large windows at top of building

3 August 202610 minute read

Department of War suspends CMMC Phase 2 assessment requirements: Top points for defense contractors

On July 13, 2026, the United States Department of War (DoW, formerly the Department of Defense) announced the immediate suspension of the implementation of Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) Program, which had been scheduled to take effect on November 10, 2026.

The suspension pauses the mandatory third-party and government-led certification assessment mechanisms for CMMC Level 2 and Level 3, but it does not relieve defense contractors of their underlying cybersecurity obligations. Those obligations include, inter alia, self-assessing and attesting to compliance with applicable cybersecurity controls, such as the basic security requirements outlined in Federal Acquisition Regulation (FAR) 52.204-21 and the 110 cybersecurity controls in National Institute of Standards and Technology (NIST) SP 800-171. These obligations remain in effect and may present False Claims Act (FCA) exposure.

This alert provides background on the CMMC Program and the related cybersecurity requirements; discusses potential FCA exposure associated with cybersecurity certifications, self-assessments, and affirmations; and outlines the practical implications of the recent CMMC suspension for defense contractors and subcontractors.

Background

CMMC is a tiered cybersecurity certification framework, codified at 32 C.F.R. Part 170 and implemented contractually through Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7021, that applies to DoW contractors and subcontractors that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).

The framework establishes three tiers of required cybersecurity maturity:

  • Level 1: Applies to contractors handling FCI and is aligned with the basic safeguarding requirements of FAR 52.204-21. It requires an annual self-assessment and affirmation, with no Plans of Action and Milestones (POA&Ms) permitted.

  • Level 2: Applies to contractors handling CUI and is aligned with DFARS 252.204-7012 and the 110 security controls in NIST SP 800-171. Depending on the sensitivity of the information involved, Level 2 may be satisfied through self-assessment or, prior to the suspension discussed below, through third-party certification by a CMMC Third-Party Assessor Organization (C3PAO).

  • Level 3: Applies to the most sensitive programs and requires assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

After years of development and revisions to the model, the CMMC final rule became effective on November 10, 2025, beginning a three-year phased implementation.

Phase 1, which took effect on that date, requires Level 1 and Level 2 self-assessments and corresponding reporting in the Supplier Performance Risk System (SPRS). These requirements generally reflected preexisting FAR and DFARS cybersecurity obligations prior to the finalization of the CMMC framework, including FAR 52.204-21 (similar to Level 1), and DFARS 252.204-7012 (similar to Level 2).

Phase 2 of the CMMC implementation, which had been scheduled to take effect on November 10, 2026, would have added mandatory third-party C3PAO certification assessments for applicable Level 2 contracts and DIBCAC assessments for Level 3. It is this Phase 2 transition – the addition of mandatory independent or government-led certification for Level 2 and Level 3 – that the DoW has since suspended. Contractors remain subject to the underlying obligations that existed prior to the implementation of CMMC.

Affirmation requirement

A central feature of the CMMC Program, and one unaffected by the Phase 2 suspension, is the self-assessment and associated affirmation requirement.

Under the CMMC framework, as set out in 32 C.F.R. § 170.22, an “affirming official” – defined as the senior-level representative within an Organization Seeking Assessment (OSA) who is responsible for the OSA’s compliance with CMMC Program requirements and who has the authority to affirm continuing compliance – must submit an affirmation electronically in SPRS attesting that the organization “has implemented and will maintain implementation of all applicable CMMC security requirements.”

The affirmation must include the affirming official’s name, title, and contact information, and it must be submitted at each of the following points:

  • Upon achievement of conditional CMMC status, if applicable
  • Upon achievement of the final CMMC status
  • Annually, following the final CMMC status date, and
  • Following a POA&M closeout assessment, as applicable.

DoW uses these affirmations, together with SPRS scores, in evaluating a contractor’s continued compliance with CMMC solicitation and contract requirements. A “current” affirmation is a prerequisite to contract award and the exercise of contract options under DFARS 252.204-7021.

Even with the CMMC requirement, DFARS 252.204-7020(d) requires self-reporting in SPRS of the extent of a contractor’s compliance with the cybersecurity controls in NIST SP 800-171. While FAR 52.204-21 does not contain an express affirmation or reporting, it requires compliance with the listed controls.

FCA exposure

CMMC and DFARS cybersecurity certifications, including annual affirmations and SPRS self-assessment scores, function as legal certifications. When a contractor certifies compliance with DFARS 252.204-7012 or CMMC requirements as a condition of contract eligibility or payment, and that certification is false, the contractor may be exposed to liability under the FCA, 31 U.S.C. § 3729.

A false certification made when it was known to be false, or made with reckless disregard for its truth, may result in treble damages, per-claim civil penalties, and qui tam actions brought by private whistleblowers (i.e., relators), who may recover 15–25 percent of any resulting proceeds. Contract requirements that do not expressly require a certification, such as FAR 52.204-21, may also be relevant to FCA risk if non-compliance is deemed material and was knowing or reckless.

