Contractors handling CUI have been required to meet all 110 NIST 800-171 controls since 2017. For years, enforcement was light and many companies waited, but that period is over.
CMMC Phase 2 is paused. The requirements underneath it are not.
On July 13, 2026, the Department of War (DoW) suspended CMMC Phase 2 and launched a 60-day review. DoW CIO Kirsten Davies was direct about the reason: “We are not reducing cybersecurity through this measure. We are reducing the red tape.”
As Thomas Graham, a Lead CMMC Assessor at Redspin, stated:
All that’s been paused is the third-party validation component. That’s it. Implementation is still there. Self-assessments are still there. The CMMC program itself is still there.
To this point, on Sep 3, 2026, the government confirmed that contracting officers can only require Level 1 or Level 2 self-assessments.
That doesn’t mean the rules got softer. NIST 800-171, DFARS 252.204-7012, and Prime flowdown obligations still apply, and you still have to submit an honest score in SPRS. If anything, the lack of outside verification raises the stakes: with no third party catching your mistakes, an inflated or careless score is now entirely on you to defend.
But don’t just take our word for it. Here are 4 reasons to get compliant, directly from the experts.
1. Primes are still requiring compliance
Prime contractors aren’t waiting for the government; They are responsible for the security of their supply chains, and they are already cutting subcontractors who can’t show progress.
Lockheed Martin made this explicit. In its June 30, 2025 supplier announcement, they stated:
By now, all DIB companies managing CUI should have fully implemented and be confidently meeting NIST SP 800-171 (r2) requirements.
CISOs at other major primes said the same thing at PreVeil’s CMMC Summit. JR Williamson, CISO at Leidos, emphasized:
We may have a really great supplier with a perfect solution, but if they’re not certified and won’t be for another 12-15 months, we just can’t use them.
The primes aren’t only applying pressure. They are also helping. As Williamson described the effort to bring suppliers along, “there’s a lot of hugging going on to help folks get there.” But the message is consistent: demonstrate CMMC readiness or lose your place in the supply chain.
2. Level 2 self-certification is how you win new business
Travis Goldbach, VP at the C3PAO CoalFire Federal, confirmed that:
DFARS says that contracting officers still need to check their SPRS to confirm an active status
Katie Arrington, who ran CMMC’s rollout as the Pentagon’s chief information officer before leaving for private industry, has made the case herself:
CMMC is a business enabler, not a business hindrance. Why wouldn’t you want to say, I’m CMMC Level 2 certified?
Outside counsel are telling clients the same thing. Michael Gruden, a partner at Crowell & Moring, has advised contractors that if they handle CUI,
You really need to have that certification, or it’s likely you’re going to miss out on future business opportunities, either directly from the government or within the defense industrial base supply chain.
Some RFPs already use Level 2 certification as a pass/fail gate but increasingly it’s a differentiator that you can put in front of a prime or a contracting officer who’s choosing between you and a competitor.
3. Non-compliance is now a False Claims Act problem
When you certify an SPRS score you can’t back up, you aren’t just out of compliance; You may be making a false claim to the government. The DOJ’s Civil Cyber-Fraud Initiative, launched in 2021, uses the False Claims Act to hold contractors accountable for cybersecurity misrepresentations. The False Claims Act recovered $52 million in 2025 and has produced at least 14 settlements to date.
The June 2026 LOGZONE case shows how this plays out. The Huntsville, Alabama contractor agreed to pay $507,144 to resolve allegations that it submitted false claims on two Navy contracts while failing to implement required NIST SP 800-171 controls. When the government’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assessed its implementation, LOGZONE scored -170 on a scale that runs from -203 to 110.
What makes LOGZONE notable is how it surfaced. Most earlier Civil Cyber-Fraud cases started with a whistleblower. This one came out of a DIBCAC assessment. As Assistant Attorney General Brett Shumate said:
Government contractors that obtain sensitive defense information in administering their contracts must follow required cybersecurity standards. The Justice Department will continue to investigate potential violations of these cybersecurity requirements in order to protect this critical information from external threats.
LOGZONE is one of a growing list. Recent cybersecurity False Claims Act settlements include Raytheon and Nightwing Group at $8.4 million, MORSECORP at $4.6 million, Penn State at $1.25 million, and Georgia Tech Research Corp at $875,000. The penalties dwarf the cost of getting compliant in the first place. LOGZONE’s $507,144 settlement was most of the value of the contract it won.
The late cyber attorney, Robert Metzger, framed the exposure simply in PreVeil’s webinar on the legal risks of non-compliance:
The smart move is to protect yourself. Now. Not because you have to comply but because you want your enterprise to stay in business.
4. The DoW can assess you at any time
Under 252.240-7020, the DoW reserves the right to conduct Medium and High assessments of a contractor’s NIST SP 800-171 implementation based on the criticality of the contract or the data involved. The LOGZONE case shows an assessment can become an enforcement action.
Metzger’s point from the same webinar cuts through the temptation to wait for CMMC to become fully mandatory:
CMMC is beside the point for the present obligation to comply. If you have Controlled Unclassified Information, you are in possession of information which the government has concluded that law or regulation require you to protect.
You don’t control when the assessment comes. You only control whether you’re ready for it.
Achieve CMMC with PreVeil
Trusted by thousands of defense contractors, PreVeil is the leading CMMC solution for small and midsize businesses- validated in over 100 CMMC L2 assessments. It includes end-to-end encrypted email + file sharing to protect CUI, pre-filled, assessment-ready documentation, and a network of preferred MSPs, consultants and assessors. The result: contractors save up to 75% compared to legacy solutions like GCC High and get to certification faster.
Don’t wait for the RFP, the option year, the prime’s email, or DIBCAC requesting an assessment. Schedule a free 15-minute call with our compliance team.