What the Suspension Removed
The November 10 date was never a universal certification deadline. It marked the beginning of the next acquisition phase, during which additional solicitations and contracts may require a Level 2 C3PAO or Level 3 DIBCAC assessment. That transition is now suspended.
The operative instructions are in the memorandum implementing the suspension, signed by Kirsten A. Davies, the Department of War Chief Information Officer. Program Managers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self), and may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). Active solicitations carrying those requirements are to be amended, and contracting officers are directed to remove them from existing contracts by modification prior to the exercise of the next option period or during the next scheduled administrative modification. No waivers will be granted during the review.
What Remains in Force
Contractors hold one of two kinds of SPRS records, and sometimes both. The older record is the Basic NIST SP 800-171 DoD Assessment score, submitted under DFARS 252.204-7019 and DFARS 252.204-7020. The newer record is CMMC Level 2 (Self), which applies when a contract requires that status and carries its own scoping rules, a self-assessment every three years, an annual affirmation by a senior official, and six-year retention of the supporting evidence. The two records measure related requirements, and one does not substitute for the other.
The suspension revised neither record. An inaccurate Basic Assessment score remains inaccurate. An unsupported Level 2 self-assessment and affirmation remain unsupported. Chief Information Officer Davies made the point directly at the Pentagon media roundtable announcing the suspension, telling reporters that the action does not eliminate the legal requirement for industry partners to protect federal data.
What the Enforcement Record Shows
Unverified self-reported scores have a documented reliability problem, and the numbers are a matter of public record. The claims resolved in the matters below are allegations, and the settlements are not determinations of liability.
The gap between reported and assessed. The Government alleged that MORSECORP Inc. submitted a score of 104 in January 2021 and that a third-party consultant found the actual score was negative 142 in July 2022. LOGZONE Inc. is alleged to have reported a perfect 110 in October 2021 against a Defense Contract Management Agency result of negative 170.
The distance is 246 points and 280 points. In neither matter did the company identify its own gap. A consultant identified one and the Government identified the other.
Enforcement did not pause with the program. False Claims Act settlements and judgments reached $6.8 billion in the fiscal year ending September 30, 2025, including over $52 million across nine cybersecurity fraud settlements, a category the Department of Justice reports has more than tripled in each of the past two years. The exposure in these matters arises from billing the Government against requirements the company had not met, and the reported score is evidence of what the company knew when it billed. A truthful low score does not cure the underlying noncompliance, and declining to examine the score offers no protection, because the statute reaches deliberate ignorance and reckless disregard.
Company size is not a mitigating factor. In December 2025, an Illinois precision machining company paid $421,234 to resolve allegations that it failed to provide adequate cybersecurity for technical drawings supplied to defense prime contractors, in a case brought by a former quality control manager.
The Suspension Removed the Verification Mechanism
The C3PAO assessment was the independent verification gate at the end of the compliance process. The approaching gate prompted corrective action: contractors engaged outside professionals, corrected the scope, reviewed System Security Plans, remediated deficient controls, and assembled evidence because an independent party would eventually test the result. The score was typically fixed before it was tested.
Without a scheduled examination, that correction does not occur on its own. In most small and mid-sized contractors, the same people who built and administer the environment also write the documentation and score the self-assessment, and a senior official affirms the result relying on both. The suspension therefore does not reduce attestation risk. It removes the process that was reducing it, and it leaves the affirmation in place.
The Next Affirmation Is the Decision Point
Every contractor with a Level 2 self-assessment obligation will submit an affirmation again. The question before that signature is whether the number in SPRS describes the environment that exists and whether the company can produce evidence supporting it. If the answer is yes, the affirmation is routine. If the answer is no or unknown, the affirmation renews an inaccurate representation with a current date. The suspension is the interval in which that question can be answered before the signature rather than after.
The one fixed date in the interim period. The CMMC Reform Task Force is collecting industry feedback through a public Request for Information, with responses due by 12 PM Eastern on August 14, 2026, and will deliver recommendations to the CIO within 60 days.
What the RFI asks. Contractors are asked to identify their most prohibitive cost drivers, the controls that deliver the most actual risk reduction and the least, how the Department might recognize existing commercial cybersecurity capabilities within a compliance framework, and how self-assessment could be streamlined. The questionnaire is available here.
Use of the Interim Period
The sequence is straightforward. Confirm which contracts and systems involve CUI. Correct the CMMC scope to match that answer. Perform the Level 2 self-assessment against NIST SP 800-171A rather than the requirements' summary language. Remediate the material deficiencies the assessment exposes. Retain objective evidence that the requirements operate in practice. Obtain an independent review that challenges it all. Submit the score and the management affirmation when both can be defended.
An independent consultant can challenge the scope, test the self-assessment results against NIST SP 800-171A, examine the evidence, and compare the documented posture to the operating environment. A consultant cannot issue a CMMC status or make the company's affirmation. The company corrects what the challenge exposes, and the authorized official submits the affirmation and remains responsible for it. The value of this work does not depend on the Reform Task Force's recommendations, because every model under discussion measures the contractor's actual environment against NIST SP 800-171.
Download the Full White Paper
The full paper covers the implementing memorandum and its directives, the distinction between a Basic NIST SP 800-171 DoD Assessment and a CMMC Level 2 (Self) record, a table comparing reported SPRS scores against the results of outside review, the published False Claims Act record and the statutory knowledge standard, the loss of the independent verification gate, prime contractor obligations during the suspension including the SPRS visibility constraint, and the 60-day review. Every claim is supported by a citation to the CIO memorandum, 32 CFR Part 170, the DFARS clauses, Department of Justice announcements, and the CMMC Request for Information.
The CMMC Decision, Second Edition
Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.
Read More →