In October 2021, the Department of Justice (DOJ) announced its Civil Cyber-Fraud Initiative, which uses the FCA as a primary enforcement tool against government contractors and grantees that fail to meet cybersecurity obligations. The initiative addresses:

  • Knowing failures to comply with cybersecurity standards
  • Knowing misrepresentations of security practices or protocols and
  • Knowing failures to report cyber incidents.

Since then, DOJ has continued to identify cybersecurity compliance as an FCA enforcement priority. In January 2026, DOJ announced that it recovered USD 52 million through nine cybersecurity-related FCA settlements in the fiscal year ending September 2025, and that civil cybersecurity fraud settlements have more than tripled in each of the past two years. A number of these matters involved contractors’ failures to implement the NIST SP 800-171 cybersecurity controls. These matters arose before CMMC certification requirements took effect.

The Phase 2 suspension

The DoW has established a CMMC Reform Task Force, which will review industry feedback from a public request for information and deliver a report to the DoW Chief Information Officer (CIO) within 60 days, including recommendations on scalable security measures.

The suspension only pauses the third-party and government-led certification assessment mechanisms for Level 2 and Level 3. It does not pause or excuse the underlying cybersecurity obligations, and the federal government may still include CMMC Level 1 or Level 2 self-assessment requirements in solicitations and contracts. In other words, FAR 52.204-21 and DFARS 252.204-7012 and the underlying NIST SP 800-171 Rev. 2 control requirements remain unchanged.

Because independent, third-party verification of Level 2 and Level 3 compliance is paused, the accuracy of contractor self-assessments and affirmations submitted to SPRS may receive increased attention during the suspension period. Contractors are not currently required to obtain an independent C3PAO or DIBCAC assessment to identify or excuse gaps. As a result, the suspension may increase practical attention on the accuracy of self-assessments and affirmations.

Practical implications

The suspension of CMMC Phase 2 raises contracting considerations and highlights the self-assessment and affirmation obligations that remain in place. Contractors and subcontractors may wish to consider the following implications:

  • Review solicitations and existing contracts for Level 2 (C3PAO) or Level 3 (DIBCAC) requirements. Contractors responding to active solicitations or performing under existing contracts that designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments may wish to seek clarification from the contracting officer regarding the impact of the CMMC suspension. Contractors may wish to confirm that a pending third-party certification requirement has been automatically waived absent such action.

  • Evaluate affirmations as legal certifications. Because affirmations submitted in SPRS are the primary compliance touchpoint, contractors may wish to ensure that the designated affirming official reviews the organization’s compliance posture before submitting or renewing an affirmation, rather than treating the submission as a routine administrative task.

  • Consider third-party internal gap assessments before affirming. Although an independent assessment is not required at this time, contractors may wish to consider retaining a third party to assess the company’s compliance with applicable cybersecurity requirements prior to submitting an affirmation. Such an assessment may help confirm that the self-assessment score reported to SPRS accurately reflects the organization’s actual implementation status. Contractors may wish to consult counsel regarding whether and how privilege may apply to such assessments.

  • Document remediation through POA&Ms. Where gaps are identified, contractors may wish to document remediation efforts through a POA&M and track closeout, consistent with the affirmation obligations that apply following a POA&M closeout assessment.

  • Maintain SPRS reporting and Phase 1 self-assessment discipline. Level 1 and Level 2 self-assessment and SPRS reporting obligations continue during the suspension. Contractors remain subject to DoW enforcement obligations, and inaccurate certifications, attestations, or other representations may present FCA risk where applicable legal standards are met.

  • Monitor for changes affecting the continued accuracy of an affirmation. Because an affirmation attests to ongoing compliance, contractors may wish to consider establishing internal processes to monitor for events (e.g., personnel departures, system migrations, or the addition of new subcontractors) that could affect whether a previously submitted affirmation remains accurate.

  • Track the CMMC Reform Task Force’s 60-day review. Contractors may wish to monitor guidance from the CMMC Reform Task Force and the DoW CIO, as the Reform Task Force’s report and any resulting policy changes may affect the scope, timing, or design of the Phase 2 certification requirements. Contractors may also consider providing feedback for any DoW requests for public comment.

Conclusion

DoW’s suspension of CMMC Phase 2 requirements means defense contractors are not currently required to obtain mandatory third-party or government-led certification assessments for CMMC Level 2 and Level 3. The suspension does not, however, relieve contractors of their underlying cybersecurity obligations under FAR 52.204-21 and DFARS 252.204-7012, nor does it pause the self-assessment, SPRS reporting, or annual affirmation requirements.

The suspension may increase the practical and legal significance of those remaining obligations, since self-assessments and affirmations are now the primary mechanism through which the federal government – and qui tam relators – will evaluate contractor compliance.

FCA exposure could have financial consequences, particularly for small- and mid-sized contractors. Under the FCA, contractors may face criminal and civil liability, including civil penalties for each false claim and treble damages. In some circumstances, cybersecurity non-compliance or false statements may also create additional legal, contractual, or suspension-and-debarment risks.

Learn more

DLA Piper will continue to monitor these developments. For more information, please contact the authors or your DLA Piper relationship attorney.