If you’ve been waiting to sort out your cybersecurity compliance because CMMC is on hold, this is the article worth reading before 2027.

The pause is real. Phase II requirements, the third-party assessments by certified C3PAO organizations, are now suspended by binding acquisition regulation, not just an administrative memo. A class deviation signed September 3, 2026 directs contracting officers to strip those requirements out of contracts. For the duration of the suspension, you won’t be required to pass a third-party CMMC assessment to win or keep a defense contract.

That’s genuinely good news. But what the pause suspended is narrower than many contractors assume. The obligations that remain are the ones with active enforcement behind them.

How we got here

On July 13, 2026, the Department of Defense suspended CMMC Phase II requirements and announced a 60-day review of the program. The suspension was real but administratively fragile: a memo can be reversed with another memo.

On September 3, 2026, DoD issued Class Deviation 2026-O0025, Revision 3, signed by John Tenaglia, the Department’s Principal Director for Defense Pricing, Contracting, and Acquisition Policy. That document converted the suspension into binding acquisition regulation. Contracting officers are now required to remove CMMC Phase II clauses from contracts. Undoing this takes a formal regulatory process through DFARS rulemaking.

A DoD task force is conducting the broader review; its report was due around September 11, 2026. As of this writing, that report has not been made public, and there is no announced timeline for when, or whether, Phase II requirements will be reinstated. We’re watching and will update this page when the picture clarifies.

What the pause did not suspend

DFARS 252.204-7012 — the clause requiring contractors to implement NIST SP 800-171 and self-report their compliance score in the Supplier Performance Risk System (SPRS) — is still in your contracts. It was in contracts before CMMC Phase II existed, and it’s there now.

Your SPRS score is self-reported: you submit it, the government accepts it, and the government reserves the right to audit it.

DIBCAC, the Defense Industrial Base Cybersecurity Assessment Center, conducts those audits. DIBCAC assessments are ongoing and unaffected by the CMMC pause. If DIBCAC audits your organization and finds that your reported score doesn’t match reality, that gap is not a compliance issue. It’s a False Claims Act issue. As a smaller manufacturer, you’re probably not DIBCAC’s first call, but your SPRS score is still a legal attestation and the FCA doesn’t require an audit to bite you.

Why that distinction matters: the LOGZONE case

In June 2026, the Department of Justice announced a settlement with LOGZONE Inc., an Alabama defense contractor, for $507,144, resolving False Claims Act liability for cybersecurity deficiencies on Navy contracts.

The details are worth sitting with. LOGZONE self-assessed their NIST 800-171 compliance in 2021 and submitted a score of 110 to SPRS. That’s a perfect score saying every control is fully implemented. When DIBCAC conducted its own assessment, they scored LOGZONE at -170 out of a possible -203.

The CMMC pause did not create a safe harbor for SPRS scores. If your self-assessed score and your actual control implementation are materially different, the FCA exposure is the same in September 2026 as it was in September 2025.

What this means for small manufacturers going into 2027

Whatever the task force recommends, some obligations haven’t moved:

You are still contractually required to implement NIST 800-171. The controls in that framework (access control, incident response, configuration management, audit and accountability, and the rest) are in your DFARS clause, not in the CMMC rule. The pause didn’t touch them.

Your SPRS score is still a legal attestation. When you submit or maintain a score in SPRS, you are representing to the government that the score accurately reflects your implementation. The LOGZONE case confirmed what attorneys have been saying for years: an inflated score isn’t optimistic self-assessment, it’s a potential FCA claim.

DIBCAC audits still happen. They’re not random. DIBCAC tends to focus on contractors with larger dollar values, elevated risk profiles, or prior compliance concerns. If your organization is at a point where a DIBCAC audit is plausible, your SPRS score should reflect reality, not aspiration.

The practical question for any small manufacturer with defense contracts right now: does your SPRS score accurately represent where you are? Not where you’re planning to be, not where you were before the last configuration change: where you are today.

If the honest answer is “probably not” or “we’re not sure,” that’s the problem worth solving before Phase II requirements return, before a DIBCAC audit surfaces, and before a competitor or attorney decides to look more closely.

What to do now

Know your actual SPRS score. Run or update your NIST 800-171 self-assessment against your current environment, not the environment from two years ago. Systems change, staff change, configurations drift. The score you submitted may not reflect where you stand today.

Document what you’ve implemented and what you haven’t. NIST 800-171 has 110 controls. Most smaller manufacturers aren’t fully compliant, and that’s not automatically disqualifying — what matters is that your score reflects reality and that you have a plan of action for gaps. A documented Plan of Action and Milestones (POA&M) demonstrates that you know where you are and you’re moving toward where you need to be.

Don’t treat the pause as a runway to stop moving. The organizations that use this period to genuinely improve their NIST 800-171 posture, not just their score, will be better positioned when Phase II requirements return. The ones that interpret the pause as permission to deprioritize are setting themselves up for a harder conversation later.

This is work OrbitalFire does regularly with smaller manufacturers: helping you run an accurate NIST 800-171 self-assessment, build a realistic POA&M for the gaps, and get your SPRS score to a place that reflects where you actually are. If that’s useful, we’d welcome the conversation. Reach out and connect with us.

If you’re looking for a structured starting point on your own, the Small Business Cybersecurity Readiness Checklist  is a good first step. 

Frequently Asked Questions

Is CMMC Phase 2 still paused?
Yes. A class deviation signed September 3, 2026 (Class Deviation 2026-O0025, Revision 3) converted the July 13 suspension into binding acquisition regulation. Contracting officers are directed to remove CMMC Phase II third-party assessment requirements from contracts. This stays in effect until it is formally rescinded.

Do defense contractors still have to comply with NIST 800-171 while CMMC is paused?
Yes. The CMMC pause suspended third-party assessment (C3PAO) requirements only. NIST SP 800-171 compliance and self-attestation in the Supplier Performance Risk System (SPRS) remain contractual requirements under DFARS 252.204-7012. The obligation to actually implement the controls — and accurately report your score — has not changed.

Can a defense contractor get in legal trouble for their SPRS score during the CMMC pause?
Yes. The False Claims Act applies to self-attestations regardless of the CMMC pause. In June 2026, LOGZONE Inc. settled a Department of Justice FCA case for $507,144 after self-reporting a perfect SPRS score of 110 while a DIBCAC audit found their actual score was -170.

What is a DIBCAC assessment and is it affected by the CMMC pause?
The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) is a DoD audit function that independently verifies contractor cybersecurity compliance. DIBCAC assessments are unaffected by the CMMC pause: they continue, and DOJ can and does use DIBCAC audit data to build False Claims Act cases.

When will CMMC Phase 2 requirements come back?
Unknown. A DoD task force is reviewing the CMMC program; its report was due around September 11, 2026, but has not been made public. Any changes to the program will require regulatory action through the standard DFARS rulemaking process. There is no announced timeline for resuming Phase II requirements.