NetCov Resources

The CMMC Pause Made Self-Attestation More Dangerous

Written by Nicolas Morris | Aug 19, 2026, 2:09:14 PM

When the Department of Defense announced the CMMC Phase II pause on July 13, 2026, many defense contractors interpreted it as a moment to relax. The deadline was gone. The assessments were postponed. The pressure was off.

Now that we are about a month into this pause, it’s important to understand that interpretation is dangerously wrong, especially when it comes to self-attestation and False Claims Act exposure. The pause didn’t make compliance easier. It made the legal risk of inaccuracy much higher.

The Self-Attestation Problem No One Is Talking About

Here’s what’s happening right now, as CMMC Phase II requirements are paused. Defense contractors are still:

  • Required to maintain accurate SPRS (System for Award Management Representation) scores

  • Bound by DFARS 252.204-7012 to protect CUI

  • Obligated to implement NIST SP 800-171 controls

But for the 60 days during the pause (or longer), they aren’t required to do it with third-party verification. No C3PAO assessments, external auditors verifying their systems, or independent eyes catching gaps, misconfigurations, or inaccuracies in their compliance posture.

Meanwhile, the government is increasingly reliant on contractor self-attestation to maintain visibility into cybersecurity compliance across the defense supply chain. With third-party assessments paused, the government has limited ability to verify what contractors are claiming. This creates a unique legal window, and it’s opening right now.

False Claims Act Exposure

Most defense contractors understand that CMMC compliance is contractually required. Fewer understand that misrepresenting your compliance status can expose your firm to False Claims Act (FCA) liability.

The False Claims Act allows the government to recover treble damages plus penalties when a contractor knowingly submits false claims, which includes false certifications about compliance with contract requirements.

In 2022, Aerojet Rocketdyne settled an FCA case for $9 million over CUI security failures. Similarly, in 2024, Penn State University agreed to pay $1.25 million after violating the False Claims Act by failing to comply with cybersecurity requirements in fifteen contracts or subcontracts involving the DoD or NASA. Both cases centered on false or incomplete representations about security compliance.

The government doesn’t have to prove intentional fraud. The FCA standard is “knowing or with reckless disregard.” That means a contractor who knowingly submits inaccurate SPRS scores or who claims to have implemented controls that are actually incomplete can face FCA liability, even without deliberate deception.

During normal times, this risk is mitigated by regular third-party assessments. Assessors catch gaps. Contractors remediate. The government gets reasonable assurance that compliance claims are accurate.

During the pause, that mitigation is gone.

Why the Pause Makes This Worse

With CMMC Phase II requirements on hold, contractors have no external verification mechanism for their compliance claims. The gap between “what we claim to have” and “what we actually have” can grow unchecked, both intentionally and unintentionally.

Consider a typical scenario:

A contractor maintains a current SPRS score claiming 800-171 implementation across their CUI environment. They passed their last assessment three months ago. The pause is announced. Third-party assessment requirements disappear. The contractor’s compliance team shifts to lower priority work. Over the next 90 days, staff turnover, configuration drift, incomplete patching, or process gaps create vulnerabilities. The contractor still maintains their SPRS score that’s unchanged from the last assessment.

Six months later, if Phase II resumes or when a government audit occurs, the gap becomes visible. The contractor’s current compliance posture doesn’t match their SPRS attestation. They’re now in a position where they’ve been claiming compliance they didn’t actually have. That’s FCA exposure.

The AEC Industry Angle

For architecture, engineering, and construction firms, this risk is even more complex.

AEC firms often operate across federal and commercial projects on overlapping systems. They use shared BIM platforms. They work through joint ventures with multiple parties. They have transient labor on job sites accessing sensitive project data. Their CUI boundaries are rarely clean or simple.

During normal assessment periods, a C3PAO would identify these complexities and ensure that contractors document them accurately. With assessments paused, AEC firms have no external verification of how well their controls actually match their claimed CUI protections. The disconnect between what they claim and what they have can grow larger, undetected.

When verification resumes, the exposure comes due.

Long Story, Short

The CMMC pause paused the assessment timeline. It did not pause your compliance obligations. It did not eliminate False Claims Act exposure. It did not reduce the legal risk of maintaining inaccurate SPRS scores or incomplete control documentation.

What it did do: it removed the external verification mechanism that normally catches these gaps.

That combination, ongoing obligations without external verification, is what makes self-attestation more dangerous right now, not less.

Contractors that use this window to audit their actual compliance posture, document it accurately, and keep foundational security work on track will be protected if and when Phase II resumes, and a government-funded evaluation occurs. Those that treat the pause as permission to ease off will be exposed.

The False Claims Act, your legal risk, and your obligation to maintain accurate compliance representations doesn’t pause.  

Looking For More Information?

Download our ebook that was made specifically for AEC firms trying to navigate this pause.