The July 13th DoW Announcement
On July 13, 2026, the DoW announced a temporary pause of CMMC Phase II third-party certification requirements while conducting a comprehensive 60-day review of the CMMC program. The review determines whether CMMC program changes can reduce costs, improve efficiency, and better support the Defense Industrial Base without compromising cybersecurity.
The July 13th SBA Announcement
The SBA issued a coordinated CMMC review press release. Of particular interest, the SBA noted that approximately 120K defense contractors may require CMMC certification, but today there are only 100 approved C3PAOs. David highlighted that simple math says there is almost zero chance of 120K contractors being assessed by 100 (or 200 or 300) C3PAOs by the end of Phase IV (i.e., in 3 years) of the CMMC’s introduction.
DoW’s July 13th Request for CMMC Information
The DoW also issued an RFI seeking industry feedback before determining the future direction of the CMMC program. The RFI has seven questions
- Compliance Costs and Burden - What are the biggest cost, administrative, and operational challenges of achieving and maintaining CMMC compliance?
- Cybersecurity Value vs. Compliance Burden - Which CMMC/NIST controls provide the greatest real-world cybersecurity benefit, and which create the most burden with the least security value?
- Assessment, Commercial Solutions, and Compliance Modernization - How can self-assessments, commercial cybersecurity solutions, and compliance processes be streamlined to improve efficiency while maintaining assurance?
- Policy and Regulatory Reform - What specific policy or regulatory changes should the CMMC Reform Task Force recommend reducing compliance costs and improve cybersecurity resilience?
What Was Not Paused?
Although the DoW paused Phase II’s introduction, the DoW specifically indicated that all Phase I self-assessment requirements remain firmly in-place. This includes maintain compliance with NIST SP 800-171 Rev. 2 under DFARS 252.204-7012, maintain a current System Security Plan (SSP) documenting all 320 Assessment Objectives (AOs), complete required CMMC Level 1 or Level 2 self-assessments, and preserve evidence demonstrating that required security controls are implemented. These obligations continue throughout the review period and remain essential for protecting CUI.
Key reminders
|
|
Your SPRS Submission & New False Claims Act Warning
One of the webinar's most significant takeaways was the updated SPRS submission process. Previously, organizations could submit a new SPRS score by completing the required information and selecting Submit. The new CMMC Level 2 Self-Assessment process now requires organizations to acknowledge a warning stating that any misrepresentation of their cybersecurity compliance status may result in criminal prosecution or civil liability under the False Claims Act.
This is one of the most significant changes to the CMMC program because, by acknowledging the warning, organizations are formally affirming that their SPRS score is accurate. He also referenced the June 18, 2026, Department of Justice settlement with LogZone, Inc., which agreed to pay $508,000 to resolve allegations related to inaccurate SPRS submissions. The example reinforces the importance of ensuring that SPRS submissions accurately reflect an organization's cybersecurity implementation and supporting documentation.
Why Accurate Affirmations Matter (False Claims Act / LogZone)
It was emphasized that inaccurate SPRS representations can expose organizations to significant legal and financial risk. The webinar highlighted the recent LogZone, Inc. enforcement where they claimed a SPRS score of 110, while the Government found their actual score to be a minus 173. This resulted in a $508,000 settlement, demonstrating why accurate self-assessments, documentation, and executive affirmations are essential.
SecureITSM Recommendation
Do not pause your cybersecurity program. Continue strengthening your security posture, validating implementation of NIST SP 800-171 controls, maintaining current documentation, and ensuring SPRS submissions accurately represent your organization's compliance status.
Questions about your SPRS submission or cybersecurity compliance program?
Whether you're reviewing your SPRS submission, strengthening your NIST SP 800-171 implementation, or planning your next steps toward CMMC readiness, our team is happy to answer your questions and provide practical guidance.
Contact SecureITSM to speak with a CMMC expert.