the exact step built to catch inflated self-scores, and inflated self-scores are what the Justice Department has been going after.
And if reform scales third-party audits back for most contractors, or removes them entirely, your risk does not drop. It moves onto one number you report yourself, with no assessor behind it, and that number is exactly what a False Claims Act case turns on. The less anyone else checks your score, the more it is the one thing you are accountable for.
The reason CMMC called for an outside assessor in the first place was a pattern the government kept finding: when it examined contractor environments, real implementation fell well short of the scores companies had posted. One 2026 settlement shows how wide that gap can run.
That contractor agreed to pay $507,144 to resolve the Justice Department’s False Claims Act allegations, including $253,572 in restitution. The case came down to the distance between the score the company certified and the controls it had actually put in place. While the pause leaves self-attestation as the only gate, that distance is your exposure.
What Happens When a Self-Assessed Score Doesn’t Hold Up?
An inaccurate SPRS score can become a False Claims Act case. Every payment claim you submit against a contract that requires NIST 800-171 carries an implied certification that you meet it. The Department’s Civil Cyber-Fraud Initiative has spent the last several years treating a knowingly inflated score as fraud, and it does not need a breach to act. A government audit or a whistleblower is enough.
None of this hinges on Phase 2, a C3PAO, or any certification date. It comes down to one question: was the score you posted accurate? That question was live before the pause and it is live now. If your affirmed score counts controls that are planned rather than actually in place, the pause does not help you. Every day it runs, that unverified number sits on the record with your name on it. This is why it helps to understand how CMMC and NIST 800-171 fit together: the certification wrapper can change, but 800-171 is the standard underneath both, and it is not going anywhere.
The Real Deadline Didn’t Move
A lot of teams anchored to November 10. That date is on hold, but the one that actually matters never had a date on it. Your SPRS affirmation is a legal statement the day you post it, and it stays that way for as long as the government could review it, pause or no pause. Teams that treat the pause as a reason to stand down are betting that no government review and no insider finds the gap first. Teams that use it to get their score right remove that exposure and walk into any future CMMC readiness requirement on solid ground. The certification timeline may keep moving. Your reported score is already on the record, and that is the piece worth getting right now.
How to Make Your SPRS Score Defensible Now
Making that number true is the one thing you control and the one thing the government is measuring. Three moves matter most.
Validate your SPRS score independently. Have an outside assessor recalculate your score against all 110 requirements and compare it to what you posted. An independent NIST 800-171 assessment is the fastest way to find out whether your affirmed number would survive a government review, before a government reviewer or a whistleblower finds the gap for you. TestPros does not sell scanning software, so the number you get back is an honest read, with nothing to upsell off the back of it.
Close the real gaps, not the paperwork ones. A gap assessment against all 110 controls shows which ones carry the most scoring weight and the most breach risk, so you fix those first and treat a plan of action as a schedule with dates, not a placeholder. A control marked “planned” for three years is the profile these enforcement cases keep describing.
Keep your documentation current. Your system security plan and affirmation should reflect the environment as it is today, not as it was when you first stood the program up. If the environment changed and the score did not, that mismatch is the liability.
None of this is wasted effort under any outcome reform can reach. Whether Phase 2 comes back on a revised timeline, in a revised form, or as a scaled-back self-attestation model, the work still gets measured against the NIST 800-171 compliance requirements. That is what makes an independent compliance assessment the safe move either way.
Make your SPRS score defensible
Find out whether your SPRS score would hold up, while you still have room to fix it.
Whatever CMMC reform decides, and however far it scales back third-party audits, your score is still measured against NIST 800-171, and it is still the number the government relies on. TestPros runs an independent assessment against all 110 requirements and tells you where your real number lands before a government review does.
Request a NIST 800-171 readiness assessmentFrequently Asked Questions
Is CMMC cancelled?
No. CMMC is suspended at Phase 2, not cancelled. On July 13, 2026, the Department of War paused the third-party assessment milestone and stood up a Reform Task Force to review the program. Phase 1 self-assessments, DFARS 252.204-7012, and NIST SP 800-171 all remain in force. Because the pause came through a memo rather than a rule change, it can be reversed the same way, so the prudent read is a pause of the certification step, not a repeal of the underlying security requirement.
Do I still have to meet NIST 800-171 during the pause?
Yes. NIST SP 800-171 remains the contractual baseline throughout the pause. If your contract includes DFARS 252.204-7012, you are still required to implement the standard’s 110 requirements, calculate a self-assessment score, and post it to the Supplier Performance Risk System. The Phase 2 suspension changed who verifies your compliance, not whether you owe it. Contractors that keep implementing during the review enter whatever program follows without losing the value of that work, exactly as happened when CMMC 1.0 was reworked into 2.0.
Can I be sued over an inaccurate SPRS score even if there was no breach?
Yes. Under the Justice Department’s Civil Cyber-Fraud Initiative, a knowingly inflated SPRS score can create False Claims Act liability with no data breach involved. Enforcement turns on the gap between the score you certified and the controls you actually implemented. In one June 2026 settlement, a contractor that had posted a perfect self-assessed score of 110 was scored -170 by government assessors and paid $507,144 to resolve the case. An independent validation of your score before you rely on it is the most direct way to manage that exposure.
Primary source: “Alabama Defense Contractor Agrees to Pay $507,144 to Resolve False Claims Act Liability Relating to Cybersecurity Violations,” U.S. Department of Justice, Office of Public Affairs, June 18, 2026. Backs the −170 assessment score, the −203 to 110 range, the $507,144 settlement, and the quoted statement (LOGZONE Inc. of Huntsville, Alabama).
Additional sources:
- CMMC Phase 2 suspension and Reform Task Force: Department of War CMMC program.
- The 110 requirements and CUI baseline: NIST SP 800-171, NIST Computer Security Resource Center. DFARS 252.204-7012 currently operationalizes Revision 2, with Revision 3 finalized.


