cmmctrade-pressNewsThe Broadside2 min read

CMMC self-attestation during Phase Two freeze carries FCA risk

Annual compliance affirmations without documented evidence of continuous monitoring could face False Claims Act scrutiny if a breach later exposes control gaps, and the July suspension of third-party assessments extends the window.


TL;DR

DoD's July 13 suspension of Phase Two CMMC mandatory third-party assessments has extended the period in which contractors rely on self-attestation. While the department conducts its 60-day review, Phase One self-assessment requirements remain in force. For contractors handling CUI at Level 2, that means senior officials continue signing annual compliance affirmations under DFARS 252.204-7021. The less-visible risk: if a cyber incident later triggers an investigation and documented evidence of continuous control monitoring isn't there, those affirmations can face FCA scrutiny. The Civil Cyber-Fraud Initiative has already yielded settlements where contractors allegedly misrepresented their implementation of NIST SP 800-171 controls.

The timeline matters because it's the gap between what a contractor affirms and what it can prove that creates the exposure.

Phase Two was scheduled to expand mandatory C3PAO assessments across a broader range of contracts starting November 10, 2026. DoD put that on hold (effectively immediately) on July 13, with a 60-day review window. The suspension doesn't touch Phase One. Self-assessments continue. And for most contractors handling CUI, that means the annual senior-official affirmation required under DFARS 252.204-7021 remains the mechanism for representing compliance with all 110 NIST SP 800-171 Rev. 2 controls.

Here's the problem that doesn't pause: security environments shift continuously. Personnel change roles. Systems get patched. Configurations drift. Software gets introduced. Compliance isn't a point-in-time snapshot, maintaining it requires ongoing oversight. If a senior official signs an affirmation of compliance and the organization can't produce evidence that controls were monitored, reviewed, and documented throughout the cycle, that representation may attract scrutiny under the False Claims Act.

What FCA exposure looks like in practice

The Justice Department's Civil Cyber-Fraud Initiative, launched in October 2021, has already pursued settlements where contractors allegedly misrepresented their implementation of required cybersecurity controls. A recent case involved an Alabama-based logistics provider that agreed to pay to resolve allegations that it failed to implement certain NIST SP 800-171 controls over several years despite contractual obligations to do so. The MORSECORP settlement similarly involved allegations that the company's reported cybersecurity posture differed materially from findings later identified through an independent assessment.

These aren't hypotheticals. The FCA carries treble damages plus inflation-adjusted penalties. And because the statute permits qui tam relators (private whistleblowers who can sue on the government's behalf and share in the recovery) enforcement doesn't depend solely on agency action. DOJ logged a record 979 qui tam filings in fiscal 2024 alone, across all sectors.

What doesn't go on pause

The DoD review doesn't relieve contractors of their existing obligations under the FAR and DFARS. As Eric Crusius of Hunton-Andrews-Kurth noted in July, the CMMC program is a certification layer on top of security controls that remain contractually required. The suspension delays independent validation, it doesn't suspend the underlying requirement to implement and maintain those controls.

For the compliance director or CISO reading this: the operational question is whether your organization can produce a continuous record of control effectiveness when asked. That means current system security plans, plans of action and milestones, documented internal audit findings, and evidence that monitoring activities actually occurred between formal assessments. If the answer today is "not confidently," the extended self-attestation window is also an extended exposure window.

Whether DoD's 60-day review results in permanent changes to Phase Two or a resumption of assessments as originally planned, the self-attestation gap won't close retroactively. The affirmations signed during this period will remain on file, and the FCA doesn't have a "the rules were in flux" safe harbor.


Published ·Deep Fathom

CMMC self-attestation during Phase Two freeze carries FCA risk — The Broadside