Question we hear weekly · Updated August 2026
Short answer: the CMMC Level 2 pause means fewer scheduled assessments — not fewer obligations. Your DFARS clauses are still in force, your SPRS self-assessment is still a certification to the U.S. Government, and the DOJ fined a contractor $507,144 in June 2026 over exactly this scenario. Here is what “paused” actually changes, and what it absolutely does not.
What the pause changed
The CMMC program’s Phase 2 rollout — the wave of mandatory third-party (C3PAO) assessments — has shifted. Fewer contracts are inserting the CMMC clause on the original timeline, and many contractors have concluded their certification deadline moved comfortably into the future. On the narrow question of when a C3PAO shows up, that is true. Our CMMC pause explainer covers the timeline in detail.
What the pause did NOT change
- DFARS 252.204-7012 — you must implement all 110 NIST SP 800-171 controls. In force since 2017. Still in your contract.
- DFARS 252.204-7019 — you must have a current SPRS score from the official methodology before award. Still required.
- DFARS 252.204-7020 — the government may come and assess your environment itself. This is the clause that produced the −170.
- The False Claims Act — treble damages, roughly $14,000–$28,000 per invoice in penalties, and a 15–30% bounty for any insider who reports you. Never paused, never will be.
The LOGZONE lesson: self-assessment does not mean unassessed
LOGZONE Inc., a Huntsville, Alabama contractor, self-assessed and kept billing two Navy contracts. Then DCMA exercised its 7020 rights and scored the environment at −170 on the −203-to-110 scale. Result: a $507,144 False Claims Act settlement announced in June 2026 — during the pause. Georgia Tech Research Corp. paid $875,000 in October 2025 over false 7019/7020 scores. The government does not need CMMC to audit you; it has had the authority all along.
“But nobody will ever know our real score”
Somebody already does. Your system administrator, your MSP, the engineer who wrote the POA&M, the compliance manager who left in March — each of them can file a qui tam suit and keep 15–30% of what the government recovers. The Aerojet Rocketdyne whistleblower collected $2.61 million. Retaliation is separately unlawful. In practice, your own org chart is the audit function — see the full list of cybersecurity FCA settlements for how often insiders started the case.
The honest path costs less than the optimistic one
Here is the asymmetry most contractors miss: an honest low score is legal; an inflated high score is a federal case. The defensible position during the pause is (1) a real SPRS score you can evidence, (2) an SSP that describes your actual environment, and (3) a dated, funded POA&M. That posture also puts you first in line when assessments resume — while competitors fight for scarce C3PAO slots with programs they have to build from zero. A well-scoped enclave gets there for a fraction of what most US consultancies quote; our Virginia enclave case study shows the approach at ~$5,000 where the incumbent quoted $20,000.
FAQ
Can I just do a CMMC self-assessment while the program is paused?
You can and must keep your SPRS self-assessment current — but it has to be accurate. The self-assessment is a certification under DFARS 7019, and knowingly inflating it is False Claims Act exposure. “Self-assessed” is not a lower standard; it is the same 110 controls with your signature on the number.
Who actually checks my self-assessed SPRS score?
DCMA’s DIBCAC can assess you under DFARS 7020, primes increasingly verify their subcontractors, and any insider can trigger a DOJ investigation via a qui tam filing. LOGZONE was checked by DCMA; Penn State and Aerojet were reported from inside.
What should I do first if my score is probably wrong?
Re-score honestly under the official methodology (our free SPRS calculator uses the exact weights), correct SPRS, build the POA&M, then remediate the 5-point controls first. Correcting a score proactively is dramatically safer than defending one — the Aero Turbine settlement was reduced specifically for voluntary disclosure.
Next: every cybersecurity FCA settlement 2022–2026 · the full enforcement briefing · the CMMC compliance checklist
Is your SPRS score defensible — or just optimistic?
Free CMMC Level 2 gap assessment: we score your environment the way DCMA would, show you the evidence gaps, and give you a fixed-fee remediation plan. Confidential, senior-led, no obligation.