
The suspension of CMMC Phase II has led some defense contractors to believe they can safely pause their compliance efforts. However, the suspension did not eliminate the cybersecurity requirements that already apply to organizations handling Controlled Unclassified Information (CUI).
It also did not relieve contractors of responsibility for the accuracy of their self-assessments and Supplier Performance Risk System (SPRS) scores.
In fact, relying more heavily on self-assessments may increase the risk for contractors that report compliance without having the controls, documentation and evidence to support their claims.
What Did the Phase II Suspension Change?
The Department suspended the transition to CMMC Phase II, which had been scheduled for November 10, 2026, while it conducts a 60-day review of the program.
During the suspension, Department program managers and requiring activities may include CMMC Level 1 or Level 2 self-assessment requirements in procurement documents. They may not designate Level 2 C3PAO assessments or Level 3 government assessments as procurement requirements during the review period.
However, several important responsibilities remain:
- Phase I self-assessment requirements remain in place.
- Applicable NIST SP 800-171 requirements continue to apply.
- DFARS 252.204-7012 cybersecurity and incident-reporting requirements remain in effect.
- Contractors must continue to submit accurate and supportable SPRS scores when required.
- Additional cybersecurity requirements may appear in solicitations and contracts when permitted by law and regulation.
The suspension changes which CMMC assessments may currently be required in Department procurements. It does not suspend the contractor’s responsibility to comply with existing contractual cybersecurity requirements.
Can Contractors Still Obtain CMMC Certification?
Yes. C3PAOs can continue performing Level 2 assessments for organizations that voluntarily choose to proceed.
What has been suspended is the use of CMMC Level 2 C3PAO certification as a procurement requirement during the review period. The assessment process itself has not been eliminated.
Some organizations may decide to continue pursuing certification because of customer expectations, their contract pipeline or the possibility that third-party certification requirements will return after the review. Others may focus on closing gaps and strengthening their readiness before scheduling an assessment.
Either way, putting all compliance activity on hold could be a costly gamble.
Your SPRS Score Must Reflect Reality
An SPRS score is not simply a number entered to satisfy an administrative requirement. It represents an organization’s implementation of the applicable NIST SP 800-171 security requirements.
Some RFPs and contracts may require contractors to have a particular SPRS score, including a perfect score of 110. When eligibility for a contract depends on a self-reported score, organizations may feel pressure to report that they have implemented more than they can support.
However, every claimed control should be reflected in the organization’s actual environment and supported by appropriate documentation and evidence.
A contractor reporting a score of 110 should be able to demonstrate that all applicable requirements included in the assessment have been fully implemented. Policies copied from a template, planned improvements or controls that are only partially operational do not support a claim of full implementation.
If a contractor’s reported score does not accurately reflect its cybersecurity posture, the organization may face contractual consequences and potential exposure under the False Claims Act.
The LOGZONE Settlement Provides a Timely Warning
A recent Department of Justice settlement demonstrates how serious unsupported cybersecurity representations can become.
In June 2026, Alabama defense contractor LOGZONE Inc. agreed to pay $507,144 to resolve False Claims Act allegations related to cybersecurity requirements in two Department of the Navy contracts.
According to the settlement agreement, LOGZONE submitted a perfect SPRS self-assessment score of 110 in October 2021. A subsequent Defense Industrial Base Cybersecurity Assessment Center assessment resulted in a score of -170.
The government alleged that LOGZONE had not fully implemented certain NIST SP 800-171 controls while submitting claims for payment under contracts containing applicable DFARS cybersecurity requirements.
The settlement resolved allegations only, and there was no determination of liability. Nevertheless, the case provides an important warning for other defense contractors: cybersecurity claims must be accurate, defensible and consistent with the organization’s actual practices.
Additional details are available in the Department of Justice announcement.
Why Self-Assessment Can Increase Contractor Risk
Third-party certification provides an external review of an organization’s compliance posture. When procurement eligibility relies instead on a contractor’s own assessment, responsibility for the accuracy of that assessment rests heavily with the contractor.
That creates several potential risks:
- Overestimating the implementation of security requirements
- Counting planned controls as fully implemented
- Submitting a score that conflicts with the System Security Plan
- Relying on policies that do not reflect actual business practices
- Lacking evidence that controls operate as described
- Failing to update the assessment after systems or practices change
- Treating a consultant’s recommendations as proof of implementation
An inaccurate score does not become defensible simply because the organization misunderstood a requirement or felt pressure to qualify for a contract.
Contractors should be able to explain how they calculated their scores and produce evidence supporting each claimed implementation.
What Should Defense Contractors Do Now?
The suspension gives contractors an opportunity to validate their compliance position before the next stage of CMMC implementation becomes clear.
Organizations should use this period to:
- Review their SPRS score. Confirm that the score accurately reflects the controls currently implemented.
- Validate the System Security Plan. Make sure the SSP describes the actual systems, boundaries, responsibilities and security practices used by the organization.
- Evaluate control implementation. Determine whether each claimed requirement is fully operational, partially implemented or still planned.
- Organize supporting evidence. Collect policies, procedures, configurations, logs, training records and other materials that substantiate compliance claims.
- Address identified gaps. Create and follow a realistic remediation plan for incomplete or ineffective controls.
- Monitor contract requirements. Review active contracts, upcoming RFPs and communications from prime contractors for applicable cybersecurity and SPRS requirements.
- Consider assessment readiness. Evaluate whether voluntarily moving forward with a C3PAO assessment makes sense based on the organization’s readiness and business objectives.
Can Your Organization Defend Its SPRS Score?
The Phase II suspension may change the immediate certification timeline, but it does not make unsupported cybersecurity claims less serious.
SME can help your organization validate its NIST SP 800-171 implementation, review the accuracy of its SPRS score, identify compliance gaps and strengthen the documentation and evidence supporting its assessment.
Do not wait for a government or third-party assessment to discover that your reported score cannot be defended.



